Техническая информация
- [HKLM\System\CurrentControlSet\Services\Microsoft Telemetry] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Microsoft Telemetry] 'ImagePath' = '%WINDIR%\Fonts\sys\LogonUI.exe'
- 'Microsoft Telemetry' %WINDIR%\Fonts\sys\LogonUI.exe
- %WINDIR%\fonts\sys\logonui.exe
- 'on#.#xcvb.pw':80
- DNS ASK on#.#xcvb.pw
- '%WINDIR%\fonts\sys\logonui.exe'
- '<SYSTEM32>\cmd.exe' /c sc stop "Microsoft Telemetry"
- '<SYSTEM32>\sc.exe' stop "Microsoft Telemetry"
- '<SYSTEM32>\cmd.exe' /c sc delete "Microsoft Telemetry"
- '<SYSTEM32>\sc.exe' delete "Microsoft Telemetry"
- '<SYSTEM32>\cmd.exe' /c sc create "Microsoft Telemetry" binpath= "%WINDIR%\Fonts\sys\LogonUI.exe" start= auto
- '<SYSTEM32>\sc.exe' create "Microsoft Telemetry" binpath= "%WINDIR%\Fonts\sys\LogonUI.exe" start= auto
- '<SYSTEM32>\cmd.exe' /c sc failure "Microsoft Telemetry" actions= restart/10/restart/10/reboot/20 reset= 1
- '<SYSTEM32>\sc.exe' failure "Microsoft Telemetry" actions= restart/10/restart/10/reboot/20 reset= 1
- '<SYSTEM32>\cmd.exe' /c sc start "Microsoft Telemetry"
- '<SYSTEM32>\sc.exe' start "Microsoft Telemetry"
- '<SYSTEM32>\cmd.exe' /c icacls %WINDIR%\fonts\sys /deny *S-1-1-0:F
- '<SYSTEM32>\icacls.exe' %WINDIR%\fonts\sys /deny *S-1-1-0:F