echo @@ netsh advfirewall firewall add rule name="Deny TCP 123" dir=out action=block protocol=TCP localport=123 netsh advfirewall firewall add rule name="Deny UDP 123" dir=out action=block protocol=UDP localport=123 netsh advfirewall firewall add rule name="Deny TCP 135" dir=out action=block protocol=TCP localport=135 netsh advfirewall firewall add rule name="Deny UDP 135" dir=out action=block protocol=UDP localport=135 netsh advfirewall firewall add rule name="Deny TCP 137" dir=out action=block protocol=TCP localport=137 netsh advfirewall firewall add rule name="Deny UDP 137" dir=out action=block protocol=UDP localport=137 netsh advfirewall firewall add rule name="Deny TCP 138" dir=out action=block protocol=TCP localport=138 netsh advfirewall firewall add rule name="Deny UDP 138" dir=out action=block protocol=UDP localport=138 netsh advfirewall firewall add rule name="Deny TCP 139" dir=out action=block protocol=TCP localport=139 netsh advfirewall firewall add rule name="Deny UDP 139" dir=out action=block protocol=UDP localport=139 netsh advfirewall firewall add rule name="Deny TCP 445" dir=out action=block protocol=TCP localport=445 netsh advfirewall firewall add rule name="Deny UDP 445" dir=out action=block protocol=UDP localport=445 netsh advfirewall firewall add rule name="Deny TCP 3389" dir=out action=block protocol=TCP localport=3389 netsh advfirewall firewall add rule name="Deny UDP 3389" dir=out action=block protocol=UDP localport=3389 end
1、以管理员身份运行“1封端口”文件夹中的bat文件
2、根据电脑版本以管理员身份运行“2打补丁”中x64或者x86文件夹中的文件
被勒索病毒感染的机器中文件如下:
任何txt等被加密的文档都是乱码