Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Set-MpPreference -DisableRealtimeMonitoring $true -ErrorAction SilentlyContinue"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '%TEMP%\' -ErrorAction SilentlyContinue"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '<Полный путь к файлу>' -ErrorAction SilentlyContinue; Add-MpPreference -ExclusionProcess '<Полный путь к файлу>' -ErrorAction SilentlyContinue; Add-Mp...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Set-MpPreference -DisableRealtimeMonitoring $false -ErrorAction SilentlyContinue"
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name=svchost_update dir=out action=allow program=<Полный путь к файлу>
- %HOMEPATH%\desktop\rust_stealer_debug.txt
- %TEMP%\bd_login data_82e8be4a.db
- %TEMP%\bd_login data_82e8be4a.db
- %LOCALAPPDATA%\microsoft\windows\explorer\thumbcache_idx.db
- DNS ASK di##ord.com
- '<SYSTEM32>\fltmc.exe' unload aswMonFlt
- '<SYSTEM32>\fltmc.exe' unload aswSnx
- '<SYSTEM32>\fltmc.exe' unload aswSP
- '<SYSTEM32>\fltmc.exe' unload aswArPot
- '<SYSTEM32>\fltmc.exe' unload aswVmm
- '<SYSTEM32>\fltmc.exe' unload klif
- '<SYSTEM32>\fltmc.exe' unload klflt
- '<SYSTEM32>\fltmc.exe' unload klkbdflt
- '<SYSTEM32>\fltmc.exe' unload klbackupdisk
- '<SYSTEM32>\fltmc.exe' unload klhk
- '<SYSTEM32>\fltmc.exe' unload bdsandbox
- '<SYSTEM32>\fltmc.exe' unload bdfsfltr
- '<SYSTEM32>\fltmc.exe' unload bdfwfpf
- '<SYSTEM32>\fltmc.exe' unload bdprivmon
- '<SYSTEM32>\fltmc.exe' unload eamonm
- '<SYSTEM32>\fltmc.exe' unload ehdrv
- '<SYSTEM32>\fltmc.exe' unload ekbdflt
- '<SYSTEM32>\fltmc.exe' unload mbamswissarmy
- '<SYSTEM32>\fltmc.exe' unload MbamChameleon
- '<SYSTEM32>\fltmc.exe' unload symefasi
- '<SYSTEM32>\fltmc.exe' unload SRTSP64
- '<SYSTEM32>\fltmc.exe' unload SRTSP
- '<SYSTEM32>\fltmc.exe' unload ccSet_N360
- '<SYSTEM32>\fltmc.exe' unload ccSet_NSE
- '<SYSTEM32>\fltmc.exe' unload BHDrvx64
- '<SYSTEM32>\fltmc.exe' unload BHDrvx86
- '<SYSTEM32>\fltmc.exe' unload IDSVia64
- '<SYSTEM32>\fltmc.exe' unload naveng
- '<SYSTEM32>\fltmc.exe' unload navex15
- '<SYSTEM32>\fltmc.exe' unload WdFilter
- '<SYSTEM32>\fltmc.exe' unload WdNisDrv
- '<SYSTEM32>\fltmc.exe' unload WdBoot
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Norton\Antivirus\properties\BrowserProtection\Common /v TemporaryDisabled /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Norton\Antivirus\properties\BrowserProtection\Common /v ProviderEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\CurrentVersion\SharedDefs" /v TemporaryDisabled /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\CurrentVersion\SharedDefs" /v ProviderEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Norton\Antivirus\properties\exclusions\PasswordProtection /v ExcludedFiles /t REG_SZ /d <Полный путь к файлу> /f
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Norton\Antivirus\properties\exclusions\FileProtection /v ExcludedFiles /t REG_SZ /d <Полный путь к файлу> /f
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\KasperskyLab\protected\AVP\settings /v EnableSelfProtection /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Norton\Antivirus\properties\BrowserProtection\Common /v TemporaryDisabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Norton\Antivirus\properties\BrowserProtection\Common /v ProviderEnabled /t REG_DWORD /d 1 /f