瑞星卡卡安全论坛
妍汐 - 2007-6-7 16:02:00
老是提示“应用程序正常初始化(oxc00000ba)失败”
杀毒软件不能打开,卸载之后重新装还是这样~
请问下是什么原因~
tongtree - 2007-6-7 16:16:00
下载 System Repair Engineer,
http://www.kztechs.com/sreng/download.html
1 解压缩sreng2.zip
2 运行SREng.exe
3 智能扫描=》扫描=》保存报告
4 把日志中的报告完整拷贝贴上来,不要修改
日志一次发不完,请分次发上来
(扫日志前请尽可能的关闭能手动关闭的窗口 如:QQ、音乐、网业)
妍汐 - 2007-6-7 16:26:00
[CODE]
2007-06-07,16:10:49
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 2 (Build 2600) - 管理权限用户 - 完整功能
以下内容被选中:
所有的启动项目(包括注册表、启动文件夹、服务等)
浏览器加载项
正在运行的进程(包括进程模块信息)
文件关联
Winsock 提供者
Autorun.inf
HOSTS 文件
启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Windows Publisher]
<PHIME2002ASync><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Windows Publisher]
<PHIME2002A><C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Windows Publisher]
<NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<nwiz><nwiz.exe /install> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<SoundMan><SOUNDMAN.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<RavTask><"d:\Program Files\Rising\Rav\RavTask.exe" -system> [Beijing Rising Technology Co., Ltd.]
<runeip><D:\Program Files\Rising\KakaToolBar\runiep.exe> [Beijing Rising Technology Co., Ltd.]
<MSConfig><C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\WINDOWS\system32\RavExt.dll> [Beijing Rising Technology Co., Ltd.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
<WinlogonNotify: WgaLogon><WgaLogon.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<DAEMON Tools><; "d:\Program Files\DAEMON Tools\daemon.exe" -lang 1033> [(Verified)DAEMON Tools Code Signing Services]
<dasa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\daso.exe> [N/A]
<fysa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\fyso.exe> [N/A]
<Google IME Autoupdater><; "d:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe"> [N/A]
<jtsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\jtso.exe> [N/A]
<mhsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\mhso.exe> [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<MsnMsgr><; "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<qjsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\qjso.exe> [N/A]
<rxsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\rxso.exe> [N/A]
<SoundMan><; SOUNDMAN.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<tlsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\tlso.exe> [N/A]
<wdsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\wdso.exe> [N/A]
<wgsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\wgso.exe> [N/A]
<WinampAgent><; d:\Program Files\Winamp\winampa.exe> []
<wlsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\wlso.exe> [N/A]
<wmsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\wmso.exe> [N/A]
<wosa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\woso.exe> [N/A]
<ztsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\ztso.exe> [N/A]
妍汐 - 2007-6-7 16:27:00
==================================
启动文件夹
N/A
==================================
服务
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart][Stopped/Auto Start]
<C:\WINDOWS\system32\ati2sgag.exe><>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Driver Helper Service / NVSvc][Stopped/Auto Start]
<C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>
[Windows Live Setup Service / WLSetupSvc][Stopped/Manual Start]
<"C:\Program Files\Windows Live\installer\WLSetupSvc.exe"><>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
<"d:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
==================================
驱动程序
[Service for WDM 3D Audio Driver / ALCXSENS][Stopped/Manual Start]
<system32\drivers\ALCXSENS.SYS><Sensaura Ltd>
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Running/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Rising TDI Base Driver / BaseTDI][Running/Auto Start]
<System32\DRIVERS\BaseTDI.SYS><Beijing Rising Technology Co., Ltd.>
[ExpScaner / ExpScaner][Stopped/Auto Start]
<\??\d:\Program Files\Rising\Rav\ExpScan.sys><>
[GMSIPCI / GMSIPCI][Stopped/Manual Start]
<\??\G:\INSTALL\GMSIPCI.SYS><N/A>
[HookCont / HookCont][Stopped/Auto Start]
<\??\d:\Program Files\Rising\Rav\HOOKCONT.sys><Rising tech Co. ltd>
[HookReg / HookReg][Stopped/Auto Start]
<\??\d:\Program Files\Rising\Rav\HookReg.sys><>
[HookSys / HookSys][Stopped/Auto Start]
<\??\d:\Program Files\Rising\Rav\HookSys.sys><Rising>
[MEMSCAN / MEMSCAN][Stopped/Auto Start]
<\??\d:\Program Files\Rising\Rav\MEMSCAN.sys><瑞星软件有限公司>
[npkcrypt / npkcrypt][Running/Auto Start]
