Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'bat' = '%WINDIR%\System Id1e Process.exe'
- '<SYSTEM32>\wscript.exe' "%WINDIR%\creatlink.vbs"
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /d "http://www.92#3.cc/" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{8515FC11-B332-447E-8056-1197551CFDB4}" /f /v "Icon" /t REG_SZ /d "shell32.dll,255"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{8515FC11-B332-447E-8056-1197551CFDB4}" /f /v "HotIcon" /t REG_SZ /d "shell32.dll,255"
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\绿色单文件封装工具 v1.5\360dh1.bat"
- '%WINDIR%\regedit.exe' /s x.reg
- '<SYSTEM32>\reg.exe' ADD "HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command" /ve /t REG_EXPAND_SZ /d "%ProgramFiles%\Internet Explorer\iexplore.exe http://www.92#3.cc/" /f
- %TEMP%\绿色单文件封装工具 v1.5\x.reg
- %TEMP%\aut4.tmp
- %WINDIR%\startpage.reg
- %WINDIR%\RestoreStartPage.lnk
- %WINDIR%\creatlink.vbs
- %TEMP%\绿色单文件封装工具 v1.5\360dh1.bat
- %TEMP%\绿色单文件封装工具 v1.5\1.bat
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut3.tmp
- %TEMP%\绿色单文件封装工具 v1.5\36.bat
- %TEMP%\aut4.tmp
- %TEMP%\绿色单文件封装工具 v1.5\x.reg
- %TEMP%\aut3.tmp
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- ClassName: 'RegEdit_RegEdit' WindowName: ''