|
本帖最后由 wangtingting118 于 2022-3-20 13:49 编辑
大师你给的ADMIN\pecmd.ini的内容:
//根据EXPLORER进程情况调用不同的命令
FIND EXPLORER.EXE,CALL DESKTOPLNK!CALL INITPE
//进入桌面前的初始化操作
_SUB INITPE
EXEC !%WINDIR%\SYSTEM32\WPEINIT.EXE
INIT U,3600
FILE %Windir%\System32\config\Default=>X:\Users\Default\NTUSER.DAT
DEVI %WinDir%\inf\display.inf
REGI HKLM\SYSTEM\Setup\SystemSetupInProgress=#0
serv netprofm
exec !netcfg.exe -c s -i MS_NATIVEWIFIP
serv Wlansvc
EXEC !startnet.exe -wg WORKGROUP
SERV Server
SERV FDResPub
EXEC !wpeutil.exe DisableFirewall
SERV Spooler
REGI HKLM\SYSTEM\Setup\SystemSetupInProgress=#1
TEAM TEXT 切换到管理员登陆(按Ctrl键)...... #0xEE $20|WAIT -3000|TEXT
FIND KEY=#17,CALL ADMIN!CALL DESKTOPLNK
_END
_SUB ADMIN
REGI HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\AutoAdminLogon=#1
REGI HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DefaultUserName=Administrator
REGI HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DefaultPassword=""
REGI HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList\Guest=#0
REGI HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\EnableSIHostIntegration=#0
REGI HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Init=PECMD.EXE MAIN %SystemRoot%\System32\PECMD.ini
//REGI HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath=X:\Users\Administrator
EXEC !=net start gpsvc
EXEC !=net start ProfSvc
EXEC !=net start seclogon
WAIT 666
EXEC !%SystemRoot%\System32\tsdiscon.exe
_END
//进入桌面后执行的命令
_SUB DESKTOPLNK
EXEC %Windir%\system32\ctfmon.exe
FIND EXPLORER.EXE,!SHEL %WINDIR%\EXPLORER.EXE
LINK %DESKTOP%\PECMD,%WINDIR%\SYSTEM32\PECMD.EXE
_END |
|