You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

非管理员用户下以管理员权限运行C#代码禁用任务管理器无效问题

问题原因

当非管理员用户通过UAC提升权限到管理员身份运行程序时,Registry.CurrentUser指向的是管理员账户的当前用户注册表 hive,而非原本登录的普通用户的注册表。你看到的"注册表键创建成功",实际是在管理员的用户配置里创建了设置,所以普通用户的任务管理器自然不会被禁用。

解决办法

办法1:修改当前登录普通用户的注册表(仅对该用户生效)

要修改原普通用户的注册表,需要手动加载该用户的NTUSER.DAT文件(存储用户注册表的核心文件),修改后再卸载临时加载的注册表项。具体实现如下:

using System;
using System.Runtime.InteropServices;
using Microsoft.Win32;

class TaskManagerDisabler
{
    [DllImport("advapi32.dll", SetLastError = true)]
    private static extern int RegLoadKey(IntPtr hKey, string lpSubKey, string lpFile);

    [DllImport("advapi32.dll", SetLastError = true)]
    private static extern int RegUnLoadKey(IntPtr hKey, string lpSubKey);

    private const int HKEY_LOCAL_MACHINE = -2147483646;
    private const int ERROR_SUCCESS = 0;

    static void Main(string[] args)
    {
        // 获取当前登录的普通用户SID(提升权限后,需通过会话所有者获取原用户身份)
        var currentUser = System.Security.Principal.WindowsIdentity.GetCurrent(System.Security.Principal.TokenAccessLevels.Read);
        string userSid = currentUser.User.Value;
        string userProfilePath = Environment.GetFolderPath(Environment.SpecialFolder.UserProfile);
        string ntuserPath = $@"{userProfilePath}\NTUSER.DAT";

        const string tempHiveKey = @"TempUserHive";
        IntPtr hklm = new IntPtr(HKEY_LOCAL_MACHINE);

        try
        {
            // 加载用户的NTUSER.DAT到HKLM的临时项
            int loadResult = RegLoadKey(hklm, tempHiveKey, ntuserPath);
            if (loadResult != ERROR_SUCCESS)
            {
                throw new System.ComponentModel.Win32Exception(loadResult);
            }

            // 访问加载后的注册表项,修改DisableTaskMgr
            string targetPath = $@"{tempHiveKey}\Software\Microsoft\Windows\CurrentVersion\Policies\System";
            using (var regKey = Registry.LocalMachine.CreateSubKey(targetPath))
            {
                regKey.SetValue("DisableTaskMgr", 1, RegistryValueKind.DWord);
            }

            Console.WriteLine("任务管理器已针对当前用户禁用");
        }
        catch (Exception ex)
        {
            Console.WriteLine($"操作失败: {ex.Message}");
        }
        finally
        {
            // 卸载临时注册表项
            int unloadResult = RegUnLoadKey(hklm, tempHiveKey);
            if (unloadResult != ERROR_SUCCESS)
            {
                Console.WriteLine($"卸载临时注册表项失败: {new System.ComponentModel.Win32Exception(unloadResult).Message}");
            }
        }
    }
}

办法2:修改本地机器注册表(对所有用户生效)

如果需要禁用所有用户的任务管理器,可以直接修改Registry.LocalMachine下的对应路径,该路径的设置会全局应用到所有账户。代码如下:

using Microsoft.Win32;

RegistryKey regKey;
string subKey = @"Software\Microsoft\Windows\CurrentVersion\Policies\System";

regKey = Registry.LocalMachine.CreateSubKey(subKey);
regKey.SetValue("DisableTaskMgr", 1, RegistryValueKind.DWord);
regKey.Close();

注意:此修改会影响所有用户,包括管理员账户,管理员需手动将值改回0才能重新启用任务管理器。

内容的提问来源于stack exchange,提问作者Lior v

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 23:55:23