[問題] 可以上bbs卻無法開啟網頁
2.請詳細將問題描述在下方並建議使用系統分析軟體附上:
我可以上bbs,但是卻無法開啟網頁
Internet Explorer 無法顯示網頁
最有可能的原因:
您並未連線至網際網路。
該網站發生問題。
位址可能輸入錯誤。
您可以嘗試的方式:
診斷連線問題
其他資訊
有用小紅傘專業板更新到11/4,掃描過沒事
efix489也沒事
3.系統分析軟體使用方式:
請盡可能將分析軟體報告附上,解決機率才較高。
使用方式在下方連結內
Combofix : http://reinfors.googlepages.com/combofix.html
Hijackthis: http://reinfors.googlepages.com/hijackthis
SRENG : http://reinfors.googlepages.com/sreng.html
沒法上網,所以這三個沒做,抱歉
efix的log在此,對不起因為無法上網,請多多包含
4.89 2008-11-04 15:18:58 GMT+00:00
EFIX 4.89 - duu 2008-11-04 23:19:48.89 - NTFS
Microsoft Windows XP [版本 5.1.2600] - Service Pack 3
執行位置: D:\Software\security
=======================================================
EFix刪除的檔案列表:
沒有刪除任何檔案.
=======================================================
EFix刪除的登錄值列表:
沒有刪除任何登錄值.
=======================================================
EFix刪除的檔案備份位置列表:
I:\autorun.inf => C:\NEFix\backup\files\I\autorun.inf
k:\autorun.inf => C:\NEFix\backup\files\k\autorun.inf
=======================================================
各磁碟根目錄含有隱藏和系統屬性的檔案 :
--sh--w 374 2008-04-16 03:12:03 D:\desktop.ini
--sha-w 141,824 2008-08-25 00:11:01 D:\Thumbs.db
--sha-w 1,609,801,728 2008-11-03 22:29:32 E:\pagefile.sys
=======================================================
****** Created 2008-10 to 2008-11 Files ******
2008-11-04 . 2008-11-04 23:19 d-------- C:\WINDOWS\EFIXUNT
2008-11-04 . 2008-11-04 06:35 dr-h----- C:\Documents and Settings\duu\Recent
2008-10-05 . 2008-10-05 21:43 d-------- C:\Program Files\Google
=======================================================
執行中的程序:
E:\Avira\AntiVir PersonalEdition Premium\sched.exe <Avira GmbH>
E:\Avira\AntiVir PersonalEdition Premium\avguard.exe <Avira GmbH>
E:\Avira\AntiVir PersonalEdition Premium\avesvc.exe <Avira GmbH>
E:\Comodo\Firewall\cmdagent.exe <COMODO>
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
<Microsoft Corporation>
C:\WINDOWS\System32\nvsvc32.exe <NVIDIA Corporation>
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
<Rocket Division Software>
E:\Avira\AntiVir PersonalEdition Premium\avmailc.exe <Avira GmbH>
E:\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE <Avira GmbH>
C:\WINDOWS\System32\alg.exe <Microsoft Corporation>
E:\Avira\AntiVir PersonalEdition Premium\avgnt.exe <Avira GmbH>
E:\Comodo\Firewall\CPF.exe <COMODO>
C:\Program Files\KKMAN\KKMAN.exe <N/A>
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE <Microsoft Corporation>
E:\Microsoft Office\Office12\WINWORD.EXE <Microsoft Corporation>
C:\Program Files\Windows Live\Messenger\msnmsgr.exe <Microsoft Corporation>
C:\Program Files\Windows Live\Messenger\usnsvc.exe <Microsoft Corporation>
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
<Microsoft Corporation>
C:\WINDOWS\System32\wbem\wmiprvse.exe <Microsoft Corporation>
C:\WINDOWS\system32\cmd.exe <Microsoft Corporation>
C:\WINDOWS\explorer.exe <Microsoft Corporation>
=======================================================
Hosts:
Hosts Path: C:\WINDOWS\System32\drivers\etc\hosts
127.0.0.1 blogo.tw
127.0.0.1 club.blogo.tw
127.0.0.1 sedewanion.com
127.0.0.1 www.blogo.tw
127.0.0.1 www.1a123.com
127.0.0.1 www.lovebak.com
127.0.0.1 www.microsofttw.com
127.0.0.1 www.456kill.com
127.0.0.1 www.tw7890.com
127.0.0.1 366ip.com
登錄值列表 *** 注意 : 部分正常值不會顯示 ***
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 22:00]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
[2004-02-25 06:58]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-03 22:32]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-01-06 10:18]
"avgnt"="E:\Avira\AntiVir PersonalEdition Premium\avgnt.exe"
[2008-07-17 23:31]
"COMODO Firewall Pro"="E:\Comodo\Firewall\CPF.exe" [2008-04-22 15:23]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 22:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
. 2006-10-22 23:08 C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\
AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
. 2008-02-01 17:26 C:\Program Files\Skype\Toolbars\Internet Explorer\
SkypeIEPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
