<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Eiven     记录生活 励志人生 &#187; 病毒</title>
	<atom:link href="http://eiven.com/tag/%e7%97%85%e6%af%92/feed/" rel="self" type="application/rss+xml" />
	<link>http://eiven.com</link>
	<description>健康、做自己喜欢的事、快乐。</description>
	<lastBuildDate>Fri, 30 Jul 2010 03:25:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>最新病毒播报</title>
		<link>http://eiven.com/2008/11/bingdu1119/</link>
		<comments>http://eiven.com/2008/11/bingdu1119/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 01:18:26 +0000</pubDate>
		<dc:creator>eiven</dc:creator>
				<category><![CDATA[日记]]></category>
		<category><![CDATA[33093 端口]]></category>
		<category><![CDATA[arp]]></category>
		<category><![CDATA[go.qwertyy.cn]]></category>
		<category><![CDATA[UDP 数据包]]></category>
		<category><![CDATA[攻击]]></category>
		<category><![CDATA[木马程序]]></category>
		<category><![CDATA[病毒]]></category>

		<guid isPermaLink="false">http://www.eiven.com/?p=144</guid>
		<description><![CDATA[  为什么最新的病毒总是会出现在我电脑里？ 很郁闷，今天下班之后什么也没做，就研究这个病毒了，只要一打开浏览器，就会出现这个网马，网络一直受到攻击，为此专门下载了防火墙，貌... ]]></description>
			<content:encoded><![CDATA[<p> </p>
<div><span style="font-size: 9pt">为什么最新的病毒总是会出现在我电脑里？</span></div>
<div><span style="font-size: 9pt">很郁闷，今天下班之后什么也没做，就研究这个病毒了，只要一打开浏览器，就会出现这个网马，网络一直受到攻击，为此专门下载了防火墙，貌似一年都没专门下过防火墙用了</span></div>
<div><span style="font-size: 9pt">nod不管用了，卡巴不管用了</span></div>
<div><span style="font-size: 9pt">大家谁有虚拟机抓个样本下来研究下，我电脑虚拟机可能被捆绑了</span></div>
<table style="width: 150pt;" border="1" cellspacing="1" cellpadding="0" width="200" align="left">
<tbody>
<tr>
<td style="border-right: #e9e9e9; padding-right: 0.75pt; border-top: #e9e9e9; padding-left: 0.75pt; padding-bottom: 0.75pt; border-left: #e9e9e9; padding-top: 0.75pt; border-bottom: #e9e9e9; background-color: transparent">
<div><span style="font-size: 9pt; color: #ff0000;">2008-11-18 23:28:16 </span><span style="font-size: 9pt"><span style="color: #ff0000;">http://go.qwertyy.cn/gg.htm</span><span style="color: #ff0000;"> Internet Explorer </span></span><span style="font-size: 9pt; color: #ff0000;">检测到威胁</span> <span style="font-size: 9pt; color: #ff0000;">木马程序</span><span style="font-size: 9pt; color: #ff0000;"> Trojan-Clicker.HTML.IFrame.yo </span><span style="font-size: 9pt; color: #ff0000;">高</span> <span style="font-size: 9pt; color: #ff0000;">精确</span><span style="font-size: 9pt; color: #ff0000;">  </span></div>
</td>
</tr>
</tbody>
</table>
<div> </div>
<div> </div>
<div> </div>
<div><span style="font-size: 9pt">防火墙一直顽抗</span></div>
<div><span style="font-size: 9pt">[22:37:26] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 60.221.210.229 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 33093 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 27447</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:37:26] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 58.252.70.115 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 33093 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 21028</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:37:26] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 63.216.168.163 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 40953 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 43563</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:37:26] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 63.216.168.163 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 14294 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 15300</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:37:27] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 125.46.72.254 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 33093 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 21275</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:50:47] 60.7.198.169</span><span style="font-size: 9pt">试图连接本机的</span><span style="font-size: 9pt">Http[80]</span><span style="font-size: 9pt">端口，</span></div>
<div><span style="font-size: 9pt">           TCP</span><span style="font-size: 9pt">标志：</span><span style="font-size: 9pt">S</span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该操作被拒绝。</span></div>
<div><span style="font-size: 9pt">[22:50:50] 60.7.198.169</span><span style="font-size: 9pt">试图连接本机的</span><span style="font-size: 9pt">Http[80]</span><span style="font-size: 9pt">端口，</span></div>
<div><span style="font-size: 9pt">           TCP</span><span style="font-size: 9pt">标志：</span><span style="font-size: 9pt">S</span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该操作被拒绝。</span></div>
<div><span style="font-size: 9pt">[22:50:52] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 221.11.56.130 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 12543 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 41454</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:50:52] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 119.118.133.164 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 12543 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 24046</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:50:52] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 58.242.167.191 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 12543 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 4194</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:50:52] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 123.185.114.93 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 12543 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 15000</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span><span style="font-size: 9pt">………………………………</span></div>
<div><span style="font-size: 9pt">最终并没有解决这个病毒，还有这个攻击怎么防御，简直郁闷死</span></div>
<div><span style="font-size: 9pt">进一步研究中</span></div>
<div><span style="font-size: 9pt">抓住这小子一定判他妈死刑</span></div>
<div> </div>
<div>进一步研究结果</div>
<div>这个是arp</div>
<div>解决方法如下</div>
<div>先关闭浏览器（一定要关），清空所有浏览器缓存文件，如果是局域网建议安装个好一点的arp防火墙</div>
