WIN服务器安全批处理文件
这个的确不错,指量设置,免去手动设置的繁琐/uploadfiles/okay_77574.rar
复制代码 代码如下:
echo.
echo ------------------------------------------------------
echo.
echo ...........
echo.
net share c$ /delete
net share d$ /delete
net share e$ /delete
net share f$ /delete
net share admin$ /delete
net share ipc$ /delete
net stop server
net stop lanmanworkstation regsvr32/u C:WINNTSystem32wshom.ocx
regsvr32/u C:WINNTsystem32shell32.dll
regsvr32/u C:WINNTsystem32shell.dll
cacls c:WINNTsystem32shell32.dll /g administrators:f system:f
cacls c:WINNTsystem32shell.dll /g administrators:f system:f
cacls c: /g administrators:f system:f
cacls d: /g administrators:f system:f
echo.
echo ..........
echo.
echo ------------------------------------------------------
echo.
echo .................
echo.
echo .. delshare.reg .......
echo Windows Registry Editor Version 5.00> c:delshare.reg
echo [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServiceslanmanserverparameters]>> c:delshare.reg
echo "AutoShareWks"=dword:00000000>> c:delshare.reg
echo "AutoShareServer"=dword:00000000>> c:delshare.reg
echo .. delshare.reg .....
regedit /s c:delshare.reg
echo .. delshare.reg ....
del c:delshare.reg
echo .
echo ........
echo .
echo =========================================================
echo .
echo .....................dos....
echo .
echo .........
echo Windows Registry Editor Version 5.00> c:dosforwin.reg
echo [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTcpipParameters]>> c:dosforwin.reg
echo "EnableICMPRedirect"=dword:00000000>> c:dosforwin.reg
echo "DeadGWDetectDefault"=dword:00000001>> c:dosforwin.reg
echo "DontAddDefaultGatewayDefault"=dword:00000000>> c:dosforwin.reg
echo "EnableSecurityFilters"=dword:00000000">> c:dosforwin.reg
echo "AllowUnqualifiedQuery"=dword:00000000>> c:dosforwin.reg
echo "PrioritizeRecordData"=dword:00000001>> c:dosforwin.reg
echo "ReservedPorts"=hex(7):31,00,34,00,33,00,33,00,2d,00,31,00,34,00,33,00,34,00,>> c:dosforwin.reg
echo 00,00,00,00>> c:dosforwin.reg
echo "SynAttackProtect"=dword:00000002>> c:dosforwin.reg
echo "EnablePMTUDiscovery"=dword:00000000>> c:dosforwin.reg
echo "NoNameReleaseOnDemand"=dword:00000001>> c:dosforwin.reg
echo "EnableDeadGWDetect"=dword:00000000>> c:dosforwin.reg
echo "KeepAliveTime"=dword:00300000>> c:dosforwin.reg
echo "PerformRouterDiscovery"=dword:00000000>> c:dosforwin.reg
echo "EnableICMPRedirects"=dword:00000000>> c:dosforwin.reg
echo .
echo ==========================================================
echo .. dosforwin.reg .....
regedit /s c:dosforwin.reg
echo .. dosforwin.reg ....
del c:dosforwin.reg
echo ==============================================================
echo .
echo ..........(......................).
echo .
echo ..telnet,......telnet.
echo ..........
echo Windows Registry Editor Version 5.00> c:telnet.reg
echo [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTlntSvr]>> c:telnet.reg
echo "Start"=dword:00000004>> c:telnet.reg
echo .
echo .. telnet.reg .....
regedit /s c:telnet.reg
echo .
echo .. telnet.reg ....
del c:telnet.reg
echo .
echo ===============================================================
echo ..Remote Registry Service...........
echo .........
echo .
echo Windows Registry Editor Version 5.00> c:regedit.reg
echo [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesRemoteRegistry]>> c:regedit.reg
echo "Start"=dword:00000004>> c:regedit.reg
echo .
echo .. regedit.reg .....
regedit /s c:regedit.reg
echo .
echo ......
del c:regedit.reg
echo ===============================================================
echo ..Messenger.......
echo .........
echo Windows Registry Editor Version 5.00> c:message.reg
echo [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMessenger]>> c:message.reg
echo "Start"=dword:00000004>> c:message.reg
echo .
echo .. message.reg .....
regedit /s c:message.reg
echo .
echo .. message.reg
del c:message.reg
echo ===============================================================
echo ..lanmanworkstation.......
echo .........
echo Windows Registry Editor Version 5.00> c:lanmanworkstation.reg
echo [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServiceslanmanworkstation]>> c:lanmanworkstation.reg
echo "Start"=dword:00000004>> c:lanmanworkstation.reg
echo .
echo .. lanmanworkstation.reg .....
regedit /s c:lanmanworkstation.reg
echo .
echo .. lanmanworkstation.reg
del c:lanmanworkstation.reg
echo ===============================================================
echo ..lanmanserver.......
echo .........
echo Windows Registry Editor Version 5.00> c:lanmanserver.reg
echo [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServiceslanmanserver]>> c:lanmanserver.reg
echo "Start"=dword:00000004>> c:lanmanserver.reg
echo .
echo .. lanmanserver.reg .....
regedit /s c:lanmanserver.reg
echo .
echo .. lanmanserver.reg
del c:lanmanserver.reg
echo ===============================================================
echo ..alerter.......
echo .........
echo Windows Registry Editor Version 5.00> c:alerter.reg
echo [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesalerter]>> c:alerter.reg
echo "Start"=dword:00000004>> c:alerter.reg
echo .
echo .. alerter.reg .....
regedit /s c:alerter.reg
echo .
echo .. alerter.reg
del c:alerter.reg
echo ===============================================================
echo ..Browser.......
echo .........
echo Windows Registry Editor Version 5.00> c:Browser.reg
echo [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesBrowser]>> c:Browser.reg
echo "Start"=dword:00000004>> c:Browser.reg
echo .
echo .. Browser.reg .....
regedit /s c:Browser.reg
echo .
echo .. Browser.reg
del c:Browser.reg
echo ===============================================================
echo ..Dfs.......
echo .........
echo Windows Registry Editor Version 5.00> c:Dfs.reg
echo [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesDfs]>> c:Dfs.reg
echo "Start"=dword:00000004>> c:Dfs.reg
echo .
echo .. Dfs.reg .....
regedit /s c:Dfs.reg
echo .
echo .. Dfs.reg
del c:Dfs.reg
echo ===============================================================
echo ..Spooler.......
echo .........
echo Windows Registry Editor Version 5.00> c:Spooler.reg
echo [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSpooler]>> c:Spooler.reg
echo "Start"=dword:00000004>> c:Spooler.reg
echo .
echo .. Spooler.reg .....
regedit /s c:Spooler.reg
echo .
echo .. Spooler.reg
del c:Spooler.reg
echo ==============================================================
echo ...TCP/IP NetBIOS Helper Service
echo .........
echo Windows Registry Editor Version 5.00> c:netbios.reg
echo [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesLmHosts]>> c:netbios.reg
echo "Start"=dword:00000004>> c:netbios.reg
echo .
echo .. netbios.reg .....
regedit /s c:netbios.reg
echo .
echo .. netbios.reg
del c:netbios.reg
echo ===============================================================
echo ===============================================================
echo powered by zgsj.com
echo web@zgsj.com
goto :END



