Windows XP Hacking Tips & Tricks
Windows XP Hacking Tips & Tricks
Now what you have just done is told the computer to backup the command program and the
screen saver file, then edits the settings so when the machine boots the screen saver you will get an
unprotected dos prompt with out logging into XP.
Once this happens if you enter this command minus the quotes
"net user <admin account name here> password"
If the Administrator Account is called Admin and you want the password blah enter this "net user
Admin blah" and this changes the password on Admen's machine to blah and you're in.
Note: Don't forget to copy the contents of tem hack back into the system32 dir to cover tracks.
Note: This is for learning purpose only. I am not responsible for any liabilities.
lol = msgbox ("Warning a virus has been detected on your PC. Press YES to format your
hard disk now or press NO to format your hard disk after system reboot",20,"Warning")
Then save it as Chandu.vbs Or Save in any name and go to the folder that contains it and open it
if a window pops out saying a virus has been detected it's working. Press yes or no to close the
window and put it in the startup folder of the victim's account on startup the window should
appear.
Note: This does not harm your computer as it does not contain virus.
2. Open the file with Notepad and add "/noguiboot" after "/fastdetect".
1. All you need is your friends IP address and your Command Prompt.
2. Open your notepad and write this code as it is.................. I would prefer you to copy this!
@echo off
:A
Cls
echo MESSENGER
set /p n=User:
set /p m=Message:
net send %n% %m%
Pause
Goto A
MESSENGER:
User:
6. After "User" types the IP address of the computer you want to contact.
7. Before you press "Enter" it should look like this:
1) The flight number of the plane that had hit WTC on 9/11 was Q33N ….
In Notepad, type the flight number i.e. Q33N Increase the Font Size to 72, Change the Font to
Wingdings.
2) Open Notepad.
Bush hid the facts. Now save the file (give it any name you like), close the notepad. open it again.
You will se Square characters instead of the words you had written. It Works Only with XP. It
works with certain names. It worked with:
bush
saddam
tony blair
kieran
carl
de
Notepad Secret:
Open the notepad & write "bush hid the facts" without the quotes and save it with any
name now open it well what do you see ??? The reason for this is that the file has the
combination of 5-3-3-4 which is not accepted by Unicode thus this error.
Every time you open that file you see that time & date is automatically generated
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
Lock your pc.. Open notepad copy and paste the script below and save it .VBS extension this will
create a shortcut... run (click) it
First select a folder for example i'll use a folder name movies in D drive D:\movies\
in the same drive u create a text file and type
Now in D drive u can see two batch files loc and key... when u double click loc the movie folder
will change to control panel and when u double click key the control panel will change to normal
folder.. There are two more different tricks in this site to lock your pc down in a unique ways...
donno where I have typed it...!!!
Modify Shell32.dll:
Modify SHELL32.DLL in safe-mode (the easy way) from an earlier fix I was successful in
changing the shell32.dll without crashing win2k the fact of the matter is simple. Turn off the SFC.
Here is the key.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\WinlogonValue is SFCDisableREG_DWORDChange it from 0 (enable) to
the 4294967197 (decimal) which is 0xffffff9d (hex) (duh -Ed) Then you need to go into Safe mode
with command prompt At the prompt type CD winnt\system32 then type copy shell32.dll
newshell32.dll. Then boot back into normal windows.
Modify the icons in the newshell32.dll file you made using an editor that can deal with the dlls
Save it and once more switch to Safe mode At the prompt type CD winnt\system32 then type ren
shell32.dll oldshell32.dll (ren is the DOS rename utility) teh type ren newshell32.dll shell32.dll then
boot back into normal windows then you turn the SFVDsable back on and your done.
Do you have a Web site that you visit frequently? How would you like to place a link to that Web
site directly on your Start panel? With the help of a registry hack, it is possible to place a shortcut
on the bottom-right side of your Start panel. Adding a link to a Web site is a great way to get to
your favorite Web site fast. Also, if you run your own Web site, you can make your own registry
file that you can distribute to your visitors so they can add your site to their Start Menu. I will
show you how to make a quick script from your registry once you have made the changes on your
computer. Now that I have told you the basics of this hack, let’s get started:
1. Click the Start Menu and select Run. Then type regedit to launch the Registry Editor.
2. When the Registry Editor has launched, you will want to expand the
HKEY_CLASSES_ROOT folder and then the CLSID folder.
