1. Autostart folder
Everything in here will restart.
C:\windows\start menu\programs\startup {english}
C:\windows\Menu Démarrer\Programmes\Démarrage {french}
This Autostart Directory is saved in HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell
Folders Startup="C:\windows\start menu\programs\startup"
'So it could be easily changed by any program.
2. Win.ini
[windows]
load=file.exe
run=file.exe
3. System.ini [boot]
Shell=Explorer.exe file.exe
4. c:\windows\winstart.bat
'Note behaves like an usual BAT file. Used for copying deleting specific files. Autostarts
everytime
5. Registry
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices]
6. c:\windows\wininit.ini
'Often Used by Setup-Programs when the file exists it is run ONCE and then is deleted by windows
Example: (content of wininit.ini)
[Rename]
NUL=c:\windows\picture.exe
'This example sends c:\windows\picture.exe to NUL, which means that it is deleted. This
requires no interactivity with the user and runs totaly stealth.
7. Autoexec.bat
Starts everytime at Dos Level.
8. Registry Shell Spawning
[HKEY_CLASSES_ROOT\exefile\shell\open\command] @="\"%1\" %*"
[HKEY_CLASSES_ROOT\comfile\shell\open\command] @="\"%1\" %*"
[HKEY_CLASSES_ROOT\batfile\shell\open\command] @="\"%1\" %*"
[HKEY_CLASSES_ROOT\htafile\Shell\Open\Command] @="\"%1\" %*"
[HKEY_CLASSES_ROOT\piffile\shell\open\command] @="\"%1\" %*"
[HKEY_LOCAL_MACHINE\Software\CLASSES\batfile\shell\open\command] @="\"%1\" %*"
[HKEY_LOCAL_MACHINE\Software\CLASSES\comfile\shell\open\command] @="\"%1\" %*"
[HKEY_LOCAL_MACHINE\Software\CLASSES\exefile\shell\open\command] @="\"%1\" %*"
[HKEY_LOCAL_MACHINE\Software\CLASSES\htafile\Shell\Open\Command] @="\"%1\" %*"
[HKEY_LOCAL_MACHINE\Software\CLASSES\piffile\shell\open\command] @="\"%1\" %*"
The key should have a value of Value "%1 %*", if this is changed to "server.exe %1 %*",
the server.exe is executed EVERYTIME an exe/pif/com/bat/hta is executed.
Known as Unkown Starting Method and is currently used by Subseven.
9. Icq Inet
[HKEY_CURRENT_USER\Software\Mirabilis\ICQ\Agent\Apps\test]
"Path"="test.exe"
"Startup"="c:\\test"
"Parameters"=""
"Enable"="Yes"
[HKEY_CURRENT_USER\Software\Mirabilis\ICQ\Agent\Apps\
This key includes all the APPS which are executed IF ICQNET Detects an Internet Connection.
9. Misc Information
[HKEY_LOCAL_MACHINE\Software\CLASSES\ShellScrap]
@="Scrap object" "NeverShowExt"=""
The NeverShowExt key has the function to HIDE the real extension of the file (here) SHS.
This means if you rename a file as "Girl.jpg.shs" it displays as "Girl.jpg" in all programs
including Explorer.
Your registry should be full of NeverShowExt keys, simply delte the key to get the real
extension to show up.
_____________________________________________________________________________________________
Ini Blog pertama ane, jadi maaf klo masih newbie agak membosankan tapi makasih juga telah mengunjungi situs ini.
Search This Blog
NavBar
The Muzic
Global Variables
Click here for Myspace Layouts
Minggu, 05 Februari 2012
All Known and Unknown Autostart Methods In Windows All Known and Unknown Autostart Methods In Windows
[FUD]Predator Pain HiJacker v.5[Keylogger,Stealers,Easy USE,Auto Update,Encrypted] [FUD]Predator Pain HiJacker v.5[Keylogger,Stealers,Easy USE,Auto Update,Encrypted]
Well it's been a while since i made a free logger and if you remember back in your Predator daysPredator Pain was the most widely used free logger around because it was effective and it was FUD.
Now the older versions are more detected than Aradamax and kinda out dated. I recieved many PMS requesting for me to FUD Predator or make a newer updated version since it was the only free logge
around that actually worked as described. Well Predator Pain is back introducing Predator Hijacker a new state of the art keylogger better than any and all free versions around find out why and this
time Predator Free version is here to stay.
