本帖最后由 fireherman 于 2016-10-3 19:27 编辑
2013-05-15,三年前的东西啊……
ESET 中断连接 and kill (PUA)
[mw_shl_code=css,true]http://14.29.44.201/2032158219/baidu.dnsgslb.c4hcdn.com/file/5a8b6dd9a44e73a5d12b92ea7e5c8ae6?bkt=p-d9a3b68bf9a22f6eb0ec56e2d74192d0&xcode=b22318c2b0eb9d5876d7fe3617616aa77f45afa30a3e85003e2db067c7d4aee3&fid=4228079396-250528-1131535832&time=1475493693&sign=FDTAXGERLBH-DCb740ccc5511e5e8fedcff06b081203-nzNUBLXVT1tsauh9JSY2zPUbFmw=&to=sd&fm=Qin,B,U,t&sta_dx=6373274&sta_cs=33947&sta_ft=zip&sta_ct=7&sta_mt=7&fm2=Qingdao,B,U,t&newver=1&newfm=1&secfm=1&flow_ver=3&pkey=14005a8b6dd9a44e73a5d12b92ea7e5c8ae6c8e73c9a000000613f9a&sl=79364174&expires=8h&rt=sh&r=692297761&mlogid=6419927400792168284&vuk=-&vbdid=1967604620&fin=Thunder.v5.8.14.706.NoAD-Ayu.zip&fn=Thunder.v5.8.14.706.NoAD-Ayu.zip&slt=pm&uta=0&rtype=1&iv=0&isw=0&dp-logid=6419927400792168284&dp-callid=0.1.1&sdk_id=258&csl=100&csign=3jGVYYASHQbhGvneTvxf2DSEuc8= Win32/XunleiHD.A 潜在的不受欢迎应用程序 的变种 连接中断 通过应用程序访问 web 时检测到威胁: C:\Program Files\Mozilla Firefox\firefox.exe.
http://14.29.44.201/2032158219/b ... mp;to=sd&fm=Qin,B,U,t&sta_dx=6373274&sta_cs=33947&sta_ft=zip&sta_ct=7&sta_mt=7&fm2=Qingdao,B,U,t&newver=1&newfm=1&secfm=1&flow_ver=3&pkey=14005a8b6dd9a44e73a5d12b92ea7e5c8ae6c8e73c9a000000613f9a&sl=79364174&expires=8h&rt=sh&r=692297761&mlogid=6419927400792168284&vuk=-&vbdid=1967604620&fin=Thunder.v5.8.14.706.NoAD-Ayu.zip&fn=Thunder.v5.8.14.706.NoAD-Ayu.zip&slt=pm&uta=0&rtype=1&iv=0&isw=0&dp-logid=6419927400792168284&dp-callid=0.1.1&sdk_id=258&csl=100&csign=3jGVYYASHQbhGvneTvxf2DSEuc8= > ZIP > Thunder.v5.8.14.706.NoAD-Ayu.exe Win32/XunleiHD.A 潜在的不受欢迎应用程序 的变种 连接中断
http://14.29.44.201/2032158219/b ... mp;to=sd&fm=Qin,B,U,t&sta_dx=6373274&sta_cs=33947&sta_ft=zip&sta_ct=7&sta_mt=7&fm2=Qingdao,B,U,t&newver=1&newfm=1&secfm=1&flow_ver=3&pkey=14005a8b6dd9a44e73a5d12b92ea7e5c8ae6c8e73c9a000000613f9a&sl=79364174&expires=8h&rt=sh&r=692297761&mlogid=6419927400792168284&vuk=-&vbdid=1967604620&fin=Thunder.v5.8.14.706.NoAD-Ayu.zip&fn=Thunder.v5.8.14.706.NoAD-Ayu.zip&slt=pm&uta=0&rtype=1&iv=0&isw=0&dp-logid=6419927400792168284&dp-callid=0.1.1&sdk_id=258&csl=100&csign=3jGVYYASHQbhGvneTvxf2DSEuc8= > ZIP > Thunder.v5.8.14.706.NoAD-Ayu.exe > NSIS > BHOInstall.exe 正常
