趁要重新恢复系统再次做了下实验,根据我浅薄的电脑知识,应该是注入注册表权限的问题(有的电脑有,有的没)。如果解包程序注入App.reg不能成功,就不能用PE添加的方式。手工添加时删除[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\InboxApp]
"F2F852BA90DD4456_Embedded_Lockdown_Manager_lnk_amd64.lnk"=hex(2):43,00,3a,00,\
5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,44,00,61,00,74,00,61,00,5c,\
00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,5c,00,57,00,69,00,\
6e,00,64,00,6f,00,77,00,73,00,5c,00,53,00,74,00,61,00,72,00,74,00,20,00,4d,\
00,65,00,6e,00,75,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,73,00,\
5c,00,4c,5d,65,51,0f,5f,01,95,9a,5b,a1,7b,06,74,68,56,5c,00,4c,5d,65,51,0f,\
5f,01,95,9a,5b,a1,7b,06,74,68,56,2e,00,6c,00,6e,00,6b,00,00,00
即可注入,不影响生成快捷方式。 |