|
本帖最后由 在秋天拐弯 于 2016-3-10 11:02 编辑
不知道为什么不能上传附件,我把pecmd的脚本贴上来吧,你自己安装后提取文件就可以。
下面的脚本是从 527104427 http://bbs.wuyou.net/?378114 的PE里面提取的。
7zip
- REGI $HKLM\SOFTWARE\7-Zip\Path="%CurDir%"
- REGI $HKCR\*\shellex\ContextMenuHandlers\7-Zip\={23170F69-40C1-278A-1000-000100020000}
- REGI $HKCR\CLSID\{23170F69-40C1-278A-1000-000100020000}\=7-Zip Shell Extension
- REGI $HKCR\CLSID\{23170F69-40C1-278A-1000-000100020000}\InprocServer32\="%CurDir%\7-zip.dll"
- REGI $HKCR\CLSID\{23170F69-40C1-278A-1000-000100020000}\InprocServer32\ThreadingModel=Apartment
- REGI $HKCR\Directory\shellex\ContextMenuHandlers\7-Zip\={23170F69-40C1-278A-1000-000100020000}
- REGI $HKCR\Directory\shellex\DragDropHandlers\7-Zip\={23170F69-40C1-278A-1000-000100020000}
- REGI $HKCR\Drive\shellex\DragDropHandlers\7-Zip\={23170F69-40C1-278A-1000-000100020000}
- REGI $HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\7zFM.exe\="%CurDir%\7zFM.exe"
- REGI $HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\7zFM.exe\Path="%CurDir%"
- REGI $HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{23170F69-40C1-278A-1000-000100020000}=7-Zip Shell Extension
- REGI $HKCU\Software\7-Zip\Lang=zh-cn
- REGI $HKCU\Software\7-Zip\Path="%CurDir%"
- REGI $HKCU\Software\7-Zip\Compression\Archiver=7z
- REGI #HKCU\Software\7-Zip\Compression\EncryptHeaders=0
- REGI #HKCU\Software\7-Zip\Compression\Level=5
- REGI #HKCU\Software\7-Zip\Compression\ShowPassword=0
- REGI #HKCU\Software\7-Zip\Compression\Options\7z\BlockSize=64
- REGI #HKCU\Software\7-Zip\Compression\Options\7z\Dictionary=67108864
- REGI #HKCU\Software\7-Zip\Compression\Options\7z\Level=9
- REGI $HKCU\Software\7-Zip\Compression\Options\7z\Method=LZMA
- REGI #HKCU\Software\7-Zip\Compression\Options\7z\NumThreads=2
- REGI #HKCU\Software\7-Zip\Compression\Options\7z\Order=273
- REGI #HKCU\Software\7-Zip\Compression\Options\bzip2\Dictionary=921600
- REGI #HKCU\Software\7-Zip\Compression\Options\bzip2\Level=9
- REGI #HKCU\Software\7-Zip\Compression\Options\bzip2\NumThreads=2
- REGI #HKCU\Software\7-Zip\Compression\Options\gzip\Level=9
- REGI #HKCU\Software\7-Zip\Compression\Options\gzip\Order=258
- REGI #HKCU\Software\7-Zip\Compression\Options\xz\Dictionary=67108864
- REGI #HKCU\Software\7-Zip\Compression\Options\xz\Level=9
- REGI #HKCU\Software\7-Zip\Compression\Options\xz\NumThreads=2
- REGI #HKCU\Software\7-Zip\Compression\Options\xz\Order=273
- REGI #HKCU\Software\7-Zip\Compression\Options\zip\Level=9
- REGI $HKCU\Software\7-Zip\Compression\Options\zip\Method=Deflate
- REGI #HKCU\Software\7-Zip\Compression\Options\zip\NumThreads=2
- REGI #HKCU\Software\7-Zip\Compression\Options\zip\Order=258
- REGI #HKCU\Software\7-Zip\FM\FlatViewArc0=0
- REGI #HKCU\Software\7-Zip\FM\FlatViewArc1=0
- REGI #HKCU\Software\7-Zip\FM\ListMode=771
- REGI $HKCU\Software\7-Zip\FM\Editor=%Windir%\System32\notepad.exe
- REGI #HKU\.DEFAULT\Software\7-Zip\Options\ContextMenu=359
- REGI #HKU\.DEFAULT\Software\7-Zip\Options\CascadedMenu=1
- REGI #HKU\.DEFAULT\Software\7-Zip\Options\MenuIcons=0
复制代码
winrar
- #!PECMD
- FIND $0=%&::bX64%, TEAM ENVI &&RarExt="%CurDir%\RarExt.dll"|ENVI &&CLSID=8EE4! TEAM ENVI &&RarExt="%CurDir%\RarExt64.dll"|ENVI &&CLSID=64E4
- `IFEX %&RarExt%,! TEAM MESS 找不到 %&RarExt% @错误#OK*5000|EXIT _SUB
- `FORX * RarExt.dll WinRAR.exe rarreg.key Zip.SFX WinCon.SFX Default.SFX rarnew.dat zipnew.dat ,&&DLL,IFEX "%CurDir%\%&DLL%",! TEAM MESS 找不到 %&DLL% @错误#OK*5000|EXIT _SUB
- REGI HKCR\.gz\!
