hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

GhostShell
I lost my internet connection yesterday so I was bored and I made this. I ripped through windows registry to find all the tags some of these have already been found. So here is my new batch method to create windows hidden folders. This was tested on windows xp. Im not sure if all of these tags have been posted on the net yet. The reason why a few options on the batch file are missing is bcuz they sorta had bugs. well most likely i screwed something on it up so let me know smile.gif.
CODE

@echo off
color 0c
:menu
echo [1]  create folder hidden as network and internet connections
echo [2]  create folder hidden as media clip
echo [3]  create folder hidden as video clip
echo [4]  create folder hidden as MIDI sequence
echo [5]  create folder hidden as taskbar and menu properties
echo [7]  create folder hidden as scheduled tasks icon
echo [8]  create folder hidden as windows search
echo [9]  create folder hidden as network places
echo [10] create folder hidden as my computer
echo [11] create folder hidden as control panel
echo [12] create folder hidden as printers and faxes
echo [13] create folder hidden as html document
echo [14] create folder hidden as search icon
echo [15] create folder hidden as help and support icon
echo [16] create folder hidden as lock icon
echo [17] create folder hidden as run icon
echo [18] create folder hidden as default browser
echo [19] create folder hidden as outlook
echo [20] create folder hidden as properties icon
echo [21] create folder hidden as network setup wizard
echo [22] create folder hidden as MHTML document
echo [23] create folder hidden as html application
echo [24] create folder hidden as unknown file type
echo [25] create folder hidden as wireless network setup wizard
echo [26] create folder hidden as my documents
echo [27] create folder hidden as XML document
echo [30] create folder hidden as recycle bin [full]
echo [31] create folder hidden as FTP
echo [32] create folder hidden as recycle bin [empty]
echo [33] create folder hidden as installation cd icon
echo [34] create folder hidden as umm looks like its where browser plugins are kept
echo [35] create folder hidden as folder options
echo [36] create folder hidden as network and internet connections
echo [38] create folder hidden as clipboard icon
echo [77] create folder hidden as system restore icon
echo [78] create folder hidden as wordpad document
echo [79] create folder hidden as unknown folder type
echo [80] create folder hidden as user accounts
echo [81] create folder hidden as scheduled tasks
echo [82] create folder hidden as [internet explorer installations like activex]icon
echo [83] create folder hidden as briefcase
echo [84] create folder hidden as internet explorer
echo [85] create folder hidden as zip folder
echo [86] create folder hidden as internet explorer installations like activex
echo [87] create folder hidden as unknown folder icon
echo [88] create folder hidden as network and internet connections
echo [89] create folder hidden as lock icon
echo [90] create folder hidden as restore icon
echo [91] create folder hidden as mail icon
echo [92] create folder hidden as desktop icon
echo [93] create folder hidden as search icon
echo [94] create folder hidden as unknown file type
echo [95] create folder hidden as unknown folder type
echo [96] create folder hidden as favorites
echo [97] create folder hidden as unknown file type
echo [98] create folder hidden as another damn icon
echo [99] create folder hidden as unknown file type
echo [100]create folder hidden as unknown file type
echo [101]create folder hidden as unknown file type
echo [102]create folder hidden as webfolders
echo [103]create folder hidden as unknown file type
echo [104]create folder hidden as fonts folder
echo [105]create folder hidden as admin settings
echo [106]create folder hidden as bitmap image
echo [107]create folder hidden as add network place wizard
echo [108]create folder hidden as scheduled tasks
echo [109]create folder hidden as search
echo [110]create folder hidden as scanners and cameras
echo [111]create folder hidden as zip folder
echo [112]create folder hidden as policy package
echo [113]create folder hidden as my documents
echo [114]create folder hidden as unknown file type
echo [115]create folder hidden as another icon
echo [116]create folder hidden as unknown file type
echo [117]create folder hidden as another unknown folder type
echo [118]create folder hidden as XML document
echo [119]create folder hidden as unknown folder type
echo [120]create folder hidden as scanner and cameras
echo [121]create folder hidden as internet explorer
echo [122]create folder hidden as scheduled tasks
echo [0] exit
echo +-----------------------------------------------------------+
echo +                  Making hidden folders                    +
echo + [2005]             [by Gh0stSheLL]                        +
echo +-----------------------------------------------------------+
echo +     greetz @ Joepi ViCiOuS and the whole GSO team         +
echo +-----------------------------------------------------------+
echo.
@echo make your Choice?
@echo off
set /p menu=

