Technical Information
- [HKLM\SOFTWARE\Classes\htmlfile\shell\open\command] '' = '"%ProgramFiles(x86)%\Internet Explorer\IEXPLORE.EXE" -nohome'
- %TEMP%\54a4.tmp\54a5.tmp\54a6.ps1
- <Current directory>\close.bat
- <Current directory>\nircmd.exe
- %TEMP%\54a4.tmp\54a5.tmp\54a6.ps1
- %APPDATA%\microsoft\windows\start menu\programs\internet explorer (64-bit).lnk
- %APPDATA%\microsoft\windows\start menu\programs\desktop.ini
- %APPDATA%\microsoft\windows\start menu\programs\accessories\system tools\internet explorer (no add-ons).lnk
- %APPDATA%\microsoft\windows\start menu\programs\accessories\system tools\desktop.ini
- %APPDATA%\microsoft\windows\start menu\programs\internet explorer.lnk
- %APPDATA%\microsoft\internet explorer\quick launch\launch internet explorer browser.lnk
- %APPDATA%\microsoft\internet explorer\quick launch\desktop.ini
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' –NoProfile -ExecutionPolicy Bypass -File %TEMP%\54A4.tmp\54A5.tmp\54A6.ps1
- '<SYSTEM32>\ie4uinit.exe' -show
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' –NoProfile -ExecutionPolicy Bypass -File %TEMP%\54A4.tmp\54A5.tmp\54A6.ps1' (with hidden window)