免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 3660 | 回复: 9
打印 上一主题 下一主题

windows无止境地发送数据包,这是为什么? [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2007-04-21 07:37 |只看该作者 |倒序浏览
我的windows无止境地发送数据包,这是为什么?
弄地我的路由器也经常需要重起,各位帮我想个办法吧?!
指望杀毒软件似乎是行不通了。

img001.GIF (17.86 KB, 下载次数: 26)

img001.GIF

img002.GIF (28.3 KB, 下载次数: 31)

img002.GIF

论坛徽章:
0
2 [报告]
发表于 2007-04-21 08:06 |只看该作者
继续添加信息!

img003.GIF (25.7 KB, 下载次数: 33)

img003.GIF

论坛徽章:
0
3 [报告]
发表于 2007-04-21 09:52 |只看该作者
为什么看的人多,说的人少呢?

论坛徽章:
0
4 [报告]
发表于 2007-04-21 11:20 |只看该作者
用autorun看啊

论坛徽章:
0
5 [报告]
发表于 2007-04-21 21:30 |只看该作者
用System Repair Engineer 的智能扫描,发个Log上来;
spooler、alg这样的服务可以关掉;
在80端口监听,可能有个木马;

把所有与网络相关的程序关掉,用Wireshark抓包看看;

论坛徽章:
0
6 [报告]
发表于 2007-04-22 01:22 |只看该作者
原帖由 deeperpurple 于 2007-4-21 21:30 发表
用System Repair Engineer 的智能扫描,发个Log上来;
spooler、alg这样的服务可以关掉;
在80端口监听,可能有个木马;

把所有与网络相关的程序关掉,用Wireshark抓包看看;


这是我的扫描结果,请帮我分析一下。谢谢了



  1. 2007-04-22,01:21:33

  2. System Repair Engineer 2.4.12.806
  3. Smallfrogs (http://www.KZTechs.com)

  4. Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能

  5. 以下内容被选中:
  6.     所有的启动项目(包括注册表、启动文件夹、服务等)
  7.     浏览器加载项
  8.     正在运行的进程(包括进程模块信息)
  9.     文件关联
  10.     Winsock 提供者
  11.     Autorun.inf
  12.     HOSTS 文件


  13. 启动项目
  14. 注册表
  15. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
  16.     <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Publisher]
  17.     <DAEMON Tools><"e:\Program Files\DAEMON Tools\daemon.exe" -lang 1033>  [(Verified)DAEMON Tools Code Signing Services]
  18. [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  19.     <load><>  [N/A]
  20. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
  21.     <runeip><C:\Program Files\Rising\AntiSpyware\runiep.exe>  [Beijing Rising Technology Co., Ltd.]
  22.     <RavTask><"e:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
  23.     <RfwMain><"e:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
  24.     <SynTPLpr><C:\Program Files\Synaptics\SynTP\SynTPLpr.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  25.     <SynTPEnh><C:\Program Files\Synaptics\SynTP\SynTPEnh.exe>  [(Verified)Microsoft Windows Publisher]
  26.     <SunJavaUpdateSched><E:\Program Files\Java\jre1.5.0_01\bin\jusched.exe>  [Sun Microsystems, Inc.]
  27.     <PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Windows Publisher]
  28.     <PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Windows Publisher]
  29.     <IMSCMIG40W><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40W\IMSCMIG.EXE /SetPreload /Log>  [Microsoft Corporation]
  30.     <IMSCMig><C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload>  [(Verified)Microsoft Corporation]
  31.     <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Windows Publisher]
  32.     <ATIPTA><C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe>  [ATI Technologies, Inc.]
  33.     <ATIModeChange><Ati2mdxx.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  34.     <AGRSMMSG><AGRSMMSG.exe>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
  35. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  36.     <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
  37.     <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
  38. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  39.     <AppInit_DLLs><>  [N/A]
  40. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
  41.     <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
  42. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
  43.     <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]

