解锁注册表的方法有很多,当reg命令被病毒禁用以后咱办?google告诉我们:可以用inf、vbs、js、hta等各种代码来解锁注册表^_^
病毒可能修改了很多注册表项,有时并非一两句reg命令就能搞定的。网上比较流行的做法是导入以下xxx.reg文件: | Windows Registry Editor Version 5.00 | | | | [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] | | "RegPath"="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced" | | "Text"="@shell32.dll,-30501" | | "Type"="radio" | | "CheckedValue"=dword:00000002 | | "ValueName"="Hidden" | | "DefaultValue"=dword:00000002 | | "HKeyRoot"=dword:80000001 | | "HelpID"="shell.hlp#51104" | | [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] | | "RegPath"="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced" | | "Text"="@shell32.dll,-30500" | | "Type"="radio" | | "CheckedValue"=dword:00000001 | | "ValueName"="Hidden" | | "DefaultValue"=dword:00000002 | | "HKeyRoot"=dword:80000001 | | "HelpID"="shell.hlp#51105" | | [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden] | | "Type"="checkbox" | | "Text"="@shell32.dll,-30508" | | "WarningIfNotDefault"="@shell32.dll,-28964" | | "HKeyRoot"=dword:80000001 | | "RegPath"="Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced" | | "ValueName"="ShowSuperHidden" | | "CheckedValue"=dword:00000000 | | "UncheckedValue"=dword:00000001 | | "DefaultValue"=dword:00000000 | | "HelpID"="shell.hlp#51103" | | [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy] | | [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]COPY |
我给转成.exe格式了,大家放心使用!校内不支持附件,我给大家个链接址大家可以自己下
咱们论坛提倡开源的交流和切磋,反对这种敝帚自珍的转exe做法,建议楼主给出源代码。否则,下载链接将会被删除。
bat转exe是很容破解的,参考:批处理bat转exe加密之后的解密破解还原方法
http://bbs.bathome.net/thread-3343-1-1.html |