Техническая информация
- <SYSTEM32>\tasks\tstheme server module{q4f5h2c4v3-j6f4m7o4-a3e4f2q1}
- %APPDATA%\microsoft\windows\tstheme\tstheme.exe
- %APPDATA%\microsoft\windows\tstheme\6745645343447557
- %APPDATA%\microsoft\windows\tstheme\6745645343447557
- %APPDATA%\microsoft\windows\tstheme\6745645343447557
- '%WINDIR%\syswow64\schtasks.exe' /create /F /sc minute /mo 5 /tn "TSTheme Server Module{Q4F5H2C4V3-J6F4M7O4-A3E4F2Q1}" /tr "%APPDATA%\Microsoft\Windows\TSTheme\TSTheme.exe"
- '%WINDIR%\syswow64\schtasks.exe' /Query /XML /TN "TSTheme Server Module{Q4F5H2C4V3-J6F4M7O4-A3E4F2Q1}"