Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Optimizations' = 'wscript C:\Users\Public\Documents\system.vbs'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Optimizations' = 'wscript C:\Users\Public\Documents\system.vbs'
- <SYSTEM32>\tasks\microsoft\windowsoptimizationsservice
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\Documents\system.vbs"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle hidden -ExecutionPolicy Bypass -nologo -noprofile -file C:\Users\Public\Documents\system.ps1
- C:\users\public\documents\system.ps1
- C:\users\public\documents\system.vbs
- C:\users\public\documents\system.vbs
- C:\users\public\documents\system.ps1
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle hidden -ExecutionPolicy Bypass -nologo -noprofile -file C:\Users\Public\Documents\system.ps1' (со скрытым окном)
- '<SYSTEM32>\attrib.exe' +s +h C:\Users\Public\Documents\system.vbs
- '<SYSTEM32>\attrib.exe' +s +h C:\Users\Public\Documents\system.ps1
- '<SYSTEM32>\schtasks.exe' /Create /RU system /SC ONLOGON /TN Microsoft\WindowsOptimizationsService /TR "wscript C:\Users\Public\Documents\system.vbs" /F