关闭

杀毒后无法安装运行瑞星等杀毒软件的解决办法

1707人阅读 评论(0) 收藏 举报
最近学校流行一种病毒,中毒机器无法运行Icesword.exe、autoruns.exe和大部分的杀毒软件(够狠啊,要知道我平时手工查杀病毒都是靠这些家伙的),把这些文件的改名后就可以运行了,之前我一直以为是病毒程序一发现这些文件名就kill掉这些进程了。但是今天用icesword却没有发现有进程kill这些程序的痕迹,可见原理不是这样的。google后才知道根注册表有关,所以即使是清除病毒后这些名字的文件依然还是无法执行的。相关地方在[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options]中。
下面是该病毒在这些地方添加的选项,凡是有debugger=xxx字样的都是该病毒做了手脚的,应该是添加这些选项后,windows一执行这些文件就会先执行"debugger="后面的地址文件,又由于病毒文件已经被清除,所以会弹出一个警告框说是找不到文件。解决的办法就是把这些添加的东东都删掉。手工活,累啊,以后有空再写个简单程序来清除吧。(由于太多了,后面的忽略掉很多了。)
 
============================================================================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options]
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360rpt.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360Safe.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360tray.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/adam.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/AgentSvr.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/apitrap.dll]
"CheckAppHelp"=dword:00000001
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/AppSvc32.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/ASSTE.dll]
"CheckAppHelp"=dword:00000001
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/autoruns.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avconsol.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avgrssvc.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/AvMonitor.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avp.com]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
…………………………
===================================
 
0
0

查看评论
* 以上用户言论只代表其个人观点,不代表CSDN网站的观点或立场
    个人资料
    • 访问:222825次
    • 积分:3507
    • 等级:
    • 排名:第9876名
    • 原创:123篇
    • 转载:16篇
    • 译文:1篇
    • 评论:21条
    文章分类
    最新评论