当前位置:网站首页>The startup mode of cloudbase init is \Cloudbase init has hidden dangers
The startup mode of cloudbase init is \Cloudbase init has hidden dangers
2022-06-24 07:43:00 【shawyang】
Suggest cloudbase-init The startup mode of is changed to “ Local system accounts ”, Now find .\cloudbase-init The startup mode of exists explorer.exe Abnormal probability
Abnormal phenomenon :
explorer loop crash(explorer loop crash, In a flash ,appplication.evtx There are multiple appplication error journal )
perhaps
explorer No icon on solid background , Need to send Ctrl Alt Del Call up the task manager to run explorer To pull up the Explorer
It is recommended to adjust the image when making it cloudbase-init Start mode of , Several considerations for creating images :
If the original machine is useful userdata, Do not perform cleanup cloudbase-init The registry , as a result of , If a message is passed when the machine is created userdata, and userdata There is code for writing operations in the code , So you deleted cloudbase-init The registry of causes initialization to be marked as 0, The next time I turn on cloudbase-init You will think that the machine has not been initialized , It's a new machine , It will automatically trigger the re execution userdata Code in , The severity assumption , Suppose there is an operation to format the data disk in the code , Don't you want to be cool
1、 uninstall winagent( If there is one , No, please skip ) sc.exe stop winagent 2>$null 1>$null sc.exe config winagent start= disabled 2>$null 1>$null sc.exe delete winagent 2>$null 1>$null schtasks.exe /delete /tn "WinAgentKeepAlive" /F 2>$null 1>$null 2、 Turn off cloud monitoring 、 Cloud security services stop-service BaradAgentSvc 2>$null 1>$null stop-service StargateSvc 2>$null 1>$null stop-service YDLive 2>$null 1>$null stop-service YDService 2>$null 1>$null 3、 Enable group policy password complexity ( Cannot be disabled , It has to be Enabled )
4、 Set up cloudbase-init For the local system account 、 Clean up local users and groups cloudbase-init user
services.msc ( Change the startup mode in the service list to “ Local system account ”)
lusrmgr.msc ( Delete cloudbase-init account number )
sysdm.cpl( Delete cloudbase-init Home directory , After deleting the user name, it will be displayed as “ Unknown ”)
5、 Turn off cloud monitoring 、 Cloud security services , Clean up old logs
stop-service BaradAgentSvc 2>$null 1>$null
stop-service StargateSvc 2>$null 1>$null
stop-service YDLive 2>$null 1>$null
stop-service YDService 2>$null 1>$null
del "C:\Program Files\Cloudbase Solutions\Cloudbase-Init\log\cloudbase-init.log" 2>$null 1>$null
del "C:\Program Files\QCloud\Logs\*" 2>$null 1>$null
del "C:\Program Files\QCloud\Monitor\Barad\logs\*" 2>$null 1>$null
del "C:\Program Files\QCloud\Stargate\logs\*" 2>$null 1>$null
del "C:\Program Files\QCloud\YunJing\log\*" 2>$null 1>$null
6、disable network location wizard
In order to avoid the right side of the newly purchased machine network location wizard, It can be executed 2 Sentence command
reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles" /f 2>&1 > $null
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Network\NewNetworkWindowOff" /f
7、 Clean up the system log
wevtutil el | Foreach-Object {wevtutil cl "$_" 2>$null}
wevtutil cl security 2>$null
wevtutil cl system 2>$null
边栏推荐
- 【Django中运行scrapy框架,并将数据存入数据库】
- How to realize multi protocol video capture and output in video surveillance system?
- MSSQL high permission injection write horse to Chinese path
- [OGeek2019]babyrop
- Global and Chinese market of basketball uniforms 2022-2028: Research Report on technology, participants, trends, market size and share
- 2.1.1 QML grammar foundation I
- 【NILM】非入侵式负荷分解模块nilmtk安装教程
- What industries and scenarios can the easynvr/easygbs/easycvr platform developed by tsingsee green rhino video be used in?
- Detailed explanation of PHP data serialization test example
- Q & A on cloud development cloudbase hot issues of "Huage youyue phase I"
猜你喜欢

Ultra wideband pulse positioning scheme, UWB precise positioning technology, wireless indoor positioning application

图形技术之坐标转换
![[vulhub shooting range]] ZABBIX SQL injection (cve-2016-10134) vulnerability recurrence](/img/c5/f548223666d7379a7d4aaed2953587.png)
[vulhub shooting range]] ZABBIX SQL injection (cve-2016-10134) vulnerability recurrence

Only two lines are displayed, and the excess part is displayed with Ellipsis

Analog display of the module taking software verifies the correctness of the module taking data, and reversely converts the bin file of the lattice array to display

光照使用的简单总结
![[frame rate doubling] development and implementation of FPGA based video frame rate doubling system Verilog](/img/38/92486c92557e6e5a10a362eb2b7bdf.png)
[frame rate doubling] development and implementation of FPGA based video frame rate doubling system Verilog

jarvisoj_ level2

Buuctf misc grab from the doll
![[WUSTCTF2020]alison_ likes_ jojo](/img/a9/dcc6f524772cd0b8781289cbaef63f.png)
[WUSTCTF2020]alison_ likes_ jojo
随机推荐
Global and Chinese market of water massage column 2022-2028: Research Report on technology, participants, trends, market size and share
Domain environment importing Tencent cloud considerations
Global and Chinese markets for maritime transport of perishable goods 2022-2028: Research Report on technology, participants, trends, market size and share
Tencent cloud security and privacy computing has passed the evaluation of the ICT Institute and obtained national recognition
Win10 build webservice
LeetCode 207:课程表(拓扑排序判断是否成环)
[GUET-CTF2019]zips
MaxCompute远程连接,上传、下载数据文件操作
图形技术之管线概念
How VPN works
jarvisoj_ level2
How to realize multi protocol video capture and output in video surveillance system?
Lend you a pair of insight, Frida native trace
《canvas》之第1章 canvas概述
[OGeek2019]babyrop
Global and Chinese markets for food puffers 2022-2028: Research Report on technology, participants, trends, market size and share
Camera calibration (calibration purpose and principle)
Continue to have a fever. Try the asynchronous operation of dart language. The efficiency is increased by 500%
Analog display of the module taking software verifies the correctness of the module taking data, and reversely converts the bin file of the lattice array to display
Anaconda 中使用 You Get