回复 1# xianjie
问了下度娘,你参考下
以下为批处理
映像劫持法(会被360自动阻止。如已安装360此法不能凑效)
@echo off
echo Windows Registry Editor Version 5.00>>123.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qq.EXE] >>123.reg
echo "Debugger"="禁止启动" >>123.reg
regedit /s 123.reg
del /q 123.reg
建立特殊文件于QQ目录下(此处路径为C:\Progra~1\Tencent\QQ,可以自己稍微改变下)
echo off
copy > 111.txt
echo y|copy nul 111.txt
rename 111.txt ws2_32.dll
move ws2_32.dll C:\Progra~1\Tencent\QQ
以下为vbs
每隔1000毫秒结束1次QQ进程
dim bag,pipe,good
do
good="."
set bag=getobject("winmgmts:\\"&good&"\root\cimv2")
set pipe=bag.execquery("select * from win32_process where name='qq.exe'")
for each i in pipe
i.terminate()
next
wscript.sleep 1000
loop |