熱門圖片 |
YMSGAnother.rar常見的即時通木馬其它種417 次觀看傻眼..很多這種號稱.scr的
根本就是RAR自解檔
裡面竟然還有MPG檔案- -||
日期跟放在Server上的日期相同
原始木馬下載路徑:
http://www.phonetw.com/photo/20060329_r30334547.scr
http://yahoolove.vicp.net/a.com
http://gangdao1.w67a.chinanetidc.com/ggwe.scr
http://www.phonetw.com/wisdom/image_0976.scr
http://www.yahoo119.net/love.com
http://www.phonetw.com/images/p597446_jpg.scr
http://bbs.taiwan-home.com/photo/r060411_052159.scrjokera
|
|
|
懶人包:那些服貿反對者(故意)忘記告訴你的事.rar懶人包:那些服貿反對者(故意)忘記告訴你的事414 次觀看來源:
http://www.slideshare.net/weiyuchen01/ss-32492655jokera
|
|
|
|
龐克風桌布.rar龐克風桌布,上菜了~412 次觀看敝廢材將其各種Size壓成一包...含
1920x1200
1680x1050
1400x1050
1440x900
1280x1024
1280x960
1280x800
1152x864
1024x768
800x600
PSP 480x272
NDS 256x192jokera
|
|
|
chr_toutakugun.jpg410 次觀看ysboy
|
|
|
|
chr_kakouton.jpg409 次觀看ysboy
|
|
0712_tw_lineage_org_tw.rar0712 即時通木馬本體408 次觀看girls.exe,lEXPRESS.exe,jpg1jpg.exe為本體
會在system32裡生成兩個檔案
23sidfdll.dll及可能的up.exe
dll為執行檔本體後半所脫離出來之程序
目前木馬版本為透過
http://www.spr1t3.com/update.xml
得知仍然為1.5
不過lEXPRESS.exe,jpg1jpg.exe仍為7/3??
注意:
tw.lineage.org.tw及www.spr1t3.com
兩個均為木馬作者的假像網站jokera
|
|
0719_tw_lineage_org_tw.rar0719 即時通木馬本體408 次觀看木馬作者很貼心的都有更新到
所以jpg1jpg.exe = lEXPRESS.exe = photjpg.exe = girls.exe
有其它從同一網站出來的應該都相同
會產生iuxwua86sd3dll.dll
up.exe 23sidfdll.dll(??)
lEXPLORE.exe
附上透過upx decompress的dll
解壓縮後的檔案,暫定為fakedll.dat
裡面可看到不少重要資訊
比如傳送的網站,送信的大概內容,透過的信件主機等等
甚至連即時通所要傳的假訊息都在裡面..
卡巴斯基判斷為Email-Worm.Win32.Chifir.cjokera
|
|
c_junniku.jpg408 次觀看ysboy
|
|
|
1155213080665.jpg407 次觀看ysboy
|
|
|
Standard+Pack1-set-en.pdfDungeon Roll Standard+Pack1 player cards (en)407 次觀看The PDF include standard and Hero Booster Pack #1 cards, and made by Magic Card Creator.
So the Card size will be 6.5x9, suitable for the Magic sleeves.
Besides Nagato Yuki created by myself, others' abilities are same of originals.
This is made for ACG fans and everyone, wish you will love it. :)
sliderliu
|
|
Virtemp08.rar頗糟糕的木馬..407 次觀看wintems.exe - infected by Email-Worm.Win32.Bagle.gi
hidn2.exe - infected by Email-Worm.Win32.Bagle.gm
m_hook.sys - infected by Email-Worm.Win32.Bagle.gm
re_file.exe - OK
flec006.exe - infected by Trojan-Downloader.Win32.Bagle.y
ixnkmdixmpva.exe - infected by Email-Worm.Win32.Bagle.gm
隨著Email傳播,會有一個加密壓縮檔外加一個圖檔
圖檔為壓縮檔的密碼
笨笨的會以為是重要檔案就解開來執行........
ixnkmdixmpva.exe為信件附檔解開來的原始木馬
其它為衍生物及復活檔jokera
|
|
DSCN2085.JPG406 次觀看第二步:
請準備好CPU的序號
從SL6SW那行(含)
以下的全部需要jokera
|
|
|