Техническая информация
- <SYSTEM32>\tasks\hghh
- %ALLUSERSPROFILE%\hghh\hghh.ps1
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<Имя файла>.exe.log
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -WindowStyle Hidden -File "%ALLUSERSPROFILE%\hghh\hghh.ps1"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -File "%ALLUSERSPROFILE%\hghh\hghh.ps1" -Role Monitor
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -File "%ALLUSERSPROFILE%\hghh\hghh.ps1" -Role Worker