. 2007-08-06 17:11 C:\Program Files\FlashGet\jccatch.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
. 2007-08-24 07:01 E:\Microsoft Office\Office12\GrooveShellExtensions.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
. 2007-05-19 00:13 C:\Program Files\FlashGet\getflash.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\
notify\WgaLogon\Settings]
"DLLName"="wlnotify.dll" --a------
2008-04-14 22:00 C:\WINDOWS\system32\wlnotify.dll
MD5: f7a2245d8bd832d1e7a01c26d5e6efd0 2008-04-14 22:00 978432
C:\WINDOWS\explorer.exe
MD5: 50d8db3bf83670339a8616eb5a75bf06 2007-06-13 21:10 977920
C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
MD5: f7a2245d8bd832d1e7a01c26d5e6efd0 2008-04-14 22:00 978432
C:\WINDOWS\ServicePackFiles\i386\explorer.exe
MD5: 613d7c29c9e3e2375971da7e42e4e330 2008-04-14 22:01 25088
C:\WINDOWS\ServicePackFiles\i386\userinit.exe
MD5: 613d7c29c9e3e2375971da7e42e4e330 2008-04-14 22:01 25088
C:\WINDOWS\system32\userinit.exe
MD5: 82fe81c7f30172a315ad70327b868436 2008-04-14 22:01 108544
C:\WINDOWS\ServicePackFiles\i386\services.exe
MD5: 82fe81c7f30172a315ad70327b868436 2008-04-14 22:01 108544
C:\WINDOWS\system32\services.exe
C:\Documents and Settings\duu\「開始」功能表\程式集\啟動\
清除系統垃圾文件.lnk - D:\Software\清除系統垃圾文件.bat
[2006-06-07 00:31:44 720]
服務 \ 驅動 列表:
顯示方式 : 啟動狀態 服務名稱;顯示名稱;檔案名稱
啟動狀態 : S0 = Boot Start S1 = System Start S2 = Auto Start
S3 = Manual Start S4 = Disable S9 = Unknow
S1 AmdPPM;AMD HwPState Processor Driver;
"C:\WINDOWS\SYSTEM32\DRIVERS\AmdPPM.sys" [2007-04-16 21:46]
S2 AntiVirMailService;Avira AntiVir Premium MailGuard;
""E:\Avira\AntiVir PersonalEdition Premium\avmailc.exe"" [2008-07-17 23:31]
S2 antivirwebservice;Avira AntiVir Premium WebGuard;
""E:\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE"" [2008-07-17 23:31]
S2 AVEService;Avira AntiVir Premium MailGuard helper service;
""E:\Avira\AntiVir PersonalEdition Premium\avesvc.exe"" [2008-07-17 23:31]
S3 MobileAdapter;Huawei Mobile Adapter USB Modem and USB Serial;
"C:\WINDOWS\SYSTEM32\DRIVERS\hmumdm.sys" [2007-03-27 10:26]
S3 napagent;Network Access Protection Agent;
"C:\WINDOWS\System32\svchost.exe -k netsvcs" [X]
S3 NOWMEMDF;NOWMEMDF;"C:\WINDOWS\system32\NOWMEMDF.sys" [2005-11-02 10:23]
S0 SI3112r;Silicon Image SiI 3512 SATARaid Controller;
"C:\WINDOWS\SYSTEM32\DRIVERS\SI3112r.sys" [2003-05-30 16:05]
S3 usb2vcom;Nokia CA-42 USB;
"C:\WINDOWS\SYSTEM32\DRIVERS\usb2vcom.sys" [2005-05-25 11:24]
napagent;Network Access Protection Agent;
C:\WINDOWS\System32\qagentrt.dll [2008-04-14 21:59]
=======================================================
winsock file list:
工作排程資料夾內的資料:
2008-10-30 C:\WINDOWS\TASKS\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 13:42]
=======================================================
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
hxxp://www.gmer.net
SCANNING HIDDEN FILES ...
SCANNING HIDDEN PROCESSES ...
SCANNING HIDDEN AUTOSTART ENTRIES ...
=======================================================
2008-07-09 0:13:22.98 C:\NEFIX\BACKUP\log1.txt
4.89 2008-11-03 22:19:00 GMT+00:00 C:\NEFIX\BACKUP\LOG10.TXT
2008-07-22 15:36:12.18 C:\NEFIX\BACKUP\log2.txt
2008-08-13 12:36:02.60 C:\NEFIX\BACKUP\log3.txt
2008-08-17 22:33:42.85 C:\NEFIX\BACKUP\log4.txt
2008-08-30 12:06:09.53 C:\NEFIX\BACKUP\log5.txt
2008-09-18 23:03:23.96 C:\NEFIX\BACKUP\LOG6.TXT
4.88 2008-10-20 09:26:17 GMT+00:00 C:\NEFIX\BACKUP\LOG7.TXT
4.88 2008-10-27 22:57:47 GMT+00:00 C:\NEFIX\BACKUP\LOG8.TXT
4.88 2008-10-28 23:24:54 GMT+00:00 C:\NEFIX\BACKUP\LOG9.TXT
=======================================================
磁碟空間 C: - 634,695,680 位元組可用
磁碟空間 D: - 1,139,589,120 位元組可用
磁碟空間 E: - 731,947,008 位元組可用
掃描結束時間: 2008-11-04 23:21:54.40
--
※ 發信站: 批踢踢實業坊(ptt.cc)
◆ From: 140.112.5.53
推
11/05 00:35, , 1F
11/05 00:35, 1F
推
11/05 01:27, , 2F
11/05 01:27, 2F
推
11/05 06:52, , 3F
11/05 06:52, 3F
推
11/05 10:01, , 4F
11/05 10:01, 4F
→
11/05 18:47, , 5F
11/05 18:47, 5F
推
11/06 00:19, , 6F
11/06 00:19, 6F
→
11/10 20:51, , 7F
11/10 20:51, 7F
→
11/21 12:42, , 8F
11/21 12:42, 8F