Техническая информация
- <SYSTEM32>\tasks\nvngxupdatecheckdaily_{aefe271c-271c-271c-271c-aefe271c271c}
- %TEMP%\5c1b.tmp
- %APPDATA%\rwgwrsw
- %APPDATA%\uffrihh
- %APPDATA%\rwgwrsw
- %APPDATA%\uffrihh
- 'ol##us.casa':443
- 'ol##us.casa':443
- DNS ASK ol##us.casa
- DNS ASK microsoft.com
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\net.exe' share
- '<SYSTEM32>\net1.exe' share
- '<SYSTEM32>\net.exe' user
- '<SYSTEM32>\net1.exe' user
- '<SYSTEM32>\net.exe' user /domain
- '<SYSTEM32>\net1.exe' user /domain
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_Process Get Caption,CommandLine,ExecutablePath,ProcessId /format:csv
- '<SYSTEM32>\net.exe' use
- '<SYSTEM32>\net1.exe' group
- '<SYSTEM32>\net.exe' localgroup
- '<SYSTEM32>\net1.exe' localgroup
- '<SYSTEM32>\netstat.exe' -r
- '<SYSTEM32>\cmd.exe' /c "<SYSTEM32>\route.exe" print
- '<SYSTEM32>\netstat.exe' -nao
- '<SYSTEM32>\net.exe' accounts /domain
- '<SYSTEM32>\net1.exe' accounts /domain
- '<SYSTEM32>\tasklist.exe' /v
- '<SYSTEM32>\systeminfo.exe'
- '<SYSTEM32>\netsh.exe' firewall show state
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\SecurityCenter2 Path FirewallProduct Get displayName /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\SecurityCenter2 Path AntiSpywareProduct Get displayName /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_Processor Get Name,DeviceID,NumberOfCores /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_Product Get Name,Version /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_NetworkAdapter Where PhysicalAdapter=TRUE Get Name,MACAddress,ProductName,ServiceName,NetConnectionID /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_StartupCommand Get Name,Location,Command /format:csv
- '<SYSTEM32>\schtasks.exe' /query
- '<SYSTEM32>\net.exe' group
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_OperatingSystem Get Caption,CSDVersion,BuildNumber,Version,BuildType,CountryCode,CurrentTimeZone,InstallDate,LastBootUpTime,Locale,OSArchitecture,OSLanguage,O...
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_UserAccount Get Name,Domain,AccountType,LocalAccount,Disabled,Status,SID /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_GroupUser Get GroupComponent,PartComponent /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_ComputerSystem Get Caption,Manufacturer,PrimaryOwnerName,UserName,Workgroup /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_PnPEntity Where ClassGuid="{50dd5230-ba8a-11d1-bf5d-0000f805f530}" Get Name,DeviceID,PNPDeviceID,Manufacturer,Description /format:csv
- '<SYSTEM32>\ipconfig.exe' /displaydns
- '<SYSTEM32>\route.exe' print
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_Volume Get Name,Label,FileSystem,SerialNumber,BootVolume,Capacity,DriveType /format:csv
- '%ProgramFiles%\internet explorer\iexplore.exe' -Embedding