Техническая информация
- <SYSTEM32>\tasks\googleupdatetaskmachineqc
- <SYSTEM32>\conhost.exe
- %ProgramFiles%\google\chrome\updater.exe
- '%ProgramFiles%\google\chrome\updater.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand "PAAjAHYAbQAjAD4AIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAAPAAjAGIAaQBvACMAPgAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgADwAIwB1AHcAIwA+ACAAQAAoACAAPAAjAGwAYwAjAD4AIAAkAGUA...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /ru "System" /tn "GoogleUpdateTaskMachineQC" /tr "\"%ProgramFiles%\Google\Chrome\updater.exe\""' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c schtasks /run /tn "GoogleUpdateTaskMachineQC"' (со скрытым окном)
- '%ProgramFiles%\google\chrome\updater.exe' ' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand "PAAjAHYAbQAjAD4AIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAAPAAjAGIAaQBvACMAPgAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgADwAIwB1AHcAIwA+ACAAQAAoACAAPAAjAGwAYwAjAD4AIAAkAGUA...
- '<SYSTEM32>\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /ru "System" /tn "GoogleUpdateTaskMachineQC" /tr "\"%ProgramFiles%\Google\Chrome\updater.exe\""
- '<SYSTEM32>\schtasks.exe' /create /f /sc onlogon /rl highest /ru "System" /tn "GoogleUpdateTaskMachineQC" /tr "\"%ProgramFiles%\Google\Chrome\updater.exe\""
- '<SYSTEM32>\cmd.exe' /c schtasks /run /tn "GoogleUpdateTaskMachineQC"
- '<SYSTEM32>\schtasks.exe' /run /tn "GoogleUpdateTaskMachineQC"