  44. ==================================
  45. 启动文件夹
  46. [腾讯QQ]
  47.   <C:\Documents and Settings\HollyLee\「开始」菜单\程序\启动\腾讯QQ.lnk --> E:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>

  48. ==================================
  49. 服务
  50. [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  51.   <C:\WINDOWS\system32\Ati2evxx.exe><>
  52. [Human Interface Device Access / HidServ][Stopped/Disabled]
  53.   <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
  54. [Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  55.   <e:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
  56. [Rising Personal Firewall Service / RfwService][Running/Auto Start]
  57.   <e:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
  58. [Remote Packet Capture Protocol v.0 (experimental) / rpcapd][Stopped/Manual Start]
  59.   <"C:\Program Files\WinPcap\rpcapd.exe" -d -f "C:\Program Files\WinPcap\rpcapd.ini"><N/A>
  60. [Rising Process Communication Center / RsCCenter][Running/Auto Start]
  61.   <"e:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
  62. [Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  63.   <"E:\PROGRAM FILES\RISING\RAV\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>

  64. ==================================
  65. 驱动程序
  66. [SENS LT56ADW Modem / AgereSoftModem][Running/Manual Start]
  67.   <system32\DRIVERS\AGRSM.sys><Agere Systems>
  68. [ati2mtag / ati2mtag][Running/Manual Start]
  69.   <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
  70. [Rising TDI Base Driver / BaseTDI][Running/Auto Start]
  71.   <System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
  72. [Cirrus Logic WDM Audio Codec Driver / cs429x][Running/Manual Start]
  73.   <system32\drivers\cwawdm.sys><Cirrus Logic, Inc.>
  74. [Intel(R) PRO Adapter Driver / E100B][Running/Manual Start]
  75.   <system32\DRIVERS\e100b325.sys><Intel Corporation>
  76. [ExpScaner / ExpScaner][Running/Auto Start]
  77.   <\??\E:\PROGRAM FILES\RISING\RAV\ExpScan.sys><>
  78. [HookCont / HookCont][Running/Auto Start]
  79.   <\??\E:\PROGRAM FILES\RISING\RAV\HOOKCONT.sys><Rising>
  80. [HookReg / HookReg][Running/Auto Start]
  81.   <\??\E:\PROGRAM FILES\RISING\RAV\HookReg.sys><>
  82. [HookSys / HookSys][Running/Auto Start]
  83.   <\??\E:\PROGRAM FILES\RISING\RAV\HookSys.sys><Rising>
  84. [HookUrl / HookUrl][Running/Auto Start]
  85.   <\??\e:\Program Files\Rising\Rfw\HookUrl.sys><Beijing Rising Technology Co., Ltd.>
  86. [MEMSCAN / MEMSCAN][Running/Auto Start]
  87.   <\??\E:\PROGRAM FILES\RISING\RAV\MEMSCAN.sys><瑞星软件有限公司>
  88. [mProcRs / mProcRs][Running/Auto Start]
  89.   <\??\e:\program files\rising\rfw\mProcRs.sys><Beijing Rising Technology Co., Ltd.>
  90. [NetGroup Packet Filter Driver / NPF][Stopped/Manual Start]
  91.   <system32\drivers\npf.sys><Politecnico di Torino>
  92. [npkcrypt / npkcrypt][Running/Auto Start]
  93.   <\??\e:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
  94. [Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  95.   <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
  96. [PxHelp20 / PxHelp20][Running/Boot Start]
  97.   <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
  98. [RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
  99.   <\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
  100. [RsFwDrv / RsFwDrv][Running/Auto Start]
  101.   <\??\e:\Program Files\Rising\Rfw\RsFwDrv.sys><Beijing Rising Technology Co., Ltd.>
  102. [RsNTGDI / RsNTGDI][Running/Boot Start]
  103.   <\SystemRoot\system32\Drivers\RsNTGdi.sys><Beijing Rising Technology Co., Ltd.>
  104. [RSPPSYS / RSPPSYS][Running/Auto Start]
  105.   <\??\E:\PROGRAM FILES\RISING\RAV\RSPPSYS.sys><Rising>
  106. [Secdrv / Secdrv][Stopped/Manual Start]
  107.   <system32\DRIVERS\secdrv.sys><N/A>
  108. [sptd / sptd][Running/Boot Start]
  109.   <\SystemRoot\System32\Drivers\sptd.sys><N/A>
  110. [Synaptics TouchPad Driver / SynTP][Running/Manual Start]
  111.   <system32\DRIVERS\SynTP.sys><Synaptics, Inc.>