<\??\D:\Program Files\Tencent\QQ\npkcrypt.sys><INCA Internet Co., Ltd.>
[nv / nv][Stopped/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[RsAntiSpyware / RsAntiSpyware][Running/Boot Start]
<\SystemRoot\system32\drivers\RsBoot.sys><Beijing Rising>
[RSPPSYS / RSPPSYS][Stopped/Auto Start]
<\??\d:\Program Files\Rising\Rav\RSPPSYS.sys><Rising>
[Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver / rtl8139][Running/Manual Start]
<system32\DRIVERS\R8139n51.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[sptd / sptd][Running/Boot Start]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
[Sony Ericsson W800 driver (WDM) / w800bus][Stopped/Manual Start]
<system32\DRIVERS\w800bus.sys><MCCI>
[Sony Ericsson W800 USB WMC Modem Filter / w800mdfl][Stopped/Manual Start]
<system32\DRIVERS\w800mdfl.sys><MCCI>
[Sony Ericsson W800 USB WMC Modem Drivers / w800mdm][Stopped/Manual Start]
<system32\DRIVERS\w800mdm.sys><MCCI>
[Sony Ericsson W800 USB WMC Device Management Drivers / w800mgmt][Stopped/Manual Start]
<system32\DRIVERS\w800mgmt.sys><MCCI>
[Sony Ericsson W800 USB WMC OBEX Interface Drivers / w800obex][Stopped/Manual Start]
<system32\DRIVERS\w800obex.sys><MCCI>
==================================
浏览器加载项
[Thunder Browser Helper]
{02478D37-C3F9-4EFB-9B51-7695ECA05670} <d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
[Yahoo! Toolbar Helper]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, N/A>
[BitComet Helper]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <d:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll, BitComet>
[启动迅雷5]
{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} <d:\Program Files\Thunder Network\Thunder\Thunder.exe, Thunder Networking Technologies,LTD>
[信息检索(&R)]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL, Microsoft Corporation>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683}? <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[卡卡上网安全助手]
{DB9ECD4F-FB8F-4311-B3CE-90B976C2707C} <C:\WINDOWS\system32\KakaTool.dll, Beijing Rising Technology Co., Ltd.>
[Yahoo! Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, N/A>
[Office Genuine Advantage Validation Tool]
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} <C:\WINDOWS\system32\OGACheckControl.DLL, >
[Edit Class]
{0CA54D3F-CEAE-48AF-9A2B-31909CB9515D} <C:\WINDOWS\system32\CMBEdit.dll, >
[EditCtrl Class]
{488A4255-3236-44B3-8F27-FA1AECAA8844} <C:\WINDOWS\system32\aliedit\aliedit.dll, >
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, Microsoft Corporation>
[WebActivater Control]
{C661F36D-DF85-4EF4-83C7-E107B83D04B1} <C:\WINDOWS\system32\3DShowVM.ocx, QQ>
[Office Update Installation Engine]
{C7DB51B4-BCF7-4923-8874-7F1A0DC92277} <C:\WINDOWS\opuc.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Thunder Browser Helper]
{02478D37-C3F9-4EFB-9B51-7695ECA05670} <d:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_007.dll, Thunder Networking Technologies,LTD>
[Yahoo! Toolbar Helper]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, N/A>
[BitComet Helper]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <d:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll, BitComet>
[&使用BitComet下载]
<res://d:\Program Files\BitComet\BitComet.exe/AddLink.htm, N/A>
[&使用BitComet下载全部链接]
<res://d:\Program Files\BitComet\BitComet.exe/AddAllLink.htm, N/A>
[&使用BitComet下载本页视频]
<res://d:\Program Files\BitComet\BitComet.exe/AddVideo.htm, N/A>
[&使用迅雷下载]
<d:\Program Files\Thunder Network\Thunder\Program\geturl.htm, N/A>
[&使用迅雷下载全部链接]
<d:\Program Files\Thunder Network\Thunder\Program\getallurl.htm, N/A>
[导出到 Microsoft Excel(&X)]
<res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000, N/A>
[导出到 Microsoft Office Excel(&X)]
<res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000, N/A>
[添加到QQ表情]
<D:\Program Files\Tencent\QQ\AddEmotion.htm, N/A>
妍汐 - 2007-6-7 16:27:00
==================================
正在运行的进程
[PID: 516][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 572][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 600][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4132]
[C:\WINDOWS\system32\WgaLogon.dll] [Microsoft Corporation, 1.7.0018.5]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 644][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 656][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 816][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4132]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2500]
