Skip to content

Instantly share code, notes, and snippets.

@Albirew
Last active November 14, 2024 18:15
Show Gist options
  • Save Albirew/27fce325d3f54b5023773ee1f61f39a0 to your computer and use it in GitHub Desktop.
Save Albirew/27fce325d3f54b5023773ee1f61f39a0 to your computer and use it in GitHub Desktop.
evolution of a "harmless" troll batch file (see revisions)

FILE MOVED IN IT'S OWN REPOSITORY HERE

@NosabeYT1
Copy link

How can I return my watch to normal?

@Albirew
Copy link
Author

Albirew commented Dec 8, 2019

watch?
if you're asking how to remove yoloV4 from your computer, you need to:

  • boot in fail safe mode
  • delete all bat files located in %appdata%\Microsoft\Windows\Start Menu\Programs\Startup
  • delete all bat files located in %windir%\System32\
  • delete all bat files located in "infected" user's %appdata%
  • delete all bat files located in %allusersprofile%\Microsoft\Windows\Start Menu\Programs\Startup\
  • start regedit and delete these keys if they're pointing to a bat file:
    • HKCU\Software\Microsoft\Windows\CurrentVersion\Run\YourOwnLifeOrganizer
    • HKLM\Software\Microsoft\Windows\CurrentVersion\Run\IgfxTray

@extrazalf
Copy link

Please don't do this. I did it and now my computer is fucked up. If you don't want a fucked up computer please DON'T do this!!

@Albirew
Copy link
Author

Albirew commented Feb 21, 2020

see above post to remove it, but seriously, why in the world would you start a troll file found on the internet on your own volition?
Did someone linked this file saying it was a cure to whatever virus or something?

@extrazalf
Copy link

No i just thought it was a normal batch file but i didn't knew it installed shit in my system

@InfinityDevTech
Copy link

You dont even know what your talking about khyrus

@Albirew
Copy link
Author

Albirew commented Sep 22, 2020

dunno if i should be amazed or ashamed that in 2020, people would still launch some unknown program found on the internet without knowing what does or even checking comments to see if safe or not...

edit: @Kyruhs don't forget the diseases it brings and the way it was used on sept 11...

@InfinityDevTech
Copy link

What is the main purpose of this (besides the nice fake BSOD)?

@Albirew
Copy link
Author

Albirew commented Sep 22, 2020

actually, the fake BSOD is just an excuse for reboot (and to learn batch escape characters)
script was made at first to punish students who go to smoke without locking their computer (i was an IT teacher at that time)
finally, some students evolved it (see code revisions) to make this "armagetroll" version. it was so beautiful that i kept it here. tehee 😜

@InfinityDevTech
Copy link

I did not know you were a teacher. That's PURE GENIOUS. You should have tried to make it USB spreadable so it's even easier and all you had to do was just plug in a USB drive. But still, it must have been funny watching students come back to find their computer has a 'virus'.

@Kyruhs1
Copy link

Kyruhs1 commented Sep 25, 2020

What do you mean "don't forget the diseases it brings and the way it was used on sept 11..."

@Albirew
Copy link
Author

Albirew commented Sep 25, 2020

oh, that was maybe too subtle. i mean this script CANNOT in ANY FUCKING WAY corrupt tokens and files (i mean: what it does is wrote in clear text before the eyes of everyone). If it could, it means it have self-evolved, injected itself in living being creating a bizarre living/binary virus that could infect animals, and at he peak of it's existence, would have even returned to the past to infect planes to self-destruct at 9/11...

@InfinityDevTech
Copy link

InfinityDevTech commented Sep 27, 2020

That was wayyyy to confusing to decode

Something as specific requires some context

@Albirew
Copy link
Author

Albirew commented Sep 27, 2020

well...
everything before empty line is troll batch file creation using escape characters (double percent gives unprocessed simple percent)
almost everything after empty line is just an html webpage created then started fullscreen
last 5 lines should replace AM/PM near clock with custom text and reboot machine
something like this?

@david232143
Copy link

Hey, i hope you are active and could help me. So i started the bat file and thought its just a little joke. I followed all ur steps to remove this harmless malware. Then i found out if i made a screenshot via Microsoft the file was names at the end with "YOLO BATCHMEN". how can i Remove it

@Albirew
Copy link
Author

Albirew commented Apr 22, 2021

Then i found out if i made a screenshot via Microsoft the file was names at the end with "YOLO BATCHMEN". how can i Remove it

ah, it uses the "customized" AM/PM, in a way, i'm glad this work (even if that was supposed to place the "YOLO BatchMan" next to the clock, but since i'm from a country with 24h format, i never saw it)
you may get it fixed by starting a command prompt and pasting these 2 lines in it:

reg add "HKCU\Control Panel\international" /v s1159 /t REG_SZ /d "AM" /f
reg add "HKCU\Control Panel\international" /v s2359 /t REG_SZ /d "PM" /f

@david232143
Copy link

omg thanks for your help, sorry for not replying for so long

@Maple38
Copy link

Maple38 commented Mar 30, 2022

Hey what does this do? I'm putting it on a school library computer regardless, but still kinda curious.

@Albirew
Copy link
Author

Albirew commented Mar 30, 2022

Hey what does this do? I'm putting it on a school library computer regardless, but still kinda curious.

Hey! it puts a fake BSOD (to force user to reboot after batch silent installlation) and change AM/PM to some "yolo batchman" text
it also create a self-replicating batch file (that starts some shit like web browser, notepad, paint and file explorer in a loop) and register it in startup,
Some shit may not work anymore (like the website, i believe it was playing some cursed video in loop at the time) since it was made in 2015 (and for windows 7)

@Miguel-EpicJS
Copy link

lol, should a put this in my school computer

@Maple38
Copy link

Maple38 commented Mar 31, 2022

Hey what does this do? I'm putting it on a school library computer regardless, but still kinda curious.

Hey! it puts a fake BSOD (to force user to reboot after batch silent installlation) and change AM/PM to some "yolo batchman" text it also create a self-replicating batch file (that starts some shit like web browser, notepad, paint and file explorer in a loop) and register it in startup, Some shit may not work anymore (like the website, i believe it was playing some cursed video in loop at the time) since it was made in 2015 (and for windows 7)

Nice perfect for school PCs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment