Техническая информация
- '%TEMP%\TBSetup.exe'
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Default_Page_URL" /t reg_sz /d http://www.wa##ogu.com /f
- '<SYSTEM32>\reg.exe' add "HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command"
- '<SYSTEM32>\reg.exe' add "HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command" /f /ve /t REG_SZ /d "\"%PROGRAM_FILES%\Internet Explorer\iexplore.exe\" http://www.wa###gu.com"
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Search Bar" /t reg_sz /d http://www.wa##ogu.com /f
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tool.bat" "
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t reg_sz /d http://www.wa##ogu.com /f
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Search Page" /t reg_sz /d http://www.wa##ogu.com/SearchWeb.htm?ke################ /f
- %TEMP%\nsj2.tmp\ioSpecial.ini
- %TEMP%\360safe.ico
- %TEMP%\nsj2.tmp\InstallOptions.dll
- %TEMP%\nsj2.tmp\modern-wizard.bmp
- %TEMP%\360.jpg
- %TEMP%\AlexaInstaller.exe
- %TEMP%\360安全卫士清理.bat
- %TEMP%\tool.bat
- %TEMP%\TBSetup.exe
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'