核心vbs代码
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
|
'变量定义
Dim writeName,writeValue,fileName,regLoaction,regApp
'创建注册表编辑器对象
Set regApp=WScript.CreateObject( "WScript.Shell" )
'配置文件名
fileName= "FullScan.txt"
'输入键名
writeName= "xiaoqiang"
'输入键值
writeValue= "test"
'************************脚本运行区间********************************
'根据配置文件获取注册表路径数组
regLoaction=getRegPathArray(getFileText(fileName))
'写入注册表
write regLoaction,writeName,writeValue
'读取写入的键值 生成并生成结果文件
read regLoaction,writeName
'************************函数定义********************************
'读注册表
Function read(regLoaction,writeName)
Dim returnStrArray(),j
j=0
If writeName= "" or writeValue= "" then
msgbox "错误!!请输入键名和键值"
else
for i=0 to ubound(regLoaction)
ReDim Preserve returnStrArray(j)
regPath=regLoaction(i)&"\"&writeName
returnStrArray(j)=regPath& "? " ®App.RegRead(regPath)
j=j+1
Next
End if
writeResult returnStrArray
End Function
'写入注册表
Function write(regLoaction,writeName,writeValue)
If writeName= "" or writeValue= "" then
msgbox "错误!!请输入键名和键值"
else
for i=0 to ubound(regLoaction)
regApp.RegWrite regLoaction(i)&"\"&writeName,writeValue
Next
End if
End Function
'输出结果文件
sub writeResult(contentArray)
Const ForReading = 1, ForWriting = 2
Dim fso,f,returnStrArray(),i
Set fso = CreateObject( "Scripting.FileSystemObject" )
Set f = fso.OpenTextFile( "result.txt" , 2,true)
for i=0 to ubound(contentArray)
f.writeline(contentArray(i))
Next
f.close()
End Sub
'得到注册表路径数组
Function getRegPathArray(sourceArray)
Dim head,returnStrArray(),j
j=0
for i=0 to ubound(sourceArray)
If sourceArray(i)= "[HKEY_LOCAL_MACHINE]" then
head= "HKLM"
elseif sourceArray(i)= "[HKEY_USERS]" then
head= "HKEY_USERS\.DEFAULT"
elseif sourceArray(i)= "[HKEY_CURRENT_USER]" then
head= "HKCU"
elseif sourceArray(i)= "[HKEY_CLASSES_ROOT]" then
head= "HKCR"
elseif sourceArray(i)= "[HKEY_CURRENT_CONFIG]" then
head= "HKEY_CURRENT_CONFIG"
else
ReDim Preserve returnStrArray(j)
str=head&split(sourceArray(i), "=" )(1)
returnStrArray(j)=str
j=j+1
End If
Next
getRegPathArray=returnStrArray
End Function
'得到文件内容存入数组
Function getFileText(fileName)
Const ForReading = 1, ForWriting = 2
Dim fso,f,returnStrArray(),i
Set fso = CreateObject( "Scripting.FileSystemObject" )
Set f = fso.OpenTextFile(fileName, 1)
i=0
do while f.atendofstream<>true
ReDim Preserve returnStrArray(i)
returnStrArray(i)=f.readline()
i=i+1
loop
f.close()
getFileText=returnStrArray
End Function
|
//配置文件
FullScan.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
|
[HKEY_LOCAL_MACHINE]
1=\Software\Microsoft\Windows\CurrentVersion\Run
2=\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\
3=\Software\Microsoft\Windows\CurrentVersion\RunOnce\
4=\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce\
5=\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
6=\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell\
7=\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
8=\Software\Policies\Microsoft\Windows\System\Scripts\
[HKEY_CURRENT_USER]
1=\Software\Microsoft\Windows\CurrentVersion\Run
2=\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\
3=\Software\Microsoft\Windows\CurrentVersion\RunOnce\
4=\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce\
5=\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
6=\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell\
7=\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
8=\Software\Policies\Microsoft\Windows\System\Scripts\
|
运行后得到result.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
|
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\xiaoqiang? test
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\\xiaoqiang? test
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\xiaoqiang? test
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce\\xiaoqiang? test
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\xiaoqiang? test
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell\\xiaoqiang? test
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\xiaoqiang? test
HKLM\Software\Policies\Microsoft\Windows\System\Scripts\\xiaoqiang? test
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\xiaoqiang? test
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\\xiaoqiang? test
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\\xiaoqiang? test
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce\\xiaoqiang? test
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\xiaoqiang? test
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell\\xiaoqiang? test
HKCU\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\xiaoqiang? test
HKCU\Software\Policies\Microsoft\Windows\System\Scripts\\xiaoqiang? test
|
注册表中的值
以下是服务器之家小编补充
运行后就会发现在系统开始自动运行的一些启动项加入了如上值,所以不建议普通用户运行。
既然批量添加那么也可以批量删除
将上面的vbs代码中的
regApp.RegWrite regLoaction(i)&"\"&writeName,writeValue
替换为
regApp.RegDelete regLoaction(i)&"\"&writeName
发现直接运行不行,其实注册表的删除需要用管理员权限才可以。
怕有些新手不知道如何管理员权限运行vbs
其实右键cmd中看到 以管理员权限运行 打开 dos窗口,然后将vbs文件拖到这个dos窗口里面,回车运行即可
然后拖拉
回车后发现,并没有提示任何错误信息,从注册表中看到,确定这个字段已经没了。完全解决。