1、编写语言:PHP
2、使用范围:浏览器主页被其他主页劫持
3、使用方法:复制代码→新建文档、保存→右键重命名→更改后缀名为bat→右键以管理员身份运行

echo off:begin
cls
Echo ---------------------------------
Echo I   1 判断病毒文件和注册表      I
Echo I   2 ie首页相关                I
Echo I   3 修复ie首页                I
Echo I   4 打开浏览器配置目录        I
Echo ---------------------------------
Set /P var=
If not "%var%"=="" (If "%var%"=="1"  goto 判断If "%var%"=="2"  goto ie首页If "%var%"=="3"  goto 修复ie首页If "%var%"=="4"  goto 打开浏览器配置目录
)goto :begin:判断
echo 判断病毒文件和注册表等
if exist "%ProgramFiles%\Common Files\System\safemonn64.dll" echo safemonn64.dll safemonn64.dll  存在
if exist %windir%\AppPatch\MexLayout.dll echo MexLayout.dll  存在if exist %windir%\system32\usb4399.sys echo usb4399.sys  存在
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usb4399"
if exist %windir%\system32\DRIVERS\usb4399.sys echo usb4399.sys  存在
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usb4399"if exist %windir%\system32\fhdisbfasu.sys echo fhdisbfasu.sys  存在
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fhdisbfasu"
if exist %windir%\system32\FDSOIvdaosifid.sys echo FDSOIvdaosifid.sys  存在
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FDSOIvdaosifid"
if exist %windir%\system32\DRIVERS\PGFltMgr.sys echo PGFltMgr.sys  存在
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PGFltMgr"
if exist %windir%\system32\DRIVERS\mssafel.sys echo mssafel.sys  存在
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mssafel"if exist %windir%\System32\GroupPolicy\Machine\Registry.pol echo Registry.pol  存在
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome" /v DefaultSearchProviderSearchURLdir  %windir%\system32\DRIVERS\usb*.sysdir  %windir%\system32\DRIVERS\hp*.sysif exist %appdata%\pcmaster echo 软媒魔方  存在
reg query HKEY_CURRENT_USER\Software\RuanMei
echo UC浏览器推广id
reg query "HKEY_LOCAL_MACHINE\Software\Wow6432Node\UCBrowserPID"
reg query "HKEY_CURRENT_USER\Software\UCBrowserPID"
echo UC浏览器配置文件
if exist "C:\Program Files (x86)\UCBrowser\Application\Share\Custom.dat" echo Custom.dat  存在
if exist "C:\Program Files (x86)\UCBrowser\Application\Share\Config.dat" echo Config.dat  存在
goto exit:ie首页
echo ie首页其他
reg query "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page"
reg query "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Search Bar"
reg query "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Search Page"
reg query "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Default_Page_URL"
reg query "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Default_Search_URL"reg query "HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main" /v "Start Page"
reg query "HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main" /v "Search Bar"
reg query "HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main" /v "Search Page"
reg query "HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main" /v "Default_Page_URL"
reg query "HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main" /v "Default_Search_URL"reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN" /v "Start Page"
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN" /v "Search Bar"
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN" /v "Search Page"
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN" /v "Default_Page_URL"
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN" /v "Default_Search_URL"reg query "HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command"echo Windows10 禁止修改首页(如果内包含内容)
reg query "HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Main\SecondaryStartPages"
::[HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer]echo 禁用更改主页设置 正常值“HomePage”的DWORD值,值为“00000000”
reg query "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v "HomePage"
reg query "HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel" /v "HomePage"echo ie首页修改后无法保存
reg query "HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Main" /v "Start Page"
reg query "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main" /v "First Home Page"
reg query "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main" /v "Default_Page_URL"reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main" /v "Start Page"
reg query "HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main" /v "First Home Page"
