[問題] 可以上bbs卻無法開啟網頁

看板AntiVirus作者 (Hello Kitty水果酥)時間17年前 (2008/11/05 00:06), 編輯推噓5(503)
留言8則, 5人參與, 最新討論串1/1
2.請詳細將問題描述在下方並建議使用系統分析軟體附上: 我可以上bbs,但是卻無法開啟網頁 Internet Explorer 無法顯示網頁 最有可能的原因: 您並未連線至網際網路。 該網站發生問題。 位址可能輸入錯誤。 您可以嘗試的方式: 診斷連線問題 其他資訊 有用小紅傘專業板更新到11/4,掃描過沒事 efix489也沒事 3.系統分析軟體使用方式: 請盡可能將分析軟體報告附上,解決機率才較高。 使用方式在下方連結內 Combofix : http://reinfors.googlepages.com/combofix.html Hijackthis: http://reinfors.googlepages.com/hijackthis SRENG : http://reinfors.googlepages.com/sreng.html 沒法上網,所以這三個沒做,抱歉 efix的log在此,對不起因為無法上網,請多多包含 4.89 2008-11-04 15:18:58 GMT+00:00 EFIX 4.89 - duu 2008-11-04 23:19:48.89 - NTFS Microsoft Windows XP [版本 5.1.2600] - Service Pack 3 執行位置: D:\Software\security ======================================================= EFix刪除的檔案列表: 沒有刪除任何檔案. ======================================================= EFix刪除的登錄值列表: 沒有刪除任何登錄值. ======================================================= EFix刪除的檔案備份位置列表: I:\autorun.inf => C:\NEFix\backup\files\I\autorun.inf k:\autorun.inf => C:\NEFix\backup\files\k\autorun.inf ======================================================= 各磁碟根目錄含有隱藏和系統屬性的檔案 : --sh--w 374 2008-04-16 03:12:03 D:\desktop.ini --sha-w 141,824 2008-08-25 00:11:01 D:\Thumbs.db --sha-w 1,609,801,728 2008-11-03 22:29:32 E:\pagefile.sys ======================================================= ****** Created 2008-10 to 2008-11 Files ****** 2008-11-04 . 2008-11-04 23:19 d-------- C:\WINDOWS\EFIXUNT 2008-11-04 . 2008-11-04 06:35 dr-h----- C:\Documents and Settings\duu\Recent 2008-10-05 . 2008-10-05 21:43 d-------- C:\Program Files\Google ======================================================= 執行中的程序: E:\Avira\AntiVir PersonalEdition Premium\sched.exe <Avira GmbH> E:\Avira\AntiVir PersonalEdition Premium\avguard.exe <Avira GmbH> E:\Avira\AntiVir PersonalEdition Premium\avesvc.exe <Avira GmbH> E:\Comodo\Firewall\cmdagent.exe <COMODO> C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe <Microsoft Corporation> C:\WINDOWS\System32\nvsvc32.exe <NVIDIA Corporation> C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe <Rocket Division Software> E:\Avira\AntiVir PersonalEdition Premium\avmailc.exe <Avira GmbH> E:\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE <Avira GmbH> C:\WINDOWS\System32\alg.exe <Microsoft Corporation> E:\Avira\AntiVir PersonalEdition Premium\avgnt.exe <Avira GmbH> E:\Comodo\Firewall\CPF.exe <COMODO> C:\Program Files\KKMAN\KKMAN.exe <N/A> C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE <Microsoft Corporation> E:\Microsoft Office\Office12\WINWORD.EXE <Microsoft Corporation> C:\Program Files\Windows Live\Messenger\msnmsgr.exe <Microsoft Corporation> C:\Program Files\Windows Live\Messenger\usnsvc.exe <Microsoft Corporation> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe <Microsoft Corporation> C:\WINDOWS\System32\wbem\wmiprvse.exe <Microsoft Corporation> C:\WINDOWS\system32\cmd.exe <Microsoft Corporation> C:\WINDOWS\explorer.exe <Microsoft Corporation> ======================================================= Hosts: Hosts Path: C:\WINDOWS\System32\drivers\etc\hosts 127.0.0.1 blogo.tw 127.0.0.1 club.blogo.tw 127.0.0.1 sedewanion.com 127.0.0.1 www.blogo.tw 127.0.0.1 www.1a123.com 127.0.0.1 www.lovebak.com 127.0.0.1 www.microsofttw.com 127.0.0.1 www.456kill.com 127.0.0.1 www.tw7890.com 127.0.0.1 366ip.com 登錄值列表 *** 注意 : 部分正常值不會顯示 *** [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 22:00] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-25 06:58] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-03 22:32] "NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-01-06 10:18] "avgnt"="E:\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [2008-07-17 23:31] "COMODO Firewall Pro"="E:\Comodo\Firewall\CPF.exe" [2008-04-22 15:23] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 22:00] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] . 2006-10-22 23:08 C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\ AcroIEHelper.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}] . 2008-02-01 17:26 C:\Program Files\Skype\Toolbars\Internet Explorer\ SkypeIEPlugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}] . 2007-08-06 17:11 C:\Program Files\FlashGet\jccatch.