http://14.29.44.201/2032158219/b ... mp;to=sd&fm=Qin,B,U,t&sta_dx=6373274&sta_cs=33947&sta_ft=zip&sta_ct=7&sta_mt=7&fm2=Qingdao,B,U,t&newver=1&newfm=1&secfm=1&flow_ver=3&pkey=14005a8b6dd9a44e73a5d12b92ea7e5c8ae6c8e73c9a000000613f9a&sl=79364174&expires=8h&rt=sh&r=692297761&mlogid=6419927400792168284&vuk=-&vbdid=1967604620&fin=Thunder.v5.8.14.706.NoAD-Ayu.zip&fn=Thunder.v5.8.14.706.NoAD-Ayu.zip&slt=pm&uta=0&rtype=1&iv=0&isw=0&dp-logid=6419927400792168284&dp-callid=0.1.1&sdk_id=258&csl=100&csign=3jGVYYASHQbhGvneTvxf2DSEuc8= > ZIP > Thunder.v5.8.14.706.NoAD-Ayu.exe > NSIS > TSearch.exe Win32/XunleiHD.A 潜在的不受欢迎应用程序 的变种 连接中断
http://14.29.44.201/2032158219/b ... mp;to=sd&fm=Qin,B,U,t&sta_dx=6373274&sta_cs=33947&sta_ft=zip&sta_ct=7&sta_mt=7&fm2=Qingdao,B,U,t&newver=1&newfm=1&secfm=1&flow_ver=3&pkey=14005a8b6dd9a44e73a5d12b92ea7e5c8ae6c8e73c9a000000613f9a&sl=79364174&expires=8h&rt=sh&r=692297761&mlogid=6419927400792168284&vuk=-&vbdid=1967604620&fin=Thunder.v5.8.14.706.NoAD-Ayu.zip&fn=Thunder.v5.8.14.706.NoAD-Ayu.zip&slt=pm&uta=0&rtype=1&iv=0&isw=0&dp-logid=6419927400792168284&dp-callid=0.1.1&sdk_id=258&csl=100&csign=3jGVYYASHQbhGvneTvxf2DSEuc8= > ZIP > Thunder.v5.8.14.706.NoAD-Ayu.exe > NSIS > Thunder5.exe Win32/Patched.F 潜在的不安全应用程序 的变种 连接中断
http://14.29.44.201/2032158219/b ... mp;to=sd&fm=Qin,B,U,t&sta_dx=6373274&sta_cs=33947&sta_ft=zip&sta_ct=7&sta_mt=7&fm2=Qingdao,B,U,t&newver=1&newfm=1&secfm=1&flow_ver=3&pkey=14005a8b6dd9a44e73a5d12b92ea7e5c8ae6c8e73c9a000000613f9a&sl=79364174&expires=8h&rt=sh&r=692297761&mlogid=6419927400792168284&vuk=-&vbdid=1967604620&fin=Thunder.v5.8.14.706.NoAD-Ayu.zip&fn=Thunder.v5.8.14.706.NoAD-Ayu.zip&slt=pm&uta=0&rtype=1&iv=0&isw=0&dp-logid=6419927400792168284&dp-callid=0.1.1&sdk_id=258&csl=100&csign=3jGVYYASHQbhGvneTvxf2DSEuc8= > ZIP > Thunder.v5.8.14.706.NoAD-Ayu.exe > NSIS > CloseBox.bmp 压缩文件已损坏 - 文件无法解压。
http://14.29.44.201/2032158219/b ... mp;to=sd&fm=Qin,B,U,t&sta_dx=6373274&sta_cs=33947&sta_ft=zip&sta_ct=7&sta_mt=7&fm2=Qingdao,B,U,t&newver=1&newfm=1&secfm=1&flow_ver=3&pkey=14005a8b6dd9a44e73a5d12b92ea7e5c8ae6c8e73c9a000000613f9a&sl=79364174&expires=8h&rt=sh&r=692297761&mlogid=6419927400792168284&vuk=-&vbdid=1967604620&fin=Thunder.v5.8.14.706.NoAD-Ayu.zip&fn=Thunder.v5.8.14.706.NoAD-Ayu.zip&slt=pm&uta=0&rtype=1&iv=0&isw=0&dp-logid=6419927400792168284&dp-callid=0.1.1&sdk_id=258&csl=100&csign=3jGVYYASHQbhGvneTvxf2DSEuc8= > ZIP > 压缩文件已损坏 [/mw_shl_code]
|