楼主: hilan
收起左侧

[其他相关] 卡饭疑被挂马?????

  [复制链接]
hilan
 楼主| 发表于 2011-5-2 15:19:25 | 显示全部楼层
byxxdrls 发表于 2011-5-2 15:16
http://bbs.kafan.cn/home/photo/2011.php?listcscf=37&cscfid=8034478
貌似是这个链接,先前可打开的,现 ...

不是的,有的链接再次打开后会显示no input file specified,1楼有更新,病毒救援区也有人发现了类似问题
byxxdrls
头像被屏蔽
发表于 2011-5-2 15:22:27 | 显示全部楼层
回复 11楼 cnlan 的帖子

CSCF是什么?
hilan
 楼主| 发表于 2011-5-2 15:24:47 | 显示全部楼层
byxxdrls 发表于 2011-5-2 15:22
回复 11楼 cnlan 的帖子

CSCF是什么?

不懂~
zhou0197
发表于 2011-5-2 16:06:36 | 显示全部楼层
回复 12楼 byxxdrls 的帖子

试着把地址部分输入,到home时没有问题,到photo枫树就报警了……
jack1986001
发表于 2011-5-2 16:15:59 | 显示全部楼层
Log generated by anonymous use mdecoder 0.67
[root]http://www.game163.in/baike/rj.htm(软件大全辅助外-挂_百度百科 )
    [exp]http://www.game163.in/baike/rj.html(Exploit.Ie0dayCVE0806.a)
        [virus]http://www.game163.in/d/rj1.exe
    [script]http://js.users.51.la/4650229.js
    [script]http://event.youku.com/dabao/public/images/btn/time.js
Hopesky
发表于 2011-5-2 16:16:01 | 显示全部楼层
回复 1楼 cnlan 的帖子

关于:hxxp://www.game163.in/baike/rj.htm解密的日志(全体输出 -  5):

Level  1>hxxp://www.game163.in/baike/rj.html
Level  2>hxxp://www.game163.in/d/rj1.exe ●
Level  1>hxxp://event.youku.com/dabao/public/images/btn/time.js
Level  1>hxxp://www.game163.in/baike/rj.htm

By : Hopesky
唯我独尊
发表于 2011-5-5 09:27:08 | 显示全部楼层
Hopesky 发表于 2011-5-2 16:16
回复 1楼 cnlan 的帖子

关于:hxxp://www.game163.in/baike/rj.htm解密的日志(全体输出 -  5):

关键是为何会到卡饭这域名上来,求解释
http://bbs.kafan.cn/home/zt/cont ... 43&rjid=7845107
光之优雅
发表于 2011-5-5 09:32:51 | 显示全部楼层
本帖最后由 hsgeorge 于 2011-5-5 09:35 编辑

威胁名称:Infostealer.Gampass  
位置: hXXp://d.game163.in/d/dh.exe
Discovered:
November 12, 2006
Updated:
March 16, 2007 7:51:32 AM
Also Known As:
LIneage YI [Computer Associates],        Bloodhound.KillAV [Symantec]
Type:
Trojan
Infection Length:
Varies
Systems Affected:
Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000
Infostealer.Gampass is a detection for Trojan horses that specifically target video game credentials.

Most threats will attempt to log details such as video game registration keys and online account information for massively multiplayer online role playing games (MMORPG). In order to successfully achieve its primary function, the threat must run on a computer that contains the video game in question and is connected to a network.

The threats often arrive by the following means:
File-sharing networks, as game enhancements
Online forum posts

If a Symantec antivirus product displays a detection alert for this threat, it means the computer is already protected and the Symantec product will effectively remove it from the computer.
Antivirus Protection Dates
Initial Rapid Release version November 12, 2006
Latest Rapid Release version May 4, 2011 revision 057
Initial Daily Certified version November 12, 2006
Latest Daily Certified version May 4, 2011 revision 019
Initial Weekly Certified release date November 15, 2006
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
Wild Level: Low
Number of Infections: 0 - 49
Number of Sites: 0 - 2
Geographical Distribution: Low
Threat Containment: Easy
Removal: Easy
Damage
Damage Level: Medium
Payload: The threats log video game credentials and send them to a hacker.
Distribution
Distribution Level: Low

jinyuming
头像被屏蔽
发表于 2011-5-5 09:58:29 | 显示全部楼层
卡饭可能是有点问题,有的时候连接打开就是那个网站,有时候又是NO input
麻辣豆腐
发表于 2011-5-5 12:30:10 | 显示全部楼层
回复 1楼 cnlan 的帖子

我表示你这个游览器不是FF吗,哪里来谷歌,我刚才用谷歌点了下 拦截了
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-15 20:10 , Processed in 0.098807 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表