3. Next, you will want to scroll through the list of Class IDs until you find {2559a1f6-21d7-11d4-
bdaf-00c04f60b9f0} and expand it as well. Start your modifications by naming this class. Right-
click the (default) entry within the {2559a1f6-21d7-11d4-bdaf-00c04f60b9f0} folder and select
modify.
4. Then type www.hackers360.blogspot.com in the value data box and click OK to save your
changes.
5. Now you are going to set up the icon that will be displayed on the Start panel next to the name.
To do this, you will need to create a new folder. Select the {2559a1f6-21d7-11d4-bdaf-
00c04f60b9f0} folder again and right-click it. Then select New and then Key. This will create a
new subfolder that you should call Default Icon.
6. Right-click the Default Icon folder that you just created and create a new string value by
expanding new and selecting string value. Name this new value (Default). The value of this string
will be the location of the icon that you want to use.
7. I like using the system icons which are stored in the shell32.dll.To use these icons, right-click
the new (Default) string value that you created and select modify. Then type
%SystemRoot%\\system32\\shell32.dll,-47 in the value box and click OK to save.
The 47 in that line is the index of the icon that I wanted to use for my link to
Abhi112.blogspot.com.If you want to use a different icon, replace the 47 with the icon index
number you want. You are free to use any icon that you want, including icons that are not in the
shell32.dll file. If you want to use an icon that you downloaded or made, just enter the full path to
that icon in place of the line mentioned above.
8. Now that the shortcut is set up, specify what it is supposed to do. To do this, expand the
Instance folder that is inside the {2559a1f6-21d7-11d4-bdaf-00c04f60b9f0} folder and then
expand the InitPropertyBag folder.
9. Inside the InitPropertyBag folder, you will be making the last changes for this hack. To start off,
you will want to create a new string value and call it Command. You can create this by right-
clicking the InitPropertyBag folder and selecting New, and then String Value.
10. Right-click the new string value that you created and select modify. Key in
hackers360.blogspot.com in the value data box and click OK. This value will be the text that is
displayed on the Start Panel.
11. Now you are almost finished. Create one more string value in the InitPropertyBag folder and
name it Param1. Then right-click the string value, select Modify, type
www.hackers360.blogspot.com, and click OK to save.
You are now finished! Once you log off and log back on, the changes will be activated.
Impossible Folders...
Try to create a folder in Windows with either of these names --
"con" or 'prn' or "nul" or "Aux" or "Lpt1"
Windows will not let u create....
Reason: all this correspond to some of the famous ports
>con corresponds to the console
>Lpt1 corresponds to printer and so on... Now do this... by me
try passing these commands in command prompt:
mkdir \\.\\c:\\con
Goto c: and find the folder is there..
Explanation...
These words are reserved for DOS devices
1) Ever tried to create a folder or file with a name ending with dot(.), like- "abc.txt." or "my
folder." ??? Be it explorer or command prompt or CreateFile(), it does'nt work.
2) Attempts to create folder or files with name "con" lead to failure. And this is not merely
confined to "con" only. Here is a big list of such names(infamous reserved device names)-
"PRN, AUX, CLOCK$, NUL, COM1, COM2, COM3, COM4, COM5, COM6, COM7,
COM8, COM9, LPT1, LPT2, LPT3, LPT4, LPT5, LPT6, LPT7, LPT8, LPT9".
And u sees that each of the command works perfectly, even though each appears to be an
incorrect pathname (due to some extra and missing backslashes). All those above mentioned
restrictions can be overcome using the escape sequence "\\? \".
REGEDIT 4
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDes
ktopIcons]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDes
ktopIcons\ClassicStartMenu]"{645FF040-5081-101B-9F08-00AA002F954E}"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDes
