近几天电脑中毒,发现局域网中的某些电脑(我的网段是:192.168.3.X)向192.168.X.X:445(X为随机变动的)发送数据包,现在这个对方的445端口会变动,现在变为6或17端口,
这是我的路由器的一些日志:
WAN Type: PPP over Ethernet (V1.43)
Display time: Thursday March 19, 2009 11:40:40
Thursday March 19, 2009 11:26:53 Blocked access attempt from 192.168.3.193: to 192.168.2.214:6 rule=1 (by firewall)
Thursday March 19, 2009 11:26:53 Blocked access attempt from 192.168.3.204: to 192.168.2.238:6 rule=1 (by firewall)
Thursday March 19, 2009 11:26:53 Blocked access attempt from 192.168.3.204: to 192.168.2.238:6 rule=1 (by firewall)
Thursday March 19, 2009 11:26:58 Blocked access attempt from 192.168.3.15: to 192.168.2.214:6 rule=1 (by firewall)
Thursday March 19, 2009 11:26:58 Blocked access attempt from 192.168.3.193: to 192.168.2.214:6 rule=1 (by firewall)
Thursday March 19, 2009 11:26:59 Blocked access attempt from 192.168.3.204: to 192.168.2.238:6 rule=1 (by firewall)
Thursday March 19, 2009 11:27:01 Blocked access attempt from 192.168.3.15: to 192.168.2.214:6 rule=1 (by firewall)
Thursday March 19, 2009 11:27:01 Blocked access attempt from 192.168.3.15: to 192.168.2.214:6 rule=1 (by firewall)
Thursday March 19, 2009 11:27:07 Blocked access attempt from 192.168.3.15: to 192.168.2.214:6 rule=1 (by firewall)
Thursday March 19, 2009 11:27:25 Blocked access attempt from 192.168.3.167: to 204.11.104.250:6 rule=0 (by firewall)
Thursday March 19, 2009 11:27:28 Blocked access attempt from 192.168.3.167: to 204.11.104.250:6 rule=0 (by firewall)
Thursday March 19, 2009 11:27:29 Blocked access attempt from 210.128.238.74:51829 to TCP port 443
Thursday March 19, 2009 11:27:30 Blocked access attempt from 192.168.3.56: to 192.168.2.238:6 rule=1 (by firewall)
Thursday March 19, 2009 11:27:32 Blocked access attempt from 210.128.238.74:51829 to TCP port 443
Thursday March 19, 2009 11:27:33 Blocked access attempt from 192.168.3.56: to 192.168.2.238:6 rule=1 (by firewall)
Thursday March 19, 2009 11:27:33 Blocked access attempt from 192.168.3.56: to 192.168.2.238:6 rule=1 (by firewall)
Thursday March 19, 2009 11:27:34 Blocked access attempt from 192.168.3.167: to 204.11.104.250:6 rule=0 (by firewall)
Thursday March 19, 2009 11:27:35 Blocked access attempt from 192.168.3.153: to 192.168.2.238:6 rule=1 (by firewall)
Thursday March 19, 2009 11:27:38 Blocked access attempt from 192.168.3.153: to 192.168.2.238:6 rule=1 (by firewall)
Thursday March 19, 2009 11:27:38 Blocked access attempt from 192.168.3.153: to 192.168.2.238:6 rule=1 (by firewall)
此为我路由器拦截的日志
附件为扫的日志,高手指点!
用户系统信息:Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; .NET CLR 1.1.4322)