Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\winsvc] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\winsvc] 'ImagePath' = '<SYSTEM32>\winsvc.exe'
- 'winsvc' <SYSTEM32>\winsvc.exe
- '<SYSTEM32>\taskkill.exe' "/F" "/IM" "winnet.exe"
- '<SYSTEM32>\taskkill.exe' "/F" "/IM" "wincfg.exe"
- <SYSTEM32>\.co7ac9.tmp
- %TEMP%\temp-513450bebb9fdf3c\o
- %TEMP%\temp-144c7733b016a3f2\o
- %TEMP%\temp-8b6a466ef57b6e4e\o
- %TEMP%\temp-8776334c2ff9f07f\o
- %WINDIR%\temp\__psscriptpolicytest_3yqtsmlv.534.ps1
- %WINDIR%\temp\__psscriptpolicytest_dnuh2q42.nis.psm1
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-19-130.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-19-416.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-19-542.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-19-763.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-19-832.dump
- %WINDIR%\temp\__psscriptpolicytest_1p55njjq.21v.ps1
- %WINDIR%\temp\__psscriptpolicytest_owrscf0o.wbb.psm1
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-20-195.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-20-233.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-20-295.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-20-427.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-20-667.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-21-069.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-21-286.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-21-332.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-21-386.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-21-433.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-21-471.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-21-549.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-21-603.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-22-809.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-22-909.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-22-956.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-22-972.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-23-025.dump
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-23-057.dump
- %WINDIR%\temp\temp-5d647268d07cdc6c\e
- %WINDIR%\temp\content\4840-740-powershell.exe-15-26-23-110.dump
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\powershell\startupprofiledata-noninteractive
- %WINDIR%\temp\__psscriptpolicytest_jpwqtlwf.byd.ps1
- %WINDIR%\temp\__psscriptpolicytest_3muh5gkd.zwa.psm1
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-26-397.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-26-683.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-26-823.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-27-228.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-27-317.dump
- %WINDIR%\temp\__psscriptpolicytest_0fuy4xej.vog.ps1
- %WINDIR%\temp\__psscriptpolicytest_235sj1ke.0nk.psm1
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-27-875.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-27-922.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-28-023.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-28-185.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-28-435.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-28-585.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-28-757.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-28-822.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-28-865.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-28-918.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-28-981.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-29-078.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-29-132.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-29-800.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-29-894.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-29-932.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-29-948.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-30-002.dump
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-30-033.dump
- %WINDIR%\temp\temp-169d125dfd2bdaae\e
- %WINDIR%\temp\content\2776-4812-powershell.exe-15-26-30-095.dump
