不是吧,好吧,教你个杀招:进去PE,导出HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects
然后挂载DEFAULT注册表,加载配置单元比如为1,导入过去吧....
HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects
比如:
- Windows Registry Editor Version 5.00
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist]
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{9E04CAB2-CC14-11DF-BB8C-A2F1DED72085}]
- "Version"=dword:00000005
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{9E04CAB2-CC14-11DF-BB8C-A2F1DED72085}\Count]
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{A3D53349-6E61-4557-8FC7-0028EDCEEBF6}]
- "Version"=dword:00000005
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{A3D53349-6E61-4557-8FC7-0028EDCEEBF6}\Count]
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{B267E3AD-A825-4A09-82B9-EEC22AA3B847}]
- "Version"=dword:00000005
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{B267E3AD-A825-4A09-82B9-EEC22AA3B847}\Count]
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CAA59E3C-4792-41A5-9909-6A6A8D32490E}]
- "Version"=dword:00000005
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CAA59E3C-4792-41A5-9909-6A6A8D32490E}\Count]
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}]
- "Version"=dword:00000005
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count]
- "{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\\ertrqvg.rkr"=hex:00,00,00,00,01,00,00,\
- 00,02,00,00,00,0b,08,00,00,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,\
- 00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,ff,\
- ff,ff,ff,a0,41,ad,6c,9a,91,d1,01,00,00,00,00
- "HRZR_PGYFRFFVBA"=hex:00,00,00,00,01,00,00,00,03,00,00,00,c7,2a,00,00,01,00,00,\
- 00,02,00,00,00,0b,08,00,00,7b,00,46,00,33,00,38,00,42,00,46,00,34,00,30,00,\
- 34,00,2d,00,31,00,44,00,34,00,33,00,2d,00,34,00,32,00,46,00,32,00,2d,00,39,\
- 00,33,00,30,00,35,00,2d,00,36,00,37,00,44,00,45,00,30,00,42,00,32,00,38,00,\
- 46,00,43,00,32,00,33,00,7d,00,5c,00,52,00,45,00,47,00,45,00,44,00,49,00,54,\
- 00,2e,00,45,00,58,00,45,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,01,00,00,00,02,00,00,00,0b,08,00,00,7b,00,46,00,33,00,38,00,42,\
- 00,46,00,34,00,30,00,34,00,2d,00,31,00,44,00,34,00,33,00,2d,00,34,00,32,00,\
- 46,00,32,00,2d,00,39,00,33,00,30,00,35,00,2d,00,36,00,37,00,44,00,45,00,30,\
- 00,42,00,32,00,38,00,46,00,43,00,32,00,33,00,7d,00,5c,00,52,00,45,00,47,00,\
- 45,00,44,00,49,00,54,00,2e,00,45,00,58,00,45,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,01,00,00,00,02,00,00,00,0b,08,00,00,7b,00,\
- 46,00,33,00,38,00,42,00,46,00,34,00,30,00,34,00,2d,00,31,00,44,00,34,00,33,\
- 00,2d,00,34,00,32,00,46,00,32,00,2d,00,39,00,33,00,30,00,35,00,2d,00,36,00,\
- 37,00,44,00,45,00,30,00,42,00,32,00,38,00,46,00,43,00,32,00,33,00,7d,00,5c,\
- 00,52,00,45,00,47,00,45,00,44,00,49,00,54,00,2e,00,45,00,58,00,45,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
- "HRZR_PGYPHNPbhag:pgbe"=hex:ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,\
- 80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,ff,ff,ff,ff,00,00,00,00,00,00,00,\
- 00,00,00,00,00
- "Zvpebfbsg.Jvaqbjf.Furyy.EhaQvnybt"=hex:00,00,00,00,00,00,00,00,00,00,00,00,09,\
- 17,00,00,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,\
- 80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,ff,ff,ff,ff,00,00,00,\
- 00,00,00,00,00,00,00,00,00
- "Zvpebfbsg.Jvaqbjf.Rkcybere"=hex:00,00,00,00,00,00,00,00,01,00,00,00,b3,0b,00,\
- 00,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,\
- 00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,ff,ff,ff,ff,00,00,00,00,00,\
- 00,00,00,00,00,00,00
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F2A1CB5A-E3CC-4A2E-AF9D-505A7009D442}]
- "Version"=dword:00000005
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F2A1CB5A-E3CC-4A2E-AF9D-505A7009D442}\Count]
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}]
- "Version"=dword:00000005
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count]
- "HRZR_PGYPHNPbhag:pgbe"=hex:ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- 00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,00,00,\
- 80,bf,00,00,80,bf,00,00,80,bf,00,00,80,bf,ff,ff,ff,ff,00,00,00,00,00,00,00,\
- 00,00,00,00,00
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{FA99DFC7-6AC2-453A-A5E2-5E2AFF4507BD}]
- "Version"=dword:00000005
- [HKEY_LOCAL_MACHINE\1\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{FA99DFC7-6AC2-453A-A5E2-5E2AFF4507BD}\Count]
复制代码 |