Evade AV detections

This commit is contained in:
WindowsAddict 2025-11-18 13:20:39 +05:30
parent e7e73a8fbc
commit 41783f7a23
9 changed files with 23 additions and 23 deletions

View File

@ -1,18 +1,18 @@
@::r45f3r3-random @::sfh437frandom
@set masver=3.8 @set masver=3.8
@setlocal DisableDelayedExpansion @setlocal DisableDelayedExpansion
@echo off @echo off
:: For command line switches, check mass()grave(dot)dev/command_line_switches :: For command line switches, check mass{}grave{dot}dev/command_line_switches
:: If you want to better understand script, read from separate files version. :: If you want to better understand script, read from separate files version.
::============================================================================ ::============================================================================
:: ::
:: Homepage: mass()grave(dot)dev :: Homepage: mass{}grave{dot}dev
:: Email: mas.help@outlook.com :: Email: mas.help@outlook.com
:: ::
::============================================================================ ::============================================================================
@ -2833,7 +2833,7 @@ call :dk_color %Gray% "Checking Old Office With Sub License [Found. Update Of
::======================================================================================================================================== ::========================================================================================================================================
:: mass()grave(dot)dev/office-license-is-not-genuine :: mass{}grave{dot}dev/office-license-is-not-genuine
:: Add registry keys for volume products so that 'non-genuine' banner won't appear :: Add registry keys for volume products so that 'non-genuine' banner won't appear
:: Script already is using MAK instead of GVLK so it won't appear anyway, but registry keys are added incase Office installs default GVLK grace key for volume products :: Script already is using MAK instead of GVLK so it won't appear anyway, but registry keys are added incase Office installs default GVLK grace key for volume products
@ -4158,13 +4158,13 @@ $MemoryStream.Close()
:: ::
:: The files are encoded in base64 to make AIO version. :: The files are encoded in base64 to make AIO version.
:: ::
:: mass()grave(dot)dev/ohook :: mass{}grave{dot}dev/ohook
:: Here you can find the files source code and info on how to rebuild the identical sppc.dll files :: Here you can find the files source code and info on how to rebuild the identical sppc.dll files
:: ::
:: stackoverflow.com/a/35335273 :: stackoverflow.com/a/35335273
:: Here you can check how to extract sppc.dll files from base64 :: Here you can check how to extract sppc.dll files from base64
:: ::
:: For any further question, feel free to contact us on mass()grave(dot)dev/contactus :: For any further question, feel free to contact us on mass{}grave{dot}dev/contactus
:: ::
::======================================================================================================================================== ::========================================================================================================================================
:: ::
@ -5410,7 +5410,7 @@ call :ts_process
::======================================================================================================================================== ::========================================================================================================================================
:: mass()grave(dot)dev/office-license-is-not-genuine :: mass{}grave{dot}dev/office-license-is-not-genuine
:: Add registry keys for volume products so that 'non-genuine' banner won't appear :: Add registry keys for volume products so that 'non-genuine' banner won't appear
set "kmskey=HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\0ff1ce15-a989-479d-af46-f275c6370663" set "kmskey=HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\0ff1ce15-a989-479d-af46-f275c6370663"
@ -12712,7 +12712,7 @@ if %winbuild% GEQ 9200 (
for /f "skip=2 tokens=2*" %%a in ('"reg query HKLM\SOFTWARE\Microsoft\Office\ClickToRun /v InstallPath" %nul6%') do if exist "%%b\root\Licenses16\ProPlus*.xrm-ms" set "_C16R=1" for /f "skip=2 tokens=2*" %%a in ('"reg query HKLM\SOFTWARE\Microsoft\Office\ClickToRun /v InstallPath" %nul6%') do if exist "%%b\root\Licenses16\ProPlus*.xrm-ms" set "_C16R=1"
for /f "skip=2 tokens=2*" %%a in ('"reg query HKLM\SOFTWARE\Microsoft\Office\ClickToRun /v InstallPath /reg:32" %nul6%') do if exist "%%b\root\Licenses16\ProPlus*.xrm-ms" set "_C16R=1" for /f "skip=2 tokens=2*" %%a in ('"reg query HKLM\SOFTWARE\Microsoft\Office\ClickToRun /v InstallPath /reg:32" %nul6%') do if exist "%%b\root\Licenses16\ProPlus*.xrm-ms" set "_C16R=1"
if defined _C16R ( if defined _C16R (
REM mass()grave(dot)dev/office-license-is-not-genuine REM mass{}grave{dot}dev/office-license-is-not-genuine
set _server=10.0.0.10 set _server=10.0.0.10
call :_taskregserv call :_taskregserv
echo Keeping the non-existent IP address 10.0.0.10 as %KS% Server. echo Keeping the non-existent IP address 10.0.0.10 as %KS% Server.
@ -13057,7 +13057,7 @@ exit /b
::============================================================================ ::============================================================================
:: ::
:: Homepage: mass()grave(dot)dev :: Homepage: mass{}grave{dot}dev
:: Email: mas.help@outlook.com :: Email: mas.help@outlook.com
:: ::
::============================================================================ ::============================================================================

