Техническая информация
- <SYSTEM32>\tasks\google
- %ProgramFiles%\google\chromeupdater.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' <#nkdsuy#> IF((New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { schtasks /...
- '%ProgramFiles%\google\chromeupdater.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' <#thakcjdi#> IF((New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { IF([Syst...
- '%ProgramFiles%\google\chromeupdater.exe' ' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath @($env:UserProfile, $env:ProgramFiles) -Force
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' <#thakcjdi#> IF((New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { IF([Syst...
- '<SYSTEM32>\schtasks.exe' /create /f /sc onlogon /rl highest /ru System /tn Google /tr "'%ProgramFiles%\Google\chromeupdater.exe'"
- '<SYSTEM32>\cmd.exe' /c choice /C Y /N /D Y /T 3 & Del "<Полный путь к файлу>"
- '<SYSTEM32>\choice.exe' /C Y /N /D Y /T 3
- '<SYSTEM32>\schtasks.exe' /run /tn Google
- '<SYSTEM32>\cmd.exe' /c wmic PATH Win32_VideoController GET Name, VideoProcessor > "%ProgramFiles%\Google\Libs\g.log"
- '<SYSTEM32>\wbem\wmic.exe' PATH Win32_VideoController GET Name, VideoProcessor