- REGI HKCR\.tar\!
- REGI HKCR\.tgz\!
- REGI HKCR\.z\!
- REGI HKCR\.zip\!
- REGI $HKCR\*\shellex\ContextMenuHandlers\WinRAR\={B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}
- REGI $HKCR\.7z\=WinRAR
- REGI $HKCR\.ace\=WinRAR
- REGI $HKCR\.arj\=WinRAR
- REGI $HKCR\.bz\=WinRAR
- REGI $HKCR\.bz2\=WinRAR
- REGI $HKCR\.cab\=WinRAR
- REGI $HKCR\.gz\=WinRAR
- REGI $HKCR\.iso\=WinRAR
- REGI $HKCR\.jar\=WinRAR
- REGI $HKCR\.lha\=WinRAR
- REGI $HKCR\.lzh\=WinRAR
- REGI $HKCR\.r00\=WinRAR
- REGI $HKCR\.r01\=WinRAR
- REGI $HKCR\.r02\=WinRAR
- REGI $HKCR\.r03\=WinRAR
- REGI $HKCR\.r04\=WinRAR
- REGI $HKCR\.r05\=WinRAR
- REGI $HKCR\.r06\=WinRAR
- REGI $HKCR\.r07\=WinRAR
- REGI $HKCR\.r08\=WinRAR
- REGI $HKCR\.r09\=WinRAR
- REGI $HKCR\.r10\=WinRAR
- REGI $HKCR\.r11\=WinRAR
- REGI $HKCR\.r12\=WinRAR
- REGI $HKCR\.r13\=WinRAR
- REGI $HKCR\.r14\=WinRAR
- REGI $HKCR\.r15\=WinRAR
- REGI $HKCR\.r16\=WinRAR
- REGI $HKCR\.r17\=WinRAR
- REGI $HKCR\.r18\=WinRAR
- REGI $HKCR\.r19\=WinRAR
- REGI $HKCR\.r20\=WinRAR
- REGI $HKCR\.r21\=WinRAR
- REGI $HKCR\.r22\=WinRAR
- REGI $HKCR\.r23\=WinRAR
- REGI $HKCR\.r24\=WinRAR
- REGI $HKCR\.r25\=WinRAR
- REGI $HKCR\.r26\=WinRAR
- REGI $HKCR\.r27\=WinRAR
- REGI $HKCR\.r28\=WinRAR
- REGI $HKCR\.r29\=WinRAR
- REGI $HKCR\.rar\=WinRAR
- `REGI $HKCR\.rar\ShellNew\FileName="%CurDir%\rarnew.dat"
- REGI $HKCR\.rev\=WinRAR.REV
- REGI $HKCR\.tar\=WinRAR
- REGI $HKCR\.taz\=WinRAR
- REGI $HKCR\.tbz\=WinRAR
- REGI $HKCR\.tbz2\=WinRAR
- REGI $HKCR\.tgz\=WinRAR
- REGI $HKCR\.uu\=WinRAR
- REGI $HKCR\.uue\=WinRAR
- REGI $HKCR\.xxe\=WinRAR
- REGI $HKCR\.z\=WinRAR
- REGI $HKCR\.zip\=WinRAR.ZIP
- `REGI $HKCR\.zip\ShellNew\FileName="%CurDir%\zipnew.dat"
- REGI $HKCR\CLSID\{B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}\=WinRAR
- REGI $HKCR\CLSID\{B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}\InProcServer32\=%&RarExt%
- REGI $HKCR\CLSID\{B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}\InProcServer32\ThreadingModel=Apartment
- REGI $HKCR\Drive\shellex\DragDropHandlers\WinRAR\={B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}
- REGI HKCR\exefile\shellex\PropertySheetHandlers\{B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}\=
- REGI $HKCR\Folder\ShellEx\ContextMenuHandlers\WinRAR\={B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}
- REGI $HKCR\Folder\ShellEx\DragDropHandlers\WinRAR\={B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}
- REGI $HKCR\WinRAR\=WinRAR 压缩文件
- REGI $HKCR\WinRAR\DefaultIcon\="%CurDir%\WinRAR.exe",0
- REGI $HKCR\WinRAR\shell\open\command\="%CurDir%\WinRAR.exe" "%%1"
- REGI HKCR\WinRAR\shellex\ContextMenuHandlers\{B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}\=
- REGI $HKCR\WinRAR\shellex\DropHandler\={B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}
- REGI HKCR\WinRAR\shellex\PropertySheetHandlers\{B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}\=
- REGI $HKCR\WinRAR.REV\=RAR 恢复卷
- REGI $HKCR\WinRAR.REV\DefaultIcon\="%CurDir%\WinRAR.exe",1
- REGI $HKCR\WinRAR.REV\shell\open\command\="%CurDir%\WinRAR.exe" "%%1"
- REGI $HKCR\WinRAR.ZIP\=WinRAR ZIP 压缩文件
- REGI $HKCR\WinRAR.ZIP\DefaultIcon\="%CurDir%\WinRAR.exe",0
- REGI $HKCR\WinRAR.ZIP\shell\open\command\="%CurDir%\WinRAR.exe" "%%1"
- REGI HKCR\WinRAR.ZIP\shellex\ContextMenuHandlers\{B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}\=
- REGI $HKCR\WinRAR.ZIP\shellex\DropHandler\={B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}
- REGI HKCR\WinRAR.ZIP\shellex\PropertySheetHandlers\{B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}\=
- FIND $0=%&::bX64%,!