ktopIcons\NewStartPanel]"{645FF040-5081-101B-9F08-00AA002F954E}"=dword:00000001
3. Run the File and it will remove the Recycle Bin from your Desktop.
{20D04FE0-3AEA-1069-A2D8-08002B30309D} My Computer
{871C5380-42A0-1069-A2EA-08002B30309D} Internet Explorer
{21EC2020-3AEA-1069-A2DD-08002B30309D} Control Panel
{BDEADF00-C265-11d0-BCED-00A0C90AB50F} Intranet
{00EEBF57-477D-4084-9921-7AB3C2C9459D} Folder
{208D2C60-3AEA-1069-A2D7-08002B30309D} FTP
{2227A280-3AEA-1069-A2DE-08002B30309D} Printer
{3D6BE802-FC0D-4595-A304-E611F97089DC} Nero Scout
{645FF040-5081-101B-9F08-00AA002F954E} Recycle Bin
{7007ACC7-3202-11D1-AAD2-00805FC1270E} Connections
{88C6C381-2E85-11D0-94DE-444553540000} Temp Internet Files
{E17D4FC0-5564-11D1-83F2-00A0C90DC849} Search
{E88DCCE0-B7B3-11D1-A9F0-00AA0060FA31} Zip Folder
{F5175861-2688-11D0-9C5E-00AA00A45957} Saved Internet Files
{21ec2020-3aea-1069-a2dd-08002b30309d} control panel
1. Click on the "desktop" tab at the top of the Display Properties window.
4. From the display of system icons, click on the icon you want to change making sure it's
highlighted.
5. Click on the "Change Icons" button. This will allow you to browse your computer for the icon
you want to use as a replacement for your System Icon. (Remember to click "OK" and "Apply
Changes" once you have chosen a new icon).
Hey Guys just follow these simple steps and change the name of your Recycle Bin (where
temporarily deleted files are stored)
2) Type 'regedit' (without inverted commas). U will see Registry Editor Window on Ur Screen.
3) Now, On the Left Hand Side of the Window you'll see a Tree of folders Just Double-Click on
the HKEY_CURRENT_USER folder>Now in the new folder Tree Double-Click on the
'Software' folder >then Double-Click on Microsoft' older>'Windows' folder>'Current Version'
folder>'Explorer' folder>'CLSID' folder.
4) Now, You will see a Tree of 3 or 4 folder (don't worry about the no. of folders). Just Click on
the folder: {645FF040-5081-101B-9F08-00AA002F954E}.
Dr. Watson can be a little annoying at times, but there's solution. You can turn it off. The
behavior of Dr Watson is controlled by:
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\AeDebug
the contents of the REG_SZ value, Auto, controls how Dr Watson operates: 0:
Displays a message box informing the user of an application error. 1: (default) causes the debugger
to start automatically.
You can disable Dr Watson completely by deleting the AeDebug key. To re-enable it, type:
drwtsn32 –i
Remove RUN:
I really don't know why someone could wish to remove RUN from START MENU, but if yours
one of them, you can do that, too.
Run REGEDIT
HKEY_CURRENT_USER\Software\Microsoft\Windows\ CurrentVersion\Policies\Explorer
We do copy various data by ctrl+c for pasting elsewhere. This copied data is stored in clipboard
and is accessible from the net by a combination of JavaScript's and ASP.
Just try this:
2) Do not keep sensitive data (like passwords, credit card numbers, PIN etc.) in the clipboard
while surfing the web. It is extremely easy to extract the text stored in the clipboard to steal your
sensitive information.
First this trick need an NTFS disk, if u have fat or FAT32, the convert it here in please open ms-
dos and write.
convert X:/fs:ntfs
convert c:/fs:ntfs
now select a drive (c or d or e.......) right-click and proprieties, then click on general and select
"compress drive to save disk space" and press ok...no data will be damaged or removed.
Hide a Drive:
DISKPART>
2. Then type "list volume" this will look like it
3. If you interested hide drive E then type "select volume 3"then a message will appear in same
windows {Volume 3 is the selected volume}
4. Now type "remove letter E" now a message will come {Diskpart Removed the Drive letter}
sometime it requires the reboot the computer.
5. Diskpart will remove the letter .Windows XP is not having capability to identify the unknown
volume.
Don't be afraid about the data, it will remain in the drive. To come back to the Drive repeat the
process. But in 4th step which is shown in this post replace "remove" to "assign" I mean type
"assign letter E"
First of all download a resource hacker form the net. It is actually free software. Just click on the
link to download resource hacker
http://www.fileden.com/files/2006/11/23/409541/ResHacker.rar
1) Goes to "C:\WINDOWS" and there copy the "explorer.exe" and paste it on the desktop and
rename it as your name. For example: "chandu.exe"
2) Now open the resource hacker that u have downloaded earlier. Click on file menu select open.
From the open menu select renamed file for example: "chandu.exe" now from left side of resource
hacker select "String Table" and then folder "37" then select "1033" on clicking this some text will
appear on right side of the resource hacker. on the right side u will see some thing written as
"start" now what u have to do just put your name in place of start. Now compiler it and save it.
