杀毒后无法安装运行瑞星等杀毒软件的解决办法
2007-09-30 12:41
746 查看
最近学校流行一种病毒,中毒机器无法运行Icesword.exe、autoruns.exe和大部分的杀毒软件(够狠啊,要知道我平时手工查杀病毒都是靠这些家伙的),把这些文件的改名后就可以运行了,之前我一直以为是病毒程序一发现这些文件名就kill掉这些进程了。但是今天用icesword却没有发现有进程kill这些程序的痕迹,可见原理不是这样的。google后才知道根注册表有关,所以即使是清除病毒后这些名字的文件依然还是无法执行的。相关地方在[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options]中。
下面是该病毒在这些地方添加的选项,凡是有debugger=xxx字样的都是该病毒做了手脚的,应该是添加这些选项后,windows一执行这些文件就会先执行"debugger="后面的地址文件,又由于病毒文件已经被清除,所以会弹出一个警告框说是找不到文件。解决的办法就是把这些添加的东东都删掉。手工活,累啊,以后有空再写个简单程序来清除吧。(由于太多了,后面的忽略掉很多了。)
============================================================================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options]
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360rpt.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360Safe.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360tray.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/adam.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/AgentSvr.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/apitrap.dll]
"CheckAppHelp"=dword:00000001
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/AppSvc32.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/ASSTE.dll]
"CheckAppHelp"=dword:00000001
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/autoruns.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avconsol.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avgrssvc.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/AvMonitor.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avp.com]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
…………………………
===================================
下面是该病毒在这些地方添加的选项,凡是有debugger=xxx字样的都是该病毒做了手脚的,应该是添加这些选项后,windows一执行这些文件就会先执行"debugger="后面的地址文件,又由于病毒文件已经被清除,所以会弹出一个警告框说是找不到文件。解决的办法就是把这些添加的东东都删掉。手工活,累啊,以后有空再写个简单程序来清除吧。(由于太多了,后面的忽略掉很多了。)
============================================================================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options]
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360rpt.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360Safe.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360tray.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/adam.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/AgentSvr.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/apitrap.dll]
"CheckAppHelp"=dword:00000001
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/AppSvc32.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/ASSTE.dll]
"CheckAppHelp"=dword:00000001
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/autoruns.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avconsol.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avgrssvc.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/AvMonitor.exe]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avp.com]
"Debugger"="C://Program Files//Common Files//Microsoft Shared//hwxwctd.exe"
…………………………
===================================
相关文章推荐
- autorun.inf病毒与杀毒软件无法启动,及映像劫持(Image File Execution Options)解决办法
- 转:WIN7上搭建Windows Phone 8 开发环境——VMware Workstation下Win8 “无法安装Hyper-V, 某个虚拟机监控程序正在运行”问题解决的办法
- 安装Win7X64出现“windows安装程序无法将windows配置为在此计算机的硬件上运行”解决办法
- VS2015 安装mvc4安装包以及vs2010 sp1后导致Razor语法失效代码不高亮(能正常运行)/视图页面无法智能提示(.cshtml)解决办法
- 让任何杀毒软件都无法安装和运行的病毒,有谁见过并且知道该怎么办吗?
- VS.NET 2005安装中出现的"dte80a.olb could not be loaded"无法启动软件的原因和解决办法
- Win7 64位下安装MATLAB7.0后,无法正常运行的解决办法
- Ubuntu中apt-get 安装失败,导致无法安装其他软件的解决办法。
- 无法启动调试 未安装silverlight developer 运行时 解决办法
- Android Studio升级到2.3.1,小米MI无法安装apk,安装失败,闪退,即时运行 失败,Session 'app': Error Installing APKs,问题解决办法
- 软件包 xxx需要重新安装,但是我(apt)无法找到相应的安装文件的解决办法
- 【Windows8无法使用杀毒软件的解决办法】
- vs2003启动调试时出现“无法启动调试器,请运行安装程序安装或修复调试器”的解决办法
- 无法启动调试 未安装silverlight developer 运行时 解决办法
- MAC上搭建Windows Phone 8 开发环境——VMware Fusion下Win8 “无法安装Hyper-V, 某个虚拟机监控程序正在运行”问题解决的办法
- 关于linux(CentOS)无法更新安装软件出错的解决办法(提示The program package-cleanup is found in the yum-utils package)
- 无法启动调试 未安装silverlight developer 运行时 解决办法
- 系统同时安装多种杀毒软件的解决办法
- Vbsedit 安装 8.0 导致 7.x无法运行的解决办法
- 关于redhat5.4的最新QT SDK的安装后无法编译运行的解决办法(我弄了好几天亲测好用)