查看: 3177|回复: 10
收起左侧

[已鉴定] 病毒网址

 关闭 [复制链接]
majsma
发表于 2008-5-10 17:00:00 | 显示全部楼层 |阅读模式
占用内存太大了,卡死我了,直接下网页下来是一个加密的,看不懂
谁能解析一下?
http://www.wodegezi.cn/gm.htm
http://www.wodegezi.cn/webx.asp
dikex
发表于 2008-5-10 17:09:59 | 显示全部楼层
http://down.wodegezi.cn/down.exe
Exia 该用户已被删除
发表于 2008-5-10 17:12:22 | 显示全部楼层
Starting the file scan:

Begin scan in 'E:\AV\down.exe'
E:\AV\down.exe
      [DETECTION] Is the Trojan horse TR/Downloader.Gen
      [NOTE]      The file was deleted!
爱·妖姬
发表于 2008-5-10 17:13:07 | 显示全部楼层
wodegezi我的鸽子
majsma
 楼主| 发表于 2008-5-10 17:17:57 | 显示全部楼层
噢~噢~下载者,偶运行一下看有啥反应


——————————————————————————
进程里面从1.exe到20.exe挨个运行- -

[ 本帖最后由 majsma 于 2008-5-10 17:20 编辑 ]
冷冷
发表于 2008-5-10 17:38:09 | 显示全部楼层
  1. http://gm.wodegezi.cn/1.exe
  2. http://gm.wodegezi.cn/2.exe
  3. http://gm.wodegezi.cn/3.exe
  4. http://gm.wodegezi.cn/4.exe
  5. http://gm.wodegezi.cn/5.exe
  6. http://gm.wodegezi.cn/6.exe
  7. http://gm.wodegezi.cn/7.exe
  8. http://gm.wodegezi.cn/8.exe
  9. http://gm.wodegezi.cn/9.exe
  10. http://gm.wodegezi.cn/10.exe
  11. http://gm.wodegezi.cn/11.exe
  12. http://gm.wodegezi.cn/12.exe
  13. http://gm.wodegezi.cn/13.exe
  14. http://gm.wodegezi.cn/14.exe
  15. http://gm.wodegezi.cn/15.exe
  16. http://gm.wodegezi.cn/16.exe
  17. http://gm.wodegezi.cn/17.exe
  18. http://gm.wodegezi.cn/18.exe
  19. http://gm.wodegezi.cn/19.exe
  20. http://gm.wodegezi.cn/20.exe
  21. http://gm.wodegezi.cn/21.exe
  22. http://gm.wodegezi.cn/22.exe
复制代码
 
22.exe无法下载 只有21个

[ 本帖最后由 冷冷 于 2008-5-10 17:53 编辑 ]

list.rar

351.63 KB, 下载次数: 72

Exia 该用户已被删除
发表于 2008-5-10 17:51:10 | 显示全部楼层


Starting the file scan:

Begin scan in 'E:\AV\list.rar'
E:\AV\list.rar
E:\AV\list.rar
  [0] Archive type: RAR
    --> 6.exe
      --> Object
        [2] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/Proxy.Xorpix.EN
        --> Object
            [DETECTION] Contains detection pattern of the rootkit RKIT/Agent.aks.1
    --> 7.exe
          [DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
    --> 9.exe
          [DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
    --> 10.exe
          [DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
    --> 11.exe
      --> Object
        [2] Archive type: RSRC
        --> Object
          [3] Archive type: RSRC
          --> Object
              [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.abzd.34
    --> 13.exe
          [DETECTION] Is the Trojan horse TR/Hijacker.Gen
    --> 14.exe
      --> Object
        [2] Archive type: RSRC
        --> Object
            [DETECTION] Is the Trojan horse TR/PSW.OnlineGames.adqz
    --> 19.exe
          [DETECTION] Is the Trojan horse TR/PSW.Online.ddo
    --> 17.exe
          [DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
    --> 20.exe
          [DETECTION] Is the Trojan horse TR/Spy.Gen
    --> 21.exe
          [DETECTION] Is the Trojan horse TR/PSW.Online.ddo
    --> 1.exe
          [DETECTION] Is the Trojan horse TR/PSW.Online.ddo
      [NOTE]      The file was deleted!


End of the scan: 2008年5月10日  18:17
Used time: 00:20 min

The scan has been done completely.

      0 Scanning directories
     22 Files were scanned
     23 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      1 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     -1 Files not concerned
      1 Archives were scanned
      0 Warnings
      1 Notes

[ 本帖最后由 Exia 于 2008-5-10 18:15 编辑 ]
qigang
发表于 2008-5-10 20:12:42 | 显示全部楼层

2/0

RS20.43.52未杀!
qigang
发表于 2008-5-10 20:14:23 | 显示全部楼层

60/23




瑞星病毒查杀结果报告

清除病毒种类列表:
病毒: Trojan.PSW.Win32.SunOnline.nx
病毒: Harm.Win32.AntiSig.a     
病毒: Trojan.PSW.Win32.GameOL.ka
病毒: Trojan.PSW.Win32.GamesOnline.yk
病毒: Trojan.PSW.Win32.GameOL.gau
病毒: Trojan.PSW.Win32.GameOL.nfp
病毒: Trojan.PSW.Win32.GameOL.gbk
病毒: Trojan.PSW.Win32.SunOnline.ny
病毒: RootKit.Win32.Mnless.oe  
病毒: Trojan.DL.Win32.Baser.av
病毒: Trojan.PSW.Win32.GamesOnline.yi
病毒: Trojan.PSW.Win32.QQGame.bz
病毒: Trojan.PSW.Win32.GameOL.im

MAC 地址:00:11:5B:F3:6D:69

用户来源:互联网

软件版本:20.43.52
mingpds
头像被屏蔽
发表于 2008-5-11 10:39:42 | 显示全部楼层
2008-05-11 10:33:37        文件保护(创建文件)     操作:阻止
进程路径:C:\program files\Internet Explorer\IEXPLORE.EXE
文件路径:C:\Documents and Settings\Administrator\Local Settings\Temp\~~.exe
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-16 23:47 , Processed in 0.136381 second(s), 20 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表