赛门铁克产品卸载方法

近期研究铁壳企业版,感觉这软件中规中矩,功能也不错,唯一的缺点就是太消耗资源,虽然新版本在资源优化上有了巨大的进步,但是对客户端还是有一定的资源开销。某些情况下,对于第三方cookie的判断还有待提高,个别的客户端QQ空间可能导致无法访问。

不过,最大的问题还是在于铁壳系列产品的通病:卸载不干净,安装失败后无法卸载或清理等。网上找了些方法,用来共享。

对于企业用户,如果之前被域管理员取消脚本或注册表执行权限的,可以用安全模式或者PE挂盘清理。如果不是很熟悉安全模式或者pe的使用方法,这步最好要管理员亲自来做。

铁壳企业版多了一个监测子网内未保护计算机的功能,卸载后最好和管理员说一下,当然也有小道方法可以绕过这个监测,这里就不拿出来害人了。

注册表清理密码:(默认密码:symantec)

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\VirusProtect6\CurrentVersion\AdministratorOnly\Security]

 "UseVPUninstallPassword"=dword:00000001

脚本卸载法:(–>下载)

'DECLARE VARIABLES
'On Error Resume Next
Dim path

Const HKEY_LOCAL_MACHINE = &H80000002
strComputer = "."

Set shell = CreateObject("WScript.Shell")
set fso = CreateObject("Scripting.FileSystemObject")
Set env = shell.Environment("Process")
Systemdrive = env.Item("Systemdrive")
Set oReg=GetObject("winmgmts:{impersonationLevel=impersonate}!\\" & _
 strComputer & "\root\default:StdRegProv")
'===========================================================
'CHANGE THE PATH OF THE EXE ACCORDING TO YOUR REQUIREMENT
path = Chr(34) & "C:\altiris\aclient\aclient.exe" & Chr(34) & " /remove /silent"
'===========================================================
'shell.Run(path, 1, true)

'WScript.Sleep 30000

'=======================================================================
'FIND AND DELETE FILES
'=======================================================================
If fso.FileExists (Systemdrive & "\aclient.cfg") Then
 fso.DeleteFile (Systemdrive & "\aclient.cfg"), true
End If
If fso.FileExists (Systemdrive & "\WINDOWS\System32\drivers\AlKernel.sys") Then
 fso.DeleteFile Systemdrive & "\WINDOWS\System32\drivers\AlKernel.sys", true
End If
If fso.FileExists (Systemdrive & "\WIndows\Temp\alsmb.exe") Then
 fso.DeleteFile Systemdrive & "\Windows\Temp\alsmb.exe", True
End If
If fso.FolderExists (Systemdrive & "\Altiris\AClient") Then
 fso.DeleteFolder Systemdrive & "\Altiris\AClient", true
End If
If fso.FolderExists (Systemdrive & "\altiris") Then
 fso.DeleteFolder Systemdrive & "\Altiris", True
End If
'=======================================================================

'=======================================================================
'FIND AND DELETE REGISTRY KEYS
'=======================================================================
strKeyPath = "SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ACLIENT"
oReg.EnumValues HKEY_LOCAL_MACHINE,strKeyPath,arrValueNames, arrValueTypes
If IsNull(arrValueNames) Then 
 'Wscript.Echo "The registry key does not exist!"
Else
 'Wscript.Echo "The registry key exists!"
 shell.RegDelete "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ACLIENT\"
End If

strKeyPath = "SYSTEM\ControlSet001\Enum\Root\LEGACY_ACLIENT"
oReg.EnumValues HKEY_LOCAL_MACHINE,strKeyPath,arrValueNames, arrValueTypes
If IsNull(arrValueNames) Then 
 'Wscript.Echo "The registry key does not exist!"
Else
 'Wscript.Echo "The registry key exists!"
 shell.RegDelete "HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_ACLIENT\"
End If

strKeyPath = "SYSTEM\ControlSet001\Services\AClient"
oReg.EnumValues HKEY_LOCAL_MACHINE,strKeyPath,arrValueNames, arrValueTypes
If IsNull(arrValueNames) Then 
 'Wscript.Echo "The registry key does not exist!"
Else
 'Wscript.Echo "The registry key exists!"
 shell.RegDelete "HKLM\SYSTEM\ControlSet001\Services\AClient\"
End If

'shell.RegDelete "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ACLIENT\"
'shell.RegDelete "HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_ACLIENT\"
'shell.RegDelete "HKLM\SYSTEM\ControlSet001\Services\AClient\"
'=======================================================================

strKeyPath = "SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List"
strStringValueName = "C:\Program Files\Altiris\AClient\AClntUsr.EXE"
oReg.DeleteValue HKEY_LOCAL_MACHINE,strKeyPath,strStringValueName

strKeyPath = "SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List"
strStringValueName = "C:\Program Files\Altiris\AClient\AClntUsr.EXE"
oReg.DeleteValue HKEY_LOCAL_MACHINE,strKeyPath,strStringValueName
shell.LogEvent 0, "Successfully removed aclient"

Set shell = Nothing
Set fso = Nothing

WScript.Quit

官方卸载工具 (–>打开

Related posts

发表评论