“时间病毒”,症状为:
1,重装系统无效(病毒可能感染了其他盘)【P.S.我那位朋友的就是他是IBM R52的机子,他重装无效后就全格了,再恢复成出厂设置】
2,系统时间的年份被改成2005年,月日时间不变,卡巴斯基无效(改了时间重启后又被改回去了)【所有杀毒软件失效,包括绿色杀毒软件和专杀】
3,查看隐藏文件无法设置
4,从安全模式一进去就蓝屏,停止错误编号:0x0000007B
5,所有关于杀毒软件的网页都打不开,一打开马上自动关了.
解决办法:
从注册表更改时间服务器----下载路径
http://www.neustyle.com.cn
把文件解压至C盘。双击time.reg。修改time.vbs里的服务器地址!
time.reg如下
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\Scripts]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Shutdown]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Shutdown\0]
"GPO-ID"="LocalGPO"
"SOM-ID"="Local"
"FileSysPath"="C:\\WINDOWS\\System32\\GroupPolicy\\Machine"
"DisplayName"="Local Group Policy"
"GPOName"="Local Group Policy"
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Shutdown\0\0]
"Script"="C:\\time.vbs"
"Parameters"=""
"ExecTime"=hex(b):00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Startup]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Scripts\Shutdown\0\0]
"Script"="C:\\time.vbs"
"Parameters"=""
"ExecTime"=hex(b):00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Shutdown\0\0]
"Script"="C:\\time.vbs"
"Parameters"=""
"ExecTime"=hex(b):00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"MRUList"="febcda"
"e"="C:\\time.vbs"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bat]
"c"="C:\\time.vbs"
因为QM用的是只读更新,禁了cmd。所以我做成vbs
time.vbs内容如下
set Ws = WScript.CreateObject("WScript.Shell")
ws.run "sc config w32time start= auto",0
ws.run "net stop w32time",0
ws.run "net start w32time",0
ws.run "net time \\server /set /y",0
可穿透冰点进行时间同步,在xp sp1,sp2,冰点6.0环境测试通过。穿透冰点的原理,来自网上收集。之后自己稍加修改。希望大家不再为时间病毒烦闷!