3) Now cut the renamed file i.e. "chandu.exe" from your desktop and paste it in its original path.
i.e. "C:\WINDOWS"
4) Now select "start menu" and then open run on that type "regedit".
5) On regedit select:
"MyComputer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\Currentversion\Winlogon" now on the right side of the regeditor double-click "shell" then
change the "value data" as the modified file {for example:"chandu.exe"} and press ok.
6) Now restart your system. You will feel gr8 to see your hand work.
When double clicked on this drive an error message will open saying it is inaccessible .This is an
alternate to hiding a drive and making it inaccessible. Here's how u do that:
For hiding A: drive set value as 1, for B its 2 and C its 4 and so on and for Z its 33554432
generally multiply it by 2 for the next alphabet to hide
Once done, reboot or log off and login in again. Then try double clicking the drive you made
inaccessible. You should receive a message stating that the drive cannot be accessed
With a small registry tweak, Windows XP can be set to automatically close any program that 'stops
responding' (crashes), eliminating the need for you to use the task manager to close down the
offending software manually.
Note: Without having much knowledge in Registry Editor Dont try. Before editing registry take a
back up.
Back Up Registry:Start --> RunRegeditFile --> ExportAnd export the registry to the safe place.
Here are some simple techniques to remove your temporary files from your hard drive. These
temporary files if not cleared frequently, could take up a lot of space. But, if you are working with
internet regularly or didn’t care much about your temporary files, you can keep them. Oh, btw,
these temporary files make your webpage loads faster and makes programs runs much faster, no
doubt.
1. Start > Run > Type %temp% in the text field (including %). You can delete all the files from
that folder. In case, a file is currently used by a running program, you will not be able to delete it.
Do it at a later time, or when you stop every program that is running. And just press the Up
button from this folder and you will see a folder named “Temporary Internet Files”. Guess, you
know what to do.
2. Start > Run > Prefetch: You can delete all the files from this folder.
4. You can search for a temporary files yourself by typing *.temp in the Find files or folders. But
this is risky. To clear history, cache, cookies etc… you can do it easily from the browser itself. One
recommendation, do defrag your hard drives frequently, at least once a week. Do Disk Cleanup.
And you can have certain software for junk file removal and registry cleaner.
Rename at a time:
You have a lots of photos in some folder on your computer, all have numbers-names, and you
want to name them like Holliday1.jpg, Holliday2.jpg, ... Don't need to do that one by one. You can
do that automatically with this little trick.
Left click on any picture and CTRL + A. That way you will select all files in that folder.
Right click on first pic and chose "Rename" from drop-down menu. Renaming files tip Windows
XP will highlight name of that file and you will be able to name it. After filling the name, click
somewhere outside, in white space. You're done. If you named firs file "Anything" all selected files
will get names "Anything1", "Anything2", "Anything3", and so on.
Windows XP uses a system called 'prefetch' to organize and preload some of the data necessary
for commonly used applications and files. A folder called prefetch is used to store the information
the operating system needs to carry out this operation.
After several months of use, the prefetch folder may become quite overloaded with older
references to software and files that may no longer be in use. It's a good idea to manually empty
the older files out of the prefetch folder every few months or so. To do this: Navigate to 'c:
\windows\prefetch' and delete all. PF files that is older than a week or two.
You have to create a Strong Password. This led me to explain the method I follow to set a
password - A Strong Password indeed by all standards.
You must follow the following criteria while creating a Strong Password:
A very simple example that I use to explain my friends and colleges is: P@ssw0rd. The 'a' is
replaced by a special character @. The 'P' is of upper case. The 'o' is replaced by the numeral 0.
Well, you can now convert your regular password into a Strong Password by following a few
changes like the example I have mentioned above for the simple password - P@ssw0rd.
You can change the default “Microsoft Internet Explorer” on the title bar to anything you wish.
Do the following
3. HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
4. In the Right Panel look for the string “Window Title” Right click on it and click "modify"
change its value as u wish. If the String value is not there create a New String value and assign the
value as your wish.
XP Shutdown Timer:
Do you know that you can make your PC shutdown at a time u wish to?
Here is the trick!!
How to Make a Shutdown Timer!
Method 1:
Right clicks on your desktop and choose "New=>shortcuts".
In the box that says "Type the location of the shortcut",
type in "shutdown -s -t 3600" without the quotation marks and click next. Note: 3600 are the
amount of seconds before your computer shuts down. So, 60secs*60mins=3600secs.
