1   1  /  1  页   跳转

请教怎样处理?

请教怎样处理?

我的机器只要联接到网络,瑞星防火墙就会提示机器自动向SUVSOFT.COM和JJAD.NET发送数据包
59.151.19.23:80[WEB网页] ;满足规则:Suvsoft.com
222.38.208.10:80[WEB网页] ;满足规则:jjad.net

但是不管是用瑞星还是其他的木马查杀工具都没有检查出木马或病毒,还请高手帮忙分析。

最近我的电脑经常断线,不知是不是上述因素所致? 是否受黑客远程攻击所致或受了什么病毒?

最后编辑2006-11-27 21:23:02
分享到:
gototop
 

HijackThis1.99.1
扫描日志上来
中文版:
http://free5.ys168.com/?ufwihgu168
gototop
 

以下为近期IP事件
2006-11-26 11:44:47, 系统禁止发送TCP数据包;地址为:192.168.5.58:1058 => 222.38.208.10:80[WEB网页] ;满足规则:jjad.net
2006-11-26 11:43:25, 系统禁止发送TCP数据包;地址为:192.168.5.58:1043 => 59.151.19.23:80[WEB网页] ;满足规则:Suvsoft.com
2006-11-26 11:43:03, 系统禁止发送TCP数据包;地址为:192.168.5.58:1042[Bla木马] => 59.151.19.23:80[WEB网页] ;满足规则:Suvsoft.com
2006-11-26 11:42:41, 系统禁止发送TCP数据包;地址为:192.168.5.58:1041 => 59.151.19.23:80[WEB网页] ;满足规则:Suvsoft.com
2006-11-25 22:17:37, 系统禁止发送TCP数据包;地址为:192.168.5.58:1091 => 222.38.208.10:80[WEB网页] ;满足规则:jjad.net
2006-11-25 22:17:12, 系统禁止发送TCP数据包;地址为:192.168.5.58:1090[Extreme木马] => 222.38.208.10:80[WEB网页] ;满足规则:jjad.net
2006-11-25 22:15:47, 系统禁止发送TCP数据包;地址为:192.168.5.58:1089 => 222.38.208.10:80[WEB网页] ;满足规则:jjad.net
2006-11-25 22:15:24, 系统禁止发送TCP数据包;地址为:192.168.5.58:1086 => 222.38.208.10:80[WEB网页] ;满足规则:jjad.net
2006-11-25 22:15:02, 系统禁止发送TCP数据包;地址为:192.168.5.58:1084 => 222.38.208.10:80[WEB网页] ;满足规则:jjad.net
2006-11-25 22:13:32, 系统禁止发送TCP数据包;地址为:192.168.5.58:1047 => 59.151.19.23:80[WEB网页] ;满足规则:Suvsoft.com
2006-11-25 22:13:10, 系统禁止发送TCP数据包;地址为:192.168.5.58:1045[RASmin木马] => 59.151.19.23:80[WEB网页] ;满足规则:Suvsoft.com
2006-11-25 22:12:48, 系统禁止发送TCP数据包;地址为:192.168.5.58:1041 => 59.151.19.23:80[WEB网页] ;满足规则:Suvsoft.com
2006-11-24 22:21:25, 系统禁止发送ICMP数据包;地址为:192.168.5.58 => 59.151.19.23 Code=0, Type=8 ;满足规则:Suvsoft.com
2006-11-24 22:21:24, 系统禁止发送ICMP数据包;地址为:192.168.5.58 => 59.151.19.23 Code=0, Type=8 ;满足规则:Suvsoft.com
2006-11-24 22:21:23, 系统禁止发送ICMP数据包;地址为:192.168.5.58 => 59.151.19.23 Code=0, Type=8 ;满足规则:Suvsoft.com
2006-11-24 22:21:22, 系统禁止发送ICMP数据包;地址为:192.168.5.58 => 59.151.19.23 Code=0, Type=8 ;满足规则:Suvsoft.com
2006-11-24 22:10:33, 系统禁止发送TCP数据包;地址为:192.168.5.58:1134 => 222.38.208.10:80[WEB网页] ;满足规则:jjad.net
2006-11-24 22:10:11, 系统禁止发送TCP数据包;地址为:192.168.5.58:1132 => 222.38.208.10:80[WEB网页] ;满足规则:jjad.net
2006-11-24 22:09:49, 系统禁止发送TCP数据包;地址为:192.168.5.58:1127 => 222.38.208.10:80[WEB网页] ;满足规则:jjad.net
2006-11-24 22:08:26, 系统禁止发送TCP数据包;地址为:192.168.5.58:1041 => 59.151.19.23:80[WEB网页] ;满足规则:Suvsoft.com
2006-11-24 22:08:04, 系统禁止发送TCP数据包;地址为:192.168.5.58:1040 => 59.151.19.23:80[WEB网页] ;满足规则:Suvsoft.com
2006-11-24 22:07:42, 系统禁止发送TCP数据包;地址为:192.168.5.58:1038 => 59.151.19.23:80[WEB网页] ;满足规则:Suvsoft.com
2006-11-24 09:46:14, 系统允许发送ICMP数据包;地址为:192.168.5.58 => 220.249.43.19 Code=0, Type=8 ;满足规则:允许Ping出
2006-11-24 09:46:12, 系统允许发送ICMP数据包;地址为:192.168.5.58 => 220.249.43.19 Code=0, Type=8 ;满足规则:允许Ping出
2006-11-24 09:46:10, 系统允许发送ICMP数据包;地址为:192.168.5.58 => 220.249.43.19 Code=0, Type=8 ;满足规则:允许Ping出
2006-11-24 09:46:07, 系统允许发送ICMP数据包;地址为:192.168.5.58 => 220.249.43.19 Code=0, Type=8 ;满足规则:允许Ping出
2006-11-24 09:45:35, 系统允许发送ICMP数据包;地址为:192.168.5.58 => 220.249.43.19 Code=0, Type=8 ;满足规则:允许Ping出
2006-11-24 09:45:33, 系统允许发送ICMP数据包;地址为:192.168.5.58 => 220.249.43.19 Code=0, Type=8 ;满足规则:允许Ping出
2006-11-24 09:45:31, 系统允许发送ICMP数据包;地址为:192.168.5.58 => 220.249.43.19 Code=0, Type=8 ;满足规则:允许Ping出
2006-11-24 09:45:28, 系统允许发送ICMP数据包;地址为:192.168.5.58 => 220.249.43.19 Code=0, Type=8 ;满足规则:允许Ping出
2006-11-24 09:21:46, 系统禁止发送TCP数据包;地址为:192.168.5.58:1084 => 222.38.208.10:80[WEB网页] ;满足规则:jjad.net
2006-11-24 09:21:24, 系统禁止发送TCP数据包;地址为:192.168.5.58:1083 => 222.38.208.10:80[WEB网页] ;满足规则:jjad.net
2006-11-24 09:21:02, 系统禁止发送TCP数据包;地址为:192.168.5.58:1082 => 222.38.208.10:80[WEB网页] ;满足规则:jjad.net
2006-11-24 09:19:40, 系统禁止发送TCP数据包;地址为:192.168.5.58:1080[SOCKS代理] => 59.151.19.23:80[WEB网页] ;满足规则:Suvsoft.com
2006-11-24 09:19:18, 系统禁止发送TCP数据包;地址为:192.168.5.58:1079 => 59.151.19.23:80[WEB网页] ;满足规则:Suvsoft.com
2006-11-24 09:18:56, 系统禁止发送TCP数据包;地址为:192.168.5.58:1075 => 59.151.19.23:80[WEB网页] ;满足规则:Suvsoft.com
gototop
 