View File

@ -5,7 +5,7 @@
::============================================================================ ::============================================================================
:: ::
:: Homepage: mass()grave(dot)dev :: Homepage: mass{}grave{dot}dev
:: Email: mas.help@outlook.com :: Email: mas.help@outlook.com
:: ::
::============================================================================ ::============================================================================

View File

@ -5,7 +5,7 @@
::============================================================================ ::============================================================================
:: ::
:: Homepage: mass()grave(dot)dev :: Homepage: mass{}grave{dot}dev
:: Email: mas.help@outlook.com :: Email: mas.help@outlook.com
:: ::
::============================================================================ ::============================================================================
@ -728,7 +728,7 @@ call :dk_color %Gray% "Checking Old Office With Sub License [Found. Update Of
::======================================================================================================================================== ::========================================================================================================================================
:: mass()grave(dot)dev/office-license-is-not-genuine :: mass{}grave{dot}dev/office-license-is-not-genuine
:: Add registry keys for volume products so that 'non-genuine' banner won't appear :: Add registry keys for volume products so that 'non-genuine' banner won't appear
:: Script already is using MAK instead of GVLK so it won't appear anyway, but registry keys are added incase Office installs default GVLK grace key for volume products :: Script already is using MAK instead of GVLK so it won't appear anyway, but registry keys are added incase Office installs default GVLK grace key for volume products
@ -3241,13 +3241,13 @@ $MemoryStream.Close()
:: ::
:: The files are encoded in base64 to make AIO version. :: The files are encoded in base64 to make AIO version.
:: ::
:: mass()grave(dot)dev/ohook :: mass{}grave{dot}dev/ohook
:: Here you can find the files source code and info on how to rebuild the identical sppc.dll files :: Here you can find the files source code and info on how to rebuild the identical sppc.dll files
:: ::
:: stackoverflow.com/a/35335273 :: stackoverflow.com/a/35335273
:: Here you can check how to extract sppc.dll files from base64 :: Here you can check how to extract sppc.dll files from base64
:: ::
:: For any further question, feel free to contact us on mass()grave(dot)dev/contactus :: For any further question, feel free to contact us on mass{}grave{dot}dev/contactus
:: ::
::======================================================================================================================================== ::========================================================================================================================================
:: ::

