Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NonInteractive -NoProfile -ExecutionPolicy Bypass -Command "& Import-Module '%ProgramFiles%\WindowsPowerShell\Modules\Pester\3.4.0\bin\..\Pester.psm1'; & { Invoke-Pester -EnableExit ;powersh...
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\v5r255ob.cmdline"
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESB98C.tmp" "%TEMP%\CSC264C8458AFC4F70A44CAEAAEEFB3784.TMP"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' sleep 1
- %TEMP%\v5r255ob.0.cs
- %TEMP%\v5r255ob.cmdline
- %TEMP%\v5r255ob.out
- %TEMP%\csc264c8458afc4f70a44caeaaeefb3784.tmp
- %TEMP%\resb98c.tmp
- %TEMP%\v5r255ob.dll
- DNS ASK ex##uav.org
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\v5r255ob.cmdline" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESB98C.tmp" "%TEMP%\CSC264C8458AFC4F70A44CAEAAEEFB3784.TMP" (со скрытым окном)