Техническая информация
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /d "http://www.81##15.com/?de####" /f
- '<SYSTEM32>\reg.exe' delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v "URL" /f
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" /v "URL" /d "http://ie.##1115.com/s.html?wd##############" /f
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "First Home Page" /d "http://www.81##15.com/?de####" /f
- '<SYSTEM32>\cmd.exe' /c %TEMP%\bt4032.bat
- '<SYSTEM32>\regini.exe' "%WINDIR%\ionx.ini"
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\PPStream\main" /v "client" /d "spl001@xp241" /f
- %TEMP%\bt4032.bat
- %TEMP%\bt4032.bat