Posted October 25, 200519 yr http://www.urbandictionary.com/define.php?term=sp0rke* replace the * with h plz or... The "*******" virus is actually coupled with or is a variant of the Sub7 trojan horse. The computers I have seen infected with it did lose functionality at the hands of the user, but no files or folders were deleted as far as could be seen. The computers "infected" had simple diagnostics done upon them and had antitrojan scanning done, and every one of them was infected with the exact same version of Sub7. Upon removal of the Sub7 trojan horse, the functionality of the computers in question were returned to normal. All of the computers were no longer controlled by the annoying "*******". Each of the computers in question behaved in similar ways. All of them were owned by the "*******" "virus". All of them had extremely slow mouse movement, and even setting the mouse speed within the Control Panel did nothing. This cursor movement slowdown was being caused by something interfering with the API of the curser, which is something many trojan horses have the capability for. With Sub7 for example, the remote user has the ability to sieze control of the infected hosts cursor and move it wherever they wish, along with many other remote abilities above and beyond the control of the infected computers user. Doing an ipconfig/displaydns in a command prompt revealed a DNS entry to an IRC server on all of the computers in question. After verifying each of the computers did not have active IRC clients running or any IRC clients installed, a trojan scanner was introduced. The Sub7 trojan horse family have the ability to launch a "bot" to an IRC server to announce the availabilty of the infected host. Without editing the source code or editing the trojan horse itself, there is a default server and channel the bot launches itself on. (obviously thats when someones irc says: sp0rk.eh owns me) After doing further research into the default server setting and channel, this version of Sub7 had been altered to specific IRC servers and channels. It is my best guess that "*******" is an edited version of Sub7 either through source code alterations or by hexadecimal editing or some other form of editing.
October 25, 200519 yr Interesting read, always wondered what was behind everyone's favorite virus. A shame it didn't also cover the second version of that virus.
October 25, 200519 yr The computers I have seen infected with it did lose functionality at the hands of the user, but no files or folders were deleted as far as could be seen. ahahahhaha far from the truth fucking idiots
October 25, 200519 yr " Just remember, myg0t is 15%kids,10%scriptkiddies,25%Bullshit,50%Hype." I think, more like, 95% kids, 4% scriptkiddies, 0.01% 52-year-olds, .99% sex.
October 25, 200519 yr interesting definition, not nearly complete though. /too many script kiddies renameing server.exe to sp0 rkeh.
October 25, 200519 yr sp0rk.eh was coded by [myg0t]sp0rk originally and [myg0t]SourceX rewrote it a couple of times.
October 25, 200519 yr " Just remember, myg0t is 15%kids,10%scriptkiddies,25%Bullshit,50%Hype." I think, more like, 95% kids, 4% scriptkiddies, 0.01% 52-year-olds, .99% sex. you fail at math. You cannot have 198.01% of somthing.
October 25, 200519 yr Why are we posting in this thread? Who cares about sub7 re-writes? I guess I do.
October 25, 200519 yr Originally Posted by Azide " Just remember, myg0t is 15%kids,10%scriptkiddies,25%Bullshit,50%Hype." I think, more like, 95% kids, 4% scriptkiddies, 0.01% 52-year-olds, .99% sex. you fail at math. You cannot have 198.01% of somthing. u fail at english and math
October 25, 200519 yr wow thats completely wrong, sp0rk eh has nothing to do with sub7 whatsoever, and it does not connect to any irc network. whoever wrote that definition is a wannabe it pro.
October 26, 200519 yr As v0kda said, and I will reinterate. sp0rkuh was coded from scratch via myg0t members sp0rk and SX.
October 26, 200519 yr Author oh my god it's THE ONE EVERYBODY BOW ON YOUR KNEES :gaysex: :gaysex: ooooooookay...
October 26, 200519 yr Isn't the one in this definition of the one that you can get on IRC through that exploit? eh, I don't know what I'm talking about but I'm pretty sure that sp0rk eh was a lot more destructive before all these ***s started handing out these fake copies of it.
October 26, 200519 yr The first myg0t definition is funny, I think. STEAM Account Stealer is called worthless because it steals 12 year old accounts. We're accused of having botnets (myg0t has never maintained botnets as a group). We're downtalked for spreading an "aura of fear" in the gaming community but also challenged to "try that shit in the hack/crack community." Coded "trojan" sp0rketteh but then we're called out on calling it a "virus" instead of a "trojan." myg0t has amassed a following of so-called "emo kids full of teen angst and prepubescent anger." "Rage" tactics for forum spamming are insulted. Defacements are downplayed. Pwned.nl is made fun of. All together I don't think myg0t can come back from this written essay of ownage that this man has unleashed. I think it's about time we called it quits. PS - My favorite is the "emo kids full of teen angst and prepubescent anger" part. It's completely contradictory. You can't have prepubescent anger if you're a teen full of angst. Common misconception. Sounds like the guy who wrote this is just another satisfied customer to me.
October 26, 200519 yr Opter']ahahahhaha far from the truth fucking idiots i personally was led to believe it does infact aswell as fuck up ur cursor speed and screensize, that it locks folders and deletes .DLL files..... oh well you fail at math. You cannot have 198.01% of somthing. you are a fucking idiot... lets work it out shall we! 95 + 4 = 99 .01 + .99 = 1 99 + 1 = 100 wow, that was fucking difficult wasnt it? fucking idiot solvent
October 26, 200519 yr you fail at math. You cannot have 198.01% of somthing. Actually you can have 198.01% of somthing it would just be almost double of what you began with. as for what it does i was lead to belive it either locked all of your folders and put ******* owns j00 everywhere
October 27, 200519 yr Here is a desktop ss of the first fake version of sp0rk.eh. If you didn't know, sp0rk.eh is actually a private hack for CS, CS:S, and we have a BF2 version now too. http://members.lycos.co.uk/dns2php/messedup-hack.jpg Here is a list of a few of the things it does: Install itself as a service, and will autostart every time you start Windows. Copy itself to another location . This file is an exact copy of the virus executable, and will be used to run with a fake Service. Force screen resolution changes to 648x480 Force mouse buttons reversed. Left click will become right click and vice versa. Force mouse pointer moves at a very slow speed. Changes the Windows Desktop layout, such as moving the Start button to right hand side, changes all title of windows/buttons to " ******* 0wnz y0u " Please refer to screenshot. Windows will no longer able to execute any files ended with *.exe , since virus takes over that extension. Therefore infected Windows cannot open almost any programs. Even changing Desktop resolution is impossible. Attempting to do so will only give you a ShellExt32.exe error.
October 27, 200519 yr sp0rk and source X made a good job :) not many communitys have viruses as famous as this one... pure classic