Техническая информация
- <SYSTEM32>\tasks\flash service support
- <PATH_SAMPLE>.log
- C:\users\public\bpyc\fservice.exe
- %TEMP%\bpyc.pid
- 'localhost':43990
- 'C:\users\public\bpyc\fservice.exe' frominstall
- 'C:\users\public\bpyc\fservice.exe' frominstall' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c powershell.exe -Command $taskObject = New-Object -ComObject schedule.service; $taskObject.Connect(); $rootFolder = $taskObject.GetFolder(''); $taskdefinition = $taskObject.NewTask($null);...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command $taskObject = New-Object -ComObject schedule.service; $taskObject.Connect(); $rootFolder = $taskObject.GetFolder(''); $taskdefinition = $taskObject.NewTask($null); $regInfo = $task...