Техническая информация
- <SYSTEM32>\tasks\googleupdatetaskmachineqc
- %ProgramFiles%\google\chrome\updater.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand "PAAjAG4AZgAjAD4AIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAAPAAjAGsAawBqACMAPgAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEAAKAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwA...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /ru "System" /tn "GoogleUpdateTaskMachineQC" /tr "\"%ProgramFiles%\Google\Chrome\updater.exe\""' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c schtasks /run /tn "GoogleUpdateTaskMachineQC"' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand "PAAjAG4AZgAjAD4AIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAAPAAjAGsAawBqACMAPgAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEAAKAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwA...
- '<SYSTEM32>\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /ru "System" /tn "GoogleUpdateTaskMachineQC" /tr "\"%ProgramFiles%\Google\Chrome\updater.exe\""
- '<SYSTEM32>\cmd.exe' /c schtasks /run /tn "GoogleUpdateTaskMachineQC"
- '<SYSTEM32>\schtasks.exe' /create /f /sc onlogon /rl highest /ru "System" /tn "GoogleUpdateTaskMachineQC" /tr "\"%ProgramFiles%\Google\Chrome\updater.exe\""
- '<SYSTEM32>\schtasks.exe' /run /tn "GoogleUpdateTaskMachineQC"