win7系統防止中招勒索病毒

echo @@
netsh advfirewall firewall add rule name="Deny TCP 123" dir=out action=block protocol=TCP localport=123
netsh advfirewall firewall add rule name="Deny UDP 123" dir=out action=block protocol=UDP localport=123
netsh advfirewall firewall add rule name="Deny TCP 135" dir=out action=block protocol=TCP localport=135
netsh advfirewall firewall add rule name="Deny UDP 135" dir=out action=block protocol=UDP localport=135
netsh advfirewall firewall add rule name="Deny TCP 137" dir=out action=block protocol=TCP localport=137
netsh advfirewall firewall add rule name="Deny UDP 137" dir=out action=block protocol=UDP localport=137
netsh advfirewall firewall add rule name="Deny TCP 138" dir=out action=block protocol=TCP localport=138
netsh advfirewall firewall add rule name="Deny UDP 138" dir=out action=block protocol=UDP localport=138
netsh advfirewall firewall add rule name="Deny TCP 139" dir=out action=block protocol=TCP localport=139
netsh advfirewall firewall add rule name="Deny UDP 139" dir=out action=block protocol=UDP localport=139
netsh advfirewall firewall add rule name="Deny TCP 445" dir=out action=block protocol=TCP localport=445
netsh advfirewall firewall add rule name="Deny UDP 445" dir=out action=block protocol=UDP localport=445
netsh advfirewall firewall add rule name="Deny TCP 3389" dir=out action=block protocol=TCP localport=3389
netsh advfirewall firewall add rule name="Deny UDP 3389" dir=out action=block protocol=UDP localport=3389
end

 

一、以管理員身份運行「1封端口」文件夾中的bat文件
二、根據電腦版本以管理員身份運行「2打補丁」中x64或者x86文件夾中的文件html

被勒索病毒感染的機器中文件以下:加密

任何txt等被加密的文檔都是亂碼spa

http://nic.swu.edu.cn/s/nic/gzdt/20190515/3710754.htmlcode

相關文章
相關標籤/搜索