|
本帖最后由 2010hook 于 2024-9-24 18:56 编辑
楼主,我觉得9楼 @hlowld 说的比较有道理,用白名单更靠谱,试试我写的批处理:
- @echo off
- for /f "delims=\ tokens=5" %%a in ('reg query "HKLM\SYSTEM\ControlSet001\Services" /s /v "ObjectName" ^|findstr /iv "AppXSvc AudioEndpointBuilder Audiosrv BFE BrokerInfrastructure BTAGService BthHFSrv bthserv ClipSVC CoreMessagingRegistrar CryptSvc DcomLaunch Dhcp DisplayEnhancementService Dnscache DsmSvc EventLog EventSystem FontCache gpsvc hidserv iphlpsvc KeyIso lmhosts LanmanWorkstation LanmanServer LSM mpssvc NcbService netprofm NetSetupSvc NlaSvc nsi PlugPlay Power ProfSvc RpcEptMapper RpcSs SamSs Schedule SENS SharedAccess sppsvc StateRepository SystemEventsBroker Themes TimeBrokerSvc TrustedInstaller UserManager vds Wcmsvc Winmgmt WlanSvc W32Time"') do (
- sc stop "%%~a"
- rem add "HKLM\SYSTEM\ControlSet001\Services\%%~a" /f /v "FailureActions" /t REG_BINARY /d 00
- rem add "HKLM\SYSTEM\ControlSet001\Services\%%~a" /f /v "Start" /t REG_DWORD /d 4
- )
- pause
复制代码
确认没问题就把rem改为reg
|
|