瑞星卡卡安全论坛

首页 » 技术交流区 » 反病毒/反流氓软件论坛 » Suspicious.ShellCode.Exploit木马?
ccbrucer - 2009-9-5 14:49:00
我现在电脑上有好几个浏览器,当我用IE8的时候,有时瑞星会拦截一个说是木马的东西,这是瑞星信息:
Address:http://kkam.dns0755.net/370/ff.html
Process accessing current webpage:"C:\Program Files\Internet Explorer\iexplore.exe"
Virus Name: Suspicious.ShellCode.ExploitTop of Form


我试着用腾讯的浏览器时,瑞星也拦截过:
Address:http://kkam.dns0755.net/370/4.htm
Process accessing current webpage:"C:\Program Files\Tencent\TT\bin\TTraveler.exe"
Virus Name: Suspicious.ShellCode.Exploit
Virus source:http://kkam.dns0755.net/e/aa.exe

我用Google chrome时,也有过类似的:

Warning: Visiting this site may harm your computer!
The website at news.qq.com contains elements from the site kkam.dns0755.net, which appears to host malware - software that can hurt your computer or otherwise operate without your consent. Just visiting a site that contains malware can infect your computer.
For detailed information about the problems with these elements, visit the Google Safe Browsing diagnostic page for kkam.dns0755.net.
Learn more about how to protect yourself from harmful software online.

应该是我的电脑中了木马,而不是qq.com。我电脑杀毒也没查出来。网上貌似有人说这是因为IE8的漏洞?希望高手能看看,帮忙解答一下。

用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/4.0; QQDownload 1.7; GTB6; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618; OfficeLiveConnector.1.4; OfficeLivePatch.0.0; CIBA)

附件: SREngLOG.log
lrxyhrm - 2009-9-5 14:53:00
扫SRENG日志发这论坛来

下载最新版本的SRENG工具:http://www.kztechs.com/sreng/download.html
1 下载的是压缩包,必须解压缩后再运行。
2 运行SREng***.EXE
3 选择主界面左边的:智能扫描=》扫描=》保存报告
4 把报告保存后,将日志文件发这论坛来。

建议日志文件以附件形式发来
ccbrucer - 2009-9-5 15:20:00
结果已经上传,多谢了啊:kaka12:
ccbrucer - 2009-9-7 16:36:00
继续期待高手解答~~~
1
查看完整版本: Suspicious.ShellCode.Exploit木马?