piramida48
Постоянный участник
- Сообщения
- 163
- Реакции
- 31
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Отметьте галочкой только пункт Shortcuts.
begin
RegKeyParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders', 'Favorites', 'REG_EXPAND_SZ', '%USERPROFILE%\Favorites');
RegKeyParamWrite('HKCU', 'Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders', 'Favorites', 'REG_EXPAND_SZ', '%USERPROFILE%\Favorites');
QuarantineFile(GetEnvironmentVariable('UserProfile') + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk','');
QuarantineFile(GetEnvironmentVariable('UserProfile') + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk','');
QuarantineFile(GetEnvironmentVariable('UserProfile') + '\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk','');
QuarantineFile(GetEnvironmentVariable('UserProfile') + '\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk','');
QuarantineFile(GetEnvironmentVariable('UserProfile') + '\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk','');
QuarantineFile(GetEnvironmentVariable('UserProfile') + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk','');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk','');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk','');
QuarantineFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk','');
ShowMessage('Пожалуйста, открепите все ярлыки браузеров из панели задач. После этого нажмите ОК.');
DeleteFile(GetEnvironmentVariable('UserProfile') + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk','');
DeleteFile(GetEnvironmentVariable('UserProfile') + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk','');
DeleteFile(GetEnvironmentVariable('UserProfile') + '\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk','');
DeleteFile(GetEnvironmentVariable('UserProfile') + '\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk','');
DeleteFile(GetEnvironmentVariable('UserProfile') + '\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk','');
DeleteFile(GetEnvironmentVariable('UserProfile') + '\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk','');
DeleteFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk','');
DeleteFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk','');
DeleteFile('C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk','');
CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
RebootWindows(false);
end.
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Opera\launcher.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\Internet Explorer\iexplore.exe
Procedure RemoveADs(ADirName : string; AScanSubDir : boolean);
var FS : TFileSearch;
begin
ADirName := NormalDir(ADirName);
FS := TFileSearch.Create(nil);
FS.FindFirst(ADirName + '*.lnk');
while FS.Found do
begin
SetStatusBarText(ADirName + FS.FileName);
if FS.IsDir then
begin
if AScanSubDir and (FS.FileName <> '.') and (FS.FileName <> '..') then
RemoveADs(ADirName + FS.FileName, AScanSubDir)
end
else begin
ExecuteFile('cmd.exe', '/c <NUL set /p=>"' + ADirName + FS.FileName + '":Zone.Identifier:$DATA', 0, 5000, true);
end;
FS.FindNext;
end;
FS.Free;
end;
begin
RemoveADs(GetEnvironmentVariable('UserProfile') + '\AppData\Roaming\Microsoft\Windows\Start Menu', true);
RemoveADs('C:\ProgramData\Microsoft\Windows\Start Menu', true);
end.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
begin
RegKeyParamWrite('HKCU', 'SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations', 'DefaultFileTypeRisk', 'REG_DWORD', '6151');
RegKeyParamWrite('HKCU', 'SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations', 'LowRiskFileTypes', 'REG_SZ', '.lnk');
RegKeyParamWrite('HKCU', 'SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations', 'ModRiskFileTypes', 'REG_SZ', '.lnk');
RebootWindows(false);
end.
icacls "%AllUsersProfile%\Microsoft\Windows\Start Menu" /T /C /L /setintegritylevel (OI)(CI)M > "%userprofile%\Desktop\Integrity.txt" 2>&1
icacls "%UserProfile%\AppData\Roaming\Microsoft\Windows\Start Menu" /T /C /L /setintegritylevel (OI)(CI)M >> "%userprofile%\Desktop\Integrity.txt" 2>&1
We use cookies and similar technologies for the following purposes:
Do you accept cookies and these technologies?
We use cookies and similar technologies for the following purposes:
Do you accept cookies and these technologies?