1、IIS日志文件
2009-09-10 20:40:16 222.245.211.231 - W3SVC154 IIS514 96.0.100.151 80 POST /include/UpFileSave.asp |-|0|404_Not_Found 302 0 203 1512 375 HTTP/1.1 - ASPSESSIONIDQCBRCRBD=PPCOJMLBFOEBIJNCJLNIAPCM;+KS6wwwxxsemcom=PowerList=0&SuperTF=1&AdminName=admin&AdminPass=5c3a646ebc42cd13&RndPassword=xrd3qfw%2DonXGoDJlOjSX&SkinID=1&ModelPower=%2C%2C%2C%2C%2C%2C%2C%2C%2C&AdminLoginCode=2917&Password=469e80d32c0559f8&UserName=admin http://www.xxsem.com/include/UpFileSave.asp
2009-09-10 20:40:17 222.245.211.231 - W3SVC154 IIS514 96.0.100.151 80 GET /404.htm 404;http://www.xxsem.com/include/UpFileSave.asp 200 0 761 670 0 HTTP/1.1 - ASPSESSIONIDQCBRCRBD=PPCOJMLBFOEBIJNCJLNIAPCM;+KS6wwwxxsemcom=PowerList=0&SuperTF=1&AdminName=admin&AdminPass=5c3a646ebc42cd13&RndPassword=xrd3qfw%2DonXGoDJlOjSX&SkinID=1&ModelPower=%2C%2C%2C%2C%2C%2C%2C%2C%2C&AdminLoginCode=2917&Password=469e80d32c0559f8&UserName=admin http://www.xxsem.com/include/UpFileSave.asp
2009-09-10 20:40:20 222.245.211.231 - W3SVC154 IIS514 96.0.100.151 80 POST /include/UpFileSave.asp |-|0|404_Not_Found 302 0 203 1497 375 HTTP/1.1 - ASPSESSIONIDQCBRCRBD=PPCOJMLBFOEBIJNCJLNIAPCM;+KS6wwwxxsemcom=PowerList=0&SuperTF=1&AdminName=admin&AdminPass=5c3a646ebc42cd13&RndPassword=xrd3qfw%2DonXGoDJlOjSX&SkinID=1&ModelPower=%2C%2C%2C%2C%2C%2C%2C%2C%2C&AdminLoginCode=2917&Password=469e80d32c0559f8&UserName=admin http://www.xxsem.com/include/UpFileSave.asp
2009-09-10 20:40:21 222.245.211.231 - W3SVC154 IIS514 96.0.100.151 80 GET /404.htm 404;http://www.xxsem.com/include/UpFileSave.asp 200 0 761 670 0 HTTP/1.1 - ASPSESSIONIDQCBRCRBD=PPCOJMLBFOEBIJNCJLNIAPCM;+KS6wwwxxsemcom=PowerList=0&SuperTF=1&AdminName=admin&AdminPass=5c3a646ebc42cd13&RndPassword=xrd3qfw%2DonXGoDJlOjSX&SkinID=1&ModelPower=%2C%2C%2C%2C%2C%2C%2C%2C%2C&AdminLoginCode=2917&Password=469e80d32c0559f8&UserName=admin http://www.xxsem.com/include/UpFileSave.asp
2、你被挂的网站名称
上传程序后还没建站.....都没逃过
3、网站网址
http://www.xxsem.com/
4、你的联系人/联系电话/QQ等
邮箱 xxsem@qq.com
挂马IP 222.245.211.231