Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\winsvc] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\winsvc] 'ImagePath' = '<SYSTEM32>\winsvc.exe'
- 'winsvc' <SYSTEM32>\winsvc.exe
- '<SYSTEM32>\taskkill.exe' "/F" "/IM" "winnet.exe"
- '<SYSTEM32>\taskkill.exe' "/F" "/IM" "wincfg.exe"
- <SYSTEM32>\.co85a6.tmp
- %TEMP%\temp-7ba726ae7d098915\o
- %TEMP%\temp-c00293b5068e50cb\o
- %TEMP%\temp-cf8528ed808d66be\o
- %TEMP%\temp-1edac82e4f3ef510\o
- %WINDIR%\temp\__psscriptpolicytest_fpdruhdo.i5w.ps1
- %WINDIR%\temp\__psscriptpolicytest_pwo3vfaj.nbj.psm1
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-16-539.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-16-861.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-17-084.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-17-395.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-17-526.dump
- %WINDIR%\temp\__psscriptpolicytest_3cancxyf.ovo.ps1
- %WINDIR%\temp\__psscriptpolicytest_ls0wq5kv.wfx.psm1
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-18-837.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-19-091.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-19-215.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-19-391.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-20-546.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-21-990.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-22-544.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-22-653.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-22-757.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-22-844.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-22-943.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-23-041.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-23-117.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-26-985.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-27-362.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-27-469.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-27-509.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-27-642.dump
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-27-717.dump
- %WINDIR%\temp\temp-045965a9abaf5e56\e
- %WINDIR%\temp\content\1972-6048-powershell.exe-14-08-27-798.dump
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\powershell\startupprofiledata-noninteractive
- %WINDIR%\temp\__psscriptpolicytest_z1latk1q.rvj.ps1
- %WINDIR%\temp\__psscriptpolicytest_omw5stem.wk4.psm1
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-30-919.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-31-220.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-31-374.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-31-641.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-31-717.dump
- %WINDIR%\temp\__psscriptpolicytest_np0useuw.00a.ps1
- %WINDIR%\temp\__psscriptpolicytest_szd0w0h1.bqd.psm1
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-32-053.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-32-137.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-32-222.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-32-442.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-32-697.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-32-861.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-33-034.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-33-089.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-33-141.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-33-186.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-33-229.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-33-284.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-33-327.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-33-875.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-33-943.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-33-990.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-34-006.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-34-044.dump
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-34-091.dump
- %WINDIR%\temp\temp-0632ce032dd4ee88\e
- %WINDIR%\temp\content\5240-3964-powershell.exe-14-08-34-144.dump
- %WINDIR%\temp\__psscriptpolicytest_npjucf02.l1m.ps1
- %WINDIR%\temp\__psscriptpolicytest_zzrgqq30.0mp.psm1
- %WINDIR%\temp\content\3412-3888-powershell.exe-14-08-37-114.dump
- %WINDIR%\temp\content\3412-3888-powershell.exe-14-08-37-998.dump
- %WINDIR%\temp\__psscriptpolicytest_wbmsp1se.5i0.ps1
- %WINDIR%\temp\__psscriptpolicytest_c2wbs3ue.oas.psm1
- %WINDIR%\temp\content\4132-4936-powershell.exe-14-08-40-009.dump
- %WINDIR%\temp\content\4132-4936-powershell.exe-14-08-40-867.dump
- %TEMP%\temp-7ba726ae7d098915\o
- %TEMP%\temp-c00293b5068e50cb\o
- %TEMP%\temp-cf8528ed808d66be\o
- %TEMP%\temp-1edac82e4f3ef510\o
- %WINDIR%\temp\__psscriptpolicytest_fpdruhdo.i5w.ps1
- %WINDIR%\temp\__psscriptpolicytest_pwo3vfaj.nbj.psm1
- %WINDIR%\temp\__psscriptpolicytest_3cancxyf.ovo.ps1
- %WINDIR%\temp\__psscriptpolicytest_ls0wq5kv.wfx.psm1
- %WINDIR%\temp\temp-045965a9abaf5e56\e
- %WINDIR%\temp\__psscriptpolicytest_z1latk1q.rvj.ps1
- %WINDIR%\temp\__psscriptpolicytest_omw5stem.wk4.psm1
- %WINDIR%\temp\__psscriptpolicytest_np0useuw.00a.ps1
- %WINDIR%\temp\__psscriptpolicytest_szd0w0h1.bqd.psm1
- %WINDIR%\temp\temp-0632ce032dd4ee88\e
- %WINDIR%\temp\__psscriptpolicytest_npjucf02.l1m.ps1
- %WINDIR%\temp\__psscriptpolicytest_zzrgqq30.0mp.psm1
- %WINDIR%\temp\__psscriptpolicytest_wbmsp1se.5i0.ps1
- %WINDIR%\temp\__psscriptpolicytest_c2wbs3ue.oas.psm1
- <SYSTEM32>\.co85a6.tmp в <SYSTEM32>\winsvc.exe
- '<SYSTEM32>\winsvc.exe' "<Полный путь к файлу>"
- '<SYSTEM32>\winsvc.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "\"<SYSTEM32>\sc.exe\"" "create" "winsvc" "type=own" "start=auto" "error=ignore" "binPath=\"<SYSTEM32>\winsvc.exe\"" "DisplayName=\"Windows System Service...
- '<SYSTEM32>\sc.exe' create winsvc type=own start=auto error=ignore binPath=<SYSTEM32>\winsvc.exe "DisplayName=Windows System Service"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "\"<SYSTEM32>\sc.exe\"" "failure" "winsvc" "reset=0" "actions=restart/0/restart/0/restart/0"
- '<SYSTEM32>\sc.exe' failure winsvc reset=0 actions=restart/0/restart/0/restart/0
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "\"<SYSTEM32>\sc.exe\"" "description" "winsvc" "\"Windows System Service is the main system supervision service.\""
- '<SYSTEM32>\sc.exe' description winsvc "Windows System Service is the main system supervision service."
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "\"<SYSTEM32>\sc.exe\"" "start" "winsvc"
- '<SYSTEM32>\sc.exe' start winsvc
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "Add-MpPreference" "-ExclusionPath" "\"<SYSTEM32>\""
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "Add-MpPreference" "-ExclusionPath" "\"%WINDIR%\Temp\""
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-SETACTIVE" "8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c"
- '<SYSTEM32>\powercfg.exe' -SETACTIVE 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-change" "standby-timeout-ac" "0"
- '<SYSTEM32>\powercfg.exe' -change standby-timeout-ac 0
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-change" "standby-timeout-dc" "0"
- '<SYSTEM32>\powercfg.exe' -change standby-timeout-dc 0
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-change" "hibernate-timeout-ac" "0"
- '<SYSTEM32>\powercfg.exe' -change hibernate-timeout-ac 0
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "&" "powercfg.exe" "-change" "hibernate-timeout-dc" "0"
- '<SYSTEM32>\powercfg.exe' -change hibernate-timeout-dc 0
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "-WindowStyle" "Hidden" "-Command" "Remove-NetFirewallRule" "-DisplayName" "\"Windows Network Manager\""