Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' %ALLUSERSPROFILE%\Z0ZZ.ps1
- '<SYSTEM32>\cmd.exe' /c FOR /F "tokens=5 delims=tMs." %B IN ('assoc^|find "lM"')DO %B %ALLUSERSPROFILE%\Z0ZZ.ps1
- %ALLUSERSPROFILE%\z0zz.ps1
- '<SYSTEM32>\cmd.exe' /c assoc|find "lM"
- '<SYSTEM32>\cmd.exe' /S /D /c" assoc"
- '<SYSTEM32>\find.exe' "lM"