本帖最後由 BB_HON 於 2013-6-4 13:51 編輯
我今日係 Firewire log 發現左個 Network 有個 client 用 UDP 137 port send 一堆data 去幾個IP 的port 137
開幾後幾分鐘就無左
IP 好似來自一堆外國的 ISP (?)
係咪有古怪野?
OS: Windows 7 x64
Kaspersky Internet Security 2013 installed
Log from firewall- Jun/03/2013 11:15:18 firewall,info virus: in:bridge-local out:ether01-WAN, src-mac <CLIENT MAC>, proto UDP, 192.168.1.3:137->119.255.133.33:137, len 78
- Jun/03/2013 11:15:20 firewall,info virus: in:bridge-local out:ether01-WAN, src-mac <CLIENT MAC>, proto UDP, 192.168.1.3:137->119.255.133.33:137, len 78
- Jun/03/2013 11:15:21 firewall,info virus: in:bridge-local out:ether01-WAN, src-mac <CLIENT MAC>, proto UDP, 192.168.1.3:137->119.255.133.33:137, len 78
- Jun/03/2013 11:15:23 firewall,info virus: in:bridge-local out:ether01-WAN, src-mac <CLIENT MAC>, proto UDP, 192.168.1.3:137->119.255.133.36:137, len 78
- Jun/03/2013 11:15:24 firewall,info virus: in:bridge-local out:ether01-WAN, src-mac <CLIENT MAC>, proto UDP, 192.168.1.3:137->119.255.133.36:137, len 78
- Jun/03/2013 11:15:26 firewall,info virus: in:bridge-local out:ether01-WAN, src-mac <CLIENT MAC>, proto UDP, 192.168.1.3:137->119.255.133.36:137, len 78
- Jun/03/2013 11:15:28 firewall,info virus: in:bridge-local out:ether01-WAN, src-mac <CLIENT MAC>, proto UDP, 192.168.1.3:137->202.177.216.236:137, len 78
- Jun/03/2013 11:15:30 firewall,info virus: in:bridge-local out:ether01-WAN, src-mac <CLIENT MAC>, proto UDP, 192.168.1.3:137->202.177.216.236:137, len 78
- Jun/03/2013 11:15:31 firewall,info virus: in:bridge-local out:ether01-WAN, src-mac <CLIENT MAC>, proto UDP, 192.168.1.3:137->202.177.216.236:137, len 78
- Jun/03/2013 11:15:33 firewall,info virus: in:bridge-local out:ether01-WAN, src-mac <CLIENT MAC>, proto UDP, 192.168.1.3:137->62.128.100.41:137, len 78
- ......
複製代碼 |