|
原帖由 lxl1638 于 2009-7-31 22:56 发表
7peldr.exe 没有什么特别,插件中(你的PE里),7peldr.exe 是 UPX 压缩的,解压后用 PE 资源工具一目了然。
win7peldr和7peldr类似SB,它内钳的批处理安装200多个inf。
1、在 RC_DATA\B 中放置了一个 CMD 批 ...
无独有偶,我昨天也用UPX -d解开了yahoouk的7peldr.exe,penet.exe,urgent.exe和full.exe进行研究,发了相同的东西。7peldr所做的都可以用PECMD代替,时间大概快10秒左右,由80减少至70秒。下面是我用PECMD.INI所做的的最新版本:- DISP W1024 H768 B32
- EXEC =!x:\windows\regedit.exe /s x:\windows\system32\clid.reg
- FILE x:\windows\system32\clid.reg
- LINK X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\附件\图片观赏器 I_VIEW32,x:\Program Files\Windows Photo Viewer\i_view32.exe
- LINK X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\附件\资源管理器 EXPLORER,x:\windows\explorer.exe /n /e,x:\
- LINK X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\附件\计算器 CALCULATOR,x:\windows\system32\calc.exe
- LINK X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\附件\命令提示符 CMD,x:\windows\system32\cmd.exe
- LINK X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\附件\记事本 NOTEPAD,x:\windows\system32\notepad.exe
- LINK X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\注册表编辑 REGEDIT,x:\windows\regedit.exe
- LINK X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\任务管理器 TASKMGR,x:\windows\system32\taskmgr.exe
- LINK X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\WIN7载入器 WIN7PELDR,x:\windows\system32\win7peldr.exe
- LINK X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\计算机管理 COMPMGMT,x:\windows\system32\mmc.exe /b %SystemRoot%/system32/compmgmt.msc
- LINK X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\文件工具\7z文件管理 7zFM,x:\Program Files\7-zip\7zfm.exe
- LINK X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\文件工具\文件搜索器 FILESEARCH,x:\windows\system32\filesearch.exe
- LINK X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\文件工具\图片观赏器 I_VIEW32,x:\Program Files\Windows Photo Viewer\i_view32.exe
- LINK X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\网络工具\TCPIP配置 TCPCFG,x:\windows\system32\tcpcfg.exe,,x:\windows\system32\tcpcfg.exe
- LINK X:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\网络工具\初始化网络 WPEUTIL,x:\windows\system32\wpeutil.exe,InitializeNetwork,x:\windows\icons\network.ico
- LINK X:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\命令提示符 CMD,x:\windows\system32\cmd.exe
- LINK X:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\任务管理器 TASKMGR,x:\windows\system32\taskmgr.exe
- LINK X:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\记事本 NOTEPAD,x:\windows\system32\notepad.exe
- LINK X:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\资源管理器 EXPLORER,x:\windows\explorer.exe,/n,x:\windows\icons\explorer.ico
- EXEC !cmd.exe /c "x:\windows\system32\PinItem.cmd"
- SHEL x:\windows\Explorer.exe
- CALL $setupapi.dll,InstallHinfSection DefaultInstall 132 x:\windows\inf\acpi.inf
- CALL $setupapi.dll,InstallHinfSection DefaultInstall 132 x:\windows\inf\cpu.inf
- CALL $setupapi.dll,InstallHinfSection DefaultInstall 132 x:\windows\inf\dc21x4vm.inf
- CALL $setupapi.dll,InstallHinfSection DefaultInstall 132 x:\windows\inf\disk.inf
- CALL $setupapi.dll,InstallHinfSection DefaultInstall 132 x:\windows\inf\hal.inf
- CALL $setupapi.dll,InstallHinfSection DefaultInstall 132 x:\windows\inf\hdaudbus.inf
- CALL $setupapi.dll,InstallHinfSection DefaultInstall 132 x:\windows\inf\iscsi.inf
- CALL $setupapi.dll,InstallHinfSection DefaultInstall 132 x:\windows\inf\keyboard.inf
- CALL $setupapi.dll,InstallHinfSection DefaultInstall 132 x:\windows\inf\msmouse.inf
