本帖最后由 超超~.~ 于 2016-10-22 14:08 编辑
之前问了这个问题,现在重新编辑一下,再次提问。电脑:win10 14393.321 64位 ,诺顿:NS进阶版。总是被同一个网址的不同IP攻击。大神们给看看
类别: 入侵防护
日期和时间,风险,活动,状态,推荐的操作,IPS 警报名称,默认操作,采取的操作,攻击电脑,攻击者网址,目标地址,源地址,通信说明
2016/10/22 13:42:25,高,阻止了 stat.funshion.net 的入侵企图,已阻止,不需要操作,System Infected: Adware.Funshion Activity,不需要操作,不需要操作,"stat.funshion.net (220.181.178.210, 80)","stat.funshion.net/tools/fun_vasd?rprotocol=1*_*clientFlag=3*_*fck=*_*mac=*_*userid=*_*browser=Mozilla%2F5.0%20(Windows%20NT%2010.0%3B%20WOW64%3B%20Trident%2F7.0%3B%20rv%3A11.0)%20like%20Gecko*_*source=2*_*url=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-302211.v-820029*_*ref=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-302211.v-820029*_*info=","DESKTOP-M01B365 (115.24.164.134, 56337)",stat.funshion.net (220.181.178.210),"TCP, www-http"
来自 <b>stat.funshion.net/tools/fun_vasd?rprotocol=1*_*clientFlag=3*_*fck=*_*mac=*_*userid=*_*browser=Mozilla%2F5.0%20(Windows%20NT%2010.0%3B%20WOW64%3B%20Trident%2F7.0%3B%20rv%3A11.0)%20like%20Gecko*_*source=2*_*url=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-302211.v-820029*_*ref=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-302211.v-820029*_*info=</b> 的网络通信与已知攻击的特征相匹配。攻击由 \DEVICE\HARDDISKVOLUME2\PROGRAM FILES (X86)\ADSAFE\ADSAFE.EXE 引起。 要停止接收有关此类通信的通知,请在<b>“操作”</b>面板中单击<b>“不再提醒我”</b>。
类别: 入侵防护
日期和时间,风险,活动,状态,推荐的操作,IPS 警报名称,默认操作,采取的操作,攻击电脑,攻击者网址,目标地址,源地址,通信说明
2016/10/21 9:27:17,高,阻止了 stat.funshion.net 的入侵企图,已阻止,不需要操作,System Infected: Adware.Funshion Activity,不需要操作,不需要操作,"stat.funshion.net (220.181.178.216, 80)","stat.funshion.net/tools/fun_vasd?rprotocol=1*_*clientFlag=3*_*fck=*_*mac=*_*userid=*_*browser=Mozilla%2F5.0%20(Windows%20NT%2010.0%3B%20WOW64%3B%20Trident%2F7.0%3B%20rv%3A11.0)%20like%20Gecko*_*source=2*_*url=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-25862.v-257004*_*ref=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-25862.v-257004*_*info=","DESKTOP-M01B365 (115.24.164.134, 64731)",stat.funshion.net (220.181.178.216),"TCP, www-http"
来自 <b>stat.funshion.net/tools/fun_vasd?rprotocol=1*_*clientFlag=3*_*fck=*_*mac=*_*userid=*_*browser=Mozilla%2F5.0%20(Windows%20NT%2010.0%3B%20WOW64%3B%20Trident%2F7.0%3B%20rv%3A11.0)%20like%20Gecko*_*source=2*_*url=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-25862.v-257004*_*ref=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-25862.v-257004*_*info=</b> 的网络通信与已知攻击的特征相匹配。攻击由 \DEVICE\HARDDISKVOLUME2\PROGRAM FILES (X86)\ADSAFE\ADSAFE.EXE 引起。 要停止接收有关此类通信的通知,请在<b>“操作”</b>面板中单击<b>“不再提醒我”</b>。
类别: 入侵防护
日期和时间,风险,活动,状态,推荐的操作,IPS 警报名称,默认操作,采取的操作,攻击电脑,攻击者网址,目标地址,源地址,通信说明
2016/10/20 17:22:41,高,阻止了 stat.funshion.net 的入侵企图,已阻止,不需要操作,System Infected: Adware.Funshion Activity,不需要操作,不需要操作,"stat.funshion.net (220.181.178.215, 80)","stat.funshion.net/tools/fun_vasd?rprotocol=1*_*clientFlag=3*_*fck=*_*mac=*_*userid=*_*browser=Mozilla%2F5.0%20(Windows%20NT%2010.0%3B%20WOW64%3B%20Trident%2F7.0%3B%20rv%3A11.0)%20like%20Gecko*_*source=2*_*url=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-114775.v-431368*_*ref=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-114775.v-431368*_*info=","DESKTOP-M01B365 (115.24.164.134, 50324)",stat.funshion.net (220.181.178.215),"TCP, www-http"
来自 <b>stat.funshion.net/tools/fun_vasd?rprotocol=1*_*clientFlag=3*_*fck=*_*mac=*_*userid=*_*browser=Mozilla%2F5.0%20(Windows%20NT%2010.0%3B%20WOW64%3B%20Trident%2F7.0%3B%20rv%3A11.0)%20like%20Gecko*_*source=2*_*url=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-114775.v-431368*_*ref=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-114775.v-431368*_*info=</b> 的网络通信与已知攻击的特征相匹配。攻击由 \DEVICE\HARDDISKVOLUME2\PROGRAM FILES (X86)\ADSAFE\ADSAFE.EXE 引起。 要停止接收有关此类通信的通知,请在<b>“操作”</b>面板中单击<b>“不再提醒我”</b>。
