我的是2003的服务器。这个程序应该没有问题,修改日期也是正常,用冰刃看了下居然有几百个外部链接。
而且远程IP 每个都是80端口!很不解!
PID 448 就是C:\WINDOWS\system32\service.exe 这个进程 超级郁闷了。
有高手吗?
(我的本地服务器IP 安全起见 做了下处理)
下面是有关链接的部分复制情况。 太多了只复制了那么一小段。
Active Connections
Proto Local Address Foreign Address State PID
TCP * . * . 119:4457 58.251.60.178:80 ESTABLISHED 448
TCP * . * . 216.119:4458 58.251.60.178:80 ESTABLISHED 448
TCP * . * . 216.119:4459 58.251.60.178:80 ESTABLISHED 448
TCP * . * . 216.119:4460 58.251.60.178:80 ESTABLISHED 448
TCP * . * . 216.119:4461 58.251.60.178:80 ESTABLISHED 448
TCP * . * . 216.119:4462 58.251.60.178:80 ESTABLISHED 448
TCP * . * . 216.119:4463 58.251.60.178:80 ESTABLISHED 448
TCP * . * . 216.119:4464 58.251.60.178:80 ESTABLISHED 448
TCP * . * . 216.119:4465 58.251.60.178:80 ESTABLISHED 448
TCP * . * . 216.119:4467 58.251.60.178:80 ESTABLISHED 448
TCP * . * . 216.119:4468 58.251.60.178:80 ESTABLISHED 448
TCP * . * . 216.119:4473 61.63.49.4:80 CLOSE_WAIT 448
TCP * . * . 216.119:4475 61.63.49.9:80 CLOSE_WAIT 448
TCP * . * . 216.119:4476 61.63.49.9:80 CLOSE_WAIT 448
TCP * . * . 216.119:4480 61.63.49.9:80 CLOSE_WAIT 448
TCP * . * . 216.119:4481 61.63.49.9:80 CLOSE_WAIT 448
TCP * . * . 216.119:4482 61.63.49.9:80 CLOSE_WAIT 448
TCP * . * . 216.119:4483 61.63.49.9:80 CLOSE_WAIT 448
TCP * . * . 216.119:4484 61.63.49.9:80 CLOSE_WAIT 448
TCP * . * . 216.119:4485 58.251.150.200:80 CLOSE_WAIT 448
TCP * . * . 216.119:4486 119.147.7.227:80 CLOSE_WAIT 448
TCP * . * . 216.119:4487 119.147.7.227:80 CLOSE_WAIT 448
TCP * . * . 216.119:4488 119.147.7.227:80 CLOSE_WAIT 448
TCP * . * . 216.119:4489 58.251.150.200:80 CLOSE_WAIT 448
TCP * . * . 216.119:4490 123.138.238.204:80 CLOSE_WAIT 448
用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; CIBA)