将如下内容保存为reg文件执行后重启

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender]

"DisableAntiSpyware"=dword:00000001

"DisableRealtimeMonitoring"=dword:00000001

"DisableAntiVirus"=dword:00000001

"DisableSpecialRunningModes"=dword:00000001

"DisableRoutinelyTakingAction"=dword:00000001

"ServiceKeepAlive"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection]

"DisableBehaviorMonitoring"=dword:00000001

"DisableOnAccessProtection"=dword:00000001

"DisableRealtimeMonitoring"=dword:00000001

"DisableScanOnRealtimeEnable"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Signature Updates]

"ForceUpdateFromMU"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet]

"DisableBlockAtFirstSeen"=dword:00000001