Техническая информация
- <SYSTEM32>\tasks\systemapplicationpath\dummytask
- <SYSTEM32>\tasks\systemapplicationpath\winmant_scanner
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -ExclusionPath @('<Полный путь к файлу>', '%LOCALAPPDATA%', '%APPDATA%', '%LOCALAPPDATA%', '%APPDATA%'); Add-MpPreference -ExclusionProcess '<Полный путь к ...
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- %TEMP%\content\4360-4188-<Имя файла>.exe-12-04-58-965.dump
- %LOCALAPPDATA%\winmant\lib\winmant.exe
- <SYSTEM32>\tasks\systemapplicationpath\dummytask
- ClassName: 'Registry Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '<SYSTEM32>\schtasks.exe' /Create /TN "\SystemApplicationPath\DummyTask" /TR "cmd.exe" /SC ONLOGON /F
- '<SYSTEM32>\schtasks.exe' /Delete /TN "\SystemApplicationPath\DummyTask" /F
- '<SYSTEM32>\schtasks.exe' /Create /TN "\SystemApplicationPath\WinMant_Scanner" /TR "\"%LOCALAPPDATA%\WinMant\Lib\winmant.exe\"" /SC ONLOGON /RL HIGHEST /F