Техническая информация
- <SYSTEM32>\tasks\administartor
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -Command &{schtasks.exe /create /tn administartor /sc minute /st 00:10 /tr $env:USERPROFILE\AppData\Roaming\PerfLogs\System.vbs Add-MpPreference -ExclusionPath C:\ Add...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -Command &{schtasks.exe /create /tn administartor /sc minute /st 00:10 /tr $env:USERPROFILE\AppData\Roaming\PerfLogs\System.vbs Add-MpPreference -ExclusionPath C:\ Add...
- '<SYSTEM32>\schtasks.exe' /create /tn administartor /sc minute /st 00:10 /tr %APPDATA%\PerfLogs\System.vbs
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -NoLogo -WindowStyle hidden -ExecutionPolicy Unrestricted %APPDATA%\AppXDeploymentServer.ps1
- '<SYSTEM32>\taskeng.exe' {BF662FC3-F4CE-47FF-AFD6-D8AD41354D11} S-1-5-21-1960123792-2022915161-3775307078-1001:sgcwoldvgk\user:Interactive:[1]