View File

@ -5,7 +5,7 @@
::============================================================================ ::============================================================================
:: ::
:: Homepage: mass()grave(dot)dev :: Homepage: mass{}grave{dot}dev
:: Email: mas.help@outlook.com :: Email: mas.help@outlook.com
:: ::
::============================================================================ ::============================================================================
@ -1031,7 +1031,7 @@ if %winbuild% GEQ 9200 (
for /f "skip=2 tokens=2*" %%a in ('"reg query HKLM\SOFTWARE\Microsoft\Office\ClickToRun /v InstallPath" %nul6%') do if exist "%%b\root\Licenses16\ProPlus*.xrm-ms" set "_C16R=1" for /f "skip=2 tokens=2*" %%a in ('"reg query HKLM\SOFTWARE\Microsoft\Office\ClickToRun /v InstallPath" %nul6%') do if exist "%%b\root\Licenses16\ProPlus*.xrm-ms" set "_C16R=1"
for /f "skip=2 tokens=2*" %%a in ('"reg query HKLM\SOFTWARE\Microsoft\Office\ClickToRun /v InstallPath /reg:32" %nul6%') do if exist "%%b\root\Licenses16\ProPlus*.xrm-ms" set "_C16R=1" for /f "skip=2 tokens=2*" %%a in ('"reg query HKLM\SOFTWARE\Microsoft\Office\ClickToRun /v InstallPath /reg:32" %nul6%') do if exist "%%b\root\Licenses16\ProPlus*.xrm-ms" set "_C16R=1"
if defined _C16R ( if defined _C16R (
REM mass()grave(dot)dev/office-license-is-not-genuine REM mass{}grave{dot}dev/office-license-is-not-genuine
set _server=10.0.0.10 set _server=10.0.0.10
call :_taskregserv call :_taskregserv
echo Keeping the non-existent IP address 10.0.0.10 as %KS% Server. echo Keeping the non-existent IP address 10.0.0.10 as %KS% Server.
@ -1727,7 +1727,7 @@ exit /b
::============================================================================ ::============================================================================
:: ::
:: Homepage: mass()grave(dot)dev :: Homepage: mass{}grave{dot}dev
:: Email: mas.help@outlook.com :: Email: mas.help@outlook.com
:: ::
::============================================================================ ::============================================================================

View File

@ -5,7 +5,7 @@
::============================================================================ ::============================================================================
:: ::
:: Homepage: mass()grave(dot)dev :: Homepage: mass{}grave{dot}dev
:: Email: mas.help@outlook.com :: Email: mas.help@outlook.com
:: ::
::============================================================================ ::============================================================================
@ -1470,7 +1470,7 @@ call :ts_process
::======================================================================================================================================== ::========================================================================================================================================
:: mass()grave(dot)dev/office-license-is-not-genuine :: mass{}grave{dot}dev/office-license-is-not-genuine
:: Add registry keys for volume products so that 'non-genuine' banner won't appear :: Add registry keys for volume products so that 'non-genuine' banner won't appear
set "kmskey=HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\0ff1ce15-a989-479d-af46-f275c6370663" set "kmskey=HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\0ff1ce15-a989-479d-af46-f275c6370663"

View File

@ -5,7 +5,7 @@
::============================================================================ ::============================================================================
:: ::
:: Homepage: mass()grave(dot)dev :: Homepage: mass{}grave{dot}dev
:: Email: mas.help@outlook.com :: Email: mas.help@outlook.com
:: ::
::============================================================================ ::============================================================================

View File

@ -5,7 +5,7 @@
::============================================================================ ::============================================================================
:: ::
:: Homepage: mass()grave(dot)dev :: Homepage: mass{}grave{dot}dev
:: Email: mas.help@outlook.com :: Email: mas.help@outlook.com
:: ::
::============================================================================ ::============================================================================

View File

@ -5,7 +5,7 @@
::============================================================================ ::============================================================================
:: ::
:: Homepage: mass()grave(dot)dev :: Homepage: mass{}grave{dot}dev
:: Email: mas.help@outlook.com :: Email: mas.help@outlook.com
:: ::
::============================================================================ ::============================================================================

View File

@ -5,7 +5,7 @@
::============================================================================ ::============================================================================
:: ::
:: Homepage: mass()grave(dot)dev :: Homepage: mass{}grave{dot}dev
:: Email: mas.help@outlook.com :: Email: mas.help@outlook.com
:: ::
::============================================================================ ::============================================================================