Technical Information
- <SYSTEM32>\tasks\startup_1exe
- User Account Control (UAC)
- %LOCALAPPDATA%\yourapp\资料.txt
- %LOCALAPPDATA%\yourapp\qbcore.dll
- %LOCALAPPDATA%\yourapp\wechatweb.exe
- %LOCALAPPDATA%\yourapp\空白.pptx
- C:\users\public\上线信息.ini
- %ALLUSERSPROFILE%\displaysessioncontainers.log
- %LOCALAPPDATA%\yourapp\~$空白.pptx
- '13#.#22.204.241':447
- '13#.#22.204.241':447
- '%LOCALAPPDATA%\yourapp\wechatweb.exe'
- '%WINDIR%\syswow64\schtasks.exe' /query /tn "Startup_1exe"
- '%ProgramFiles(x86)%\microsoft office\office16\powerpnt.exe' "%LOCALAPPDATA%\YourApp\空白.pptx" /ou ""
- '%WINDIR%\syswow64\schtasks.exe' /query /tn "Startup_1exe"' (with hidden window)