Техническая информация
- '<SYSTEM32>\reg.exe' QUERY "HKEY_USERS\S-1-5-21-2052111302-484763869-725345543-1003\Software\Microsoft\Internet Explorer\Main" /v "Local Page"
- '<SYSTEM32>\reg.exe' QUERY "HKEY_USERS\S-1-5-21-2052111302-484763869-725345543-1003\Software\Microsoft\Internet Explorer\Main" /v "Search Page"
- '<SYSTEM32>\reg.exe' QUERY "HKEY_USERS\S-1-5-21-2052111302-484763869-725345543-1003\Software\Microsoft\Internet Explorer\Main" /v Default_Page_URL
- '<SYSTEM32>\reg.exe' query "HKEY_USERS\S-1-5-21-2052111302-484763869-725345543-1003\Software\Microsoft\Internet Explorer\Main" /v Default_Search_URL
- '<SYSTEM32>\reg.exe' QUERY "HKEY_USERS\S-1-5-21-2052111302-484763869-725345543-1003\Software\Microsoft\Internet Explorer\Main" /v "Start Page"
- '<SYSTEM32>\reg.exe' Query HKU
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\navptemp.bat""
- '<SYSTEM32>\reg.exe' ADD "HKEY_USERS\S-1-5-21-2052111302-484763869-725345543-1003\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t REG_SZ /d http://www.google.com /f
- '<SYSTEM32>\findstr.exe' /R "S-1-5-[0-9]*-[0-9-]*$"
- %TEMP%\prueba.txt
- C:\Navegadores.txt
- %TEMP%\1.tmp\navptemp.bat
- %TEMP%\1.tmp\navptemp.bat
- %TEMP%\prueba.txt