- %WINDIR%\temp\__psscriptpolicytest_qkdt0m0t.gm0.ps1
- %WINDIR%\temp\__psscriptpolicytest_ralq0gte.wmo.psm1
- %WINDIR%\temp\content\4432-3104-powershell.exe-15-26-32-808.dump
- %WINDIR%\temp\content\4432-3104-powershell.exe-15-26-33-945.dump
- %WINDIR%\temp\__psscriptpolicytest_w2lrfqxu.mie.ps1
- %WINDIR%\temp\__psscriptpolicytest_s4xbmrxl.mwb.psm1
- %WINDIR%\temp\content\3316-2812-powershell.exe-15-26-35-911.dump
- %WINDIR%\temp\content\3316-2812-powershell.exe-15-26-36-597.dump
- %WINDIR%\temp\__psscriptpolicytest_p5a21uvn.dzw.ps1
- %WINDIR%\temp\__psscriptpolicytest_gr1djgkf.fdc.psm1
- %WINDIR%\temp\content\1756-3728-powershell.exe-15-26-38-425.dump
- %WINDIR%\temp\content\1756-3728-powershell.exe-15-26-39-121.dump
- %WINDIR%\temp\__psscriptpolicytest_4ubuc122.i3f.ps1
- %WINDIR%\temp\__psscriptpolicytest_dw4u2q2y.554.psm1
- %TEMP%\temp-513450bebb9fdf3c\o
- %TEMP%\temp-144c7733b016a3f2\o
- %TEMP%\temp-8b6a466ef57b6e4e\o
- %TEMP%\temp-8776334c2ff9f07f\o
- %WINDIR%\temp\__psscriptpolicytest_3yqtsmlv.534.ps1
- %WINDIR%\temp\__psscriptpolicytest_dnuh2q42.nis.psm1
- %WINDIR%\temp\__psscriptpolicytest_1p55njjq.21v.ps1
- %WINDIR%\temp\__psscriptpolicytest_owrscf0o.wbb.psm1
- %WINDIR%\temp\temp-5d647268d07cdc6c\e
- %WINDIR%\temp\__psscriptpolicytest_jpwqtlwf.byd.ps1
- %WINDIR%\temp\__psscriptpolicytest_3muh5gkd.zwa.psm1
- %WINDIR%\temp\__psscriptpolicytest_0fuy4xej.vog.ps1
- %WINDIR%\temp\__psscriptpolicytest_235sj1ke.0nk.psm1
- %WINDIR%\temp\temp-169d125dfd2bdaae\e
- %WINDIR%\temp\__psscriptpolicytest_qkdt0m0t.gm0.ps1
- %WINDIR%\temp\__psscriptpolicytest_ralq0gte.wmo.psm1
- %WINDIR%\temp\__psscriptpolicytest_w2lrfqxu.mie.ps1
- %WINDIR%\temp\__psscriptpolicytest_s4xbmrxl.mwb.psm1
- %WINDIR%\temp\__psscriptpolicytest_p5a21uvn.dzw.ps1
- %WINDIR%\temp\__psscriptpolicytest_gr1djgkf.fdc.psm1
- %WINDIR%\temp\__psscriptpolicytest_4ubuc122.i3f.ps1
- %WINDIR%\temp\__psscriptpolicytest_dw4u2q2y.554.psm1
- <SYSTEM32>\.co7ac9.tmp в <SYSTEM32>\winsvc.exe
- '<SYSTEM32>\winsvc.exe' "<Полный путь к файлу>"
- '<SYSTEM32>\winsvc.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "\"<SYSTEM32>\sc.exe\"" "create" "winsvc" "type=own" "start=auto" "error=ignore" "binPath=\"<SYSTEM32>\winsvc.exe\"" "DisplayName=\"Windows System Service...
- '<SYSTEM32>\sc.exe' create winsvc type=own start=auto error=ignore binPath=<SYSTEM32>\winsvc.exe "DisplayName=Windows System Service"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "\"<SYSTEM32>\sc.exe\"" "failure" "winsvc" "reset=0" "actions=restart/0/restart/0/restart/0"
- '<SYSTEM32>\sc.exe' failure winsvc reset=0 actions=restart/0/restart/0/restart/0
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "\"<SYSTEM32>\sc.exe\"" "description" "winsvc" "\"Windows System Service is the main system supervision service.\""
- '<SYSTEM32>\sc.exe' description winsvc "Windows System Service is the main system supervision service."
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "\"<SYSTEM32>\sc.exe\"" "start" "winsvc"
- '<SYSTEM32>\sc.exe' start winsvc
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "Add-MpPreference" "-ExclusionPath" "\"<SYSTEM32>\""
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "Add-MpPreference" "-ExclusionPath" "\"%WINDIR%\Temp\""
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-SETACTIVE" "8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c"
- '<SYSTEM32>\powercfg.exe' -SETACTIVE 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-change" "standby-timeout-ac" "0"
- '<SYSTEM32>\powercfg.exe' -change standby-timeout-ac 0
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-change" "standby-timeout-dc" "0"
- '<SYSTEM32>\powercfg.exe' -change standby-timeout-dc 0
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-change" "hibernate-timeout-ac" "0"
- '<SYSTEM32>\powercfg.exe' -change hibernate-timeout-ac 0
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-change" "hibernate-timeout-dc" "0"
- '<SYSTEM32>\powercfg.exe' -change hibernate-timeout-dc 0
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "Remove-NetFirewallRule" "-DisplayName" "\"Windows Network Manager\""