Техническая информация
- <SYSTEM32>\tasks\systemapplicationpath\dummytask
- <SYSTEM32>\tasks\systemapplicationpath\winrlc_driver
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -ExclusionPath @('<Полный путь к файлу>', '%LOCALAPPDATA%', '%APPDATA%', '%LOCALAPPDATA%', '%APPDATA%'); Add-MpPreference -ExclusionProcess '<Полный путь к ...
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- %TEMP%\content\4632-4608-<Имя файла>.exe-11-33-24-408.dump
- %LOCALAPPDATA%\winrlc\bin\winrlc.exe
- <SYSTEM32>\tasks\systemapplicationpath\dummytask
- ClassName: 'Registry Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '<SYSTEM32>\schtasks.exe' /Create /TN "\SystemApplicationPath\DummyTask" /TR "cmd.exe" /SC ONLOGON /F
- '<SYSTEM32>\schtasks.exe' /Delete /TN "\SystemApplicationPath\DummyTask" /F
- '<SYSTEM32>\schtasks.exe' /Create /TN "\SystemApplicationPath\WinRLC_Driver" /TR "\"%LOCALAPPDATA%\WinRLC\Bin\winrlc.exe\"" /SC ONLOGON /RL HIGHEST /F