撰寫這篇的原因:覺得 ctfmon.exe 常駐系統,讓我很不舒服,其他順帶 DEL 只是剛剛好。
以下僅作參考樣本
使用【微軟視窗內建 Reg 指令、BAT批次指令】無其他添加物
虛線以下複製 存檔為 .bat 執行
--------------------------------------------------------------------------------------------------
echo "AppPath"="C:\\Windows\\System32"
Reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}"
Reg Delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}" /v "AppName" /f
Reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}"
pause
echo "AppPath"="C:\\Windows\\System32"
Reg query "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}"
Reg Delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}" /v "AppName" /f
Reg query "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}"
pause
\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}
echo "AppPath"="C:\\Windows\\SysWOW64"
Reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}
Reg Delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd} /v "AppName" /f
Reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}
pause
echo "AppPath"="C:\\Windows\\SysWOW64"
Reg query "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}"
Reg Delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}" /v "AppName" /f
Reg query "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}"
pause
Reg query "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs"
echo set 001
pause
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "screg.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "netdde.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "clipsrv.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "lmsvcs.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "MsgSvc.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "NETSTRS.EXE" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "nddeagnt.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "os2srv.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "wfshell.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "win.com" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "conime.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "proquota.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "imepadsv.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "ctfmon.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "TaskEng.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "dwm.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "Taskhost.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "ServerManagerLauncher.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "Tlsbln.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "wisptis.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs" /v "rdpclip.exe" /f
Reg query "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\SysProcs"
pause
Reg query "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs"
echo set 002
pause
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "screg.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "netdde.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "clipsrv.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "lmsvcs.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "MsgSvc.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "NETSTRS.EXE" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "nddeagnt.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "os2srv.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "wfshell.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "win.com" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "conime.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "proquota.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "imepadsv.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "ctfmon.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "TaskEng.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "dwm.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "Taskhost.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "ServerManagerLauncher.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "Tlsbln.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "wisptis.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs" /v "rdpclip.exe" /f
Reg query "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\SysProcs"
pause
Reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs"
echo set 000
pause
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "screg.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "netdde.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "clipsrv.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "lmsvcs.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "MsgSvc.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "NETSTRS.EXE" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "nddeagnt.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "os2srv.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "wfshell.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "win.com" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "conime.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "proquota.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "imepadsv.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "ctfmon.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "TaskEng.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "dwm.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "Taskhost.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "ServerManagerLauncher.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "Tlsbln.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "wisptis.exe" /f
Reg Delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs" /v "rdpclip.exe" /f
Reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\SysProcs"
pause
c:
cd\
echo "C:\Windows\System32\ctfmon.exe" >> %USERPROFILE%\Desktop\Key-Open.bat
echo C:\Windows\System32\taskkill.exe /IM ctfmon.exe /T >> %USERPROFILE%\Desktop\Key-close.bat
--------------------------------------------------------------------------------------------------
虛線以上複製 存檔為 .bat 執行
最後,在視窗桌面留下兩個 Bat 指令,一個是啟動輸入法【Key-Open.bat】,一個關閉輸入法【Key-close.bat】
執行完之後?對於使用者來說,好處比壞處大,純粹要習慣.........
點一下【Key-Open.bat】開啟
點一下【Key-close.bat】關閉
.