Technical Information
- %APPDATA%\microsoft\excel\xlstart\工作薄.xltx
- %APPDATA%\microsoft\excel\xlstart\sheet.xltx
- '%WINDIR%\syswow64\taskkill.exe' /f /im "winword.exe"
- '%WINDIR%\syswow64\taskkill.exe' /f /im "powerpnt.exe"
- '%WINDIR%\syswow64\taskkill.exe' /f /im "excel.exe"
- C:\temp\officetemplet_silence\newofficetemplatesilence.exe
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\normal.docx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\normal.dotm
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\pwrpnt12.pptx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\annoucement.htm
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\blank.potx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\blank.pptx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\company_logo.jpg
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\book.xltx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\excel12.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\outlook_signature.htm
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\uninstall\book.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\uninstall\excel12.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\uninstall\pwrpnt12.pptx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\uninstall\blank.pptx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\uninstall\normal.docx
- %WINDIR%\shellnew\normal.docx
- %WINDIR%\shellnew\book.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\sheet.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\sheet.xltx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\book.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\english\uninstall\pwrpnt12.pptx
- C:\temp\officetemplet_silence\office templates\huawei\english\uninstall\normal.docx
- C:\temp\officetemplet_silence\msvcr110.dll
- C:\temp\officetemplet_silence\officekill.bat
- C:\temp\officetemplet_silence\office templates\huawei\english\install\book.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\book.xltx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\excel12.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\normal.docx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\pwrpnt12.pptx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\sheet.xlsx
- C:\temp\officetemplet_silence\msvcp110.dll
- C:\temp\officetemplet_silence\office templates\huawei\english\install\sheet.xltx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\blank.potx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\blank.pptx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\company_logo.jpg
- C:\temp\officetemplet_silence\office templates\huawei\english\install\normal.dotm
- C:\temp\officetemplet_silence\office templates\huawei\english\install\outlook_signature.htm
- C:\temp\officetemplet_silence\office templates\huawei\english\uninstall\blank.pptx
- C:\temp\officetemplet_silence\office templates\huawei\english\uninstall\book.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\english\uninstall\excel12.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\annoucement.htm
- %APPDATA%\microsoft\templates\blank.potx
- %WINDIR%\shellnew\blank.pptx
- C:\temp\officetemplet_silence\msvcp110.dll
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\blank.pptx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\book.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\book.xltx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\company_logo.jpg
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\excel12.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\normal.docx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\annoucement.htm
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\blank.potx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\normal.dotm
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\sheet.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\sheet.xltx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\uninstall\blank.pptx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\uninstall\book.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\uninstall\excel12.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\uninstall\normal.docx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\outlook_signature.htm
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\install\pwrpnt12.pptx
- C:\temp\officetemplet_silence\office templates\huawei\english\uninstall\pwrpnt12.pptx