if %menu% == 0 goto exit
if %menu% == 1 goto 1
if %menu% == 2 goto 2
if %menu% == 3 goto 3
if %menu% == 4 goto 4
if %menu% == 5 goto 5
if %menu% == 6 goto 6
if %menu% == 7 goto 7
if %menu% == 8 goto 8
if %menu% == 9 goto 9
if %menu% == 10 goto 10
if %menu% == 11 goto 11
if %menu% == 12 goto 12
if %menu% == 13 goto 13
if %menu% == 14 goto 14
if %menu% == 15 goto 15
if %menu% == 16 goto 16
if %menu% == 17 goto 17
if %menu% == 18 goto 18
if %menu% == 19 goto 19
if %menu% == 20 goto 20
if %menu% == 21 goto 21
if %menu% == 22 goto 22
if %menu% == 23 goto 23
if %menu% == 24 goto 24
if %menu% == 25 goto 25
if %menu% == 26 goto 26
if %menu% == 27 goto 27
if %menu% == 28 goto 28
if %menu% == 29 goto 29
if %menu% == 30 goto 30
if %menu% == 31 goto 31
if %menu% == 32 goto 32
if %menu% == 33 goto 33
if %menu% == 34 goto 34
if %menu% == 35 goto 35
if %menu% == 36 goto 36
if %menu% == 38 goto 38
if %menu% == 77 goto 77
if %menu% == 78 goto 78
if %menu% == 79 goto 79
if %menu% == 80 goto 80
if %menu% == 81 goto 81
if %menu% == 82 goto 82
if %menu% == 83 goto 83
if %menu% == 84 goto 84
if %menu% == 85 goto 85
if %menu% == 86 goto 86
if %menu% == 87 goto 87
if %menu% == 88 goto 88
if %menu% == 89 goto 89
if %menu% == 90 goto 90
if %menu% == 91 goto 91
if %menu% == 92 goto 92
if %menu% == 93 goto 93
if %menu% == 94 goto 94
if %menu% == 95 goto 95
if %menu% == 96 goto 96
if %menu% == 97 goto 97
if %menu% == 98 goto 98
if %menu% == 99 goto 99
if %menu% == 100 goto 100
if %menu% == 101 goto 101
if %menu% == 102 goto 102
if %menu% == 103 goto 103
if %menu% == 104 goto 104
if %menu% == 105 goto 105
if %menu% == 106 goto 106
if %menu% == 107 goto 107
if %menu% == 108 goto 108
if %menu% == 109 goto 109
if %menu% == 110 goto 110
if %menu% == 111 goto 111
if %menu% == 112 goto 112
if %menu% == 113 goto 113
if %menu% == 114 goto 114
if %menu% == 115 goto 115
if %menu% == 116 goto 116
if %menu% == 117 goto 117
if %menu% == 118 goto 118
if %menu% == 119 goto 119
if %menu% == 120 goto 120
if %menu% == 121 goto 121
if %menu% == 122 goto 122

:1
echo 1 is network and internet connections
echo choose folder name
set /p name=
md %name%.{7007ACC7-3202-11D1-AAD2-00805FC1270E}
goto menu

:2
echo 2 is a media clip
echo choose folder name
set /p name=
md %name%.{00022601-0000-0000-C000-000000000046}
goto menu

:3
echo 3 is a video clip
echo choose folder name
set /p name=
md %name%.{00022602-0000-0000-C000-000000000046}
goto menu

:4
echo 4 is MIDI Sequence
echo choose folder name
set /p name=
md %name%.{00022603-0000-0000-C000-000000000046}
goto menu