【回复“红夜鬼1”的帖子】
怎么不能打开目录文件夹
gototop
 

【回复“红夜鬼1”的帖子】

Logfile of HijackThis v1.99.1
Scan saved at 14:12:57, on 2006-11-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Rising\Rav\Ravmond.exe
c:\program files\rising\rfw\rfwsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
c:\program files\rising\rfw\RfwMain.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\Program Files\Rising\Rav\Ravmon.exe
C:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Tencent\QQ\QQ.exe
G:\Program Files\Tencent\QQ\TIMPlatform.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Rising\Rav\RsAgent.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\C_DILLA\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O2 - BHO: Yahoo Toolbar - {4FF076DA-65DB-4F71-A5D0-D022E2F64E97} - C:\WINDOWS\system32\ibrowser.dll (file missing)
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - G:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - G:\PROGRA~1\FlashGet\getflash.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - G:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RfwMain] "C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKLM\..\RunOnce: [RavStub] "C:\Program Files\Rising\Rav\ravstub.exe" /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Google 搜索(&G) - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: 上传到QQ网络硬盘 - G:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 使用网际快车下载 - G:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - G:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 反向链接 - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: 添加到QQ自定义面板 - G:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - G:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - G:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 类似网页 - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: 缓存的网页快照 - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: 翻译英文字词(&T) - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - G:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - G:\Program Files\Tencent\QQ\QQ.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - G:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - G:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - G:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具条设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - G:\Program Files\Tencent\QQ\QQIEHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1F831FA1-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://D:\AutoCAD 2002\InstFred.ocx
O16 - DPF: {20C2C286-BDE8-441B-B73D-AFA22D914DA5} (PowerList Control) - http://download.ppstream.com/bin/powerplayer.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1143909273751
O16 - DPF: {733652F9-53EF-4BF1-B391-375980675D6F} (V3PROXL Control) -
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday 控件) - file://D:\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {9BDBC41E-C335-4263-83C0-ECE78EE28A33} (SysMonOCX Control) -
O16 - DPF: {AE563722-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://D:\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview 控件) - file://D:\AutoCAD 2002\AcPreview.ocx
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Rising Proxy  Service (RfwProxySrv) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwproxy.exe
O23 - Service: Rising Personal Firewall Service (RfwService) - Beijing Rising Technology Co., Ltd. - c:\program files\rising\rfw\rfwsrv.exe
O23 - Service: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\CCenter.exe
O23 - Service: Rising RealTime Monitor (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\Rising\Rav\Ravmond.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel? Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
gototop
 

红夜鬼1请回复!
gototop
 

运行Hijackthis,把下面的选中打上钩,修复
O2 - BHO: (no name) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O2 - BHO: Yahoo Toolbar - {4FF076DA-65DB-4F71-A5D0-D022E2F64E97} - C:\WINDOWS\system32\ibrowser.dll (file missing)
gototop
 

【回复“红夜鬼1”的帖子】
哥们,照你的说法操作了,问题依然存在。接下来怎样处理?
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT