瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 运行大部分程序,都出现“应用程序错误,错误模块unknown”

1   1  /  1  页   跳转

运行大部分程序,都出现“应用程序错误,错误模块unknown”

运行大部分程序,都出现“应用程序错误,错误模块unknown”

电脑一直有病毒,原先安装了诺顿,后来想安装瑞星。在卸载了诺顿还没安装瑞星前,问题就出来了,切换输入法、运行系统还原、重新安装诺顿等都发生故障(IE可以使用),要么提示“应用进程关闭,服务发生意外”,要么提示“指令引用的0x00000000 内存,该内存不能read”,打开事件查看器,发现运行的大部分程序都“应用程序错误,错误模块unknown”。在安全模式下运行,也同样出现上述问题。另用瑞星查杀了56个病毒,大部分为木马。
    由于此机不在我这,暂时无法提供扫描日记,明天周一补上。
    小弟不才,还望各位哥们姐们给予解答,万分感激。。
最后编辑2006-09-25 10:35:10
分享到:
gototop
 

可能:
1、内存有问题,但系统能正常进入,且卸载诺顿前没有这样的故障。
2、病毒所致,但安全模式下运行那些程序也不正常。
3、系统极度混乱,但为什么会发生在卸载诺顿之后呢,之前不会这样的。
小弟比较菜,不知对否?
gototop
 

回楼上:没有出现256色。
我明天贴日志出来。
非常感谢仙剑VS景天,明天还得继续捧场啊。。
gototop
 

HijackThis@Qoo的扫描日志  V1.97.7
Scan saved at 9:07:30, on 2006-9-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rising\Rav\CCenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Rising\Rav\Ravmond.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Rising\Rav\RavStub.exe
C:\WINDOWS\System32\NMSSvc.exe
C:\Program Files\Rising\Rav\RavTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
D:\hijackthis1.97_qoo\HijackThis.exe

O2 - BHO: (no name) - {0237F8EA-ACCF-4966-B5B6-94158ED06726} - (no file)
O2 - BHO: (no name) - {0587B496-60E9-412A-BA18-F8BBBD00D224} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0815A83B-D33F-4934-B2D5-99C1978E9163} - (no file)
O2 - BHO: (no name) - {096CD5B3-1BD6-4AA2-A305-8961BFF0B397} - (no file)
O2 - BHO: (no name) - {1EC9AF4F-6073-410E-905C-C60A6A6DA86C} - (no file)
O2 - BHO: (no name) - {2CECAE54-E800-4B48-B6FF-58F123FAE17A} - (no file)
O2 - BHO: (no name) - {389506B1-F883-4628-B9C7-843BE1CFD79C} - (no file)
O2 - BHO: (no name) - {53D802F8-E82D-443B-B072-32C6B831141E} - (no file)
O2 - BHO: QQIEHelper - {54EBD53A-9BC1-480B-966A-843A333CA162} - C:\Program Files\Tencent\QQ\QQIEHelper.dll
O2 - BHO: (no name) - {56589274-293F-4BB1-B0B2-BA79CA8534D3} - (no file)
O2 - BHO: (no name) - {576CD809-6866-4723-8088-A47B5EDA2D42} - (no file)
O2 - BHO: (no name) - {5BDAF7D5-833A-4B6E-B57B-80FA41EF6260} - (no file)
O2 - BHO: (no name) - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: (no name) - {75BF5B37-AB0F-4669-9D39-A7C0EAF0064B} - (no file)
O2 - BHO: (no name) - {7FCAE974-35A9-452C-9279-8017C8E2E8A3} - (no file)
O2 - BHO: (no name) - {8C02EB00-6109-4DFA-A9E5-C8B8F667C57D} - (no file)
O2 - BHO: (no name) - {8F23FD06-310E-46AF-99D2-93DC3E94F994} - (no file)
O2 - BHO: (no name) - {8F2AC498-28E3-47FB-8DE6-787440D47386} - (no file)
O2 - BHO: (no name) - {8FE1065D-0BBE-4D1C-9494-BE3B6FC20E50} - (no file)
O2 - BHO: (no name) - {96FB564A-67BA-44A1-8251-03E4FB6CB3CC} - (no file)
O2 - BHO: (no name) - {A24A7B24-AF57-471F-B75D-B1644F99A1BD} - (no file)
O2 - BHO: (no name) - {ABF11BB7-598E-44AC-83F7-7F6D6E912040} - (no file)
O2 - BHO: (no name) - {B81D1C08-6902-48B3-A68B-301B0A73EE69} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O2 - BHO: (no name) - {C3778605-E9E5-4DA1-AE01-0623A1D27A1F} - (no file)
O2 - BHO: (no name) - {CBA3CB2D-2257-4646-B096-7022FC1B97CB} - (no file)
O2 - BHO: (no name) - {DF500C0E-9BA0-4DF7-9E01-AF6B4EB029B0} - (no file)
O2 - BHO: (no name) - {E8E0F920-4BC4-4C43-AF50-042AEC388F4B} - (no file)
O2 - BHO: (no name) - {EE057389-4F2A-4530-B699-5598BEF64FD7} - (no file)
O2 - BHO: (no name) - {F337E106-761B-43A1-B598-979234F8CA2A} - (no file)
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [RavTask] "C:\Program Files\Rising\Rav\RavTask.exe" -system
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ntuser.dat
O4 - Startup: NTUSER.DAT.LOG
O4 - Startup: LuResult.txt
O4 - Startup: ntuser.ini
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O8 - Extra context menu item: 访问通用网址 - C:\Program Files\CNNIC\Cdn\cnnic.htm
O11 - Options group: [CDNCLIENT] 
O14 - IERESET.INF: START_PAGE_URL=http://www.legend.com
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://mybank.icbc.com.cn/icbc/perbank/AxSafeControls.cab
O16 - DPF: {8D9E0B29-563C-4226-86C1-5FF2AE77E1D2} (AxSubmitControl Class) - http://www.icbc.com.cn/personal/perbank/AxSafeControls.cab
O16 - DPF: {A162E671-4A6F-4BC0-A598-ED17DFFBDDD7} - http://218.85.138.27/vqqspeeddl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7D5BA373-6E00-40FA-9E8D-03E5AF1929B8}: NameServer = 210.39.0.33,210.39.0.34
O17 - HKLM\System\CCS\Services\Tcpip\..\{FACDEA4C-E728-4634-8EC3-FD078356549A}: NameServer = 210.39.0.33,210.39.0.34
O17 - HKLM\System\CS1\Services\Tcpip\..\{7D5BA373-6E00-40FA-9E8D-03E5AF1929B8}: NameServer = 210.39.0.33,210.39.0.34
O17 - HKLM\System\CS2\Services\Tcpip\..\{7D5BA373-6E00-40FA-9E8D-03E5AF1929B8}: NameServer = 210.39.0.33,210.39.0.34

大家帮我看看啊,急啊,电脑用都用不了,郁闷。。
gototop
 

搞定了,原来是诺顿没有完全清除,引起冲突。
我下载了Norton官方卸载工具彻底卸载Norton,然后在注册表把含诺顿的项全部删除。
故障清除真是爽,谢谢各位的捧场。。
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT