Petik Archiver 1.0
Total Page:16
File Type:pdf, Size:1020Kb
PetiK Archiver 1.0 17/05/2009 After 7 years to stop coding virus/worms, I decided to assemble all my works. It is sorted by date like this : YYYYMMDD (where Y is the year, M the month and D the day) and the name of the works. In the begining you can see my old website page. Then my works. Newt, my not finish works and some articles. Best reading. PetiK Homepage (last update : July 9th 2002) EMAIL : [email protected] NEW : FORUM FOR ALL VXERS : CLICK HERE PLEASE SIGN MY GUESTBOOK : CLICK HERE 2002: July 9th : GOOD BYE TO ALL VXERS. I LEAVE THE VX-SCENE. I HOPE MY WORKS LIKE YOU AND WILL HELP YOU IN YOUR VX-LIFE. IF YOU WANT TO CONTACT ME, PLEASE WRITE IN THE GUESTBOOK. Special Thanx to : alc0paul, Benny/29A, Bumblebee, Vecna, Mandragore, ZeMacroKiller98and the greatest coder group : 29A July 7th : Add some new descriptions of AV (from Trend Micro and McAfee) July 3rd : Add the binary of my last Worm coded with alc0paul : VB.Brigada.Worm July 2nd : Add a new link : Second Part To Hell June 29th : Add my new tool : PetiK’s VBS Hex Convert and add my last full spread VBS worm : VBS.Hatred June 26th : Add W32/HTML.Dilan June 24th : Add VBS.Park June 22nd : I finish my new worm : VB.DocTor.Worm June 20th : PETIKVX EZINE #2 REALIZED : DOWNLOAD IT and add a new tool : CryptoText and my last worm : VB.Mars.Worm June 19th : Add VBS.Cachemire. Add my new article VBS/HTML Multi-Infection. June 16th : I join a new Virus Group : Brigada Ocho (create by alc0paul) June 1st : Add VB.Lili.Worm. My new worm is released : I-Worm.Haram May 31st : I leave the rRlf group May 23rd : New Ezine : rRlf#2 May 19th : I remove some source. You can find of them in PetiKVX#1 and the other in PetiKVX#2. Finish VB.Visual.Worm published in PetiKVX #2 May 14th : Add W97M.ApiWord May 12th : Add W32.HLLW.Archiver May 10th : Add a new tool to protect against new VBS Worm : PPVBSW May 9th : Add a new macro virus : W97M.AutoSpread May 8th : I join the rRlf group (http://www.rrlf.de). Add HTML.Welcome. May 6th : Add a new article : VBS Tutorial and exist in PDF April 27th : Add VBS.Xchange April 21st : Add all source of my works. April 7th : Add my first Ezine : PetiKVX Ezine #1. My new email is [email protected] March 15th : Add I-Worm.Together March 14th : My new email : [email protected] ([email protected] failed) March 10th : Add W32.HLLW.LiteLo March 9th : Add my articles in PDF format : articlesPDF and 29A#6. March 8th : Add my first VBS worm and HTML virus generator : PSWVG (W32.PSVG.gen : Norton AntiVirus, Constructor.VBS.PSWVG.10 : AVP) March 3rd : Add a new virus/worm : VBS/W97M.Doublet February 25th : Add a macro virus : W97M.Wolf February 24th : Add a lame love worm : HTML.Linda February 22nd : Add W32.HLLW.Wargames February 18th : Add a new Ezine : rRlf February 16th : Add my first virus (perhaps bug) : WinRAR.Linda February 14th : Add a new HTML virus : HTML.Macrophage February 10th : Can download my last worm. Add my second article : Technics February 7th : Finish my last worm : I-Worm.Falken (can’t download immediately) February 4th : Add new worm : I-Worm.Extract February 1st : New Worm : W32/W97M.Twin January 27th : I come back with a new worm : HLLW.SingLung.Worm January 20th : Add PetiKShow. This program contains all the sources of my works. January 10th : Add an old article about Worm Spreading written by me on September 19th. January 1st : HAPPY NEW YEAR. I DECIDED TO STOP TO CODE VIRII AND WORM. GOOD BYE 2001: December 10th : Add my last worm : W32.HLLW.Last November 6th : I-Worm.Anthrax October 12th : I-Worm.WTC September 8th : I-Worm.Passion September 2nd : I-Worm.Rush August 24th : I-Worm.Casper August 18th : Add the tool tElock 5.1 (A compress/encrypted PE file) August 16th : I-Worm.Kevlar August 12th : New design. You can hear one of my compositions. August 9th : New descrption from AVP about I-Worm.MadCow and I-Worm.Friends. August 8th : I-Worm.XFW July 18th : New Fanily : W32.Pet_Tick family (6), VBS.Pet_Tick family (3) from Norton Antivirus July 8th : I-Worm.MaLoTeYa July 3rd : VBS.Delirious June 30 th : I-Worm.Bush June 19th : I-Worm.Winmine June 18th : W97M.Blood June 17th : VBS.Seven June 10th : VBS.Starmania, I-Worm.Gamma, W97M.Kodak June 4th : BAT.Quatuor June 3rd : Bastille, JS.Germinal June 2nd : Add some Worms : HTML.Embargo, I-Worm.Mustard May 25th : I start my homepage. Source You can found here my different worms that I create : AntiVirus Name Real Name Date Description (TM=Trend Micro) It's a DOS worm. It uses mIRC to AVP : IRC.Worm.PetiK Bastille 06/03/2001 spread. On July 14th, he stops TM : Bat.PetiK.A the computer A BAT file which uses mIRC to BAT.Quatuor 06/04/2001 IRC.Becky.A spread. CryptoText 06/20/2002 Coded in VB6. Encrypt ASCII file. It is script that uses ActiveX controls to perform actions. It HTML.Bother.3180 modifies the default home page. It infects to all .HTM and .HTML HTML.Bother 05/13/2001 files that it founds in the \MY AVP : VBS.Both DOCUMENTS and \WINDOWS\WEB TM : HTML.Bother.A folders. The default icon for .html files is changed. It copies itself to \WINDOWS\WinHelp.htm. Change the HTML.Embargo 05/29/2001 VBS.Embaro.A.Intd AUTOEXEC.BAT. It uses mIRC channel to spread HTML.Linda 02/24/2002 Lame love worm. Infect htm,html,htt,hta and asp HTML.Prepend HTML.Macrophage 02/14/2002 files in different special Panda : HTML/Mage folders. My first virus for rRlf group. VBS.Manu@mm Infects web files HTML.Welcome 05/08/2002 (htm,html,htt,asp) and spread TM : VBS.PATIK.G with Outlook into a VBS file. W95.Pet_Tick.gen Open WAB default file to take I-Worm.Anthrax 11/06/2001 some email and spread with MAPI. TM : Worm.Pettick.A Spread with mIRC too. Sophos : W32/Petick-A W95.Pet_Tick.E@mm I-Worm.Bush 06/30/2001 Uses MAPI to spread. Not BUGS. AVP : I-Worm.PetiK.e It‘s a utility which detect I-Worm.Casper 08/24/2001 TM : Worm.Capser.A Happy99 and Icecubes. Uses MAPI. Perhaps bugz. I-Worm.Dandelion 11/16/2001 UNRELEASED WORM Panda : W32/Extract I-Worm.Extract 02/04/2002 Open KERNEL32.DLL to find API. TM : WORM.PETIK.L I-Worm.Falken 07/02/2002 First WGAA Worm. WARNING ! W32.Pet_Tick.B It uses a VBS file and mIRC to W32.Fiend.Worm I-Worm.Friends 05/05/2001 spread. he alters the Window's owner and company. AVP : I-Worm.PetiK.b W95.Pet_Tick.D@mm Scan all *.*htm* file in W95.Wormfix.Worm@mm I-Worm.Gamma 05/09/2001 "Temporary Internet Files" and uses MAPI function to spread AVP : I-Worm.PetiK.c Spread with a randome VBS file in I-Worm.Haram 06/01/2002 StartUp folder and put an HTML virus. Infect C???????.exe. Scans some W32.Pet_tick.M email address in the Outlook I-Worm.Kevlar 08/16/2001 TM : Worm.Kevlar.A Address Book and uses MAPI to Panda : Worm.PetiK.C spread. W32.Pet_Tick.Intd Sophos : W32/Petik-K Uses MAPI function to spread. I-Worm.Loft 06/23/2001 Open some DLL files to uses some AVP : I-Worm.PetiK.k API. TM : Worm.PetiK.K It's my first worm. It uses W32.Pet_Tick.A@mm Outlook and mIRC to spread. It W32.Salut.Worm@mm I-Worm.MadCow 12/01/2000 creates \SYSTEM\MSLS.ICO and will be the default icon of .exe AVP:I-Worm.PetiK.a files. W32.Pet_Tick.G W32.Malot.Int Uses MAPI to spread. Create a HTML file in the StartUp folder I-Worm.MaLoTeYa 07/08/2001 AVP : I-Worm.PetiK.f to send some informations about the user. CONTRIBUTE TO 29A#6. TM : Worm.Malot.A Modify "Exclude.dat" in the W32.Update.Worm "Install Folder" of Norton I-Worm.Mustard 05/27/2001 Antivirus to create a VBS file. AVP : I-Worm.PetiK.d The worm spread with Outlook TM : Worm.Mustard.A which use this VBS file. Copy all mail of Outlook Address Book in a file and scans this I-Worm.Passion 09/08/2001 W95.Pet_Tick.gen file to spread. Change some URL 1 times of 10. W95.Pet_Tick.C@mm W95.Buggy.Worm@mm Modify the Wallpaper with a BMP file that it download to a ftp I-Worm.PetiK 02/07/2001 AVP : I-Worm.IEPatch site. He spread with a VBS file which use Outlook. TM : Worm.PetiK.A Not bugz for MAPI functions. Start of propagation by error on I-Worm.Rush 02/09/2001 TM : Worm.Rush.A August 30th. Some payloads with some titles of windows. I-Worm.Together 03/15/2002 W32.Pet_Tick.AC@mm Kill some AV. 100% assembler. W32.Mineup.Worm AVP : I-Worm.Petik I-Worm.Winmine 06/19/2001 Uses Outlook to spread. McAfee:W32/PetTick@MM Panda : W32/PetTick Sophos : W32/Petik-WTC A Worm against the terrorism. I-Worm.WTC 10/11/2001 Infect RAR files in the Personal TM : WORM.PETTICK.Q directory. W95.Pet_tick.gen Infect WSOCK32.DLL and all DLL I-Worm.XFW 08/08/2001 TM : Trojan.PetiK.XFW files in the SYSTEM directory.