Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\vb0.vbs.lnk
- C:\users\public\music\0ps.ps1
- C:\users\public\music\vb0.vbs
- %HOMEPATH%\favorites\x.ps1
- %HOMEPATH%\favorites\assembly.vbs
- %HOMEPATH%\favorites\x.bat
- %HOMEPATH%\favorites\a.bat
- %HOMEPATH%\favorites\a.vbs
- %HOMEPATH%\favorites\b.ps1
- %HOMEPATH%\favorites\c.bat
- %HOMEPATH%\favorites\systeem.vbs
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "C:\Users\Public\Music\vb0.vbs"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass & C:\Users\Public\Music\0ps.ps1
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass & C:\Users\Public\Music\0ps.ps1' (со скрытым окном)