Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RemoteX' = '%LOCALAPPDATA%\Microsoft\Windows\<Имя файла>.exe'
- [HKCU\Environment] 'UserInitMprLogonScript' = '%LOCALAPPDATA%\Microsoft\Windows\<Имя файла>.exe'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RemoteX' = '%ALLUSERSPROFILE%\Microsoft\Windows\<Имя файла>.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WindowsManagementInstrumentation' = '"%LOCALAPPDATA%\Microsoft\Windows\WmiPrvSE.exe" --watch --exe "<Полный путь к файлу>"'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WindowsManagementInstrumentation' = '"%LOCALAPPDATA%\Microsoft\Windows\WmiPrvSE.exe" --watch --exe "<Полный путь к файлу>"'
- [HKCU\Environment] 'UserInitMprLogonScript' = '"%LOCALAPPDATA%\Microsoft\Windows\WmiPrvSE.exe" --watch --exe "<Полный путь к файлу>"'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WindowsManagementInstrumentation' = '"%ALLUSERSPROFILE%\Microsoft\Windows\WmiPrvSE.exe" --watch --exe "%ALLUSERSPROFILE%\Microsoft\Windows\...
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%ALLUSERSPROFILE%\Microsoft\Windows\<Имя файла>.exe,'
- [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{F5073CF3-1E3A-4B2E-9A5D-B1C2D3E4F506}] 'StubPath' = '%ALLUSERSPROFILE%\Microsoft\Windows\<Имя файла>.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\windowssystemcomponent.lnk
- <SYSTEM32>\tasks\microsoftwindowsmanagementclient
- <SYSTEM32>\tasks\microsoftwindowsmanagementclientboot
- <SYSTEM32>\tasks\microsoftwindowsmanagementclientperf
- <SYSTEM32>\tasks\microsoftwindowsmanagementclientsystem
- <SYSTEM32>\tasks\microsoftwindowsmanagementclientsystemboot
- <SYSTEM32>\tasks\microsoftwindowsmanagementhost
- <SYSTEM32>\tasks\microsoftwindowsmanagementhostboot
- <SYSTEM32>\tasks\microsoftwindowsmanagementhostperf
- <SYSTEM32>\tasks\microsoftwindowsmanagementhostsystem
- [HKLM\SYSTEM\CurrentControlSet\Services\winSvc] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\winSvc] 'ImagePath' = '%LOCALAPPDATA%\Microsoft\Windows\<Имя файла>.exe'
- 'winSvc' %LOCALAPPDATA%\Microsoft\Windows\<Имя файла>.exe
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule "name=RemoteX Client" dir=out action=allow program=<Полный путь к файлу>
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule "name=RemoteX Client In" dir=in action=allow program=<Полный путь к файлу>
- '<SYSTEM32>\taskkill.exe' /F /IM chrome.exe
- msedge.exe
- <SYSTEM32>\cmd.exe
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %APPDATA%\mozilla\firefox\profiles.ini
- %LOCALAPPDATA%\microsoft\windows\<Имя файла>.exe
- nul
- %ALLUSERSPROFILE%\microsoft\windows\<Имя файла>.exe
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\startup\windowssystemcomponent.lnk
- %LOCALAPPDATA%\microsoft\windows\wmiprvse.exe
- %TEMP%\rxinj1208896096\chrome_injector.exe
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\local state
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\preferences
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\secure preferences
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\login data
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\web data
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\session storage\current
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\session storage\log
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\session storage\manifest-000001
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\icon_128.png
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\icon_16.png
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\main.html
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\main.js
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\manifest.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\128.png
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ar\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\bg\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ca\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\cs\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\da\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\de\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\el\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\en_gb\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\en_us\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\es\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\es_419\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\et\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\eu\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fi\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fil\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\fr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\he\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hi\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\hu\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\id\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\it\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ja\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ko\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\lt\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\lv\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ms\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\nl\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\no\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pl\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pt_br\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\pt_pt\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ro\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\ru\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sk\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sl\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\sv\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\th\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\tr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\uk\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\vi\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\zh_cn\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\_locales\zh_tw\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\manifest.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\128.png
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ar\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\bg\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ca\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\cs\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\da\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\de\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\el\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\en\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\es\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fi\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fil\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\fr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\he\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hi\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\hu\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\id\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\it\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ja\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ko\messages.json