reg query "HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main" /v "Default_Page_URL"echo Windows10中查看到的现象
reg query "HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Mainecho 继续查看其他IE配置路径
pause
echo 其他IE配置路径
reg query "HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main"
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer"
reg query "HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main"
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN"
reg query "HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel"
reg query "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main"
reg query "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer"
reg query "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main"
reg query "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel"
goto exit:修复ie首页
echo 修复禁用更改主页设置
reg DELETE "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel" /f /v "HomePage"
reg DELETE "HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel" /f /v "HomePage"
echo 修复ie首页修改后无法保存
reg DELETE "HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main" /f /v "Start Page"
reg DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main" /f /v "Start Page"
reg DELETE "HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main" /f /v "First Home Page"
reg DELETE "HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main" /f /v "Default_Page_URL"reg DELETE "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /f /v "Start Page"
reg DELETE "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /f /v "Search Bar"
reg DELETE "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /f /v "Search Page"
reg DELETE "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /f /v "Default_Page_URL"
reg DELETE "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /f /v "Default_Search_URL"reg DELETE "HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main" /f /v "Start Page"
reg DELETE "HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main" /f /v "Search Bar"
reg DELETE "HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main" /f /v "Search Page"
reg DELETE "HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main" /f /v "Default_Page_URL"
reg DELETE "HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main" /f /v "Default_Search_URL"reg DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN" /f /v "Start Page"
reg DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN" /f /v "Search Bar"
reg DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN" /f /v "Search Page"
reg DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN" /f /v "Default_Page_URL"
reg DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN" /f /v "Default_Search_URL"::edge homepage
reg DELETE "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\EUPP" /f
reg DELETE "HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy" /f
reg DELETE "HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy" /fgoto exit:打开浏览器配置目录
echo 打开浏览器配置目录
if exist "%USERPROFILE%\AppData\Roaming\Mozilla\Firefox\Profiles" explorer "%USERPROFILE%\AppData\Roaming\Mozilla\Firefox\Profiles":: 该目录删除后并不影响配置 > %USERPROFILE%\AppData\Local\Mozilla::\xxxxxxxx.default\prefs.js::\xxxxxxxx.default\user.js
if exist "%USERPROFILE%\AppData\Local\Google\Chrome"              explorer "%USERPROFILE%\AppData\Local\Google\Chrome"
if exist "%USERPROFILE%\AppData\Roaming\360se6"                   explorer "%USERPROFILE%\AppData\Roaming\360se6"
if exist "%USERPROFILE%\AppData\Local\360Chrome\Chrome"           explorer "%USERPROFILE%\AppData\Local\360Chrome\Chrome"
if exist "%USERPROFILE%\AppData\Roaming\SogouExplorer"            explorer "%USERPROFILE%\AppData\Roaming\SogouExplorer"
if exist "%USERPROFILE%\AppData\Local\2345Explorer"               explorer "%USERPROFILE%\AppData\Local\2345Explorer"
if exist "%USERPROFILE%\AppData\Local\Tencent\QQBrowser"          explorer "%USERPROFILE%\AppData\Local\Tencent\QQBrowser"
if exist "%USERPROFILE%\AppData\Local\UCBrowser"                  explorer "%USERPROFILE%\AppData\Local\UCBrowser"
if exist "%ProgramFiles%\Internet Explorer"                       explorer "%ProgramFiles%\Internet Explorer"
goto exit:exit
pause
goto :begin

