【求助】關於木馬的問題,只要一上網就會自動不停丟封包出去.....



贊助商連結


shithappens
2003-05-27, 03:45 PM
大家好,小弟的OS是Win2000 SP3,裝有Norton Internet security 2003及AD-AWARE,只要一上網就會自動丟封包出去,執行netstat -n 得到的畫面如下
C:\>netstat -n

Active Connections

Proto Local Address Foreign Address State
TCP 219.xx.xx.xxx:1502 81.50.152.202:445 TIME_WAIT
TCP 219.xx.xx.xxx:1825 132.207.32.37:445 TIME_WAIT
TCP 219.xx.xx.xxx:2238 45.136.154.252:445 ESTABLISH
TCP 219.xx.xx.xxx:2469 162.15.170.224:445 TIME_WAIT
TCP 219.xx.xx.xxx:2523 64.12.165.57:6667 ESTABLISH
TCP 219.xx.xx.xxx:2581 217.82.178.106:445 TIME_WAIT
TCP 219.xx.xx.xxx:2588 64.46.184.201:445 TIME_WAIT
TCP 219.xx.xx.xxx:2592 64.46.184.201:80 ESTABLISH
TCP 219.xx.xx.xxx:2614 220.255.124.91:445 TIME_WAIT
TCP 219.xx.xx.xxx:2914 45.136.227.69:445 ESTABLISH
TCP 219.xx.xx.xxx:3202 203.154.13.83:445 TIME_WAIT
TCP 219.xx.xx.xxx:3293 216.181.162.29:445 TIME_WAIT
TCP 219.xx.xx.xxx:3338 216.181.162.29:445 ESTABLISH
TCP 219.xx.xx.xxx:3340 9.7.25.220:445 SYN_SENT
TCP 219.xx.xx.xxx:3341 177.242.192.245:445 SYN_SENT
TCP 219.xx.xx.xxx:3345 173.41.101.68:445 SYN_SENT
TCP 219.xx.xx.xxx:3346 129.203.140.140:445 SYN_SENT
TCP 219.xx.xx.xxx:3347 28.223.201.189:445 SYN_SENT
TCP 219.xx.xx.xxx:3348 167.139.83.87:445 SYN_SENT
TCP 219.xx.xx.xxx:3349 138.177.14.109:445 SYN_SENT
TCP 219.xx.xx.xxx:3350 195.237.187.195:445 SYN_SENT
TCP 219.xx.xx.xxx:3351 189.207.95.37:445 SYN_SENT
TCP 219.xx.xx.xxx:3352 44.241.10.113:445 SYN_SENT
TCP 219.xx.xx.xxx:3355 148.57.245.119:445 SYN_SENT
TCP 219.xx.xx.xxx:3357 32.50.48.52:445 SYN_SENT
TCP 219.xx.xx.xxx:3358 19.108.247.115:445 SYN_SENT
TCP 219.xx.xx.xxx:3359 193.213.1.151:445 SYN_SENT
TCP 219.xx.xx.xxx:3366 141.35.177.245:445 SYN_SENT
TCP 219.xx.xx.xxx:3368 30.176.8.21:445 SYN_SENT
TCP 219.xx.xx.xxx:3370 25.200.203.99:445 SYN_SENT
TCP 219.xx.xx.xxx:3371 51.41.166.151:445 SYN_SENT
TCP 219.xx.xx.xxx:3376 131.136.44.225:445 SYN_SENT
TCP 219.xx.xx.xxx:3377 20.211.14.125:445 SYN_SENT
TCP 219.xx.xx.xxx:3379 17.98.101.12:445 SYN_SENT
TCP 219.xx.xx.xxx:3382 185.117.178.28:445 SYN_SENT
TCP 219.xx.xx.xxx:3384 24.76.75.176:445 SYN_SENT
TCP 219.xx.xx.xxx:3387 218.228.27.19:445 SYN_SENT
TCP 219.xx.xx.xxx:3391 68.192.151.240:445 SYN_SENT
TCP 219.xx.xx.xxx:3392 166.175.87.46:445 SYN_SENT
TCP 219.xx.xx.xxx:3393 3.53.156.188:445 SYN_SENT
TCP 219.xx.xx.xxx:3394 147.166.68.249:445 SYN_SENT
TCP 219.xx.xx.xxx:3395 184.159.179.80:445 SYN_SENT
TCP 219.xx.xx.xxx:3396 43.30.86.215:445 SYN_SENT
TCP 219.xx.xx.xxx:3399 187.132.158.231:445 SYN_SENT
TCP 219.xx.xx.xxx:3865 217.128.94.188:445 TIME_WAIT


請問這該如何處理呢?如蒙賜教不勝感激,謝謝!

現正努力爬文中.....

贊助商連結


jackal0601
2003-05-27, 03:58 PM
你應該是打netstat而已!

照這樣看來,你不是打 netstat -n 吧!

或是你有開別的軟體

例:驢子等的分享軟體 MSN 等等!

shithappens
2003-05-27, 05:21 PM
最初由 jackal0601 發表
你應該是打netstat而已!

照這樣看來,你不是打 netstat -n 吧!

或是你有開別的軟體

例:驢子等的分享軟體 MSN 等等!
我有開MSN跟YAHOO messenger , 但是沒有裝驢子耶,emule也沒有裝啊
謝謝你的回覆.