- %TEMP%\rxinj1208896096\output\installedsoftware.txt
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\cookies.sqlite.rxcopy
- %TEMP%\rxinj1208896096\output\installedbrowsers.txt
- %TEMP%\rxlss2494495181\lss.exe
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\lt\messages.json
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\cookies.sqlite.rxcopy-shm
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\lv\messages.json
- %TEMP%\rxinj1208896096\output\screenshot.jpg
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\nl\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\no\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pl\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pt_br\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\pt_pt\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ro\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\ru\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sk\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sl\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\sv\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\th\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\tr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\uk\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\vi\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\zh_cn\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\_locales\zh_tw\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\manifest.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\128.png
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\16.png
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\32.png
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\48.png
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ar\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\bg\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ca\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\cs\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\da\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\de\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\el\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en_gb\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\en_us\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\es\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\es_419\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\et\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fi\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fil\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\fr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\he\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hi\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\hu\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\id\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\it\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ja\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ko\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\lt\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\lv\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\nl\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\no\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pl\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pt_br\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\pt_pt\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ro\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\ru\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sk\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sl\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\sv\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\th\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\tr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\uk\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\vi\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\zh_cn\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\_locales\zh_tw\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\manifest.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\128.png
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ar\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\bg\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ca\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\cs\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\da\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\de\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\el\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\en\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\es\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fi\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fil\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hi\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hu\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\id\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\it\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ja\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ko\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\lt\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\lv\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\nl\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\no\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pl\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pt_br\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\pt_pt\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ro\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ru\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\se\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sk\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sl\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\sr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\th\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\tr\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\uk\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\vi\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\zh_cn\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\zh_tw\messages.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\manifest.json
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extension state\000003.log
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extension state\current
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extension state\log
- %LOCALAPPDATA%\remotex\profiles\chrome.staging\default\extension state\manifest-000001
