Skip to content

benjaminfretez/unwanted-source-code

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

58 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

"Unwanted Virus"

Disclaimer

This program has been created for experimenting purposes, this has not the intention to be viral, the "VIRUS" in the name is just a name, it won't became viral.

Be consent about you are downloading, this malicious software (commonly called malware)

I am not responsible for any damage caused by this malware and your negligence in general.

I strongly recommend you neither run this malware on real hardware nor misuse this malware to prank your friends.

This malware causes data loss, it may affect personal or important data...

Content index (Table of contents)

  1. Main Information
  2. Payload
  3. Curiosities
  4. Bugs

Main Information

  • Creator: BenjaminFretez

  • Passwörd of the file: "*J4d'X4D;y&2$SdM" (without quotes)

  • Versions of Windows tested: Windows 7 to 11 (most tested in 10)

  • Admin rights required: yes

Payload

0** step:

Windows 10 x64-2022-03-17-18-39-43

(needs user consent)

If user selects no, the next message shows up:

Windows 10 x64-2022-03-17-18-39-49

("Ok, you missed the fun")

1st Step:

First of all, it overwrites the MBR with a game, then the malware sets the time to 6/JUN/6666 3:33:33 infinitely

Windows 10 x64-2022-03-17-18-53-21

It disables everything that every malware disables: CMD, taskmgr, etc.

It makes Start Menu and UWP taskbar options (like clock) not working (in Windows 10),

Then it infects some programs to run its own code with an infected message

If one of those programs are running, the program kills them

Windows 10 x64-2022-03-17-18-51-25

It also infects the Logon User Interface (LogonUI.exe) for making not working when E.G. you press CTRL+ALT+DEL

Windows 10 x64-2022-03-17-18-51-40

Or if you (find out the way for) log off you cannot Log-In anymore

Windows 10 x64-2022-03-17-18-51-57

And yes, your user account was deleted so you cannot recover it anymore

Maybe your files yes but your account not

It also infects programs like MS-SETTINGS (UWP) and RunDLL32 which some settings cannot be changed

2nd Step:

It starts to download from the Internet some files that in the 3rd step will be shown (Like the Wordpad, the Paint, the Background) except the notes that it will written by the program itself

There's nothing more to show, since it happens at the background so we see like everything is normal except the time

3rd Step:

After downloading everything (see 2nd Step) it follows the next steps*

  • It changes the Background

Windows 10 x64-2022-03-17-18-34-19

  • It creates random files on your desktop
  • Note: This may take a while, because it creates all of those files in one instant. It maybe shows only a few files for an instant like in the background photo.
  • Note 2: Those random files cannot be deleted because it's open with 'Unwanted.exe'

Windows 10 x64-2022-03-17-18-34-40

  • It open a note "...you ran the Unwanted Virus..."

  • Starts doing a screen effect

  • Starts a (kind of) scary music

  • Starts to pop-up random messages

  • It opens a Wordpad Document

  • It opens a Paint drawing with (I think) cute kittens

Windows 10 x64-2022-03-17-18-36-33

  • It opens notepads with Random messages

  • Open a Final Note ("10 seconds left")

After (approximately) 10 or 15 seconds the computer dies with a blue screen of death with a 0x0000029A code

Windows 10 x64-2022-03-17-18-37-06

Then Since the MBR has been overwritten it will load the game:

(this game is 'Invaders' by nanochess https://github.com/nanochess/Invaders)

image

Curiosities

The Program Itself

  • The original name was Úñåáñþéð ß¾®ü’ but clearly is named Unwanted Virus

  • It took 6 months approximately to do this malware

Rare right-click items

If you right click something you can see rare items in the menu:

Windows 10 x64-2022-03-17-18-33-45

expected

If you click one of those items, your computer will die instantly

Windows 10 x64-2022-03-17-18-40-17

"This is not a normal computer"

This is a easter egg, if you delete winlogon.exe (Without restarting, is possible) and then run the malware you got this message box, then your computer restarts

Windows 10 x64-2022-03-17-18-58-17

"We cannot found the command interpreter"

This easter egg can be found if you run the malware with 'DisableCMD=1' This malware rarely uses cmd, this messagebox was programmed because it comes from a legacy version (it used cmd for everything)

image

Internet disconnection

If you disconnect the internet before you run the malware it will show the next message

Windows 10 x64-2022-03-17-18-42-04

(ERR_INTERNET_DISCONNECTED)

Then the computer dies with BSOD

if you disconnect after you run the malware the message will be different

Windows 10 x64-2022-03-17-18-44-00

(UNKNOWN_HARD_ERROR)

Then the computer dies with BSOD

This happens because the malware checks the internet connection and then download the files, if there's no internet connection it throws the first error (ERR_INTERNET_CONNECTION), else if you disconnect while you are running the malware (downloading) it shows the last error shown (UNKNOWN_HARD_ERROR)

Run without admin rights

If you run this program without admin rights it will stop by throwing the (UNKNOWN_HARD_ERROR) shown recently.

Bugs

If you find any other, you can create an issue.

Rarely (at 3rd step) stops

A bug that I found (rarely happens) that the program stops at the 3rd step, I don't know why (maybe too many threads: I tried to add one and dies or PC specs idk) just i let it there if someone of you happens...


Discord: https://discord.gg/FgZYVKwTN4


© BenjaminFretez 2021-2022

Releases

No releases published

Packages

No packages published