Some code about recovering registry modifications

xiaoxiao2021-03-06  41

Regedit4; file is made by the mood network studio; if you find any problems in use, please contact the Make Mood (QQ: 8818190)

; Function: Restore registry modified by malicious code [HKEY_CLASS_ROOT / CLSID / {F935DC22-1CF0-11D0-ADB9-00C04FD58A0B}] @ = "Windows Scripting Host Shell Object"

[HKEY_CLASS_ROOT / CLSID / {F935DC22-1CF0-11D0-ADB9-00C04FD58A0B} / inprocserver32] @ = "wshom.ocx" "threadingmodel" = "Apartment"

[HKEY_CLASS_ROOT / CLSID / {F935DC22-1CF0-11D0-ADB9-00C04FD58A0B} / typeLib] @ = "{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}"

[HKEY_CLASS_ROOT / CLSID / {F935DC22-1CF0-11D0-ADB9-00C04FD58A0B} / progid] @ = "WScript.Shell.1"

[HKEY_CLASS_ROOT / CLSID / {F935DC22-1CF0-11D0-ADB9-00C04FD58A0B} / VersionIndependentProgid] @ = "wscript.shell"

[HKEY_CLASS_ROOT / CLSID / {F935DC22-1CF0-11D0-ADB9-00C04FD58A0B} / programmable] @ = ""

; Function: to restore internet options Security page custom buttons [HKEY_CURRENT_USER / Software / Policies / Microsoft / Internet Explorer / Control Panel] "SecChangeSettings" = dword: 0; Function: to restore IE search engine [HKEY_LOCAL_MACHINE / Software / Microsoft / Internet Explorer / Search] "Searchassist" = "http://ie.search.msn.com/ {{_rr 1asas 1t" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" "" " SRCHASST / SRCHASST.HTM "; Function: Repair IE's default page; Note: Immediately after running [HKEY_CURRENT_USER / SOFTWARE / Microsoft / Internet Explorer / Main]" default_page_url "=" http://www.microsoft.com/windows/ IE_INTL / CN / START / "; Function: Restore a series of file names; note: If you haven't changed yet, press F5 to refresh [hkey_classes_root / clsid / {bdeadf00-c265-11d0-bced-00a0c90ab50f}] @ =" Web Folder "" Infotip "=" You can create shortcuts to point to your company intranet or web folder. To publish your document into the web folder or to manage files in the folder, click this Folder shortcut. "

[HKEY_CLASS_ROOT / CLSID / {992CFFA0-F557-101A-88EC-00DD010CCC48}] @ = "Dial Network" "=" Even if the computer is not in the network, you can still use the dial network to access the sharing information on another computer. To With shared resources, the dial-in computer must be set to the web server. "[HKEY_CLASS_ROOT / CLSID / {2227A280-3AEA-1069-A2DE-08002B30309D}] @ =" Printer "Infotip" = "Add and install local using the printer folder Or network printers, or change the settings of existing printers. "

[HKEY_CLASS_ROOT / CLSID / {645FF040-5081-101B-9F08-00AA002F954E}] @ = "Recycle Bin" Infotip "=" contains deleted items that can be restored or permanently deleted. "

[HKEY_CLASS_ROOT / CLSID / {D6277990-4C6A-11CF-8D87-00AA0060F5BF}] @ = "Scheduled Tasks" "=" Use the Task Schedule to schedule repetitive tasks, such as disk defragmentation or routine report, etc. It is convenient to run. "Task Scheme" starts in the background each time you start Windows and run in the background, so the routine task will not affect your work. "

[HKEY_CLASS_ROOT / CLSID / {21EC2020-3AEA-1069-A2DD-08002B30309D}] @ = "Control Silver" "INFotip" = "Personize your computer using the Control Panel. For example, you can specify the display of the desktop (" Display "icon), the sound of the event (" Sound "icon), the size of the audio volume (" Multimedia "icon) and other content."

Function: Fix the operation of the start menu; Note: Please log out after running [HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Policies / Explorer] "Norun" = DWord: 00000000

[HKEY_USERS / .DEFAULT / CURRENTVERSION / Policies / Explorer] "Norun" = DWORD: 00000000; Function: Restore the home page modification; Note: If the IE property is opened, it takes effect after shutting [HKEY_CURRENT_USER / SOFTWARE / Policies / Microsoft / Internet Explorer / Control Panel] "HomePage" = DWORD: 00000000; Function: Restore Registry file association [HKEY_LOCAL_MACHINE / SOFTWARE / CLASSES / .REG] @ = "regfile"; function: Fix the Internet option in the IE toolbar; Note: Please turn off all browsers after running [HKEY_CURRENT_USER / SOFTWARE / Policies / Microsoft / Internet Explorer / Restrictions] "NobrowSerOptions" = dword: 00000000

[HKEY_LOCAL_MACHINE / Software / Policies / Microsoft / Internet Explorer / Restrictions] "NoBrowserOptions" = dword: 00000000; Function: to unlock the registry [HKEY_LOCAL_MACHINE / Software / Microsoft / Windows / CurrentVersion / Policies / System] "DisableRegistryTools" = dword: 00000000 [HKEY_CURRENT_USER / Software / Microsoft / Windows / CurrentVersion / Policies / System] "DisableRegistryTools" = dword: 00000000; function: restore the pages pop-up menu; Note: You need to turn off all the IE window into force [HKEY_CURRENT_USER / Software / Policies / Microsoft / Internet Explorer / Restrictions] "NoBrowserContextMenu" = dword: 00000000; function: cancel startup dialog; Note: Effective [HKEY_LOCAL_MACHINE / Software / Microsoft / Windows / CurrentVersion / Winlogon] "LegalNoticeCaption" = "" "LegalNoticeText" need to log off or restart after = ""; Function: repair IE, source file button; Note: Please turn off all browsers after running [HKEY_CURRENT_USER / SOFTWARE / Policies / Microsoft / Internet Explorer / Restrictions] "NoviewSource" = dword: 00000000

[HKEY_LOCAL_MACHINE / Software / Policies / Microsoft / Internet Explorer / Restrictions] "NoViewSource" = dword: 00000000; Function: restore OE title bar advertising; Note: You need to after OE closed to take effect [HKEY_CURRENT_USER / Software / Microsoft / Outlook Express] " WindowTitle "=" = "" "" = ""; function: Repair file properties in the file attribute; Note: You need to log out or reboot to take effect [HKEY_CURRENT_USER / SOFTWARE / Microsoft / Internet Explorer / Toolbar] "LinksFoldername" = "" : Restore the IE title bar; note: Need to take all the IE window to take effect [HKEY_CURRENT_USER / SOFTWARE / Microsoft / Internet Explorer / Main] "Window Title" = "Microsoft Internet Explorer"

[HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Internet Explorer / Main] "Window Title" = "Microsoft Internet Explorer" Note: If you want to use what function wants to copy the corresponding function to Notepad and save it to .reg files directly, Remember, don't forget that in front of the code, it is empty and empty ~~

转载请注明原文地址:https://www.9cbs.com/read-53040.html

New Post(0)