On Error Resume Next
Dim MyArray (231)
MyArray (0) = "Smss.exe"
MyArray (1) = "Csrss.exe"
MyArray (2) = "Winlogon.exe"
MyArray (3) = "Services.exe"
MyArray (4) = "Lsass.exe"
MyArray (5) = "Svchost.exe"
MyArray (6) = "Ccsetmgr.exe"
MyArray (7) = "Ccevtmgr.exe"
MyArray (8) = "Spbbcsvc.exe"
MyArray (9) = "Spoolsv.exe"
MyArray (Ten) = "Repsvc.exe"
MyArray (one) = "Defwatch.exe"
MyArray () = "Dwrcs.exe"
MyArray (+) = "Mdm.exe"
MyArray (+) = "Savroam.exe"
MyArray () = "Rtvscan.exe"
MyArray (+) = "Ccmexec.exe"
MyArray (+) = "Wmiprvse.exe"
MyArray () = "Explorer.exe"
MyArray (+) = "Dwrcst.exe"
MyArray () = "CcApp.exe"
MyArray (+) = "Vptray.exe"
MyArray (+) = "Outlook.exe"
MyArray (+) = "Pcsws.exe"
MyArray = "Ctfmon.exe"
MyArray (+) = "Msmsgs.exe"
MyArray (+) = "Xdict.exe"
MyArray (+) = "Pcscm.exe"
MyArray (+) = "Winword.exe"
MyArray = "Wuauclt.exe"
MyArray (+) = "Rundll32.exe"
MyArray = "Hkcmd.exe"
MyArray (+) = "Excel.exe"
MyArray = "Wisptis.exe"
MyArray = "Wnwb.exe"
MyArray (+) = "Lingoes.exe"
MyArray (+) = "Acs_ln.exe"
MyArray (PNS) = "Hpgs2wnd.exe"
MyArray (+) = "Hpgs2wnf.exe"
MyArray () = "Mnmsrvc.exe"
MyArray (+) = "Conime.exe"
MyArray (+) = "Wzqkpick.exe"
MyArray = "Smax4pnp.exe"
MyArray = "Dntus26.exe"
MyArray (*) = "Wdkeymonitorccb.exe"
MyArray = "Wzcsldr2.exe"
MyArray (+) = "Packone.exe"
MyArray (+) = "Iexplore.exe"
MyArray = "Igfxpers.exe"
MyArray (+) = "Igfxsrvc.exe"
MyArray () = "Jusched.exe"
MyArray (Wuyi) = "Jqs.exe"
MyArray (*) = "Ati2evxx.exe"
MyArray (+) = "Igfxtray.exe"
MyArray (SI) = "Winzip32.exe"
MyArray = "Ravmond.exe"
MyArray (+) = "Inetinfo.exe"
MyArray ($) = "Liveupdate360.exe"
MyArray (+) = "Googlepinyindaemon.exe"
MyArray = "Eyefoo.exe"
MyArray = "360sd.exe"
MyArray (+) = "Googlepinyinservice.exe"
MyArray (+) = "360rp.exe"
MyArray (+) = "Wscript.exe"
MyArray (+) = "notepad.exe"
MyArray (+) = "cmd.exe"
MyArray (*) = "Fxcalendar.exe"
MyArray (*) = "Payroll2.exe"
MyArray () = "Antiu.exe"
MyArray () = "Googletoolbarnotifier.exe"
MyArray (+) = "Doscan.exe"
MyArray () = "Userinit.exe"
MyArray (*) = "360antiarp.exe"
MyArray = "Sqlservr.exe"
MyArray (= "Sqlbrowser.exe")
MyArray (+) = "Sqlwriter.exe"
MyArray = "Ukeymonitor.exe"
MyArray (*) = "360se.exe"
MyArray (+) = "Haikeysrv.exe"
MyArray (+) = "Ekey_cli.exe"
MyArray = "Icbcbatchclient.exe"
MyArray (Bayi) = "Orderreminder.exe"
MyArray (*) = "Msiexec.exe"
MyArray = "360safe.exe"
MyArray (+) = "360tray.exe"
MyArray = "Applemobiledeviceservice.exe"
MyArray (*) = "Asfipmon.exe"
MyArray () = "Certregx.exe"
MyArray () = "Cwblmsrv.exe"
MyArray () = "Ebomain.exe"
MyArray (+) = "G2comm.exe"
MyArray (*) = "G2pre.exe"
MyArray = "G2svc.exe"
MyArray (*) = "G2tray.exe"
