Effect:
-> -〉
Tools used: Resouce hacker or exce
Description environment: Windows XP
Modified object: assumer.exe (at % SystemRoot %)
In your Windows operating system, run the %systemroot.exe command to copy explorer.exe to other places, such as the C root directory. Then, use resoucehacker or exescopeto open the explorer.exe under the C root directory and find the location:
In resoucehacker:
Exists:
I know how to change it. Change the "Start" of 578 to the desired name. The exescopecan be saved directly and renamed as assumer1.exe.
If you use resoucehacker, modify it and click "compile script". Then, the variable is assumer1.exe. then, delete the file named assumer.exe in the C-drive root directory.
Next, move the modified assumer1.exe file to % SystemRoot %.
Run regedit and locate
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon
Double-click shellon the right side, and change the value to assumer1.exe.to display the desktop with assumer1.exe.
After the modification, you can see the effect. Use the task manager to initialize the er.exe process. Then, in the task manager, file-Create task: assumer1.exe
After confirmation, you can immediately obtain the effect of cutting the knife. If you do not want to use the modified explorer later, you only need to go to HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon
And then change the shell value to assumer.exe.