:5
echo 5 is taskbar and start menu properties
echo choose folder name
set /p name=
md %name%.{0DF44EAA-FF21-4412-828E-260A8728E7F1}
goto menu

:7
echo 7 is scheduled tasks icon
echo choose folder name
set /p name=
md %name%.{148BD52A-A2AB-11CE-B11F-00AA00530503}
goto menu

:8
echo 8 is windows search
echo choose folder name
set /p name=
md %name%.{1f4de370-d627-11d1-ba4f-00a0c91eedba}
goto menu

:9
echo 9 is network places
echo choose folder name
set /p name=
md %name%.{208D2C60-3AEA-1069-A2D7-08002B30309D}
goto menu

:10
echo 10 is my computer
echo choose folder name
set /p name=
md %name%.{20D04FE0-3AEA-1069-A2D8-08002B30309D}
goto menu

:11
echo 11 is control panel
echo choose folder name
set /p name=
md %name%.{21EC2020-3AEA-1069-A2DD-08002B30309D}
goto menu

:12
echo 12 is printers and faxes
echo choose folder name
set /p name=
md %name%.{2227A280-3AEA-1069-A2DE-08002B30309D}
goto menu

:13
echo 13 is an html document
echo choose folder name
set /p name=
md %name%.{25336920-03F9-11CF-8FD0-00AA00686F13}
goto menu

:14
echo 14 is search icon
echo choose folder name
set /p name=
md %name%.{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}
goto menu

:15
echo 15 is help and support icon
echo choose folder name
set /p name=
md %name%.{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}
goto menu

:16
echo 16 is a lock icon
echo choose folder name
set /p name=
md %name%.{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}
goto menu

:17
echo 17 is run icon
echo choose folder name
set /p name=
md %name%.{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
goto menu

:18
echo 18 opens your browser
echo choose folder name
set /p name=
md %name%.{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}
goto menu

:19
echo 19 opens outlook
echo choose folder name
set /p name=
md %name%.{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}
goto menu

:20
echo 20 is properties icon
echo choose folder name
set /p name=
md %name%.{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}
goto menu

:21
echo 21 is network setup wizard
echo choose folder name
set /p name=
md %name%.{2728520d-1ec8-4c68-a551-316b684c4ea7}
goto menu

:22
echo 22 is MHTML document
echo choose folder name
set /p name=
md %name%.{3050F3D9-98B5-11CF-BB82-00AA00BDCE0B}
goto menu

:23
echo 23 is html application
echo choose folder name
set /p name=
md %name%.{3050f4d8-98B5-11CF-BB82-00AA00BDCE0B}
goto menu

:24
echo 24 is unknown filetype
echo choose folder name
set /p name=
md %name%.{30D02401-6A81-11d0-8274-00C04FD5AE38}
goto menu

:25
echo 25 is wireless network setup wizard
echo choose folder name
set /p name=
md %name%.{3c5c43a3-9ce9-4a9b-9699-2ac0cf6cc4bf}
goto menu

:26
echo 26 is my documents
echo choose folder name
set /p name=
md %name%.{450D8FBA-AD25-11D0-98A8-0800361B1103}
goto menu

:27
echo 27 is XMl document
echo choose folder name
set /p name=
md %name%.{48123bc4-99d9-11d1-a6b3-00c04fd91555}
goto menu

:30
echo 30 is recycle bin full
echo choose folder name
set /p name=
md %name%.{5ef4af3a-f726-11d0-b8a2-00c04fc309a4}
goto menu

:31
echo 31 is FTP
echo choose folder name
set /p name=
md %name%.{63da6ec0-2e98-11cf-8d82-444553540000}
goto menu

:32
echo 32 is empty recycle bin
echo choose folder name
set /p name=
md %name%.{645FF040-5081-101B-9F08-00AA002F954E}
goto menu

:33
echo 33 is installation cd icon
echo choose folder name
set /p name=
md %name%.{67cf8cbd-e5c0-44f7-9de5-e1d599d626d8}
goto menu

