July 22, 2007

Kugoo竟然会带毒,无语.[追查出病毒来源]

病毒样本 及 病毒的目标下载文件脱壳后的文件.. http://www.nov30th.com/blog/upload/kugoo_virus.rar 习惯性打开抓包工具,再开kugoo,以碰运气是否在能碰到那个木马文件.果然.被我逮到. P265   Packet Info  Flags:                0x00000000  Status:               0x00000001  Packet Length:        819  Timestamp:            14:58:35.060506000 07/22/2007 Ethernet Header  Destination:          00:19:D2:65:FB:93  Source:               00:19:5B:DB:65:74  Protocol Type:        0x0800 IP IP Header – Internet Protocol Datagram  Version:              4  Header Length:        5 (20 bytes)  Differentiated Services:%00000000                         0000 00.. Default                         …. ..00 Not-ECT...