Active Connections
Proto Local Address Foreign Address State
TCP WWW-8S633332196:1025 3929.cn:5550 ESTABLISHED
TCP WWW-8S633332196:5550 3929.cn:1025 ESTABLISHED
TCP WWW-8S633332196:8000 3929.cn:39251 TIME_WAIT
TCP WWW-8S633332196:8000 3929.cn:39253 TIME_WAIT
TCP WWW-8S633332196:8000 3929.cn:39254 TIME_WAIT
TCP WWW-8S633332196:8000 3929.cn:39255 TIME_WAIT
TCP WWW-8S633332196:8000 3929.cn:39256 TIME_WAIT
TCP WWW-8S633332196:8000 3929.cn:39261 ESTABLISHED
TCP WWW-8S633332196:8000 3929.cn:39262 TIME_WAIT
TCP WWW-8S633332196:8000 3929.cn:39263 TIME_WAIT
TCP WWW-8S633332196:8000 3929.cn:39264 TIME_WAIT
TCP WWW-8S633332196:8000 3929.cn:39265 TIME_WAIT
TCP WWW-8S633332196:8000 3929.cn:39266 TIME_WAIT
TCP WWW-8S633332196:11433 3929.cn:33766 CLOSE_WAIT
TCP WWW-8S633332196:11433 3929.cn:33767 CLOSE_WAIT
TCP WWW-8S633332196:11433 3929.cn:34193 CLOSE_WAIT
TCP WWW-8S633332196:11433 3929.cn:34194 CLOSE_WAIT
TCP WWW-8S633332196:11433 3929.cn:34438 CLOSE_WAIT
TCP WWW-8S633332196:11433 3929.cn:35073 CLOSE_WAIT
TCP WWW-8S633332196:11433 3929.cn:35074 CLOSE_WAIT
TCP WWW-8S633332196:33766 3929.cn:11433 FIN_WAIT_2
TCP WWW-8S633332196:33767 3929.cn:11433 FIN_WAIT_2
TCP WWW-8S633332196:34193 3929.cn:11433 FIN_WAIT_2
TCP WWW-8S633332196:34194 3929.cn:11433 FIN_WAIT_2
TCP WWW-8S633332196:34438 3929.cn:11433 FIN_WAIT_2
TCP WWW-8S633332196:35073 3929.cn:11433 FIN_WAIT_2
TCP WWW-8S633332196:35074 3929.cn:11433 FIN_WAIT_2
TCP WWW-8S633332196:38186 3929.cn:38187 ESTABLISHED
TCP WWW-8S633332196:38187 3929.cn:38186 ESTABLISHED
TCP WWW-8S633332196:39261 3929.cn:8000 ESTABLISHED
这样我访问本地的测试网站端口时,都会被重定向到3929.cn的端口,后果可想而知。
hosts文件被添加了如下内容,一看就知道是被篡改过的
127.0.0.1 3929.cn
127.0.0.1 aaa.369678.cn
127.0.0.1 about-blank.cc
127.0.0.1 anjdyazj.cn
127.0.0.1 caiyi8.com
127.0.0.1 hao.allxun.com
127.0.0.1 kzxf.com
127.0.0.1 scvip.com
127.0.0.1 vod.mmdy.org
127.0.0.1 www.123wa.com
127.0.0.1 www.369678.cn
127.0.0.1 www.3929.cn
127.0.0.1 www.4199.com
127.0.0.1 www.71791.com
127.0.0.1 www.7939.com
127.0.0.1 www.9505.com
127.0.0.1 www.anjdyazj.cn
127.0.0.1 www.caiyi8.com
127.0.0.1 www.feixue.net
127.0.0.1 www.kzxf.com
127.0.0.1 www.my123.com
127.0.0.1 www.piaoxue.com
127.0.0.1 www.scvip.com
127.0.0.1 www.xfkz.com
127.0.0.1 xfkz.com
可气的是,本地的hosts文件竟然无法修改。只能在windows安全模式下修改。