Техническая информация
- [<HKLM>\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command] '' = 'C:\\Program Files\Internet Explorer\iexplore.exe http://www.111333.com.cn/?in=startmenu'
- <SYSTEM32>\xcopy.exe "3\lnternet Explorer.lnk" "%APPDATA%\Microsoft\Internet Explorer\Quick Launch" /k /c /q /r /y
- <SYSTEM32>\xcopy.exe "2\lnternet Explorer.lnk" "%ALLUSERSPROFILE%\ЎёїЄКјЎ№ІЛµҐ\іМРт\" /k /c /q /r /y
- <SYSTEM32>\reg.exe delete HKEY_CLASSES_ROOT\piffile /v IsShortcut /f
- <SYSTEM32>\reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command" /ve /t REG_SZ /d "C:\\Program Files\Internet Explorer\iexplore.exe http://www.11###3.com.cn/?in########### /f
- <SYSTEM32>\reg.exe delete HKEY_CLASSES_ROOT\lnkfile /v IsShortcut /f
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Search Bar" /t REG_SZ /d "www.11###3.com.cn/?in########### /f
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Search Page" /t REG_SZ /d "www.11###3.com.cn/?in########## /f
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu" /v "{871C5380-42A0-1069-A2EA-08002B30309D}" /t REG_DWORD /d "00000001" /f
- <SYSTEM32>\xcopy.exe "1\lnternet Explorer.lnk" "%ALLUSERSPROFILE%\ЧАГж\" /k /c /q /r /y
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel" /v "{871C5380-42A0-1069-A2EA-08002B30309D}" /t REG_DWORD /d "00000001" /f