类别: 入侵防护
日期和时间,风险,活动,状态,推荐的操作,IPS 警报名称,默认操作,采取的操作,攻击电脑,攻击者网址,目标地址,源地址,通信说明
2016/10/19 12:38:34,高,阻止了 stat.funshion.net 的入侵企图,已阻止,不需要操作,System Infected: Adware.Funshion Activity,不需要操作,不需要操作,"stat.funshion.net (220.181.178.215, 80)","stat.funshion.net/tools/fun_vasd?rprotocol=1*_*clientFlag=3*_*fck=*_*mac=*_*userid=*_*browser=Mozilla%2F5.0%20(Windows%20NT%2010.0%3B%20WOW64%3B%20Trident%2F7.0%3B%20rv%3A11.0)%20like%20Gecko*_*source=2*_*url=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-106910.v-335702*_*ref=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-106910.v-335702*_*info=","DESKTOP-M01B365 (115.24.164.134, 54876)",stat.funshion.net (220.181.178.215),"TCP, www-http"
来自 <b>stat.funshion.net/tools/fun_vasd?rprotocol=1*_*clientFlag=3*_*fck=*_*mac=*_*userid=*_*browser=Mozilla%2F5.0%20(Windows%20NT%2010.0%3B%20WOW64%3B%20Trident%2F7.0%3B%20rv%3A11.0)%20like%20Gecko*_*source=2*_*url=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-106910.v-335702*_*ref=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-106910.v-335702*_*info=</b> 的网络通信与已知攻击的特征相匹配。攻击由 \DEVICE\HARDDISKVOLUME2\PROGRAM FILES (X86)\ADSAFE\ADSAFE.EXE 引起。 要停止接收有关此类通信的通知,请在<b>“操作”</b>面板中单击<b>“不再提醒我”</b>。
类别: 入侵防护
日期和时间,风险,活动,状态,推荐的操作,IPS 警报名称,默认操作,采取的操作,攻击电脑,攻击者网址,目标地址,源地址,通信说明
2016/10/18 21:50:24,高,阻止了 stat.funshion.net 的入侵企图,已阻止,不需要操作,System Infected: Adware.Funshion Activity,不需要操作,不需要操作,"stat.funshion.net (220.181.178.214, 80)","stat.funshion.net/tools/fun_vasd?rprotocol=1*_*clientFlag=3*_*fck=*_*mac=*_*userid=*_*browser=Mozilla%2F5.0%20(Windows%20NT%2010.0%3B%20WOW64%3B%20Trident%2F7.0%3B%20rv%3A11.0)%20like%20Gecko*_*source=2*_*url=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-302211.v-820029*_*ref=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-302211.v-820029*_*info=","DESKTOP-M01B365 (115.24.164.134, 61185)",stat.funshion.net (220.181.178.214),"TCP, www-http"
来自 <b>stat.funshion.net/tools/fun_vasd?rprotocol=1*_*clientFlag=3*_*fck=*_*mac=*_*userid=*_*browser=Mozilla%2F5.0%20(Windows%20NT%2010.0%3B%20WOW64%3B%20Trident%2F7.0%3B%20rv%3A11.0)%20like%20Gecko*_*source=2*_*url=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-302211.v-820029*_*ref=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-302211.v-820029*_*info=</b> 的网络通信与已知攻击的特征相匹配。攻击由 \DEVICE\HARDDISKVOLUME2\PROGRAM FILES (X86)\ADSAFE\ADSAFE.EXE 引起。 要停止接收有关此类通信的通知,请在<b>“操作”</b>面板中单击<b>“不再提醒我”</b>。
类别: 入侵防护
日期和时间,风险,活动,状态,推荐的操作,IPS 警报名称,默认操作,采取的操作,攻击电脑,攻击者网址,目标地址,源地址,通信说明
2016/10/18 12:51:17,高,阻止了 stat.funshion.net 的入侵企图,已阻止,不需要操作,System Infected: Adware.Funshion Activity,不需要操作,不需要操作,"stat.funshion.net (220.181.178.210, 80)","stat.funshion.net/tools/fun_vasd?rprotocol=1*_*clientFlag=3*_*fck=*_*mac=*_*userid=*_*browser=Mozilla%2F5.0%20(Windows%20NT%2010.0%3B%20WOW64%3B%20Trident%2F7.0%3B%20rv%3A11.0)%20like%20Gecko*_*source=2*_*url=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-201684.v-627114*_*ref=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-201684.v-627114*_*info=","DESKTOP-M01B365 (115.24.164.134, 58439)",stat.funshion.net (220.181.178.210),"TCP, www-http"
来自 <b>stat.funshion.net/tools/fun_vasd?rprotocol=1*_*clientFlag=3*_*fck=*_*mac=*_*userid=*_*browser=Mozilla%2F5.0%20(Windows%20NT%2010.0%3B%20WOW64%3B%20Trident%2F7.0%3B%20rv%3A11.0)%20like%20Gecko*_*source=2*_*url=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-201684.v-627114*_*ref=http%3A%2F%2Fwww.fun.tv%2Fvplay%2Fg-201684.v-627114*_*info=</b> 的网络通信与已知攻击的特征相匹配。攻击由 \DEVICE\HARDDISKVOLUME2\PROGRAM FILES (X86)\ADSAFE\ADSAFE.EXE 引起。 要停止接收有关此类通信的通知,请在<b>“操作”</b>面板中单击<b>“不再提醒我”</b>。
如图,这应该是诺顿防火墙的提醒。之前用卡巴,也是经常提醒我链接的学校的无线网是风险网络,现在用诺顿,使用实验室的网线,就开始提醒我大量可疑出站通信,说我可能感染病毒。我应该怎么办?我觉得我没有中毒啊。。。。 |