发现一个木马,用好几款软件都查不到,不过外国网站上有登记
发现一个木马,用好几款软件都查不到,不过外国网站上有登记。我用抓包软件抓包,发现这个木马一直向一个地方发包:
==================================================
Index : 3
Protocol : TCP
Local Address : 192.168.1.100
Remote Address : 218.106.193.184
Local Port : 3612
Remote Port : 80
Local Host : svr
Service Name : http
Remote Host :
Packets : 5
Data Size : 354 Bytes
Total Size : 698 Bytes
Capture Time : 2009-2-13 10:45:06:171
==================================================
GET /msopen/Admin.jpg HTTP/1.0
User-Agent: MSDNSurfBear
Host: ieopen.yhgames.com
Pragma: no-cache
HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
Date: Fri, 13 Feb 2009 02:39:14 GMT
Content-Type: image/jpeg
Accept-Ranges: bytes
Last-Modified: Fri, 17 Oct 2008 09:52:56 GMT
ETag: "e07ca7213e30c91:da0"
Content-Length: 24
......................
请问如何才能解决?
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; CNCDialer; QQDownload 1.7; GTB5; SV1; Maxthon; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727)