解决主页被劫持的dos脚本相关推荐

  1. 浏览器主页被劫持 解决方法

    https://www.52pojie.cn/forum.php?mod=viewthread&tid=607115&page=1&authorid=526188 看见论坛里有 ...

  2. chrome主页被劫持的解决方法

    chrome主页被劫持的解决方法 参考文章: (1)chrome主页被劫持的解决方法 (2)https://www.cnblogs.com/wyh-hde/p/6747867.html 备忘一下.

  3. 解决浏览器主页被劫持问题

    解决浏览器主页被劫持问题 参考文章: (1)解决浏览器主页被劫持问题 (2)https://www.cnblogs.com/canger/p/10320568.html 备忘一下.

  4. 手动解决浏览器主页被劫持的问题

    手动解决浏览器主页被劫持的问题 问题描述 当我打开浏览器的时候,他的主页不是我之前设置的主页,而是被第三方软件劫持.出现我个人不喜欢的广告页面.而且是试过使用安全软件的方法去掉浏览器主页拦截,但是没有 ...

  5. newduba首页怎么去掉_【主页劫持】关于浏览器主页被劫持到毒霸网址大全的解决方法...

    摘要 亲爱的360浏览器用户们近期我们收到不少用户反馈浏览器主页被劫持到https://www.duba.com/?f=qd_numswdh&开头的毒霸网址大全,经技术联系用户排查劫持的原因是 ...

  6. 解决浏览器主页被劫持为hao123

    解决浏览器主页被劫持为hao123 最近电脑浏览器主页莫名其妙被劫持了,找了好多方法都不管用,下面这个亲测有效 下载火绒安全杀毒软件 地址:https://www.huorong.cn/ 专杀工具,下 ...

  7. 关于浏览器主页被劫持

    关于浏览器主页被劫持 等待解决中 我反正是解决了!!嘿嘿 通过我的不谢百度,没有感谢. 1.可能是52快压这款软件导致的.可我一直用这款软件,没想到他还会强制打开网址?我电脑上四个浏览器为何,其他的没 ...

  8. chrome浏览器主页被劫持为hao123

    现象是打开浏览器,就会自动打开新标签,一个乱七八糟的网址,然后立即跳转到hao123,cNMB.更恶心的是开机就打开浏览器就TMD显示hao123!CNMB! https://www.zhihu.co ...

  9. Microsoft edge 主页被劫持的处理办法

    最根本的办法,如果是任务栏固定打开后发现主页被劫持,应该是弄明白任务栏的链接是来自电脑的开始页面还是桌面的快捷方式. 如果是开始界面应用固定于任务栏,那么找到开始界面的Microsoft edge,右 ...

  10. Chrome主页被劫持怎么破

    之前遇到Chrome被2345劫持了,导致的结果是每天初次打开Chrome都会进入2345的流氓主页,尝试了若干解决办法,最终得以解决.现简要记录一下所尝试过的方法以及解决过程,以下所涉及到的任何一种 ...

最新文章

  1. NPTL简介 (NATIVE POSIX Thread Library)
  2. 数学--数论--随机算法--Pollard Rho 大数分解算法(纯模板带输出)
  3. vue 组件间传值、兄弟组件 、bus方式 ( 1 分钟看懂 )
  4. SAP Study Notes: BW Queriy-Variables(变量)
  5. SIP、SAP与SDP
  6. 你可能不知道的位运算技巧
  7. oracle当前用户创建的表不可见?
  8. 那些在错误道路上一路狂奔的国产VR
  9. 等待线程结束(join)
  10. 交换机芯片笔记2.1
  11. Android 9.0 开启飞行模式
  12. 服务器就是一台性能好的电脑吗,科普:什么是服务器? 服务器与普通电脑有何区别?...
  13. denoiser降噪实例
  14. 图片数据的基本预处理与数据增强
  15. MSP430C语言编程技巧,如何提高MSP430 C语言编程效率
  16. 百度apollo源码学习(二)apollo中的工厂模式
  17. python实现文件(夹)剪切
  18. 论文第一部分引言该如何写(三步秘笈)
  19. python模块学习之locust性能测试
  20. XYT-OTN2800-X

热门文章

  1. 访问 Notes/Domino 数据的定制 DXL 框架
  2. Linkedin葵花宝典
  3. 轻量级 js取色器 JSColor
  4. linux内核源码分析系列文章汇总
  5. 【2020年CSDN技术人内推活动开始啦】多家名企员工在线内推,快人一步拿Offer
  6. 信息安全工程师(软考资料)
  7. Windows令牌窃取提权和烂土豆提权学习
  8. SCSA 模拟题 知识点 (一)
  9. android 9.0 c7Pro,低配版C9 Pro:国行三星Galaxy C7 Pro正式上线 你买吗?
  10. 使用Maven导入MySQL驱动包遇到的问题