Техническая информация
- <SYSTEM32>\tasks\exit controller
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -ExclusionPath @('<Полный путь к файлу>', '%LOCALAPPDATA%', '%APPDATA%', '%LOCALAPPDATA%', '%APPDATA%'); Add-MpPreference -ExclusionProcess '<Полный путь к ...
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- %TEMP%\content\3228-5916-<Имя файла>.exe-09-25-56-101.dump
- %LOCALAPPDATA%\exitchecker\path\exitchecker.exe
- ClassName: 'Registry Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '<SYSTEM32>\schtasks.exe' /Create /TN "Exit Controller" /TR "\"%LOCALAPPDATA%\ExitChecker\Path\ExitChecker.exe\"" /SC ONLOGON /RL HIGHEST /F