1、已导出的注册表键和项- Key : "\.DEFAULT\Software\Microsoft\Windows\ShellNoRoam\MUICache"
- Value : "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe"
- Key : "\S-1-5-21-823518204-861567501-1801674531-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache"
- Value : "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe"
- Key : "\S-1-5-21-823518204-861567501-1801674531-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache"
- Value : "C:\Program Files\Trend Micro\OfficeScan Client\pccnt.exe"
- Key : "\S-1-5-21-823518204-861567501-1801674531-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache"
- Value : "C:\Program Files\Trend Micro\OfficeScan Client\NTRmv.exe"
- Key : "\S-1-5-18\Software\Microsoft\Windows\ShellNoRoam\MUICache"
- Value : "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe"
- End of search : 5 matching string(s) found.
复制代码 规律:第一行为键,第二行为项;第三行为键,第四行为项。
要求:删除项
怎么用bat删除该项
【说明】因为卸载某杀毒软件后有残留,关键字为"officescan",所以通过批量搜索后,将该字段对应的键、项、值全部删除。
2、已导出的注册表键、项、值,怎么删除该值- Key : "\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Trend OfficeScan Client"
- Value : "ParameterMessageFile"
- Data : "C:\Program Files\Trend Micro\OfficeScan Client\TMNotify.dll"
- Key : "\SYSTEM\CurrentControlSet\Services\Eventlog\Application"
- Value : "Sources"
- Data : "WSH|WMIAdapter|WMI.NET Provider Extension|WmdmPmSN|WinMgmt|Winlogon|Windows Product Activation|Windows 3.1 Migration|WebClient|VSSetup|VSS|VBRuntime|Userinit|Userenv|User-Loader|UNS|Trend OfficeScan Client|TMNotify|System.ServiceModel.Install 3.0.0.0|System.ServiceModel 3.0.0.0|System.Runtime.Serialization 3.0.0.0|System.IO.Log 3.0.0.0|System.IdentityModel 3.0.0.0|SysmonLog|Starter|SQLNCLI|SpoolerCtrs|Software Restriction Policies|Software Installation|ServiceModel Audit 3.0.0.0|SecurityCenter|SclgNtfy|SceSrv|SceCli|safrslv|SAFrdms|RPC|Remote Assistance|PerfProc|PerfOS|PerfNet|Perfmon|Perflib|PerfDisk|Perfctrs|Outlook|Offline Files|Oakley|ntbackup|MSSQLSERVER/MSDE|MSSOAP|MSSHA|MsiInstaller|MSDTC Client|MSDTC|MSDMine|mnmsrvc|Microsoft.Transactions.Bridge 3.0.0.0|Microsoft Office 12|Microsoft Office 11|Microsoft H.323 Telephony Service Provider|Microsoft (R) Visual C# 2005 Compiler|LoadPerf|LMS|IntelDalJhi|Intel(R) Capability Licensing Service Interface|HPLaserJetService|HP DS Service|HelpSvc|Folder Redirection|File Deployment|EventSystem|ESENT|DrWatson|Dot3Svc|DiskQuota|crypt32|COM+|COM|Ci|Chkdsk|CardSpace 3.0.0.0|AutoEnrollment|Autochk|ASP.NET 2.0.50727.0|Application Management|Application Hang|Application Error|.NET Runtime Optimization Service|.NET Runtime 2.0 Error Reporting|.NET Runtime|Application|"
- Key : "\SYSTEM\CurrentControlSet\Services\Perf_iCrcPerfMonMgr\Performance"
- Value : "Library"
- Data : "C:\Program Files\Trend Micro\OfficeScan Client\perfiCrcPerfMonMgr.dll"
- Key : "\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List"
- Value : "55555:TCP"
- Data : "55555:TCP:*:Enabled:Trend Micro OfficeScan Listener"
- Key : "\SYSTEM\CurrentControlSet\Services\VSApiNt"
- Value : "ImagePath"
- Data : "\??\C:\Program Files\Trend Micro\OfficeScan Client\VSApiNt.sys"
复制代码
|