查看: 3949|回复: 14
收起左侧

[已鉴定] 召唤HUNTERS

 关闭 [复制链接]
qianwenxiang
发表于 2008-2-22 23:31:13 | 显示全部楼层 |阅读模式
好多....解不下去了....

http://allyes.shangdu.com/main/adfshow?user=sd_ad|shangdu1|fuchengzuo&db=sd_ad&border=0&local=yes&js=ie
>http://xxx.aishengho.com/2.htm
>>http://ddd.chsip.net/ww/js.js
>>>http://iii.chsip.net/cat.exe
>>http://ddd.chsip.net/ww/ed.htm
>>>http://ppp.chsip.net/wm/lz.js
>>>http://ppp.chsip.net/wm/ppp.js
>>>http://ppp.chsip.net/wm/bb.js
>>>http://ppp.chsip.net/wm/11.js

>http://allyes.shangdu.com/main/adfclick?user=sd_ad|shangdu1|fuchengzuo&db=sd_ad&log=on&ip=60.167.210.173&bid=883&cid=169719&sid=1900&kv=&exp1=-180866706&exp2=6738864793&cache=440574&url=http://www.dfnzhp.com/
>>http://OffIce.FAQServ.CoM/FAQ.js
>>>http://www.59.vc/page/add_54738542.htm
>>>>http://www.59.vc/page/addr.js
>>>>>hxxp://w18.vg/baidu.gif
>>>>>hxxp://w18.vg/bf.gif (404)
>>>>>hxxp://w18.vg/ms.gif
>>>>>hxxp://w18.vg/real.gif
>>>>>hxxp://w18.vg/lz.gif
>>>>>hxxp://w18.vg/xl.gif

>>>http://office.faqserv.com/faq.htm (clear)
tanlimo
发表于 2008-2-22 23:37:43 | 显示全部楼层
一看就没兴趣了
深红的雪
发表于 2008-2-23 00:06:17 | 显示全部楼层

回复 1楼 qianwenxiang 的帖子

这么乱,怎么不整理一下

貌似都是旧的
深红的雪
发表于 2008-2-23 00:12:36 | 显示全部楼层
Log is generated by FreShow.
[wide]http://allyes.shangdu.com/main/adfshow?user=sd_ad|shangdu1|fuchengzuo&db=sd_ad&border=0&local=yes&js=ie
    [frame]http://xxx.aishengho.com/2.htm
        [script]http://ddd.chsip.net/ww/js.js
            [object] http://iii.chsip.net/cat.exe
        [frame]http://ddd.chsip.net/ww/ed.htm
            [script]http://ppp.chsip.net/wm/11.js
                [object] http://iii.chsip.net/down.exe
            [script]http://ppp.chsip.net/wm/bb.js
                [object] http://iii.chsip.net/down.exe
            [script]http://ppp.chsip.net/wm/ppp.js
                [object] http://iii.chsip.net/down.exe
            [script]http://ppp.chsip.net/wm/lz.js
                [object] http://qqq.521town.com/down.exe


hxxp://w18.vg/baidu.gif
>>  http://w18.vg/calc.cab

>>>>>hxxp://w18.vg/bf.gif
>>>>>hxxp://w18.vg/ms.gif
>>>>>hxxp://w18.vg/real.gif
>>>>>hxxp://w18.vg/lz.gif
>>>>>hxxp://w18.vg/xl.gif
都是这个: http://w18.vg/s.exe

[ 本帖最后由 rappar 于 2008-2-23 00:16 编辑 ]
will
发表于 2008-2-23 00:49:02 | 显示全部楼层
Log is generated by FreShow.
[wide]http://xxx.aishengho.com/2.htm
    [script]http://ddd.chsip.net/ww/js.js
        [object]http://iii.chsip.net/cat.exe
    [frame]http://ddd.chsip.net/ww/ed.htm
        [script]http://ppp.chsip.net/wm/11.js
            [object]http://iii.chsip.net/down.exe
        [script]http://ppp.chsip.net/wm/bb.js
            [object]http://iii.chsip.net/down.exe
        [script]http://ppp.chsip.net/wm/ppp.js
            [object]http://iii.chsip.net/down.exe
        [script]http://ppp.chsip.net/wm/lz.js
            [object]http://qqq.521town.com/down.exe