MyArray (94) = "Hpwuschd2.exe"
MyArray (+) = "Iaanotif.exe"
MyArray (+) = "Iaantmon.exe"
MyArray (*) = "Ijplmsvc.exe"
MyArray (98) = "Isuspm.exe"
MyArray () = "Javaw.exe"
MyArray (+) = "Ktengine.exe"
MyArray (101) = "Lpdaemon.exe"
MyArray (102) = "Msnmsgr.exe"
MyArray (103) = "Mspview.exe"
MyArray (104) = "Postgres.exe"
MyArray = "Pphbuf.exe"
MyArray (106) = "Pphidpad.exe"
MyArray (107) = "Rapimgr.exe"
MyArray (108) = "Rj.communicationserver.exe"
MyArray (109) = "Rj.easy.exe"
MyArray (+) = "Rthdcpl.exe"
MyArray (111) = "Safeboxtray.exe"
MyArray () = "Seaport.exe"
MyArray (113) = "Statusclient.exe"
MyArray () = "Stormliv.exe"
MyArray (+) = "Tssb.exe"
MyArray (*) = "Wfcrun32.exe"
MyArray (117) = "Ois.exe"
MyArray (118) = "Mspscan.exe"
MyArray (119) = "Fastaitimhelper.exe"
MyArray (+) = "Wdfmgr.exe"
MyArray (121) = "360leakfixer.exe"
MyArray (122) = "360sdupd.exe"
MyArray (123) = "Acdsee.exe"
MyArray (124) = "Acrord32.exe"
MyArray = "Acrord32info.exe"
MyArray (126) = "Adobearm.exe"
MyArray (127) = "Adobeupdater.exe"
MyArray (+) = "Agent.exe"
MyArray (129) = "Agentserviceinvoker.exe"
MyArray (*) = "Agentsvr.exe"
MyArray (131) = "Alproc.exe"
MyArray () = "Atiptaxx.exe"
MyArray (133) = "Calc.exe"
MyArray (134) = "Cbtray.exe"
MyArray (135) = "Cidaemon.exe"
MyArray (136) = "Cisvc.exe"
MyArray (137) = "Clipsrv.exe"
MyArray (138) = "Cnab5rpk.exe"
MyArray (139) = "Custom.exe"
MyArray (+) = "Cwbinhlp.exe"
MyArray (141) = "Cwbtf.exe"
MyArray (142) = "Cwbunplp.exe"
MyArray (143) = "Davcdata.exe"
MyArray (144) = "Defrag.exe"
MyArray (145) = "Dfrgntfs.exe"
MyArray (146) = "Dllhost.exe"
MyArray (147) = "Drawobj.exe"
MyArray (148) = "Dsagnt.exe"
MyArray (149) = "Dumprep.exe"
MyArray () = "Dvdlauncher.exe"
MyArray (151) = "Dwhwizrd.exe"
MyArray = "Dwrcc.exe"
MyArray (153) = "Dwwin.exe"
MyArray (154) = "Epsmon.exe"
MyArray (155) = "Fontserver.exe"
MyArray (156) = "Freecell.exe"
MyArray (157) = "Fxssvc.exe"
MyArray (158) = "Handwriting.exe"
MyArray (159) = "Haozip.exe"
MyArray = "Hasplms.exe"
MyArray (161) = "Helpsvc.exe"
MyArray (162) = "hh.exe"
MyArray (163) = "Hpbpro.exe"
MyArray (164) = "Hpcmpmgr.exe"
MyArray (165) = "Hpqscnvw.exe"
MyArray (166) = "Hpztsb10.exe"
MyArray (167) = "Hz_commsrv.exe"
MyArray (168) = "Iexplor.exe"
MyArray (169) = "Imeutil.exe"
MyArray = "Itvs.exe"
MyArray (171) = "Kaqsvc.exe"
MyArray (172) = "Kdwin.exe"
MyArray (173) = "Ksdsvc.exe"
MyArray (174) = "Kswebshield.exe"
MyArray (175) = "Livesrv.exe"
MyArray (176) = "Lservnt.exe"
MyArray (177) = "Lucoms~1.exe"
MyArray (178) = "Mashmaro.exe"
MyArray (179) = "Mdnsresponder.exe"
MyArray (+) = "Mplayerc.exe"
MyArray (181) = "Msconfig.exe"
MyArray (182) = "Msnchk.exe"
MyArray (183) = "Msohtmed.exe"