  112. ==================================
  113. 浏览器加载项
  114. [Thunder Browser Helper]
  115.   {54EBD539-9BC1-480B-966A-843A333CA162} <e:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
  116. [QQBrowserHelperObject Class]
  117.   {54EBD53A-9BC1-480B-966A-843A333CA162} <e:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
  118. [BandIE Class]
  119.   {77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\PROGRA~1\baidu\bar\BaiduBar.dll, N/A>
  120. [Windows Live Sign-in Helper]
  121.   {9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
  122. [Java Plug-in 1.5.0_01]
  123.   {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <E:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll, Sun Microsystems, Inc.>
  124. [启动迅雷5]
  125.   {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <e:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
  126. [浩方对战平台]
  127.   {0A155D3C-68E2-4215-A47A-E800A446447A} <E:\Program Files\HFGameOPT\GameClient.exe, 上海浩方在线信息技术有限公司>
  128. [信息检索(&R)]
  129.   {92780B25-18CC-41C8-B9BE-3C9C571A8263} <E:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
  130. [QQ]
  131.   {c95fe080-8f5d-11d2-a20b-00aa003c157b} <e:\Program Files\Tencent\QQ\QQ.EXE, TENCENT>
  132. [QQIEFloatBarCfgCmd Class]
  133.   {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} <e:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
  134. [Messenger]
  135.   {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
  136. [百度超级搜霸]
  137.   {B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\PROGRA~1\baidu\bar\BaiduBar.dll, N/A>
  138. [Edit Class]
  139.   {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
  140. [Java Plug-in 1.5.0_01]
  141.   {8AD9C840-044E-11D1-B3E9-00805F499D93} <E:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll, Sun Microsystems, Inc.>
  142. [Java Plug-in 1.5.0_01]
  143.   {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} <E:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll, Sun Microsystems, Inc.>
  144. [Shockwave Flash Object]
  145.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  146. [Thunder Browser Helper]
  147.   {54EBD539-9BC1-480B-966A-843A333CA162} <e:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
  148. [QQBrowserHelperObject Class]
  149.   {54EBD53A-9BC1-480B-966A-843A333CA162} <e:\Program Files\Tencent\QQ\QQIEHelper.dll, 深圳市腾讯计算机系统有限公司>
  150. [Active Desktop Mover]
  151.   {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
  152. [BandIE Class]
  153.   {77FEF28E-EB96-44FF-B511-3185DEA48697} <C:\PROGRA~1\baidu\bar\BaiduBar.dll, N/A>
  154. [Thunder Browser Helper]
  155.   {889D2FEB-5411-4565-8998-1DD2C5261283} <e:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
  156. [Windows Live Sign-in Helper]
  157.   {9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
  158. [百度超级搜霸]
  159.   {B580CF65-E151-49C3-B73F-70B13FCA8E86} <C:\PROGRA~1\baidu\bar\BaiduBar.dll, N/A>
  160. [Shockwave Flash Object]
  161.   {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
  162. [&使用迅雷下载]
  163.   <e:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
  164. [&使用迅雷下载全部链接]
  165.   <e:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
  166. [上传到QQ网络硬盘]
  167.   <E:\Program Files\Tencent\QQ\AddToNetDisk.htm, N/A>
  168. [导出到 Microsoft Office Excel(&X)]
  169.   <res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
  170. [添加到QQ自定义面板]
  171.   <E:\Program Files\Tencent\QQ\AddPanel.htm, N/A>
  172. [添加到QQ表情]
  173.   <E:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
  174. [用QQ彩信发送该图片]
  175.   <E:\Program Files\Tencent\QQ\SendMMS.htm, N/A>