[PID: 828][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 892][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 956][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1000][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1072][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1672][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\system32\RavExt.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 21]
[d:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[PID: 376][C:\WINDOWS\system32\wscntfy.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 800][C:\WINDOWS\system32\conime.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1124][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 5, 1, 0, 58]
[PID: 1144][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1192][d:\Program Files\Rising\Rav\RavTask.exe] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 22]
[d:\Program Files\Rising\Rav\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[d:\Program Files\Rising\Rav\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[d:\Program Files\Rising\Rav\CfgDll.dll] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 11]
[d:\Program Files\Rising\Rav\RsCommX.dll] [rising, 18, 0, 0, 1]
[PID: 2328][E:\setup\sreng2\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
==================================
文件关联
.TXT Error. [C:\WINDOWS\notepad.exe %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM Error. ["hh.exe" %1]
.HLP Error. [winhlp32.exe %1]
.INI Error. [C:\WINDOWS\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
N/A
==================================
Autorun.inf
N/A
==================================
HOSTS 文件
N/A
==================================
API HOOK
N/A
==================================
隐藏进程
N/A
==================================
[/CODE]
妍汐 - 2007-6-7 16:33:00
<dasa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\daso.exe> [N/A]
<fysa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\fyso.exe> [N/A]
<Google IME Autoupdater><; "d:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe"> [N/A]
<jtsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\jtso.exe> [N/A]
<mhsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\mhso.exe> [N/A]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<MsnMsgr><; "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<qjsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\qjso.exe> [N/A]
<rxsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\rxso.exe> [N/A]
<SoundMan><; SOUNDMAN.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<tlsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\tlso.exe> [N/A]
<wdsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\wdso.exe> [N/A]
<wgsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\wgso.exe> [N/A]
<WinampAgent><; d:\Program Files\Winamp\winampa.exe> []
<wlsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\wlso.exe> [N/A]
<wmsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\wmso.exe> [N/A]
<wosa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\woso.exe> [N/A]
<ztsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\ztso.exe> [N/A]
这一堆应该是病毒吧~但是我已经把temp文件夹删空了~
火影忍者 - 2007-6-7 16:40:00
| 引用: |
【妍汐的贴子】<dasa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\daso.exe> [N/A] <fysa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\fyso.exe> [N/A] <Google IME Autoupdater><; "d:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe"> [N/A] <jtsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\jtso.exe> [N/A] <mhsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\mhso.exe> [N/A] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <MsnMsgr><; "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <qjsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\qjso.exe> [N/A] <rxsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\rxso.exe> [N/A] <SoundMan><; SOUNDMAN.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher] <tlsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\tlso.exe> [N/A] <wdsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\wdso.exe> [N/A] <wgsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\wgso.exe> [N/A] <WinampAgent><; d:\Program Files\Winamp\winampa.exe> [] <wlsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\wlso.exe> [N/A] <wmsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\wmso.exe> [N/A] <wosa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\woso.exe> [N/A] <ztsa><; C:\DOCUME~1\小林菜\LOCALS~1\Temp\ztso.exe> [N/A]
这一堆应该是病毒吧~但是我已经把temp文件夹删空了~ ……………… |
把这些启动项都删了!
火影忍者 - 2007-6-7 16:40:00
具体的是提示哪个应用程序错误?
