|
下面的PECMD是电脑店3.2中的文件内容,请高手看看里面还有改首页的东西?每次装完系统首页就被改了?
FIND MEM<384,FBWF P40 L96 H192!FBWF P50 L160 H256
TEAM ENVI W=%WinDir%|ENVI $WS=%WinDir%\SYSTEM32|ENVI WSD=%WS%\Drivers
TEAM LOGO %WS%\DND.JPG |WAIT 100
//TEAM TEXT 正在启动电脑店WinPE维护系统 …… #0x00ffff l150 t500 r500 b520 $20|wait 100
TEAM FILE %W%\TXTSETUP.SI*|PATH #%WS%\CONFIG|FILE %WS%\*.*_|FILE %WSD%\*.SY_
TEAM PATH %SystemDrive%\TEMP|INIT U,3690|EXEC @PECMD.EXE CALL $SHELL32.DLL,DllInstall,#1,U
//LOGS %W%\PECMD.LOG
TEAM ENVI V0=HKLM\System\CurrentControlSet\Services|ENVI V1=System32\Drivers
REGI %V0%\USBHUB\ImagePath=%V1%\USBHUB.SYS
REGI %V0%\USBCCGP\ImagePath=%V1%\USBCCGP.SYS
REGI %V0%\USBEHCI\ImagePath=%V1%\USBEHCI.SYS
REGI %V0%\USBOHCI\ImagePath=%V1%\USBOHCI.SYS
REGI %V0%\USBSTOR\ImagePath=%V1%\USBSTOR.SYS
REGI %V0%\USBUHCI\ImagePath=%V1%\USBUHCI.SYS
REGI %V0%\HIDUSB\ImagePath=%V1%\HIDUSB.SYS
REGI %V0%\MOUCLASS\ImagePath=%V1%\MOUCLASS.SYS
REGI %V0%\MOUHID\ImagePath=%V1%\MOUHID.SYS
REGI %V0%\KBDCLASS\ImagePath=%V1%\KBDCLASS.SYS
REGI %V0%\KBDHID\ImagePath=%V1%\KBDHID.SYS
REGI %V0%\CDROM\ImagePath=%V1%\CDROM.SYS
REGI HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{D20EA4E1-3957-11d2-A40B-0C5020524153}\!
REGI HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{D6277990-4C6A-11CF-8D87-00AA0060F5BF}\! `删除任务计划
REGI HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{450D8FBA-AD25-11D0-98A8-0800361B1103}\! `删除桌面我的文档
REGI HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\! `删除我的电脑文档
HOTK #112,PECMD.EXE `注册热键:F1 帮助
EXEC =!%WinDir%\SYSTEM32\SHOWDRIVE.EXE
EXEC =!%WinDir%\SYSTEM32\FIXUSB.EXE U
RAMD ImDisk,P25,NTFS,Z:,Temp
PATH Z:\Temp\
WAIT 600
EXEC =%WinDir%\SYSTEM32\dnd.exe (ud) output "udload/*" %WS%\%~nx
EXEC =%WinDir%\SYSTEM32\UDLOAD.EXE + UDLOAD/UDLOAD.INI
EXEC =!X:\WXPE\SYSTEM32\DLL.CMD
LINK %Programs%\附件工具\记事本,%WS%\NOTEPAD.EXE
LINK %Programs%\附件工具\命令提示符,%WS%\CMD.EXE
LINK %Programs%\附件工具\注册表编辑器,%W%\REGEDIT.EXE
LINK %Programs%\附件工具\资源管理器,%W%\EXPLORER.EXE,,EXPLORER.EXE#1
LINK %Programs%\系统微调\显示隐藏分区,%WS%\pecmd.exe,SHOW -1:-1,show.ico
LINK %Programs%\系统微调\分配磁盘盘符,%WS%\pecmd.exe,SHOW -1:0,Shell32.dll#83
LINK %Programs%\系统微调\设置临时文件,%WS%\PECMD.EXE,LOAD %WS%\PESET.INI,SHELL32.DLL#12
LINK %QuickLaunch%\我的电脑,%WS%\myc.lnk
EXEC =!CMD.EXE /C "REGSVR32 /S X:\WXPE\SYSTEM32\SEND.DLL"
EXEC =%WinDir%\SYSTEM32\PH7UDTOOL.EXE PH7UDload03normal.ini
ENVI $Desktop=X:\Documents and Settings\Default User\Desktop
TEAM WAIT 669|ENVI
TEAM LOGO %WS%\DND2.JPG |WAIT 100
//TEAM TEXT 正在载入桌面,请稍候 …… #0x00ffff l150 t500 r500 b520 $20|wait 300
EXEC =!X:\WXPE\SYSTEM32\MMC.CMD
LOAD %WS%\BASIC.INI
WALL X:\WXPE\SYSTEM32\DESK.JPG
TEAM FIND Explorer.EXE,!SHEL %WinDir%\EXPLORER.EXE|WAIT 1669
TEAM EXEC =!%WinDir%\SYSTEM32\OEM2.CMD|LOGO|TEXT
FILE %USERPROFILE%\「开始」菜单\PECMD说明.LNK
EXEC @ATTRIB +H "%USERPROFILE%\「开始」菜单\程序\启动"
EXEC =!%WinDir%\SYSTEM32\OEM.CMD
REGI HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}\=DVD/CD-ROM 驱动器
REGI HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}\=磁盘驱动器
REGI HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\=显示卡
REGI HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}\=软盘控制器
REGI HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}\=IDE ATA/ATAPI 控制器
REGI HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\=键盘
REGI HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96C-E325-11CE-BFC1-08002BE10318}\=声音、视频和游戏控制器
REGI HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96F-E325-11CE-BFC1-08002BE10318}\=鼠标和其它指针设备
REGI HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\=网络适配器
REGI HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E97D-E325-11CE-BFC1-08002BE10318}\=系统设备
REGI HKLM\SYSTEM\CurrentControlSet\Control\Class\{71A27CDD-812A-11D0-BEC7-08002BE2092F}\=存储卷
REGI HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView=#1
REGI HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FindExtensions\Static\WebSearch\!
REGI HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SmallIcons\SmallIcons=no
TEAM EXEC =PECMD SERV !AudioSrv|EXEC =PECMD SERV AudioSrv|SERV EVENTLOG
TEAM WAIT 900|KILL SMSS.EXE|KILL WINLOGON.EXE|FILE %WS%\SMSS.EXE|FILE %WS%\WINLOGON.EXE
TEAM WAIT 900|FILE %WS%\ORDERDRV.CMD|FILE %WS%\MBRFIX.EXE|FILE %WS%\MOUNTVOL.EXE|FILE %WS%\DLL.*
TEAM WAIT 900|FILE X:\WXPE\TEMP\*.*|FILE %WS%\INSTALLIME.EXE|FILE %WS%\LOGO2.JPG|FILE %WS%\*.*_|FILE %WS%\*.SYS
TEAM WAIT 900|EXEC =!%WinDir%\SYSTEM32\INTERNAT.EXE|WAIT 300|ENVI
//LOGS |
|