  176. ==================================
  177. 正在运行的进程
  178. [PID: 608][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  179. [PID: 692][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  180. [PID: 716][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  181.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  182. [PID: 760][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  183. [PID: 772][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  184. [PID: 936][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  185. [PID: 1004][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  186. [PID: 1116][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  187. [PID: 512][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
  188.     [C:\WINDOWS\system32\RavExt.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
  189.     [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.2.9 03Jan03]
  190.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  191. [PID: 1220][e:\program files\rising\rfw\RfwMain.exe]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 70]
  192.     [e:\program files\rising\rfw\RsGuiLib.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 33]
  193.     [e:\program files\rising\rfw\RSCOMMON.DLL]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
  194.     [e:\program files\rising\rfw\RfwCtrl.dll]  [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
  195.     [e:\program files\rising\rfw\RsXML.dll]  [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
  196.     [e:\program files\rising\rfw\PngDll.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
  197.     [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.2.9 03Jan03]
  198. [PID: 244][C:\Program Files\Synaptics\SynTP\SynTPLpr.exe]  [Synaptics, Inc., 7.2.9 03Jan03]
  199.     [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.2.9 03Jan03]
  200. [PID: 260][C:\Program Files\Synaptics\SynTP\SynTPEnh.exe]  [Synaptics, Inc., 7.2.9 03Jan03]
  201.     [C:\WINDOWS\system32\SynTPAPI.dll]  [Synaptics, Inc., 7.2.9 03Jan03]
  202.     [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.2.9 03Jan03]
  203. [PID: 264][E:\Program Files\Java\jre1.5.0_01\bin\jusched.exe]  [Sun Microsystems, Inc., 1.5.0.10]
  204. [PID: 1948][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe]  [ATI Technologies, Inc., 6.14.10.4035]
  205.     [C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.CHS]  [ATI Technologies, Inc., 6.14.10.4035]
  206.     [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.2.9 03Jan03]
  207.     [C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll]  [ATI Technologies, Inc., 6.14.10.4035]
  208. [PID: 824][C:\WINDOWS\AGRSMMSG.exe]  [Agere Systems, 2.1.18 2.1.18 09/11/2002 17:23:56]
  209.     [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.2.9 03Jan03]
  210. [PID: 1240][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
  211.     [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.2.9 03Jan03]
  212. [PID: 1480][E:\Program Files\DAEMON Tools\daemon.exe]  [DT Soft Ltd., 4.08.0.0]
  213.     [e:\Program Files\DAEMON Tools\daemon.dll]  [DT Soft Ltd., 4.08.0.0]
  214.     [e:\Program Files\DAEMON Tools\PFCTOC.DLL]  [Padus(R), Inc., 1, 0, 0, 12]
  215.     [e:\Program Files\DAEMON Tools\Plugins\Images\bw5mount.dll]  [, 1.1.0.0]
  216.     [e:\Program Files\DAEMON Tools\Plugins\Images\ccdmount.dll]  [GENERIC, 1.10.0.0]
  217.     [e:\Program Files\DAEMON Tools\Plugins\Images\cuemount.dll]  [DT Soft Ltd., 1.01.0.0]
  218.     [e:\Program Files\DAEMON Tools\Plugins\Images\mdsmount.dll]  [DT Soft Ltd., 1.18.0.0]
  219.     [e:\Program Files\DAEMON Tools\Plugins\Images\nrgmount.dll]  [DT Soft Ltd., 1.12.0.0]
  220.     [e:\Program Files\DAEMON Tools\Plugins\Images\pdimount.dll]  [GENERIC, 1.01.0.0]
  221.     [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.2.9 03Jan03]
  222. [PID: 2900][E:\Program Files\Maxthon\Maxthon.exe]  [Maxthon International Ltd., 1, 5, 9, 80]
  223.     [E:\Program Files\Maxthon\maxzlib.dll]  [ , 1, 0, 0, 2]
  224.     [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.2.9 03Jan03]
  225.     [C:\WINDOWS\system32\odbcbcp.dll]  [Microsoft Corporation, 2000.085.1117.00 (xpsp_sp2_rtm.040803-2158)]
  226.     [e:\Program Files\Rising\Rav\RavScrCh.dll]  [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
  227.     [E:\Program Files\Maxthon\Services\RealTime\real_time.dll]  [, 1, 0, 0, 1]
  228.     [C:\WINDOWS\system32\msacm32.drv]  [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
  229.     [C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx]  [Adobe Systems, Inc., 9,0,28,0]
  230. [PID: 2648][e:\Program Files\WinRAR\WinRAR.exe]  [N/A, ]
  231.     [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.2.9 03Jan03]
  232.     [C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll]  [Microsoft Corporation, 8.1.0178.00]
  233. [PID: 3248][C:\DOCUME~1\HollyLee\LOCALS~1\Temp\Rar$EX01.085\SREng.EXE]  [Smallfrogs Studio, 2.4.12.806]
  234.     [C:\WINDOWS\system32\SynTPFcs.dll]  [Synaptics, Inc., 7.2.9 03Jan03]

