Technical Information
- <SYSTEM32>\tasks\yandexstartup
- %APPDATA%\yandex\<File name>.exe
- %TEMP%\upd.ps1
- '<LOCALNET>.0.180':4444
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -File %TEMP%\upd.ps1
- '%APPDATA%\yandex\<File name>.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn YandexStartup /tr %APPDATA%\Yandex\<File name>.exe /sc onlogon /rl highest /f