Техническая информация
- '%TEMP%\多命令\获取上网帐号密码并自动保存到D盘.EXE'
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Default_Page_URL" /t reg_sz /d http://www.23##.com/?km## /f
- '%WINDIR%\regedit.exe' "%HOMEPATH%\Local Settings\Temp.\DefOpen.reg"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\7ZSfx000.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\多命令\多进程命令.bat" "
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t reg_sz /d http://www.23##.com/?km## /f
- %TEMP%\7ZSfx000.cmd
- %TEMP%\DefOpen.reg
- %TEMP%\多命令\多进程命令.bat
- %TEMP%\多命令\获取上网帐号密码并自动保存到D盘.EXE
- %TEMP%\7ZSfx000.cmd
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'