![[Image: KgYqaA.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vNXTDV0lMuuksdvumEK_Frw2HaH1_YZhTzWpO_aOx8Cp8afcq_KiXIANs8i5iID4BqLQIIGvKLm_wSXyRbGdpZpCowqm8=s0-d)
![[Image: FNS0f1.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tCe8tEWpfiECgtumNXKycjMcQsJdLrzBJ8-W1bxdWxE92hW6OhPrcEGZM5xuAQG3j7JEtBfziAbtCLJ0rvRvqloU5ZLTa7=s0-d)
![[Image: PSJDb1.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tMXOcleIqONo2TCzTqKfrV41oSBkC-W11lPnuWIpRnDfHfPw8ssKOP_ye0zDBt9Baz95PnlPiW3XIioO0NQcvemWl21g9f=s0-d)
![[Image: hgfdhgfd.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uDBv-QflaAMIqRIwFM43tVJZjPC7b0cOipnPWzQq9hjlnvhkbCLeZEDyf0_ndWvAYzyf_UBRdw7S-z3Pew2jgNMx_xdDbjrMbKhXZtUegaOuqB0w=s0-d)
[X]Uses the best Global Hooks known to man *Keystrokes will not be an issue in this case.
[X]Ability to send to any Email Host *Aol, Hotmail, Googlemail, Gmail, Live, Yahoo, your own email server, you name it as long as you know the correct port and email host you can send it there.
[X]Encrypted Smpt Server w/ (RC4 Encryption)
[X]Encrypted Email w/ (RC4 Encryption)
[X]Encrypted Password w/ (RC4 Encryption)
[X]Interval (Send every X Minutes you desire)
[X]Ability to test your email make sure everything is correct
[X]Add to Startup
[X]Bypass UAC
[X]Notify Email
[X]Clipboard Logger
[X]Screenshot Logger
[X]File Downloader
[X]Fake Error Message
[X]Assembly Change
[X]Icon Change
[X]File Pumper
[X]Auto Updater: Contains an auto updater everytime a new version is avaliable it will delete this version and send you a new version to download this is to fix bugs if any are found, new features, and FUD Updates on a weekly update.
Predator Pain Hijacker is the only Free Logger on HF that steals the newest web broswers avaliable how great is that i was debating whether or not to add these features but decided why not i haven't made a new logger in a long time.
Stealers:
[X]Firefox (Newest and Older Versions) *Steals all versions of Firefox 3.x.x., 4.x.x., 5.x.x.
[X]Internet Explorer (Newest and Older Versions) *Steals all versions of IE 6.x,7.x,8.x,9.x
[X]Opera (Newest and Older Versions) *Steals all versions of Opera 10 and 11
[X]Google Chrome (Newest and Older Versions) *Steals all Versions of Google chrome old to newest
[X]Minecraft - *What MINECRAFT STEALER? Yes, i added Minecraft was debating whether or not to make it runescape took me 20 minutes to figure it out then i decided Runescape is worth more so ill make it Minecraft. All versions of Runescape are avaliable on Private Version
Now the older versions are more detected than Aradamax and kinda out dated. I recieved many PMS requesting for me to FUD Predator or make a newer updated version since it was the only free logge
around that actually worked as described. Well Predator Pain is back introducing Predator Hijacker a new state of the art keylogger better than any and all free versions around find out why and this
time Predator Free version is here to stay.
[X]Uses the best Global Hooks known to man *Keystrokes will not be an issue in this case.
[X]Ability to send to any Email Host *Aol, Hotmail, Googlemail, Gmail, Live, Yahoo, your own email server, you name it as long as you know the correct port and email host you can send it there.
[X]Encrypted Smpt Server w/ (RC4 Encryption)
[X]Encrypted Email w/ (RC4 Encryption)
[X]Encrypted Password w/ (RC4 Encryption)
[X]Interval (Send every X Minutes you desire)
[X]Ability to test your email make sure everything is correct
[X]Add to Startup
[X]Bypass UAC
[X]Notify Email
[X]Clipboard Logger
[X]Screenshot Logger
[X]File Downloader
[X]Fake Error Message
[X]Assembly Change
[X]Icon Change
[X]File Pumper
[X]Auto Updater: Contains an auto updater everytime a new version is avaliable it will delete this version and send you a new version to download this is to fix bugs if any are found, new features, and FUD Updates on a weekly update.
Predator Pain Hijacker is the only Free Logger on HF that steals the newest web broswers avaliable how great is that i was debating whether or not to add these features but decided why not i haven't made a new logger in a long time.
Stealers:
[X]Firefox (Newest and Older Versions) *Steals all versions of Firefox 3.x.x., 4.x.x., 5.x.x.
[X]Internet Explorer (Newest and Older Versions) *Steals all versions of IE 6.x,7.x,8.x,9.x
[X]Opera (Newest and Older Versions) *Steals all versions of Opera 10 and 11
[X]Google Chrome (Newest and Older Versions) *Steals all Versions of Google chrome old to newest
[X]Minecraft - *What MINECRAFT STEALER? Yes, i added Minecraft was debating whether or not to make it runescape took me 20 minutes to figure it out then i decided Runescape is worth more so ill make it Minecraft. All versions of Runescape are avaliable on Private Version
Code:
Langganan:
Komentar (Atom)
