Техническая информация
- <SYSTEM32>\tasks\systemapplicationpath\dummytask
- <SYSTEM32>\tasks\systemapplicationpath\winople_driver
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -ExclusionPath @('<Полный путь к файлу>', '%LOCALAPPDATA%', '%APPDATA%', '%LOCALAPPDATA%', '%APPDATA%'); Add-MpPreference -ExclusionProcess '<Полный путь к ...
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- %TEMP%\content\4416-4528-<Имя файла>.exe-13-17-12-956.dump
- %LOCALAPPDATA%\winople\tlc\winople.exe
- <SYSTEM32>\tasks\systemapplicationpath\dummytask
- ClassName: 'Registry Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '<SYSTEM32>\schtasks.exe' /Create /TN "\SystemApplicationPath\DummyTask" /TR "cmd.exe" /SC ONLOGON /F
- '<SYSTEM32>\schtasks.exe' /Delete /TN "\SystemApplicationPath\DummyTask" /F
- '<SYSTEM32>\schtasks.exe' /Create /TN "\SystemApplicationPath\WinOple_Driver" /TR "\"%LOCALAPPDATA%\WinOple\TLC\winople.exe\"" /SC ONLOGON /RL HIGHEST /F