Техническая информация
- <SYSTEM32>\tasks\windowsdefendertasksupport
- %TEMP%\tmp5678.tmp.bat
- %TEMP%\tmp5678.tmp.bat
- '<SYSTEM32>\schtasks.exe' /create /sc minute /mo 5 /tn "WindowsDefenderTasksupport" /tr "powershell -ExecutionPolicy Bypass -windowstyle hidden -noexit -Command [Reflection.Assembly]::Load([System.Convert]::Frombase64S...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp5678.tmp.bat" "' (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /sc minute /mo 5 /tn "WindowsDefenderTasksupport" /tr "powershell -ExecutionPolicy Bypass -windowstyle hidden -noexit -Command [Reflection.Assembly]::Load([System.Convert]::Frombase64S...
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp5678.tmp.bat" "
- '<SYSTEM32>\attrib.exe' +s +a +h %APPDATA%\support
- '<SYSTEM32>\attrib.exe' +s +a +h %APPDATA%\support\*