杀毒后无法安装运行瑞星等杀毒软件的解决办法

最近学校流行一种病毒,中毒机器无法运行Icesword.exe、autoruns.exe和大部分的杀毒软件(够狠啊,要知道我平时手工查杀病毒都是靠这些家伙的),把这些文件的改名后就可以运行了,之前我一直以为是病毒程序一发现这些文件名就kill掉这些进程了。但是今天用icesword却没有发现有进程kill这些程序的痕迹,可见原理不是这样的。google后才知道根注册表有关,所以即使是清除病毒后这些名字的文件依然还是无法执行的。相关地方在[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options]中。
下面是该病毒在这些地方添加的选项,凡是有debugger=xxx字样的都是该病毒做了手脚的,应该是添加这些选项后,windows一执行这些文件就会先执行"debugger="后面的地址文件,又由于病毒文件已经被清除,所以会弹出一个警告框说是找不到文件。解决的办法就是把这些添加的东东都删掉。手工活,累啊,以后有空再写个简单程序来清除吧。(由于太多了,后面的忽略掉很多了。)
 
============================================================================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options]
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360rpt.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360Safe.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360tray.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/adam.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/AgentSvr.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/apitrap.dll]
"CheckAppHelp"=dword:00000001
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/AppSvc32.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/ASSTE.dll]
"CheckAppHelp"=dword:00000001
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/autoruns.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avconsol.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avgrssvc.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/AvMonitor.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avp.com]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
…………………………
===================================
 
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值