楼主: wangfeng66
收起左侧

[病毒样本] ESET id 验证网页被挂马

[复制链接]
promised
发表于 2008-10-3 21:00:31 | 显示全部楼层
qianwenxiang
发表于 2008-10-3 21:07:06 | 显示全部楼层

回复 12楼 promised 的帖子

congratulations

崩掉了 不过还是能看出来 万恶的jjyyzmj.cn ..
http://www.jjyyzmj.cn/mm.txt
qianwenxiang
发表于 2008-10-3 21:08:46 | 显示全部楼层
upload

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
fzz8848
头像被屏蔽
发表于 2008-10-3 21:12:14 | 显示全部楼层

回复 14楼 qianwenxiang 的帖子

Begin scan in 'E:\Download\Virus\04.rar'
E:\Download\Virus\04.rar
E:\Download\Virus\04.rar
    [0] Archive type: RAR
    --> 2008-10-3___1198714.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
      --> 2008-10-3___1238138.exe
          [DETECTION] Is the TR/Dropper.Gen Trojan
      --> 2008-10-3___1358350.exe
        [1] Archive type: OVL
        --> Object
          [2] Archive type: RSRC
          --> Object
            [DETECTION] Is the TR/Thief.OnLineGames.thhr Trojan
      --> 2008-10-3___1398655.exe
          [DETECTION] Is the TR/PSW.OnL.BJ.24576 Trojan
    --> 2008-10-3___1429486.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
      --> 2008-10-3___1500904.exe
        [1] Archive type: OVL
        --> Object
          [2] Archive type: RSRC
          --> Object
            [DETECTION] Is the TR/PSW.OnlineGames.ZWI Trojan
      --> 2008-10-3___1650219.exe
        [1] Archive type: OVL
        --> Object
          [2] Archive type: RSRC
          --> Object
            [DETECTION] Is the TR/Thief.OnLineGames.thhr Trojan
      --> 2008-10-3___1667071.exe
        [1] Archive type: OVL
        --> Object
          [2] Archive type: RSRC
          --> Object
            [DETECTION] Is the TR/PSW.OnlineGames.ZWI Trojan
    --> 2008-10-3___2128964.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
      --> 2008-10-3___2266779.exe
        [1] Archive type: OVL
        --> Object
          [2] Archive type: RSRC
          --> Object
            [DETECTION] Is the TR/PSW.OnlineGames.ZWI Trojan
    --> 2008-10-3___2299835.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
    --> 2008-10-3___2408238.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
      --> 2008-10-3___2565289.exe
        [1] Archive type: OVL
        --> Object
          [2] Archive type: RSRC
          --> Object
            [DETECTION] Is the TR/Thief.OnLineGames.thhr Trojan
    --> 2008-10-3___2624164.exe
      [DETECTION] Is the TR/Agent.BHQ Trojan
    --> 2008-10-3___2672064.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
    --> 2008-10-3___2726736.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
    --> 2008-10-3___309439.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
      --> 2008-10-3___454027.exe
        [1] Archive type: OVL
        --> Object
          [2] Archive type: RSRC
          --> Object
            [DETECTION] Is the TR/PSW.OnlineGames.ZWI Trojan
    --> 2008-10-3___458842.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
      --> 2008-10-3___599587.exe
        [1] Archive type: OVL
        --> Object
          [2] Archive type: RSRC
          --> Object
            [DETECTION] Is the TR/PSW.OnlineGames.ZWI Trojan
    --> 2008-10-3___624250.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
      --> 2008-10-3___707698.exe
        [1] Archive type: OVL
        --> Object
          [2] Archive type: RSRC
          --> Object
            [DETECTION] Is the TR/PSW.OnlineGames.tjox Trojan
    --> 2008-10-3___806451.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
    --> 2008-10-3___893614.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
    --> 2008-10-3___95705.exe
      [DETECTION] Is the TR/Dropper.Gen Trojan
      --> a7.css
          [DETECTION] Is the TR/Spy.Gen Trojan
    --> kclg.exe
      [DETECTION] Is the TR/PSW.QQpass.dcg.1 Trojan
    [NOTE]      The file was deleted!
kk12
发表于 2008-10-3 21:57:17 | 显示全部楼层
SEP

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
wangfeng66
 楼主| 发表于 2008-10-3 23:51:33 | 显示全部楼层
怎么没人测试下NOD阿?奇怪了
leonfg
发表于 2008-10-3 23:54:26 | 显示全部楼层
这不是中天在线吗 还以为你说官方网站

34 ALL
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___1005856.exe - probably a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___1165064.exe - Win32/PSW.OnLineGames.NXI trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___1198714.exe - Win32/PSW.Agent.NIA trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___1238138.exe - Win32/PSW.Legendmir.NGG trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___1358350.exe - Win32/PSW.OnLineGames.NRD trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___1398655.exe - a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___1429486.exe - a variant of Win32/TrojanDropper.Agent.NMA trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___1500904.exe - Win32/PSW.OnLineGames.NRD trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___1650219.exe - Win32/PSW.OnLineGames.NRD trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___1667071.exe - Win32/PSW.OnLineGames.NRD trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___1975952.exe - probably a variant of Win32/PSW.Delf.NLZ trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___2103631.exe - a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___2128964.exe - Win32/PSW.Agent.NIA trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___2266779.exe - a variant of Win32/PSW.OnLineGames.NRD trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___2299835.exe - Win32/PSW.Agent.NIA trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___2408238.exe - a variant of Win32/PSW.OnLineGames.NRF trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___2559842.exe - a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___2565289.exe - Win32/PSW.OnLineGames.NRD trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___2624164.exe - a variant of Win32/PSW.OnLineGames.NRF trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___2660110.exe - probably a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___2672064.exe - a variant of Win32/PSW.OnLineGames.NRF trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___2726736.exe - Win32/PSW.Agent.NIA trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___309439.exe - a variant of Win32/PSW.OnLineGames.NRF trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___454027.exe - a variant of Win32/PSW.OnLineGames.NRD trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___458842.exe - a variant of Win32/TrojanDropper.Agent.NMA trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___599587.exe - a variant of Win32/PSW.OnLineGames.NRD trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___624250.exe - a variant of Win32/PSW.OnLineGames.NRF trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___707698.exe - Win32/PSW.OnLineGames.NRD trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___806451.exe - a variant of Win32/PSW.OnLineGames.NRF trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___888418.exe - a variant of Win32/PSW.OnLineGames.NXI trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___893614.exe - Win32/PSW.Agent.NIA trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » 2008-10-3___95705.exe - Win32/PSW.Agent.NIA trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » a7.css - Win32/Agent.OGF trojan
C:\Documents and Settings\GUNDAM\桌面\04.rar » RAR » kclg.exe - Win32/TrojanDownloader.Agent.OCS trojan

[ 本帖最后由 leonfg 于 2008-10-3 23:56 编辑 ]
wangfeng66
 楼主| 发表于 2008-10-4 00:06:30 | 显示全部楼层
我的意思是看NOD进入这个网页的反应。LS的这个是生成物的测试
leonfg
发表于 2008-10-4 00:08:32 | 显示全部楼层
原帖由 wangfeng66 于 2008-10-4 00:06 发表
我的意思是看NOD进入这个网页的反应。LS的这个是生成物的测试

NOD基本无视htm和js。不用试都知道
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-2 06:55 , Processed in 0.099871 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表