Log is generated by FreShow.
[wide]http://www.59.vc/page/addr.js
    [frame]http://w18.vg/baidu.gif
        [object]http://w18.vg/calc.cab
    [frame]http://w18.vg/bf.gif
    [frame]http://w18.vg/ms.gif
        [object]http://w18.vg/s.exe
    [frame]http://w18.vg/real.gif
        [object]http://w18.vg/s.exe
    [frame]http://w18.vg/lz.gif
        [object]http://w18.vg/s.exe
    [frame]http://w18.vg/xl.gif
        [object]http://w18.vg/s.exe
will
发表于 2008-2-23 00:56:10 | 显示全部楼层

上面挂的马中去除重复的就只剩3个~ 打包上传在此

C:\Documents and Settings\Administrator\Desktop\Samples\Sample_Store\WM\cat.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Delf.epw.1
C:\Documents and Settings\Administrator\Desktop\Samples\Sample_Store\WM\max.exe
      [DETECTION] Is the Trojan horse TR/Dropper.Gen
C:\Documents and Settings\Administrator\Desktop\Samples\Sample_Store\WM\s.exe
      [DETECTION] Is the Trojan horse TR/Dldr.Tiny.aid



2008-02-23_005529.png

WM.zip

42.74 KB, 下载次数: 68

傻猪猪米走鸡
发表于 2008-2-23 00:59:54 | 显示全部楼层
E:\virus\WM.zip » ZIP » WM/cat.exe - Win32/TrojanDownloader.Delf.EPW trojan - was a part of the deleted object
E:\virus\WM.zip » ZIP » WM/max.exe - a variant of Win32/Jalous worm - was a part of the deleted object
E:\virus\WM.zip » ZIP » WM/s.exe - Win32/TrojanDownloader.Tiny.Y trojan - was a part of the deleted object
E:\virus\WM.zip - multiple threats - deleted - quarantined
wolffshen
发表于 2008-2-23 01:00:26 | 显示全部楼层
FS结果: 找到 3 恶意软件
Trojan-Downloader:W32/Agent.FWK (病毒)
D:\Virus\Test\cat.exe 操作: 删除
Worm.Win32.Downloader.eu (病毒)
D:\Virus\Test\max.exe 操作: 删除
Trojan-Downloader.Win32.Tiny.aid (病毒)
D:\Virus\Test\s.exe 操作: 删除
will
发表于 2008-2-23 01:05:12 | 显示全部楼层

附上 avast! & Kaspersky

Aavst! Found 2
Sign of "Win32:Downloader-RR [Wrm]" has been found in "WM\max.exe\[Upack]\[Embedded#03008]\[Embedded#08008]" file.  
Sign of "Win32:Tiny-NK [Trj]" has been found in "WM\s.exe\[Upack]" file.

Kaspersky Found 3
detected: Trojan program Trojan-Downloader.Win32.Delf.epw File:WM\cat.exe//PE_Patch//UPack
detected: virus Worm.Win32.Downloader.eu                 File:WM\max.exe//PE_Patch//UPack
detected: Trojan program Trojan-Downloader.Win32.Tiny.aid File:WM\s.exe//PE_Patch//UPack
mofunzone
发表于 2008-2-23 03:56:39 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Documents and Settings\Administrator\My Documents\WM.zip'
C:\Documents and Settings\Administrator\My Documents\
  WM.zip
    [0] Archive type: ZIP
      --> WM/cat.exe
        [1] Archive type: Runtime Packed
        --> Object
          [2] Archive type: RSRC
          --> Object
              [DETECTION] Is the Trojan horse TR/Dldr.Delf.epw.1
              [WARNING]   Infected files in archives cannot be repaired!
      --> WM/max.exe
        [1] Archive type: Runtime Packed
        --> Object
    --> WM/s.exe
        [DETECTION] Is the Trojan horse TR/Dldr.Tiny.aid
        [WARNING]   Infected files in archives cannot be repaired!
      [WARNING]   The file was ignored!
  WM.zip:Zone.Identifier


End of the scan: 2008年2月22日  11:56
Used time: 00:06 min

The scan has been done completely.

      0 Scanning directories
      5 Files were scanned
      3 viruses and/or unwanted programs were found
      1 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
      2 Files not concerned
      2 Archives were scanned
      3 Warnings
      0 Notes
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-16 18:41 , Processed in 0.143009 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表