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] . 2007-08-24 07:01 E:\Microsoft Office\Office12\GrooveShellExtensions.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}] . 2007-05-19 00:13 C:\Program Files\FlashGet\getflash.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\ notify\WgaLogon\Settings] "DLLName"="wlnotify.dll" --a------ 2008-04-14 22:00 C:\WINDOWS\system32\wlnotify.dll MD5: f7a2245d8bd832d1e7a01c26d5e6efd0 2008-04-14 22:00 978432 C:\WINDOWS\explorer.exe MD5: 50d8db3bf83670339a8616eb5a75bf06 2007-06-13 21:10 977920 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe MD5: f7a2245d8bd832d1e7a01c26d5e6efd0 2008-04-14 22:00 978432 C:\WINDOWS\ServicePackFiles\i386\explorer.exe MD5: 613d7c29c9e3e2375971da7e42e4e330 2008-04-14 22:01 25088 C:\WINDOWS\ServicePackFiles\i386\userinit.exe MD5: 613d7c29c9e3e2375971da7e42e4e330 2008-04-14 22:01 25088 C:\WINDOWS\system32\userinit.exe MD5: 82fe81c7f30172a315ad70327b868436 2008-04-14 22:01 108544 C:\WINDOWS\ServicePackFiles\i386\services.exe MD5: 82fe81c7f30172a315ad70327b868436 2008-04-14 22:01 108544 C:\WINDOWS\system32\services.exe C:\Documents and Settings\duu\「開始」功能表\程式集\啟動\ 清除系統垃圾文件.lnk - D:\Software\清除系統垃圾文件.bat [2006-06-07 00:31:44 720] 服務 \ 驅動 列表: 顯示方式 : 啟動狀態 服務名稱;顯示名稱;檔案名稱 啟動狀態 : S0 = Boot Start S1 = System Start S2 = Auto Start S3 = Manual Start S4 = Disable S9 = Unknow S1 AmdPPM;AMD HwPState Processor Driver; "C:\WINDOWS\SYSTEM32\DRIVERS\AmdPPM.sys" [2007-04-16 21:46] S2 AntiVirMailService;Avira AntiVir Premium MailGuard; ""E:\Avira\AntiVir PersonalEdition Premium\avmailc.exe"" [2008-07-17 23:31] S2 antivirwebservice;Avira AntiVir Premium WebGuard; ""E:\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE"" [2008-07-17 23:31] S2 AVEService;Avira AntiVir Premium MailGuard helper service; ""E:\Avira\AntiVir PersonalEdition Premium\avesvc.exe"" [2008-07-17 23:31] S3 MobileAdapter;Huawei Mobile Adapter USB Modem and USB Serial; "C:\WINDOWS\SYSTEM32\DRIVERS\hmumdm.sys" [2007-03-27 10:26] S3 napagent;Network Access Protection Agent; "C:\WINDOWS\System32\svchost.exe -k netsvcs" [X] S3 NOWMEMDF;NOWMEMDF;"C:\WINDOWS\system32\NOWMEMDF.sys" [2005-11-02 10:23] S0 SI3112r;Silicon Image SiI 3512 SATARaid Controller; "C:\WINDOWS\SYSTEM32\DRIVERS\SI3112r.sys" [2003-05-30 16:05] S3 usb2vcom;Nokia CA-42 USB; "C:\WINDOWS\SYSTEM32\DRIVERS\usb2vcom.sys" [2005-05-25 11:24] napagent;Network Access Protection Agent; C:\WINDOWS\System32\qagentrt.dll [2008-04-14 21:59] ======================================================= winsock file list: 工作排程資料夾內的資料: 2008-10-30 C:\WINDOWS\TASKS\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 13:42] ======================================================= catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net SCANNING HIDDEN FILES ... SCANNING HIDDEN PROCESSES ... SCANNING HIDDEN AUTOSTART ENTRIES ... ======================================================= 2008-07-09 0:13:22.98 C:\NEFIX\BACKUP\log1.txt 4.89 2008-11-03 22:19:00 GMT+00:00 C:\NEFIX\BACKUP\LOG10.TXT 2008-07-22 15:36:12.18 C:\NEFIX\BACKUP\log2.txt 2008-08-13 12:36:02.60 C:\NEFIX\BACKUP\log3.txt 2008-08-17 22:33:42.85 C:\NEFIX\BACKUP\log4.txt 2008-08-30 12:06:09.53 C:\NEFIX\BACKUP\log5.txt 2008-09-18 23:03:23.96 C:\NEFIX\BACKUP\LOG6.TXT 4.88 2008-10-20 09:26:17 GMT+00:00 C:\NEFIX\BACKUP\LOG7.TXT 4.88 2008-10-27 22:57:47 GMT+00:00 C:\NEFIX\BACKUP\LOG8.TXT 4.88 2008-10-28 23:24:54 GMT+00:00 C:\NEFIX\BACKUP\LOG9.TXT ======================================================= 磁碟空間 C: - 634,695,680 位元組可用 磁碟空間 D: - 1,139,589,120 位元組可用 磁碟空間 E: - 731,947,008 位元組可用 掃描結束時間: 2008-11-04 23:21:54.40 -- ※ 發信站: 批踢踢實業坊(ptt.cc) ◆ From: 140.112.5.53

11/05 00:35, , 1F
沒看到什麼異常的東西
11/05 00:35, 1F

11/05 01:27, , 2F
我也是醬子耶...可以上bbs不能開網頁 囧rz
11/05 01:27, 2F

11/05 06:52, , 3F
網上找的到 開始--執行--cmd 輸入 netsh winsock reset
11/05 06:52, 3F

11/05 10:01, , 4F
我也是...可以上bbs卻不能開網頁..最後只能重灌 囧
11/05 10:01, 4F

11/05 18:47, , 5F
弄好了ㄟ 遇到貴人了 感恩~~
11/05 18:47, 5F

11/06 00:19, , 6F
沒有用阿..囧rz (用Winsock也沒有用..看來只好重灌了)
11/06 00:19, 6F

11/10 20:51, , 7F
結果居然是....沒有繳錢....囧rz
11/10 20:51, 7F

11/21 12:42, , 8F
= =
11/21 12:42, 8F
文章代碼(AID): #1947C9pC (AntiVirus)