發新話題
打印

懷疑被hack/中毒??? 電腦接近垂死狀態..請大家盡快幫忙

jas39t兄, 您覺得以下批次檔, 止唔止到咳?

開啟記事本,貼上以下內容

@echo off
REG ADD "HKLM\Sofware\Microsoft\Security Center" /v Updates DisableNotify / t REG_DWORD /d 0 /F >nul
REG ADD "HKLM\Sofware\Microsoft\Security Center" /v AntiVirus DisableNotify / t REG_DWORD /d 0 /F >nul
REG ADD "HKLM\Sofware\Microsoft\Security Center" /v Firewall DisableNotify / t REG_DWORD /d 0 /F >nul
REG ADD "HKLM\Sofware\Microsoft\Security Center" /v AntiVirus Override / t REG_DWORD /d 0 /F >nul
REG ADD "HKLM\Sofware\Microsoft\Security Center" /v Firewall Override / t REG_DWORD /d 0 /F >nul
REG ADD "HKLM\Sofware\Policies\Microsoft\WindowsFirewall\DomainProfile" /v EnableFirewall / t REG_DWORD /d 1 /F >nul
REG ADD "HKLM\Sofware\Policies\Microsoft\WindowsFirewall\StandardProfile" /v EnableFirewall / t REG_DWORD /d 1 /F >nul
REG ADD "HKLM\Sofware\Policies\Microsoft\Windows\WindowsUpdate" /v DoNotAllowXPSP2 / t REG_DWORD /d 0 /F >nul
REG DELETE "HKLM\System\CurrentControlSet\Services\lanmanserver\parameters" /v AutoShareWks / t REG_DWORD /d 0 /F >nul
REG DELETE "HKLM\System\CurrentControlSet\Services\lanmanserver\parameters" /v AutoShareServer / t REG_DWORD /d 0 /F >nul
REG DELETE "HKLM\System\CurrentControlSet\Services\lanmanworkstation\parameters" /v AutoShareWks / t REG_DWORD /d 0 /F >nul
REG DELETE "HKLM\System\CurrentControlSet\Services\lanmanworkstation\parameters" /v AutoShareServer / t REG_DWORD /d 0 /F >nul
REG ADD "HKLM\System\CurrentControlSet\Services\RemoteRegistry" /v Start / t REG_DWORD /d 2 /F >nul
REG ADD "HKLM\System\CurrentControlSet\Services\TlntSvr" /v Start / t REG_DWORD /d 3 /F >nul
REG ADD "HKLM\System\CurrentControlSet\Services\wscsvc" /v Start / t REG_DWORD /d 2 /F >nul
REG ADD "HKLM\SOFTWARE\Microsoft\OLE" /v EnableDCOM / t REG_SZ /d Y /F >nul
REG ADD "HKLM\CurrentControlSet\Control\Lsa" /v restrictanonymous / t REG_DWORD /d 0 /F >nul
REG ADD "HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry" /v Start / t REG_DWORD /d 2 /F >nul

儲存--->存檔類型--->所有檔案-->檔名輸入為Fix.bat

TOP

發新話題