目前,俺的机子上一共装了三个杀毒软件,分别是
Kaspersky personal-pro 5.0.712.1
Eset NOD32 2.70.9.0
Dr.Web for windows 4.33.2.10060
我是如何这三个杀毒软件相安无事的并存的呢?
道理很简单,用哪个就开哪个的启动项、服务项、驱动,暂时屏蔽其他两个的启动项(可以通过SRENG或者msconfig),将另外两个的服务项的启动类型改为manual start...【SREng最新版用法】
1、kaspersky personal-pro 5.0.712.1
注册表 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<KAVPersonal50><; "F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize> [Kaspersky Lab]
服务项
[Kaspersky Anti-Virus Service / kavsvc]
<"F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe"><Kaspersky Lab>
驱动程序
[Kl1 / Kl1] 默认类型boot start 不用时改为manual start 下同!
<\SystemRoot\System32\drivers\kl1.sys><Kaspersky Lab>
[Klif / Klif] 默认类型system start
<System32\drivers\klif.sys><Kaspersky Labs>
[Klmc / Klmc] 默认类型system start
<System32\drivers\klmc.sys><Kaspersky Lab>
2、Eset NOD32 2.70.9.0
注册表 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<nod32kui><; "F:\Program Files\Eset\nod32kui.exe" /WAITSERVICE> [(Verified)Eset ]
服务项
[NOD32 Kernel Service / NOD32krn]
<"F:\Program Files\Eset\nod32krn.exe"><Eset>
驱动程序
[nod32drv / nod32drv] 默认类型system start
<\??\F:\WINDOWS\system32\drivers\nod32drv.sys><N/A>
3、Dr.Web for windows 4.33.2.10060
注册表 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SpIDerMail><"F:\Program Files\DrWeb\spiderml.exe"> [Doctor Web, Ltd.]
<DrWebScheduler><"F:\Program Files\DrWeb\DRWEBSCD.EXE"> [Doctor Web, Ltd.]
<SpIDerNT><F:\PROGRA~1\DrWeb\spidernt.exe /agent> [Doctor Web, Ltd.]
服务项
[SpIDer Guard for Windows NT / spidernt]
<F:\PROGRA~1\DrWeb\SpiderNT.exe><Doctor Web, Ltd.>
驱动
[SpIDer FS Monitor for Windows NT / SPIDER]默认Auto start
<\??\F:\PROGRA~1\DrWeb\spider.sys><Doctor Web, Ltd.>
[SpIDer Guard boot hook driver for Windows NT / drwebnet] 默认system start
<\SystemRoot\system32\drivers\drwebnet.sys><Doctor Web, Ltd.>
PS:Dr.Web和NOD32有点讨厌的就是要改写O10的LSP,不过我发现这两个貌似并不冲突??从SRENG的日志从能看到:
Winsock 提供者
NOD32 protected [MSAFD Tcpip [TCP/IP]]
F:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [MSAFD Tcpip [UDP/IP]]
F:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [MSAFD Tcpip [RAW/IP]]
F:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [RSVP UDP Service Provider]
F:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
NOD32 protected [RSVP TCP Service Provider]
F:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
DrwebSP.MSAFD Tcpip [TCP/IP]
F:\WINDOWS\system32\DRWEBSP.DLL(Doctor Web, Ltd., Dr.Web Winsock Provider Hook)
DrwebSP.MSAFD Tcpip [UDP/IP]
F:\WINDOWS\system32\DRWEBSP.DLL(Doctor Web, Ltd., Dr.Web Winsock Provider Hook)
DrwebSP.RSVP TCP Service Provider
F:\WINDOWS\system32\DRWEBSP.DLL(Doctor Web, Ltd., Dr.Web Winsock Provider Hook)
DrwebSP.RSVP UDP Service Provider
F:\WINDOWS\system32\DRWEBSP.DLL(Doctor Web, Ltd., Dr.Web Winsock Provider Hook)
NOD32
F:\WINDOWS\system32\imon.dll(Eset , NOD32 IMON - Internet scanning support)
----------------------------------
teYqiu【天下无毒】原创文章,转载请标明。 |