  235. ==================================
  236. 文件关联
  237. .TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
  238. .EXE  OK. ["%1" %*]
  239. .COM  OK. ["%1" %*]
  240. .PIF  OK. ["%1" %*]
  241. .REG  OK. [regedit.exe "%1"]
  242. .BAT  OK. ["%1" %*]
  243. .SCR  OK. ["%1" /S]
  244. .CHM  OK. ["C:\WINDOWS\hh.exe" %1]
  245. .HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
  246. .INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  247. .INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
  248. .VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  249. .JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
  250. .LNK  OK. [{00021401-0000-0000-C000-000000000046}]

  251. ==================================
  252. Winsock 提供者
  253. N/A

  254. ==================================
  255. Autorun.inf
  256. N/A

  257. ==================================
  258. HOSTS 文件
  259. 127.0.0.1       localhost

  260. ==================================
  261. API HOOK
  262. N/A

  263. ==================================
  264. 隐藏进程
  265. N/A

  266. ==================================


复制代码

论坛徽章:
0
7 [报告]
发表于 2007-04-22 09:01 |只看该作者
你有apache,不停地发送数据不了很正常吗?你从哪里发现不正常?
其实你可以把所有的服务都停掉,然后再看看哪个端口连接着,那它就十分可疑了。

论坛徽章:
0
8 [报告]
发表于 2007-05-01 00:11 |只看该作者
猛发包这家伙就是我同学,他好久以前用过apache,很长一段时间都没有用了.都不曾这样无休止地发包.最近才开始,最近我们局域网都变得很慢,怀疑就是因为他机器不停发包得原因.
然后前几天他把机器共享打开,另外一个同学上传文件给他,之后上传文件的这位也开始猛发包了...

论坛徽章:
0
9 [报告]
发表于 2007-05-01 08:57 |只看该作者
断开所有网络连接的程序
用netstat -ano
查看还在连接网络的进程号,然后打载任务管理器,在查看中选择是PID列,就可以找了具体的可疑程序了

论坛徽章:
0
10 [报告]
发表于 2007-05-02 21:28 |只看该作者
很明显是病毒..
只是通过LOG没有发现很可疑的进程
可以通过icesword查看一下进程和网络连接..
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP