_______________________________________________________________________

Vbs Worms Generator 1.50b By [K]Alamar
Buenos Aires - Argentina - 4/Aug/2000
Http://www.virii.com.ar
Virii Argentina - The biggest virii resource in the net.
Bugs, questions or comments: kalamar@virii.com.ar
_______________________________________________________________________

**********************************************************************
You need the microsoft Vb5 runtimes to run this program, and the 
Windows Scripting Host 5.0 too.
**********************************************************************
Remeber, this program if for educational purpose only, I take no 
responsabiliy for any damage caused for any file created whit this 
program to anything.
**********************************************************************
_______________________________________________________________________

Sorry for the bad english.
_______________________________________________________________________

PLEASE DON'T DELETE THE LAST LINE COMMENT, IS THE ONLY THING THAT I
ASK TO YOU, DON'T TRY TO MAKE PEOPLE THINK THAT YOU'VE MADE THE WORM
BY YOUR OWN, CAUSE YOU'VE BEEN HELPED BY VBSWG, AND I THINK THAT YOU
SHOULD LEAVE THE COMMENT AT THE END.
_______________________________________________________________________

Hi!:
Thanx for downloading the Vbs Worms Generator 1.50b.
If you have any idea or code that i can add to the script please
contact me and i will add it.
Sorry for the bugs, after all, I'm just 17 years old!.
_______________________________________________________________________

What's New:
Vbswg 1.50b:
*This verersion only has script modyfications to avoid Av's detection,
 if you find that any av detects the worms please let me know.
*All sourves updated
*Some little changes in the program.
*I've suspend the setup for a while, cause it has too much bugs
Vbswg 1.5:
*New code encription, fastet and smaller.
*Select the random words lenght
*New random words engine, added caps and numbers.
*File downloading an execution.
*Fixed more bugs
*Outlook script modyfication to avoid Avp Heuristic detection
*Mirc script modyfication to avoid Avp Heuristic detection
*Main script modyfication to avoid Avp detection.
*The sources have been modified to be just like the main ones.
*Added New vbs reg file to add the Vbs file type to the File/New
 explorer submenu
*Modyfied the SaveAs dialog, cause it was causing troubles in some
 computers
*Added setup!, made by me, so, it can have some bugs.
*Added welcome Screen. Thanx Pepe Lepu for the Picture!.
_______________________________________________________________________

What can be in the next version?
I'm working in Word infection html files infection.
Save the worm into a html file.
_______________________________________________________________________

HEY!
I'M TRYING TO FIND THE CREATOR OF THE LEE WORM, CAUSE ALL WORM CREATED
WITH THE OLDER VBSWG ARE DETECTED AS I-WORM.LEE
This version is not detected by Avp or F-prot when i'm writting this.
If you see that anyone of the worms created by this version is detected
please let me know, and i'll fix that.
_______________________________________________________________________

*Stuff:
The worms crated whit the program are completly randomized, so you 
will never have 2 equal worms.

What does that mean?

That all the variables are randomized words of the lenght that you
choose, so, theposibilities of having two equal words in a worm are
dificult, and the posibilities of having 2 equal worms are completily
imposible.

You must be very carefoul when you edit the worm, because if you
change a variable, you must change it every time it's shown.
_______________________________________________________________________

Thanx to:
Pepe Lepu for helping me and for the Welcome picture!
Mano/SunSoft_Team for the Pirch script.
Duke/SMF for the filez.
Satanic_Kidd for the downloading filez idea.

All the people who contact me for the congratulations for this great
program!, i can't name all her, but they know who they are.

I think that I haven't forget anybody, if i do, sorry.
_______________________________________________________________________

*Features:

Start whit windows:
This make the worm be executed every time windows is started, so your
worm can try to infect or spread every day.

Worm backup:
It's just for having a copy of the worm in a safe place, so you can
be shure that it will no be lost.

Outlook Replication:
Send as attachment: It uses the same function that all the vbs's,
js's or any other kind of
worm, it sends a message, that you can define, whit te worm attached
to every preson in the user's address list.

Send in html code: The worm is added to the html code of the message,
so, when the person views it, they'e infected!

Mirc replication:
Search for mirc.ini(what means that the mirc is there) in the most
commons floders(programfiles\mirc, c:\mirc, c:\mirc32) and if it 
is found, the worm create "script.ini" in that folder, that script make
the mirc sends the worm to every person that join to a channel.
(see "If found Mirc, infect.")

Pirch replication:
Same as mirc, but for pirch (i haven't tested the script cause i 
haven't got pirch, please someone test it and tell me if this work).

Infect Files:
The worm will search for all the hard drives (and the network drives 
too, i think) for files whit the extencion that you want(in this
version only .vbs and vbe are searched) and copy overwrite him whit
itself.
*If found Mirc, infect:
This will make the worm to search also for mirc.ini, so if it find him,
it will infect the folder where mirc is. This method works 100% of the
times.

'To do a search for all the computer could take over 5 minutes, 
depending of the hard drive size.

Payloads:
These are stuff that you can add to the worm to be done.
  Message: shows a message box whit the text and the picture that
  you want.

  Open web address: open the web address that you want.

  Crash System: Creates 1Mb variables until the system goes down of
  memory

  Crash System 2: Runs notepads until the system crash

  When?: whit this you can tell the worm when do you wan to execute
  the payloads.

*Any idea?, contact me and i will add it!.

Save as fefault:
If you click this button in any window, the optionsselected are going
to be the same everitime you run the program, i thnk that it's nice.

Extras:
  Anti deletion method: The worm load all his source in memory, and
  if the worm is deleted is created again. The worm keeps running in
  memory.

  Crypt code: The code of the worm is encrypted and nobody know what
  it says!.

  Download end execute files: Put the address of a file that you want
  to download to the infected user machine, and that will be put as the
  startup site for Ie, and if the person downloads it, will be executed
  The code is taken fro mthe Iloveyou worm, and have some 
  modifycations.
_______________________________________________________________________

Ok, this is all that the program can make, maybe i forgot something,
i don't know.
I hope that you can learn something about Visual Scripting, it's
really easy an powerfull.
Visit www.virii.com.ar often if you wnna get the newest versions.

Have fun.

[K]Alamar
kalamar@virii.com.ar
Icq: 20972032 *I'm usually offline, so, leave a message.
http://www.virii.com.ar
_______________________________________________________________________