MyArray (184) = "Mspocrdc.exe"
MyArray (185) = "Mstsc.exe"
MyArray (186) = "Nclrssrv.exe"
MyArray (187) = "Nclusbsrv.exe"
MyArray (188) = "Netdde.exe"
MyArray (189) = "Ocserv.exe"
MyArray = "Ose.exe"
MyArray (191) = "Payroll2_jj.exe"
MyArray (192) = "Penmin.exe"
MyArray (193) = "Pg_ctl.exe"
MyArray (194) = "Pinyinup.exe"
MyArray (195) = "Postmaster.exe"
MyArray (196) = "Ravcopy.exe"
MyArray (197) = "Rdpclip.exe"
MyArray (198) = "Reader_sl.exe"
MyArray (199) = "Repgui.exe"
MyArray (+) = "Scardsvr.exe"
MyArray (201) = "Searchfilterhost.exe"
MyArray (202) = "Searchindexer.exe"
MyArray (203) = "SearchProtocolHost.exe"
MyArray (204) = "Servicelayer.exe"
MyArray (205) = "Shmgrate.exe"
MyArray (206) = "Smartupg.exe"
MyArray (207) = "Sndvol32.exe"
MyArray (208) = "Spider.exe"
MyArray (209) = "Spkrmon.exe"
MyArray = "Spnsrvnt.exe"
MyArray (211) = "Srvalproc.exe"
MyArray (212) = "Startupmonitor.exe"
MyArray (213) = "Stormtray.exe"
MyArray (214) = "Svcadmin.exe"
MyArray (215) = "Systrayicon.exe"
MyArray (216) = "Taskmgr.exe"
MyArray (217) = "Tlntsvr.exe"
MyArray (218) = "Tradecardse1.exe"
MyArray (219) = "Txopshow.exe"
MyArray (+) = "Valucore.exe"
MyArray (221) = "Verclsid.exe"
MyArray (222) = "Vpdaemon.exe"
MyArray (223) = "Wcescomm.exe"
MyArray (224) = "Wfica32.exe"
MyArray (225) = "Wiaacmgr.exe"
MyArray (226) = "Windowssearch.exe"
MyArray (227) = "Winvnc.exe"
MyArray (228) = "Wnie.exe"
MyArray (229) = "Xcommsvr.exe"
MyArray = "Zhudongfangyu.exe"
Set objFSO = CreateObject ("Scripting.FileSystemObject")
Do
Set objpc = objFSO.OpenTextFile ("C:\pc.txt", 1)
Set objRS = objFSO.OpenTextFile ("C:\rs.txt", 8)
Do While objpc.atendofstream = False
Host = Objpc.readline
Set WshShell = WScript.CreateObject ("Wscript.Shell")
Ping = Wshshell.run ("Ping-n 1" & Host, 0, True)
If Ping = 0 Then
Wshshell.run "net use \ \" & Host & "\ipc$ Aa123456/user:ln-tf\liaobin", 0, True
Set Bag=getobject ("Winmgmts:\\" & Host & "\root\cimv2")
If bag <> Nothing Then
Set Pipe=bag.execquery ("Select ExecutablePath, name from Win32_Process where name is like '%.exe '")
For each i in pipe
BEx = False
For each present in MyArray
If LCase (i.name) = Present Then
BEx = True
End If
Next
If bEx = False Then
Objrs.writeline (Now () & "|" & Host & "|" & I.name & "|" & I.executablepath)
End If
Next
Else
Objrs.writeline (Host & "is denied")
End If
Set bag=nothing
Wshshell.run "net use \ \" & Host & "\ipc$/delete", 0, True
Else
Objrs.writeline (Host & "is outline")
End If
Set WshShell = Nothing
Loop
Objrs.close
Set objRS = Nothing
Objpc.close
Set objpc = Nothing
Wscript.Sleep 60000
Loop
Set objFSO = Nothing
WMI connects to a remote computer and scans for local area network processes