楼主: tophero911
收起左侧

[病毒样本] 发现一个网页木马,有胆的来试试:)

 关闭 [复制链接]
flykiss
发表于 2007-3-22 19:58:39 | 显示全部楼层
我是驱逐舰+SNS没反映啊~~
xpn282
发表于 2007-3-22 20:35:33 | 显示全部楼层
我的天啊!!!!我没打一个补丁..踩上去...IE窗口弹出N多..差点卡死..动都动不了..全靠我把网线拔了...要不然就死机了....还没动它结束..DR.WEB就报了10多个!!!!!!!!!!!!
做这个网站的人真的该死!!!!!!!!!!!



2-03-2007 19:57:22 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\C7IYS30J\haidao[1].exe\123.exe - infected with BackDoor.Pigeon.194
22-03-2007 19:57:22 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\C7IYS30J\haidao[1].exe - infected archive

22-03-2007 19:57:23 [CL] C:\DOCUME~1\xpn\LOCALS~1\Temp\svchost.exe\123.exe - infected with BackDoor.Pigeon.194
22-03-2007 19:57:23 [CL] C:\DOCUME~1\xpn\LOCALS~1\Temp\svchost.exe - infected archive

22-03-2007 19:58:39 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\C7IYS30J\haidao[1].exe - moved
22-03-2007 19:58:44 [CL] C:\DOCUME~1\xpn\LOCALS~1\Temp\svchost.exe - moved

22-03-2007 20:13:37 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\2PG5496L\theopenm[1].htm - infected with VBS.Psyme.239
22-03-2007 20:13:46 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\2PG5496L\theopenm[1].htm - deleted

22-03-2007 20:13:46 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\C7IYS30J\downloader[1].exe - infected with Trojan.DownLoader.14143
22-03-2007 20:13:46 [CL] C:\DOCUME~1\xpn\LOCALS~1\Temp\downloader.exe - infected with Trojan.DownLoader.14143

22-03-2007 20:13:53 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\C7IYS30J\downloader[1].exe - deleted
22-03-2007 20:13:54 [CL] C:\DOCUME~1\xpn\LOCALS~1\Temp\downloader.exe - deleted

22-03-2007 20:14:06 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\C7IYS30J\tianyaa[1].htm - infected with VBS.Psyme.239
22-03-2007 20:14:12 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\C7IYS30J\tianyaa[1].htm - deleted

22-03-2007 20:14:12 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\2PG5496L\lianli[1].htm - infected with VBS.Psyme.239
22-03-2007 20:14:13 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\2PG5496L\lianli[1].htm - deleted

22-03-2007 20:14:13 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\2PG5496L\zhen[1].htm - infected with VBS.Psyme.239
22-03-2007 20:14:14 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\2PG5496L\zhen[1].htm - deleted

22-03-2007 20:14:14 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\0DKNKHOT\set[1].htm - infected with VBS.Psyme.239
22-03-2007 20:14:15 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\0DKNKHOT\set[1].htm - deleted

22-03-2007 20:14:15 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\0DKNKHOT\minglang[1].htm - infected with VBS.Psyme.239
22-03-2007 20:14:15 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\0DKNKHOT\minglang[1].htm - deleted

22-03-2007 20:14:15 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\0DKNKHOT\mng[1].htm - infected with VBS.Psyme.239
22-03-2007 20:14:16 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\0DKNKHOT\mng[1].htm - deleted

22-03-2007 20:14:16 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\0DKNKHOT\miyu1[1].htm - infected with VBS.Psyme.239
22-03-2007 20:14:16 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\0DKNKHOT\miyu1[1].htm - deleted

22-03-2007 20:14:16 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\0DKNKHOT\bind_50077[1].htm - infected with VBS.Psyme.239
22-03-2007 20:14:17 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\0DKNKHOT\bind_50077[1].htm - deleted

22-03-2007 20:14:17 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\0DKNKHOT\165561[1].htm - infected with VBS.Psyme.239
22-03-2007 20:14:18 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\0DKNKHOT\165561[1].htm - deleted

22-03-2007 20:14:18 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\0DKNKHOT\cj[1].exe - infected with Trojan.PWS.Gamania

22-03-2007 20:14:18 [CL] C:\DOCUME~1\xpn\LOCALS~1\Temp\cj.exe - infected with Trojan.PWS.Gamania

22-03-2007 20:14:19 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\0DKNKHOT\cj[1].exe - deleted

22-03-2007 20:14:19 [CL] C:\DOCUME~1\xpn\LOCALS~1\Temp\cj.exe - deleted

22-03-2007 20:14:25 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\UJ676V2H\1238[1].exe - probably infected with DLOADER.Trojan
22-03-2007 20:14:25 [CL] C:\DOCUME~1\xpn\LOCALS~1\Temp\1238.exe - probably infected with DLOADER.Trojan
22-03-2007 20:14:27 [CL] C:\Documents and Settings\xpn\Local Settings\Temporary Internet Files\Content.IE5\UJ676V2H\1238[1].exe - deleted
22-03-2007 20:14:27 [CL] C:\DOCUME~1\xpn\LOCALS~1\Temp\1238.exe - deleted
jlennon
头像被屏蔽
发表于 2007-3-22 20:45:06 | 显示全部楼层

回复 #32 xpn282 的帖子

不打补丁,漏洞当然多啦
风野胤
发表于 2007-3-22 21:11:11 | 显示全部楼层
bd拦了
曲中求
发表于 2007-3-22 22:44:14 | 显示全部楼层
NOD 32:

Time        Module        Object        Name        Threat        Action        User        Information
2007-3-22 22:39:32        IMON        file        http://59.34.197.239/theopenm.js        JS/TrojanDownloader.Agent.CN trojan        Connection terminated        WWW-5688FBC3B6B\love dan       
2007-3-22 22:39:28        IMON        file        http://59.34.197.239/theopenm.asp        VBS/TrojanDownloader.Psyme.DB trojan        Connection terminated        WWW-5688FBC3B6B\love dan       

再进就没有反应了。。。。
tophero911
 楼主| 发表于 2007-3-22 23:48:49 | 显示全部楼层
我刚才又上了下,卡巴和费尔没反映是有过样本纪律免疫了还是没木马了啊

好想有啊 ,那样我的帖子人气就旺了啊
sd5428817
发表于 2007-3-23 00:39:28 | 显示全部楼层
进去一点反应都没有!
tophero911
 楼主| 发表于 2007-3-23 17:45:02 | 显示全部楼层
哈,刚才又试验了,海是有毒,费尔报的哦。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-4-28 20:34 , Processed in 0.101505 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表