Техническая информация
- [<HKLM>\system\CurrentControlSet\services\WofAdk] 'Start' = '00000000'
- [<HKLM>\System\CurrentControlSet\Services\WofAdk] 'ImagePath' = 'system32\DRIVERS\wofadk.sys'
- [<HKLM>\system\CurrentControlSet\services\ImDisk] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Imdisk] 'ImagePath' = '%TEMP%\~9160179179881234563\Tools\Imdisk\sys\amd64\imdisk.sys'
- 'WofAdk' system32\DRIVERS\wofadk.sys
- 'Imdisk' %TEMP%\~9160179179881234563\tools\imdisk\sys\amd64\imdisk.sys
- <SYSTEM32>\cmd.exe
- [<HKLM>\system\CurrentControlSet\services\WofAdk] 'Group' = 'FSFilter Compression'
- %TEMP%\~5384120271271358453~\sg.tmp
- %TEMP%\~9160179179881234563\tools\x64\bcdedit.exe
- %TEMP%\~9160179179881234563\tools\x64\bcdboot.exe
- %TEMP%\~9160179179881234563\tools\nativevhdboot_x86.dll
- %TEMP%\~9160179179881234563\tools\nativevhdboot_x64.dll
- %TEMP%\~9160179179881234563\tools\imdisk\sys\i386\imdisk.sys
- %TEMP%\~9160179179881234563\tools\imdisk\sys\amd64\imdisk.sys
- %TEMP%\~9160179179881234563\lang\2058.dll
- %TEMP%\~9160179179881234563\lang\2052.dll
- %TEMP%\~9160179179881234563\lang\1058.dll
- %TEMP%\~9160179179881234563\lang\1055.dll
- %TEMP%\~9160179179881234563\lang\1049.dll
- %TEMP%\~9160179179881234563\lang\1046.dll
- %TEMP%\~9160179179881234563\lang\1042.dll
- %TEMP%\~9160179179881234563\tools\x64\bootsect.exe
- %TEMP%\~9160179179881234563\tools\x64\bootice\booticex64.exe
- %TEMP%\~9160179179881234563\lang\1031.dll
- %TEMP%\~9160179179881234563\lang\1028.dll
- %TEMP%\~9160179179881234563\_deltapatchwinxp\x86_wimgapi.dll.xdelta
- %TEMP%\~9160179179881234563\_deltapatchwinxp\x86_bootsect.exe.xdelta
- %TEMP%\~9160179179881234563\_deltapatchwinxp\x86_bcdedit.exe.xdelta
- %TEMP%\~9160179179881234563\_deltapatchwinxp\x86_bcdboot.exe.xdelta
- %TEMP%\~9160179179881234563\_deltapatchwinxp\x64_wimgapi.dll.xdelta
- %TEMP%\~9160179179881234563\_deltapatchwinxp\x64_libwim-15.dll.xdelta
- %TEMP%\~9160179179881234563\_deltapatchwinxp\x64_bootsect.exe.xdelta
- %TEMP%\~9160179179881234563\_deltapatchwinxp\x64_bcdedit.exe.xdelta
- %TEMP%\~9160179179881234563\_deltapatchwinxp\x64_bcdboot.exe.xdelta
- %TEMP%\~9160179179881234563\_deltapatchwinxp\fixwinxp.cmd
- %TEMP%\~9160179179881234563\winntsetup.ini.txt
- %TEMP%\~9160179179881234563\lang\1040.dll
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\languages.txt
- %TEMP%\~9160179179881234563\tools\x64\dism\dismapi.dll
- <DRIVERS>\wofadk.sys
- %TEMP%\winntsetup\logs\wimgapi_error.log
- %TEMP%\~9160179179881234563\_deltapatchwinxp\xdelta3.exe
- %TEMP%\~9160179179881234563\winntsetup_x86.exe
- %TEMP%\~9160179179881234563\winntsetup_x64.exe
- %TEMP%\~9160179179881234563\tools\x86\wimlib\libwim-15.dll
- %TEMP%\~9160179179881234563\tools\x86\wimgapi.dll
- %TEMP%\~9160179179881234563\tools\x86\offreg.dll
- %TEMP%\~9160179179881234563\tools\x86\msstmake.exe
- %TEMP%\~9160179179881234563\tools\x86\dism\wofadk.sys
- %TEMP%\~9160179179881234563\tools\x86\dism\folderprovider.dll
- %TEMP%\~9160179179881234563\tools\x86\dism\dismprov.dll
- %TEMP%\~9160179179881234563\tools\x86\dism\dismcoreps.dll
- %TEMP%\~9160179179881234563\tools\x86\dism\dismcore.dll
- %TEMP%\~9160179179881234563\tools\x86\dism\dismapi.dll
- %TEMP%\~9160179179881234563\tools\x86\diskcopy.dll
- %TEMP%\~9160179179881234563\tools\x86\bootsect.exe
- %TEMP%\~9160179179881234563\tools\x86\booticex86.exe
- %TEMP%\~9160179179881234563\tools\x86\bcdedit.exe
- %TEMP%\~9160179179881234563\tools\x86\bcdboot.exe
- %TEMP%\~9160179179881234563\tools\x64\wimlib\libwim-15.dll
- %TEMP%\~9160179179881234563\tools\x64\wimgapi.dll
- %TEMP%\~9160179179881234563\tools\x64\offreg.dll
- %TEMP%\~9160179179881234563\tools\x64\msstmake.exe
- %TEMP%\~9160179179881234563\tools\x64\dism\wofadk.sys
- %TEMP%\~9160179179881234563\tools\x64\dism\logprovider.dll
- %TEMP%\~9160179179881234563\tools\x64\dism\folderprovider.dll
- %TEMP%\~9160179179881234563\tools\x64\dism\dismprov.dll
- %TEMP%\~9160179179881234563\tools\x64\dism\dismcoreps.dll
- %TEMP%\~9160179179881234563\unattend\win7-11-select.xml
- %TEMP%\~9160179179881234563\lang\1036.dll
- %TEMP%\~9160179179881234563\unattend\win10_x32.xml
- %TEMP%\~9160179179881234563\unattend\win10-11_x64.xml
- %TEMP%\~9160179179881234563\tools\winntsetup_iso.cmd
- %TEMP%\~9160179179881234563\tools\minwin\default\antilog.ini
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\edge.reg