- CALL $setupapi.dll,InstallHinfSection DefaultInstall 132 x:\windows\inf\msports.inf
- CALL $setupapi.dll,InstallHinfSection DefaultInstall 132 x:\windows\inf\usb.inf
- CALL $setupapi.dll,InstallHinfSection DefaultInstall 132 x:\windows\inf\usbport.inf
- CALL $setupapi.dll,InstallHinfSection DefaultInstall 132 x:\windows\inf\usbstor.inf
- CALL $setupapi.dll,InstallHinfSection DefaultInstall 132 x:\windows\inf\volume.inf
- EXEC =!drvload.exe x:\windows\inf\net1k32.inf
- EXEC =!drvload.exe x:\windows\inf\net1q32.inf
- EXEC =!drvload.exe x:\windows\inf\net1y32.inf
- EXEC =!drvload.exe x:\windows\inf\net44x32.inf
- EXEC =!drvload.exe x:\windows\inf\netavpna.inf
- EXEC =!drvload.exe x:\windows\inf\netavpnt.inf
- EXEC =!drvload.exe x:\windows\inf\netb57vx.inf
- EXEC =!drvload.exe x:\windows\inf\netbvbdx.inf
- EXEC =!drvload.exe x:\windows\inf\netbxndx.inf
- EXEC =!drvload.exe x:\windows\inf\nete1e32.inf
- EXEC =!drvload.exe x:\windows\inf\nete1g32.inf
- EXEC =!drvload.exe x:\windows\inf\netefe32.inf
- EXEC =!drvload.exe x:\windows\inf\netevbdx.inf
- EXEC =!drvload.exe x:\windows\inf\netgb6.inf
- EXEC =!drvload.exe x:\windows\inf\netimm.inf
- EXEC =!drvload.exe x:\windows\inf\netip6.inf
- EXEC =!drvload.exe x:\windows\inf\netk57x.inf
- EXEC =!drvload.exe x:\windows\inf\netl1c86.inf
- EXEC =!drvload.exe x:\windows\inf\netl1e86.inf
- EXEC =!drvload.exe x:\windows\inf\netl160x.inf
- EXEC =!drvload.exe x:\windows\inf\netl260x.inf
- EXEC =!drvload.exe x:\windows\inf\netloop.inf
- EXEC =!drvload.exe x:\windows\inf\netmscli.inf
- EXEC =!drvload.exe x:\windows\inf\netmyk01.inf
- EXEC =!drvload.exe x:\windows\inf\netnb.inf
- EXEC =!drvload.exe x:\windows\inf\netnvm32.inf
- EXEC =!drvload.exe x:\windows\inf\netnvmx.inf
- EXEC =!drvload.exe x:\windows\inf\netrasa.inf
- EXEC =!drvload.exe x:\windows\inf\netrass.inf
- EXEC =!drvload.exe x:\windows\inf\netrast.inf
- EXEC =!drvload.exe x:\windows\inf\netrtl32.inf
- EXEC =!drvload.exe x:\windows\inf\netrtx32.inf
- EXEC =!drvload.exe x:\windows\inf\netsstpa.inf
- EXEC =!drvload.exe x:\windows\inf\netsstpt.inf
- EXEC =!drvload.exe x:\windows\inf\nettcpip.inf
- EXEC =!drvload.exe x:\windows\inf\nettun.inf
- EXEC =!drvload.exe x:\windows\inf\netvfx86.inf
- EXEC =!drvload.exe x:\windows\inf\netvg62.inf
- EXEC =!drvload.exe x:\windows\inf\netxe32.inf
- RAMD ImDisk,P10,NTFS,B:
- EXEC =!x:\windows\system32\autorun.cmd
- LINK X:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Opera 网页浏览器,b:\opera\opera.cmd,,x:\windows\icons\opera.ico
- LINK %Quicklaunch%\网页浏览器 OPERA,b:\opera\opera.cmd,,x:\windows\icons\opera.ico
- LINK %Desktop%\网络设置器,x:\Program Files\penetcfg\PENetCfg.exe,,x:\windows\system32\networkexplorer.dll#0
- LINK %Desktop%\网页浏览器,b:\opera\opera.cmd,,x:\windows\icons\opera.ico
- LINK %Desktop%\磁盘分区经理,b:\pm85\program\launcher.exe,,x:\windows\icons\pm.ico
- LINK %Desktop%\TCPIP配置,x:\windows\system32\tcpcfg.exe
- EXEC !x:\windows\system32\winpeshl.exe
- TIPS 网络初始化正在进行中,如有需要,请于初始化完成后点击桌面的TCPIP配置图标重新配置。,8000,4,x:\windows\icons\NetworkSetup.ico
- WAIT 8000
复制代码原帖由 小咕咚 于 2009-7-31 23:59 发表
在PE3中处理掉clid.reg,winpeshl.ini只用下列一行:
[LaunchApps]
explorer.exe
启动也用快,当然没有加载网络驱动,从理论上讲应该是Explorer启动最快吧?驱动应该也是Explorer自动处理的?
不是的:clid.reg(EXEC =!x:\windows\regedit.exe), ImDisk(RAMD ImDisk),硬件检测和安装(CALL $setupapi.dll),drvload网卡(EXEC =!drvload.exe),explorer(SHEL x:\windows\Explorer.exe)都可交PECMD处理,winpeshl.ini只用下列一行:
[LaunchApps]
wpeinit.exe
[ 本帖最后由 khauyeung 于 2009-8-1 07:48 编辑 ] |
|