:34
echo 34 looks like its where browser plugins are kept
echo choose folder name
set /p name=
md %name%.{692F0339-CBAA-47e6-B5B5-3B84DB604E87}
goto menu

:35
echo 35 is folder options
echo choose folder name
set /p name=
md %name%.{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}
goto menu

:36
echo 36 is network and internet connections
echo choose folder name
set /p name=
md %name%.{7007ACC7-3202-11D1-AAD2-00805FC1270E}
goto menu

:38
echo 38 is clipboard icon
echo choose folder name
set /p name=
md %name%.{72ADFD4B-2C39-11D0-9903-00A0C91BC942}
goto menu

:77
echo 77 is system restore icon
echo choose folder name
set /p name=
md %name%.{7325c922-bb81-47b0-8b2f-a5f8605e242f}
goto menu

:78
echo 78 is wordpad document
echo choose folder name
set /p name=
md %name%.{73FDDC80-AEA9-101A-98A7-00AA00374959}
goto menu

:79
echo 79 is unknown folder type
echo choose folder name
set /p name=
md %name%.{750fdf0f-2a26-11d1-a3ea-080036587f03}
goto menu

:80
echo 80 is user accounts
echo choose folder name
set /p name=
md %name%.{7A9D77BD-5403-11d2-8785-2E0420524153}
goto menu

:81
echo 81 is scheduled tasks
echo choose folder name
set /p name=
md %name%.{7BD29E00-76C1-11CF-9DD0-00A0C9034933}
goto menu

:82
echo 82 is [internet explorer installation like activex] icon
echo choose folder name
set /p name=
md %name%.{8369AB20-56C9-11D0-94E8-00AA0059CE02}
goto menu

:83
echo 83 is briefcase
echo choose folder name
set /p name=
md %name%.{85BBD920-42A0-1069-A2E4-08002B30309D}
goto menu

:84
echo 84 is IE
echo choose folder name
set /p name=
md %name%.{871C5380-42A0-1069-A2EA-08002B30309D}
goto menu

:85
echo 85 is zip folder
echo choose folder name
set /p name=
md %name%.{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}
goto menu

:86
echo 86 is internet explorer installations like activex
echo choose folder name
set /p name=
md %name%.{88C6C381-2E85-11D0-94DE-444553540000}
goto menu

:87
echo 87 is unknown folder icon
echo choose folder name
set /p name=
md %name%.{8E6E6079-0CB7-11d2-8F10-0000F87ABD16}
goto menu

:88
echo 88 is network and internet connections
echo choose folder name
set /p name=
md %name%.{992CFFA0-F557-101A-88EC-00DD010CCC48}
goto menu

:89
echo 89 is lock icon
echo choose folder name
set /p name=
md %name%.{9B0EFD60-F7B0-11D0-BAEF-00C04FC308C9}
goto menu

:90
echo 90 is restore icon
echo choose folder name
set /p name=
md %name%.{9DB7A13C-F208-4981-8353-73CC61AE2783}
goto menu

:91
echo 91 is mail icon
echo choose folder name
set /p name=
md %name%.{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}
goto menu

:92
echo 92 is desktop icon
echo choose folder name
set /p name=
md %name%.{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}
goto menu

:93
echo 93 is search icon
echo choose folder name
set /p name=
md %name%.{A9B48EAC-3ED8-11d2-8216-00C04FB687DA}
goto menu

:94
echo 94 is unknown filetype
echo choose folder name
set /p name=
md %name%.{ADB9F5A4-E73E-49b8-99B6-2FA317EF9DBC}
goto menu

:95
echo 95 is unknown folder type
echo choose folder name
set /p name=
md %name%.{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}
goto menu

:96
echo 96 is favorites
echo choose folder name
set /p name=
md %name%.{B005E690-678D-11d1-B758-00A0C90564FE}
goto menu

:97
echo 97 is unknown file type
echo choose folder name
set /p name=
md %name%.{B12AE898-D056-4378-A844-6D393FE37956}
goto menu

:98
echo 98 is another damn icon
echo choose folder name
set /p name=
md %name%.{B50F5260-0C21-11D2-AB56-00A0C9082678}
goto menu