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\drvstore_inf.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\defender.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\defender.reg
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\active setup.reg
- %TEMP%\~9160179179881234563\tools\minwin\default\reg\usersignedin.reg
- %TEMP%\~9160179179881234563\tools\minwin\default\reg\systray_network_flyout.reg
- %TEMP%\~9160179179881234563\tools\minwin\default\reg\systray_classicvolumecontrol.reg
- %TEMP%\~9160179179881234563\tools\minwin\default\reg\stuckrects3-win10-200x.reg
- %TEMP%\~9160179179881234563\tools\minwin\default\reg\restore_photo_viewer_windows_10.reg
- %TEMP%\~9160179179881234563\tools\minwin\default\reg\gamedvr.reg
- %TEMP%\~9160179179881234563\tools\minwin\default\reg\filetrace.reg
- %TEMP%\~9160179179881234563\tools\minwin\default\antilog.reg
- %TEMP%\~9160179179881234563\tools\mergeide_9200.ini
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\fonts.txt
- %TEMP%\~9160179179881234563\tools\mergeide_7600.ini
- %TEMP%\~9160179179881234563\tools\mergeide_2600.ini
- %TEMP%\~9160179179881234563\tools\imdisk\cpl\i386\imdisk.cpl
- %TEMP%\~9160179179881234563\tools\imdisk\cpl\amd64\imdisk.cpl
- %TEMP%\~9160179179881234563\tools\diskpart\xp_legacy\disk0_bios.txt
- %TEMP%\~9160179179881234563\tools\diskpart\xp_legacy\bios.txt
- %TEMP%\~9160179179881234563\tools\diskpart\uefi.txt
- %TEMP%\~9160179179881234563\tools\diskpart\enabled=1
- %TEMP%\~9160179179881234563\tools\diskpart\disk0_uefi.txt
- %TEMP%\~9160179179881234563\tools\diskpart\disk0_bios.txt
- %TEMP%\~9160179179881234563\tools\diskpart\bios.txt
- %TEMP%\~9160179179881234563\tools\compact\wimbootcompress.ini
- %TEMP%\~9160179179881234563\tools\cattrim.ini
- %WINDIR%\temp\uddbba1.tmp
- %TEMP%\~9160179179881234563\tools\x64\dism\dismcore.dll
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\installed.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\netfx.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\edge.txt
- %TEMP%\~9160179179881234563\tools\win7usbboot.ini
- %TEMP%\~9160179179881234563\tools\win7usb3\readme.txt
- %TEMP%\~9160179179881234563\tools\win10builds.ini
- %TEMP%\~9160179179881234563\tools\wimscript\wimscript.ini
- %TEMP%\~9160179179881234563\tools\wimbootcompress.ini
- %TEMP%\~9160179179881234563\tools\minwin\readme.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\winsxs.ini
- %TEMP%\~9160179179881234563\tools\minwin\default\tasks.ini
- %TEMP%\~9160179179881234563\tools\minwin\default\services.ini
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\xps.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\xbox.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\xbox.reg
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\wuau.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\wuau.reg
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\wsearch.reg
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\wmp.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\winsat.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\windowspowershell.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\windowsapps.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\windows11.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\windows.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\syswow.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\system32.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\system32-dll.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\speech.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\programfiles.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\onedrive.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\netfx_keep.txt
- %TEMP%\~9160179179881234563\tools\minwin\default\remove\media.txt
- %WINDIR%\temp\uddbba0.tmp
- %TEMP%\~5384120271271358453~\sg.tmp
- %WINDIR%\temp\uddbba1.tmp
- %WINDIR%\temp\uddbba0.tmp
- ClassName: 'ComboBox' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\~5384120271271358453~\sg.tmp' x "<Полный путь к файлу>" -y -aoa -o"%TEMP%\~9160179179881234563"
- '%TEMP%\~9160179179881234563\winntsetup_x64.exe'
- '<SYSTEM32>\cmd.exe' /c set' (со скрытым окном)
- '%TEMP%\~5384120271271358453~\sg.tmp' x "<Полный путь к файлу>" -y -aoa -o"%TEMP%\~9160179179881234563"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c set