妍汐 - 2007-6-7 16:41:00
用SREng.EXE把这些启动的都删了~
妍汐 - 2007-6-7 16:42:00
应用程序正常初始化(oxc00000ba)失败。
水蓝浅心 - 2007-6-7 16:46:00
你的修好了吗
妍汐 - 2007-6-7 16:47:00
没用,重启了无数次了~该删的也删完了~还是不行~
水蓝浅心 - 2007-6-7 16:52:00
是不是和系统起冲突啊?有的人叫我重装系统
妍汐 - 2007-6-7 16:56:00
不至于吧,2个小时之前都是正常的~不会才这么一会就冲突了吧~
水蓝浅心 - 2007-6-7 16:58:00
我是昨天下午突然出现的这个问题,不知道是怎么回事?
见证成长 - 2007-6-7 18:42:00
救命啊!大家千万别把这帖忽略了啊!我看是新病毒-江民上说是“光标病毒”,暂时还没好的解决方案,而且重装系统后被感染的几率很高
疯狂的小鱼 - 2007-6-8 10:11:00
我的瑞星也出现这种问题了,初始化(oxc00000ba)失败,瑞星杀毒用不了,重装了也不行,急求各位高手怎么解决啊?谢谢
妍汐 - 2007-6-8 10:56:00
好吓人哦~说得越来越恐怖了~
黑羽vin - 2007-6-8 12:08:00
我的也这样~~~5555555555
昨天晚上插了下同学的u盘 然后 瑞星监控就自动全部关闭了~~
然后我用瑞星杀掉个毒~.\SysInfo2.Dll 好象是这个~~
然后过了会 就连续出现 同一个毒 被清除掉~~不知道是什么毒~~
今天早上 起来 开机 瑞星 就打不开了 初始化 失败~~
和LZ一样~~~
黑羽vin - 2007-6-8 12:20:00
启动里多了N个莫名的东西 晕死了哦
打开启动项,吓我一跳,里面出现一大堆 ztso jtso fyso wmso qjso wdso 十几个,还有几个其他莫名其妙的
黑羽vin - 2007-6-8 12:21:00
应该是新病毒吧~~网上找了下 都是这2天内的
黑羽vin - 2007-6-8 12:25:00
救救偶滴瑞星吧~~~~~
黑羽vin - 2007-6-8 12:32:00
偶现在重装下瑞星~~~~希望有救~~~~~~
loveperday - 2007-6-8 13:16:00
肯定没救。
学学手动杀毒吧
火云流舞 - 2007-6-8 13:19:00
求高手来9啊,偶这里做毕业设计的。老师与我的机器被黑了一大堆了,就是这个毒
buzui686 - 2007-6-8 13:31:00
我的也是啊 还不光是瑞星 只要是关于杀毒软件 都不行 都是初始化失败 哪位高手 出出招 救救命啊
妍汐 - 2007-6-8 13:39:00
我现在电脑里已经没有ztso jtso fyso wmso qjso wdso 这些不知道是什么的病毒了,但是杀毒软件卸载重装了两次,还是无法启动,不过很奇怪的是,瑞星的上网助手一开机就自动开了,还有那个什么硬盘自动备份的东西今天也莫名其妙的自己在运行~~~~~~很是郁闷
翔空万里 - 2007-6-8 13:51:00
相信你下了千千静听这个软件,而且是在官网上,看下我的帖子嘛(http://forum.ikaka.com/topic.asp?board=28&artid=8320771),看有帮助没,至少我知道现在瑞星没有解决办法.只能说运气不好了
黑羽vin - 2007-6-8 13:51:00
我重装了 可以哦`~~~不过还米升级好 今天的升级次数 到了 ~~郁闷 忽忽
妍汐 - 2007-6-8 14:06:00
不对,应该不是千千静听惹的祸~
我电脑里的千千静听是N久以前装系统的时候装的,版本还是4.X 绝对不是最新的~
而且我的音响坏了很久了,也就是说我很久都没有用过千千静听之类的播放器了~
昨天中午都还是好好的~就是大概在下午2点钟左右的样子,我正在看新浪的财经频道,也没有打开其他网站,突然浏览器自动报错关闭了,然后再打开,又关闭~
我原本以后是maxthon出问题了,于是我卸载后重装~
接着就是瑞星莫名其妙自动关闭~~~~~再也无法打开……
© 2000 - 2025 Rising Corp. Ltd.