Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Schedule] 'Start' = '00000002'
- <SYSTEM32>\attrib.exe -R "%HOMEPATH%\Desktop\Internet Explorer.lnk"
- <SYSTEM32>\reg.exe add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu" /v "{871C5380-42A0-1069-A2EA-08002B30309D}" /t REG_DWORD /d 1 /F
- <SYSTEM32>\reg.exe add "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel" /v "{871C5380-42A0-1069-A2EA-08002B30309D}" /t REG_DWORD /d 1 /F
- <SYSTEM32>\attrib.exe +R "%HOMEPATH%\Start Menu\Programs\Internet Explorer.lnk"
- <SYSTEM32>\attrib.exe -R "%HOMEPATH%\Start Menu\Programs\Internet Explorer.lnk"
- <SYSTEM32>\attrib.exe +R "%HOMEPATH%\Desktop\Internet Explorer.lnk"
- <SYSTEM32>\reg.exe add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel" /v "{871C5380-42A0-1069-A2EA-08002B30309D}" /t REG_DWORD /d 1 /F
- <SYSTEM32>\net1.exe start schedule
- <SYSTEM32>\reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\Schedule" /v Start /t REG_DWORD /d 2 /F
- <SYSTEM32>\cmd.exe /c c:\1.bat
- <SYSTEM32>\attrib.exe -r "%ALLUSERSPROFILE%\..\*Internet*.lnk" /s
- <SYSTEM32>\reg.exe add "HKCU\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t REG_SZ /d "http://a.##9a.cn/1" /F
- <SYSTEM32>\reg.exe add "HKLM\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t REG_SZ /d "http://a.##9a.cn/1" /F
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- <SYSTEM32>\KB920429.exe
- C:\1.bat
- C:\1.bat