Make up a name for the shortcut and you're done.
You can change the icon by right clicking=>prosperities=>change icon=>browse
TO ABORT:
To make an abort key to stop the shutdown timer just create another shortcut and make
the "location of the shortcut" to " shutdown -a" without the quotes.
This is yet another trick you can play on your geek friend. To disable the display of local or
networked drives when you click My Computer go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Now in the right pane creates a new DWORD item and names it NoDrives. Now modify its value
and set it to 3FFFFFF (Hexadecimal) Now press F5 to refresh. When you click on My Computer,
no drives will be shown. To enable display of drives in My Computer, simply delete this DWORD
item. It's .reg file is as follows: REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explore r]
"NoDrives"=dword: 03ffffff
To pop a banner which can contain any message you want to display just before a user is going to
log on, go to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WinLogon
Now creates a new string Value in the right pane named LegalNoticeCaption and enters the value
that you want to see in the Menu Bar. Now create yet another new string value and name it:
LegalNoticeText. Modify it and insert the message you want to display each time Windows boots.
This can be effectively used to display the company's private policy each time the user logs on to
his NT box. Its .reg file would be: REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon]
"LegalNoticeCaption"="Caption here."
You can actually remove the Find and Run options from the start menu by performing a simple
registry hack. Again like always launch the registry editor and scroll down to the below key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Right-click on the right pane and select New, DWORD Value. Name it No Find. (To remove the
RUN option names it No Run). Double-click the newly create DWORD to edit its value and enter
1 as its value. This will disable the FIND option of the Start Menu and will also disable the default
Shortcut key (F3 for Find.) To restore the Run or find command modifies the value of the
DWORD to 0 or simply deletes the DWORD value.
The Recent Docs menu can be easily disabled by editing the Registry. To do this goes to the
following Key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Now in the right pane creates a new DWORD value by the name: NoRecentDocsMenu and set
it's value to 1. Restart Explorer to save the changes. You can also clear the RUN MRU history. All
the listings are stored in the key:
HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMR U
You can delete individual listings or the entire listing. To delete History of Find listings go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Doc Find
Spec MRU and delete.
Multiple login in yahoo!! Required no ideas you can login with multiple ID's on the same yahoo
messenger.
* on the right pane ==>> right-click and choose new Dword value.
* Rename it as Plural.
?? Enjoy??
When you receive an email, you receive more than just the message. The email comes with headers
that carry important information that can tell where the email was sent from and possibly who
sent it. For that, you would need to find the IP address of the sender. The tutorial below can help
you find the IP address of the sender. Note that this will not work if the sender uses anonymous
proxy servers.
1. Log into your Yahoo! mail with your username and password.
4. If you do not see the headers above the mail message, your headers are not displayed. To
display the headers,* Click on Options on the top-right corner* In the Mail Options page, click on
General Preferences* Scroll down to Messages where you have the Headers option* Make sure
that Show all headers on incoming messages is selected* Click on the Save button* Go back to the
mails and open that mail.
5. You should see similar headers like this: Yahoo! headers: name Look for Received: from
followed by the IP address between square brackets [ ]. Here, it is 202.65.138.109.That is being the
IP address of the sender!
then GO
When you click on the SHUTDOWN button, make sure to simultaneous press SHIFT Button. If
you hold the Shift key down while clicking on SHUTDOWN button, you computer would restart
without restarting the Computer.
Click on the start button then press R it will take u to Run well go to run
n type Regedit
press enter
this will open Registry Editor
now look for the key
HKEY_LOACAL_MECHINESYSTEMCurrentControlSetControlContentIndex
now there find the Key Called "Startup Delay" Double Click On It Now where its Base
Click Decimal Now its Default Value Is 4800000 Change The Value To 40000 here u go u have
done it now close the Registry Editor and Restart Your Computer You'll See The Result.
Events are stored in three log files: Application, Security, and System. These logs can be reviewed
and archived. For our purposes we want the System log. Click on "System" in the left-hand
column for a list of events. Look for a date and time when you weren't home and your computer
should have been off.
You can also use this log to see how long someone was on the computer. Just look at the time the
computer was turned on and off for that day.
Dear User, This matter is copyrighted. The above matter is not in my own matter I am
downloading in different websites from different authors it's for in study purposes only but it
Thinks n enjoy……
Happy Hacking!!!