- {
- REGI $HKCR\Wow6432Node\CLSID\{B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}\=WinRAR
- REGI $HKCR\Wow6432Node\CLSID\{B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}\InProcServer32\=%&RarExt%
- REGI $HKCR\Wow6432Node\CLSID\{B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}\InProcServer32\ThreadingModel=Apartment
- }
- `查询CPU个数
- FIND --pid &&cpu
- sed &&cpu=0,[^0-9], ,%&cpu%
- MSTR &&v1,&&v2,&&v3,&&v4,&&v5=<1*>%&cpu%
- IFEX $%&v3% > 1,REGI #HKCU\Software\WinRAR\General\SMP=1
- `折叠右键
- REGI #HKCU\Software\WinRAR\Setup\CascadedMenu=1
- REGI #HKCU\Software\WinRAR\Setup\MenuItems\AddArc=1
- REGI #HKCU\Software\WinRAR\Setup\MenuItems\AddTo=1
- REGI #HKCU\Software\WinRAR\Setup\MenuItems\Convert=1
- REGI #HKCU\Software\WinRAR\Setup\MenuItems\EmailArc=1
- REGI #HKCU\Software\WinRAR\Setup\MenuItems\EmailOpt=1
- REGI #HKCU\Software\WinRAR\Setup\MenuItems\Extr=1
- REGI #HKCU\Software\WinRAR\Setup\MenuItems\ExtrHere=1
- REGI #HKCU\Software\WinRAR\Setup\MenuItems\ExtrSep=1
- REGI #HKCU\Software\WinRAR\Setup\MenuItems\ExtrTo=1
- REGI #HKCU\Software\WinRAR\Setup\MenuItems\OpenSFX=1
- REGI #HKCU\Software\WinRAR\Setup\MenuItems\SFXLocal=1
- REGI #HKCU\Software\WinRAR\Setup\MenuItems\SFXNetwork=1
- REGI #HKCU\Software\WinRAR\Setup\MenuItems\SFXOther=1
- REGI #HKCU\Software\WinRAR\Setup\MenuItems\Test=1
- REGI HKCU\Software\WinRAR\Viewer\ExternalViewer=
- REGI #HKCU\Software\WinRAR\Viewer\Type=2
- REGI #HKCU\Software\WinRAR\Viewer\Wrap=0
- REGI $HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WinRAR.exe\="%CurDir%\WinRAR.exe"
- REGI $HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WinRAR.exe\Path="%CurDir%"
- REGI $HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B41DB860-%&CLSID%-11D2-9906-E49FADC173CA}=WinRAR shell extension
- REGI $HKLM\SOFTWARE\RegisteredApplications\WinRAR=Software\WinRAR\Capabilities
- REGI $HKLM\SOFTWARE\WinRAR\exe32="%CurDir%\WinRAR.exe"
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\ApplicationDescription=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.7z=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.ace=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.arj=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.bz=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.bz2=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.cab=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.gz=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.iso=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.jar=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.lha=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.lzh=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.rar=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.tar=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.taz=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.tbz=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.tbz2=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.tgz=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.uu=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.uue=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.xxe=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.z=WinRAR
- REGI $HKLM\SOFTWARE\WinRAR\Capabilities\FileAssociations\.zip=WinRAR.ZIP
- ENVI &&tmprar=
- REGI $HKLM\SOFTWARE\RegisteredApplications\WinRAR,&&tmprar
- `FIND $"Software\WinRAR\Capabilities"="%&tmprar%",!TEAM MESS 请以管理员身份运行!@错误#OK*3000|EXIT FILE
- `"LINK %Desktop%\文件压缩 WinRAR,%CurDir%\WinRAR.exe"
- `FIND $"/S"="%~1",!MESS WinRAR 安装成功! @提示#OK*5000
复制代码
|
|