- C:\temp\officetemplet_silence\office templates\huawei\english\uninstall\normal.docx
- C:\temp\officetemplet_silence\office templates\huawei\english\uninstall\excel12.xlsx
- C:\temp\officetemplet_silence\newofficetemplatesilence.exe
- C:\temp\officetemplet_silence\office templates\huawei\english\install\annoucement.htm
- C:\temp\officetemplet_silence\office templates\huawei\english\install\blank.potx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\blank.pptx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\book.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\book.xltx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\company_logo.jpg
- C:\temp\officetemplet_silence\msvcr110.dll
- C:\temp\officetemplet_silence\office templates\huawei\english\install\excel12.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\normal.dotm
- C:\temp\officetemplet_silence\office templates\huawei\english\install\outlook_signature.htm
- C:\temp\officetemplet_silence\office templates\huawei\english\install\pwrpnt12.pptx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\sheet.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\sheet.xltx
- C:\temp\officetemplet_silence\office templates\huawei\english\uninstall\blank.pptx
- C:\temp\officetemplet_silence\office templates\huawei\english\uninstall\book.xlsx
- C:\temp\officetemplet_silence\office templates\huawei\english\install\normal.docx
- C:\temp\officetemplet_silence\office templates\huawei\simplified chinese\uninstall\pwrpnt12.pptx
- C:\temp\officetemplet_silence\officekill.bat
- %APPDATA%\microsoft\templates\normal.dotm
- ClassName: '' WindowName: ''
- 'C:\temp\officetemplet_silence\newofficetemplatesilence.exe'
- '%WINDIR%\syswow64\cmd.exe' c:\temp\OfficeTemplet_silence\officekill.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' reg add HKEY_CLASSES_ROOT\.docx\Word.Document.12\ShellNew /v FileName /t REG_SZ /d "%WINDIR%\ShellNew\Normal.docx" /f' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' reg add HKEY_CLASSES_ROOT\.docx\Word.Document.12\ShellNew /v NullFile /t REG_SZ /d "" /f' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' reg add HKEY_CLASSES_ROOT\.xlsx\Excel.Sheet.12\ShellNew /v FileName /t REG_SZ /d "%WINDIR%\ShellNew\Book.xlsx" /f' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\15.0\Excel\options" /v disableboottoofficestart /t REG_DWORD /d 0 /f /reg:64' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\options" /v disableboottoofficestart /t REG_DWORD /d 0 /f /reg:64' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' reg add HKEY_CLASSES_ROOT\.pptx\PowerPoint.Show.12\ShellNew /v FileName /t REG_SZ /d "%WINDIR%\ShellNew\Blank.pptx" /f' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' c:\temp\OfficeTemplet_silence\officekill.bat
- '%WINDIR%\syswow64\cmd.exe' reg add HKEY_CLASSES_ROOT\.docx\Word.Document.12\ShellNew /v FileName /t REG_SZ /d "%WINDIR%\ShellNew\Normal.docx" /f
- '%WINDIR%\syswow64\reg.exe' add HKEY_CLASSES_ROOT\.docx\Word.Document.12\ShellNew /v FileName /t REG_SZ /d "%WINDIR%\ShellNew\Normal.docx" /f
- '%WINDIR%\syswow64\cmd.exe' reg add HKEY_CLASSES_ROOT\.docx\Word.Document.12\ShellNew /v NullFile /t REG_SZ /d "" /f
- '%WINDIR%\syswow64\reg.exe' add HKEY_CLASSES_ROOT\.docx\Word.Document.12\ShellNew /v NullFile /t REG_SZ /d "" /f
- '%WINDIR%\syswow64\cmd.exe' reg add HKEY_CLASSES_ROOT\.xlsx\Excel.Sheet.12\ShellNew /v FileName /t REG_SZ /d "%WINDIR%\ShellNew\Book.xlsx" /f
- '%WINDIR%\syswow64\reg.exe' add HKEY_CLASSES_ROOT\.xlsx\Excel.Sheet.12\ShellNew /v FileName /t REG_SZ /d "%WINDIR%\ShellNew\Book.xlsx" /f
- '%WINDIR%\syswow64\cmd.exe' reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\15.0\Excel\options" /v disableboottoofficestart /t REG_DWORD /d 0 /f /reg:64
- '%WINDIR%\syswow64\reg.exe' add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\15.0\Excel\options" /v disableboottoofficestart /t REG_DWORD /d 0 /f /reg:64
- '%WINDIR%\syswow64\cmd.exe' reg add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\options" /v disableboottoofficestart /t REG_DWORD /d 0 /f /reg:64
- '%WINDIR%\syswow64\reg.exe' add "HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Excel\options" /v disableboottoofficestart /t REG_DWORD /d 0 /f /reg:64
- '%WINDIR%\syswow64\cmd.exe' reg add HKEY_CLASSES_ROOT\.pptx\PowerPoint.Show.12\ShellNew /v FileName /t REG_SZ /d "%WINDIR%\ShellNew\Blank.pptx" /f
- '%WINDIR%\syswow64\reg.exe' add HKEY_CLASSES_ROOT\.pptx\PowerPoint.Show.12\ShellNew /v FileName /t REG_SZ /d "%WINDIR%\ShellNew\Blank.pptx" /f