查看: 3093|回复: 7
收起左侧

[病毒样本] 脚本病毒,BD,360,AVAST,AVG PASS

[复制链接]
VISN
发表于 2008-8-3 06:38:16 | 显示全部楼层 |阅读模式
AhnLab-V32008.7.29.12008.08.02VBS/Codebaseexec
AntiVir7.8.1.152008.08.01EXP/HTML.CodeBaseExec.107
Authentium5.1.0.42008.08.01JS/MS05013
Avast4.8.1195.02008.08.02VBS:Malware-gen
AVG8.0.0.1562008.08.02-
BitDefender7.22008.08.02-
CAT-QuickHeal9.502008.08.02-
ClamAV0.93.12008.08.02Exploit.MS05-013
DrWeb4.44.0.091702008.08.02-
eSafe7.0.17.02008.07.29-
eTrust-Vet31.6.60022008.08.02-
Ewido4.02008.08.02Not-A-Virus.Exploit.HTML.CodeBaseExec
F-Prot4.4.4.562008.08.01JS/MS05013
F-Secure7.60.13501.02008.08.02Exploit.HTML.CodeBaseExec
Fortinet3.14.0.02008.08.02JS/CodeBaseExec.B!exploit
GData2.0.7306.10232008.08.02Exploit.HTML.CodeBaseExec
IkarusT3.1.1.34.02008.08.02Exploit.HTML.CodeBaseExec
K7AntiVirus7.10.4022008.08.02-
Kaspersky7.0.0.1252008.08.03Exploit.HTML.CodeBaseExec
McAfee53522008.08.01-
Microsoft1.38072008.08.03Exploit:JS/MS05013.A
NOD32v233192008.08.02HTML/Exploit.CodeBaseExec
Norman5.80.022008.08.01-
Panda9.0.0.42008.08.02Bck/Hupigon.AZG
PCTools4.4.2.02008.08.02-
Prevx1V22008.08.03-
Rising20.55.42.002008.08.02Hack.Exploit.HTML.IESpoof.a
Sophos4.31.02008.08.02-
Sunbelt3.1.1537.12008.08.01-
Symantec102008.08.03Hacktool
TheHacker6.2.96.3922008.08.02-
TrendMicro8.700.0.10042008.08.01HTML_CODEBASE.CP
VBA323.12.8.22008.08.02Exploit.HTML.CodeBaseExec
ViRobot2008.8.1.13212008.08.01-
VirusBuster4.5.11.02008.08.02-
Webwasher-Gateway6.6.22008.08.02Exploit.HTML.CodeBaseExec.107
yeandwo
发表于 2008-8-3 08:40:00 | 显示全部楼层
avast明明扫到了。怎么说PASS,
电影结束了
发表于 2008-8-3 09:37:09 | 显示全部楼层
Exploit.HTML.CodeBaseExec(KAV引擎)
Palkia
发表于 2008-8-3 10:06:17 | 显示全部楼层
病毒        2008-08-03  10:05:29        C:\Documents and Settings\Administrator\桌面\cookiepop.rar\cookiepop.js        JS.CodeBaseExec.va.1950        跳过,未处理
6466336
发表于 2008-8-3 10:18:24 | 显示全部楼层
下个试试
qigang
发表于 2008-8-3 12:43:46 | 显示全部楼层

2/1

瑞星病毒查杀结果报告

清除病毒种类列表:

病毒: Hack.Exploit.HTML.IESpoof.a

MAC 地址:00:11:5B:F3:6D:69

用户来源:互联网

软件版本:20.55.60
qigang
发表于 2008-8-3 12:44:58 | 显示全部楼层

报哪一行?

//function openwin()
//{
//window.showModelessDialog("/www.thethirdmedia.com.htm","scroll:0;status:0;help:0;resizable:1;dialogWidth:10px;dialogHeight:10px")
//}

function shellscript()
{
   var now = new Date();
   var sec = now.getSeconds();
   var poll = sec % 3;
   var popurl = "";
   if(poll == 0)
   {
          popurl = "http://www.singbomb.com/hotsingerpp.htm";
   }
   else
   {
          popurl = "http://www.thethirdmedia.com/pc/pjbj/";
   }
        window.focus();
        open(popurl,"_blank","scrollbar=no");
}

function openwinaction()
{       
  try
  {
        ;
  }
  catch(exception){;}
}

function openwin()
{
        var xssdom = '<object id="x11111" classid="clsid:2D360201-FFF5-11d1-8D03-00A0C959BC0A" width="1" height="1" align="middle"></object>';
        xpop.innerHTML = xssdom;//document.write(xssdom);

        //xssdom.ActivateApplets = "1";
        //xssdom.ActivateActiveXControls = "1";
        setTimeout('openwinaction()','500');
}



function getCookie(cookiename)
{
        var cookiestring=""+document.cookie;
        var index1=cookiestring.indexOf(cookiename);
       
        if (index1==-1 || cookiename=="") return "";
       
        var index2=cookiestring.indexOf(';',index1);
        if (index2==-1) index2=cookiestring.length;
        //return unescape(cookiestring.substring(index1+cookiename.length+1,index2));
       
        var rvalue = unescape(cookiestring.substring(index1 + cookiename.length + 1 , index2));
       
        return rvalue;
}




function newcookie(id,value,idinteral)
{
        var expires=new Date();       
        expires.setTime(expires.getTime()+ idinteral*60*1000);//idintreal * 60s       
        var expiryDate=expires.toGMTString();
        document.cookie=id+"="+value+";path=/;expires="+expiryDate;//放置到根
        //alert(document.cookie);
}

function loadpopup()
{
if (getCookie("xbtAlerted")=="")
{
  newcookie("xbtAlerted","yes",60);
  //openwin();
}
else
  {}
}
尤金卡巴斯基
发表于 2008-8-3 12:47:08 | 显示全部楼层
检测到:木马程序 Exploit.HTML.CodeBaseExec        URL: http://bbs.kafan.cn/attachment.p ... 38775//cookiepop.js
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-6 21:34 , Processed in 0.138893 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表