<div>风云防火墙吧，打开arp保护，看看是局域网中哪台机器中招了在扩散，清理干净他就好了。</div>
<h3  class="related_post_title">您可能对下面内容感兴趣</h3><ul class="related_post"><li><a href="http://eiven.com/2008/05/bingdu/" title="最新病毒报道">最新病毒报道</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://eiven.com/2008/11/bingdu1119/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>最新病毒报道</title>
		<link>http://eiven.com/2008/05/bingdu/</link>
		<comments>http://eiven.com/2008/05/bingdu/#comments</comments>
		<pubDate>Wed, 28 May 2008 09:29:44 +0000</pubDate>
		<dc:creator>eiven</dc:creator>
				<category><![CDATA[更新]]></category>
		<category><![CDATA[最强杀毒软件]]></category>
		<category><![CDATA[最新病毒]]></category>
		<category><![CDATA[病毒]]></category>
		<category><![CDATA[防范病毒]]></category>

		<guid isPermaLink="false">http://www.eiven.com/?p=44</guid>
		<description><![CDATA[在这里提醒大家 这个网站是个病毒网站http://www.51113.com 在我电脑里运行了下载者之类的程序 自动下载http://root.51113.com/root.gif 绝对的病毒 大家注意防范   病毒极为恶劣 重装系统不可以清除 Troj... ]]></description>
			<content:encoded><![CDATA[<p>在这里提醒大家<br />
这个网站是个病毒网站<a href="http://www.51113.com">http://www.51113.com</a><br />
在我电脑里运行了下载者之类的程序<br />
自动下载<a href="http://root.51113.com/root.gif">http://root.51113.com/root.gif</a><br />
绝对的病毒<br />
大家注意防范</p>
<p> </p>
<p>病毒极为恶劣</p>
<p>重装系统不可以清除</p>
<table border="0" cellspacing="0" cellpadding="5" width="100%">
<tbody>
<tr>
<td class="b_bot">Trojan-Downloader.Win32.Agent.vqt</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>22:04</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan-Downloader.Win32.Obfuscated.amx</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>21:57</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan-Downloader.Win32.Obfuscated.amw</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>21:56</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan-Downloader.Win32.Obfuscated.amv</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>21:55</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan-Downloader.Win32.Obfuscated.amu</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>21:55</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan-Downloader.Win32.Obfuscated.amt</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>21:55</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan-Downloader.Win32.Obfuscated.ams</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>21:55</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan.Win32.Obfuscated.jim</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>21:52</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Backdoor.Win32.Hupigon.csgs</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>21:40</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan-Dropper.Win32.Agent.tvc</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>20:52</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">not-a-virus:FraudTool.Win32.PC-AntiSpy.a</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>20:43</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan-GameThief.Win32.Staem.a</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>20:27</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan.Win32.Agent.ttj</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>20:20</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Backdoor.Win32.Hupigon.csgr</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>20:10</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan-Dropper.Win32.Agent.tvb</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>19:54</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan-Downloader.Win32.Agent.vqs</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>19:47</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan.Win32.Agent.tti</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>19:46</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Packed.JS.Agent.n</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>19:41</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan.Win32.Agent.tth</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>19:35</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan-Spy.Win32.Zbot.dbo</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>19:30</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan-Downloader.Win32.Winlagons.yb</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>19:27</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan-Dropper.MSWord.1Table.ga</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>19:25</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Backdoor.Win32.Agent.lzg</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>19:25</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan.Win32.Starter.do</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>19:25</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">not-a-virus:AdWare.Win32.Virtumonde.aagx</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>19:22</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">not-a-virus:AdWare.Win32.Virtumonde.aagw</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>19:22</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan.Win32.Pakes.jsb</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>19:21</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan.Win32.Agent.ttg</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>18:49</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Worm.Win32.AutoRun.ejv</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>18:48</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
<tr>
<td class="b_bot">Trojan-Banker.BAT.Qhost.b</td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"><strong>18:45</strong></td>
<td class="b_bot" align="center" bgcolor="#f5f5f5"> </td>
</tr>
</tbody>
</table>
<h3  class="related_post_title">您可能对下面内容感兴趣</h3><ul class="related_post"><li><a href="http://eiven.com/2008/11/bingdu1119/" title="最新病毒播报">最新病毒播报</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://eiven.com/2008/05/bingdu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