:99
echo 99 100 101 103 are all unknown file types
echo choose folder name
set /p name=
md %name%.{B7BBD408-F09C-4aa8-B65E-A00B8FE0F0B9}
goto menu

:100
echo choose folder name
set /p name=
md %name%.{B96D2802-4B41-4bc7-A6A4-55C5A12268CA}
goto menu

:101
echo choose folder name
set /p name=
md %name%.{BD84B380-8CA2-1069-AB1D-08000948F534}
goto menu

:103
echo choose folder name
set /p name=
md %name%.{c79d1575-b8c6-4862-a284-788836518b97}
goto menu

:102
echo 102 is webfolders
echo choose folder name
set /p name=
md %name%.{BDEADF00-C265-11d0-BCED-00A0C90AB50F}
goto menu

:104
echo 104 is fonts folder
echo choose folder name
set /p name=
md %name%.{D20EA4E1-3957-11d2-A40B-0C5020524152}
goto menu

:105
105 is admin settings
echo choose folder name
set /p name=
md %name%.{D20EA4E1-3957-11d2-A40B-0C5020524153}
goto menu

:106
echo 106 is bitmap image
echo choose folder name
set /p name=
md %name%.{D3E34B21-9D75-101A-8C3D-00AA001A1652}
goto menu

:107
echo 107 is add network place wizard
echo choose folder name
set /p name=
md %name%.{D4480A50-BA28-11d1-8E75-00C04FA31A86}
goto menu

:108
echo 108 is scheduled tasks
echo choose folder name
set /p name=
md %name%.{D6277990-4C6A-11CF-8D87-00AA0060F5BF}
goto menu

:109
echo 109 opens up search
echo choose folder name
set /p name=
md %name%.{e17d4fc0-5564-11d1-83f2-00a0c90dc849}
goto menu

:110
echo 110 is scanners and cameras
echo choose folder name
set /p name=
md %name%.{E211B736-43FD-11D1-9EFB-0000F8757FCD}
goto menu

:111
echo 111 is zip folder
echo choose folder name
set /p name=
md %name%.{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31}
goto menu

:112
echo 112 is policy package
echo choose folder name
set /p name=
md %name%.{ecabaebd-7f19-11d2-978E-0000f8757e2a}
goto menu

:113
echo 113 is my docments
echo choose folder name
set /p name=
md %name%.{ECF03A32-103D-11d2-854D-006008059367}
goto menu

echo 114 is 116 are both unknown file type

:114
echo choose folder name
set /p name=
md %name%.{EFA24E61-B078-11d0-89E4-00C04FC9E26E}
goto menu

:116
md 116.{EFA24E63-B078-11d0-89E4-00C04FC9E26E}
goto menu

:115
echo 115 is another damn icon
echo choose folder name
set /p name=
md %name%.{EFA24E62-B078-11d0-89E4-00C04FC9E26E}
goto menu

:117
echo 117 is another unknown folder type
echo choose folder name
set /p name=
md %name%.{effc2928-37b1-11d2-a3c1-00c04fb1782a}
goto menu

:118
echo 118 is XML document
echo choose folder name
set /p name=
md %name%.{f5078f28-c551-11d3-89b9-0000f81fe221}
goto menu

:119
echo 119 is an unknown folder type
echo choose folder name
set /p name=
md %name%.{F5175861-2688-11d0-9C5E-00AA00A45957}
goto menu

:120
echo 120 is scanner and cameras
echo choose folder name
set /p name=
md %name%.{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}
goto menu

:121
echo 121 is internet explorer
echo choose folder name
set /p name=
md %name%.{FBF23B42-E3F0-101B-8488-00AA003E56F8}
goto menu

:122
echo choose folder name
set /p name=
echo and 122 is scheduled tasks
md %name%.{FF393560-C2A7-11CF-BFF4-444553540000}
goto menu

