|
本帖最后由 asoaas 于 2023-11-3 09:52 编辑
路线 ----> Windows\System32\config
HiveLoad.cmd
----------------------------------------
@echo off
color 1f
cd /d %~dp0
title Hive Load
mode con cols=27 lines=7
setlocal enabledelayedexpansion
@echo Admin >%windir%\admin.confirm || @(
echo Set UAC = CreateObject^("Shell.Application"^) > "%tmp%\admin.vbs"
echo UAC.ShellExecute "%~0", "", "", "runas", 1 >> "%tmp%\admin.vbs"
"%tmp%\admin.vbs" & del "%tmp%\admin.vbs" & exit)
@del %windir%\admin.confirm
REG LOAD HKLM\1 DEFAULT
REG LOAD HKLM\2 SOFTWARE
REG LOAD HKLM\3 SYSTEM
REG LOAD HKLM\4 DRIVERS
regedit.exe -m
exit
--------------------------------------------------
HiveUnload.cmd
@echo off
color 1f
cd /d %~dp0
title Hive UnLoad
mode con cols=27 lines=7
setlocal enabledelayedexpansion
@echo Admin >%windir%\admin.confirm || @(
echo Set UAC = CreateObject^("Shell.Application"^) > "%tmp%\admin.vbs"
echo UAC.ShellExecute "%~0", "", "", "runas", 1 >> "%tmp%\admin.vbs"
"%tmp%\admin.vbs" & del "%tmp%\admin.vbs" & exit)
@del %windir%\admin.confirm
REG UNLOAD HKLM\1
REG UNLOAD HKLM\2
REG UNLOAD HKLM\3
REG UNLOAD HKLM\4
choice /t 1 /d n > nul
echo.
DEL /A/S/F/Q *.LOG1
DEL /A/S/F/Q *.LOG2
DEL /A/S/F/Q *.blf
DEL /A/S/F/Q *.regtrans-ms
tskill regedit /V
echo.
exit
|
|