:exit
exit
320X
lol nice superbat laugh.gif
Paul
You must've been really bored tongue.gif
tuttefrut
it's handy aight
but look at all that code biggrin.gif
:x
Insanity
yeah, holy crap... i was going to make something like that in C# a while ago but haha forget that now i can just take your code and change it into c and add a few more things... but good job... very easy to understand... and heck.. you must of been one bored child
GhostShell
lol yes i was really bored and it is really handy. I wanted to say that in the code you might notice that there are double functions for example...there is two or three "create a folder hidden as zip file" functions the reason for that is bcuz they are all different tags and one might be hidden better then the other look at the screen shot for example. Insanity that would be kewl if you turned into c# let me know how that goes. oh and i forgot to add a disclaimer..."I am not resposible for what you do with this. the voice inside my head told me to make it."
klapkaak
this is a very nice bat file tongue.gif
it will become very handy i think
thanks

[edit] Tibbar - no glorified thanx posts allowed either. +1 warning point +5 days vacation.
hercules
Very usefull Batch file, Tnx wink.gif



**** BN says:

Limit reached! BYE BYE Hercules!

*************

Account suspened for 1500 days. I look forward to seeing you when your suspension is finished ;-)
dolle
i'll hope you got bored again and make another great bat , thanx
KuRuPT
cool thanks for the bat works nice smile.gif

[edit] tibbar - 15 day holiday and 1 warning point. Great work...
tibbar
Guys n Girls, stop the "Thanx" posts, or you will not be at GSO for long.

Anyone I catch gets 15 day suspension + warning point. You all have been warned.
cduke250
Hey good work... cool post!

I got a question for you... How can you get these same hidden files using debug? Thats how I learned to hide files a long time ago..

How can you use default command-line tools to find these files? attrib/debug/echo/etc

Where can I find more technical info about this method?

What about converting the bat to source code or executable?

Sorry so many quesitons.. I would like to use this method to try and bypass file-integrity-checkers on my honeypot smile.gif

[ Tibbar- nice job you rock! ]
fak3
i used to hide that way my folders but i did it manually not with .bat so i am happy you were bored biggrin.gif
but what i really want to share is that this "trick" works under almost every file manager except totalcmd wub.gif (my alltyme favorite).totalcmd handles the directories other way so it is not afected.
-NL-Rippertje
I used to do this manual too, but then i only had a few things, like control panel, recycle bin etc.. And with this one i can make many more, nice work you have done on this one..
blahplok
waaaaaaa...... nice work... by the way how long did you lost your internet conection...??? biggrin.gif biggrin.gif biggrin.gif biggrin.gif biggrin.gif
GhostShell
Glad to see you guys like it wink.gif ..... @ blahplok I lost it for a whole day sad.gif lol anyway there is more of these tags depending on what you have installed...Well just glad to see you are having fun with it.
(Gh0stSheLL)
flush
real nice work, thank you very muchos wink.gif

10 day vacation for thx posts
WaTerBoy
Nice batch file work #1 thanks dude smile.gif

10 day vacation for thanks posts
GhostShell
@ THX POSTERS

Ok people I am very happy that you guys like my file but I dont want my post to be a camping ground for people who say "thx" and thats it. Please if you reply tell me what you think,if it works,suggestions. Then on the other hand go ahead post what you want its a good way to filter out the new members lol...I will have many more projects like this so I am glad you like.

Gh0stShell
lobas
is it possible to make a mini rootkit with batch files to hide proccess, folder and reg keys smile.gif
apoc_neo
very nice work dude this is going to come in handy smile.gif

EDITED BY MOD: A little too close to a thx post, slightly more but still waste of space. Warning added.
DarkRider
Thanks for the nice idea GhostShell!

I made a console application with all possible icons.

I used a clean install of the following english versions of Windows 2000, XP and 2003.

CODE

*****************************************************************
* Hidden Directory Creator v1.0 by DarkRider                    *
* ® 2005 MAP. All rights reserved.                              *
*****************************************************************
[-] Usage: hdc <type> <directory name>
[-] Example: hdc 1 test
[-] -h for help
ThEWaTcHeR
Many thanks for this it might be very usefull for me smile.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.