- %LOCALAPPDATA%\remotex\profiles\chrome\.rx_sync_stamp
- %TEMP%\rxlss2494495181\lss.dmp
- %TEMP%\rxinj1208896096\output\rdpconnections\mru_hosts.txt
- %TEMP%\rxinj1208896096\output\lateral-movement\local_users.txt
- %TEMP%\rxinj1208896096\output\lateral-movement\local_admins.txt
- %TEMP%\rxinj1208896096\output\privileges\net_user.txt
- %TEMP%\rxinj1208896096\output\mimikatz-credentials\lsass_dump.zip
- %TEMP%\rxinj1208896096\output\privileges\whoami_priv.txt
- %ALLUSERSPROFILE%\microsoft\windows\wmiprvse.exe
- %TEMP%\rxinj1208896096\output\lateral-movement\network_map.txt
- %TEMP%\rxinj1208896096\output\privileges\whoami_all.txt
- %TEMP%\rxinj1208896096\output\processlist.txt
- %TEMP%\rxinj1208896096\output\games\steam\token.txt
- %TEMP%\rxinj1208896096\data.zip
- %TEMP%\etilqs_accv7pk1dlntzmz
- %TEMP%\etilqs_gf3efezkcpzwrbp
- %TEMP%\etilqs_maoojy5iclguzvc
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\cookies.sqlite.rxcopy-shm
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\cookies.sqlite.rxcopy
- %TEMP%\rxlss2494495181\lss.dmp
- %TEMP%\rxlss2494495181\lss.exe
- %TEMP%\rxinj1208896096\chrome_injector.exe
- %TEMP%\rxinj1208896096\data.zip
- %TEMP%\rxinj1208896096\output\games\steam\token.txt
- %TEMP%\rxinj1208896096\output\installedbrowsers.txt
- %TEMP%\rxinj1208896096\output\installedsoftware.txt
- %TEMP%\rxinj1208896096\output\lateral-movement\local_admins.txt
- %TEMP%\rxinj1208896096\output\lateral-movement\local_users.txt
- %TEMP%\rxinj1208896096\output\lateral-movement\network_map.txt
- %TEMP%\rxinj1208896096\output\mimikatz-credentials\lsass_dump.zip
- %TEMP%\rxinj1208896096\output\privileges\net_user.txt
- %TEMP%\rxinj1208896096\output\privileges\whoami_all.txt
- %TEMP%\rxinj1208896096\output\privileges\whoami_priv.txt
- %TEMP%\rxinj1208896096\output\processlist.txt
- %TEMP%\rxinj1208896096\output\rdpconnections\mru_hosts.txt
- %TEMP%\rxinj1208896096\output\screenshot.jpg
- %LOCALAPPDATA%\google\chrome\user data\default\preferences
- %LOCALAPPDATA%\google\chrome\application\debug.log
- '15#.#41.66.251':80
- 'ip##pi.com':80
- 'ap#.#pify.org':443
- 'clients2.google.com':443
- 'tr######e.googleapis.com':443
- 'clients4.google.com':443
- 'localhost':49702
- 'clients3.google.com':443
- 'ss#.#static.com':443
- 'google.com':443
- 'ap#.#pify.org':443
- 'clients2.google.com':443
- 'tr######e.googleapis.com':443
- 'localhost':49712
- 'localhost':49714
- 'ss#.#static.com':443
- 'google.com':443
- DNS ASK ip##pi.com
- DNS ASK ap#.#pify.org
- DNS ASK google.com
- DNS ASK clients2.google.com
- DNS ASK tr######e.googleapis.com
- DNS ASK clients4.google.com
- DNS ASK clients3.google.com
- DNS ASK ss#.#static.com
- ClassName: '' WindowName: ''
- ClassName: 'Chrome_MessageWindow' WindowName: '%LOCALAPPDATA%\Google\Chrome\User Data'
- '%LOCALAPPDATA%\microsoft\windows\<Имя файла>.exe'
- '%LOCALAPPDATA%\microsoft\windows\wmiprvse.exe' --guard --pid 3404 --exe <Полный путь к файлу>
- '%TEMP%\rxinj1208896096\chrome_injector.exe' -f all
- '%TEMP%\rxlss2494495181\lss.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NonInteractive -WindowStyle Hidden -NoProfile -Command "$s=(New-Object -COM WScript.Shell).CreateShortcut('%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\WindowsSystemComponent.lnk');... (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /tn MicrosoftWindowsManagementClient /tr \"%LOCALAPPDATA%\Microsoft\Windows\<Имя файла>.exe\" /sc ONLOGON /rl HIGHEST /f (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /tn MicrosoftWindowsManagementClientBoot /tr \"%LOCALAPPDATA%\Microsoft\Windows\<Имя файла>.exe\" /sc ONSTART /rl HIGHEST /f (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /tn MicrosoftWindowsManagementClientPerf /tr \"%LOCALAPPDATA%\Microsoft\Windows\<Имя файла>.exe\" /sc MINUTE /mo 5 /rl HIGHEST /f (со скрытым окном)
- '<SYSTEM32>\netsh.exe' advfirewall firewall delete rule "name=RemoteX Client"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NonInteractive -WindowStyle Hidden -NoProfile -Command "$s=(New-Object -COM WScript.Shell).CreateShortcut('%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\StartUp\WindowsSystemComponen... (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /tn MicrosoftWindowsManagementClientSystem /tr \"%ALLUSERSPROFILE%\Microsoft\Windows\<Имя файла>.exe\" /sc ONLOGON /ru SYSTEM /rl HIGHEST /f (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /tn MicrosoftWindowsManagementClientSystemBoot /tr \"%ALLUSERSPROFILE%\Microsoft\Windows\<Имя файла>.exe\" /sc ONSTART /ru SYSTEM /rl HIGHEST /f (со скрытым окном)
- '<SYSTEM32>\wbem\wmic.exe' cpu get name (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /tn MicrosoftWindowsManagementHost /tr "\"%LOCALAPPDATA%\Microsoft\Windows\WmiPrvSE.exe\" --watch --exe \"<Полный путь к файлу>\"" /sc ONLOGON /rl HIGHEST /f (со скрытым окном)
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn MicrosoftWindowsManagementHostBoot /tr "\"%LOCALAPPDATA%\Microsoft\Windows\WmiPrvSE.exe\" --watch --exe \"<Полный путь к файлу>\"" /sc ONSTART /rl HIGHEST /f (со скрытым окном)
- '<SYSTEM32>\tasklist.exe' /FO CSV /NH (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c net user user (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c whoami /all (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c reg query "HKCU\Software\Microsoft\Terminal Server Client\Servers" /s (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c whoami /priv (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c wmic computersystem get partofdomain (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /tn MicrosoftWindowsManagementHostPerf /tr "\"%LOCALAPPDATA%\Microsoft\Windows\WmiPrvSE.exe\" --watch --exe \"<Полный путь к файлу>\"" /sc MINUTE /mo 10 /rl HIGHEST /f (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /create /tn MicrosoftWindowsManagementClient /tr \"<Полный путь к файлу>\" /sc ONLOGON /rl HIGHEST /f (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c arp -a (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c net user (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c net localgroup administrators (со скрытым окном)
- '<SYSTEM32>\whoami.exe' /priv
- '<SYSTEM32>\reg.exe' query "HKCU\Software\Microsoft\Terminal Server Client\Servers" /s
- '<SYSTEM32>\whoami.exe' /all
- '<SYSTEM32>\net.exe' user user
- '<SYSTEM32>\schtasks.exe' /create /tn MicrosoftWindowsManagementClientBoot /tr \"<Полный путь к файлу>\" /sc ONSTART /rl HIGHEST /f (со скрытым окном)
- '<SYSTEM32>\net1.exe' user user
- '<SYSTEM32>\cmd.exe' /c reg query "HKCU\Software\Microsoft\Terminal Server Client\Default" (со скрытым окном)
- '<SYSTEM32>\arp.exe' -a
- '<SYSTEM32>\net.exe' user
- '<SYSTEM32>\net.exe' localgroup administrators
- '<SYSTEM32>\net1.exe' user
- '<SYSTEM32>\net1.exe' localgroup administrators
- '<SYSTEM32>\reg.exe' query "HKCU\Software\Microsoft\Terminal Server Client\Default"
- '<SYSTEM32>\schtasks.exe' /create /tn MicrosoftWindowsManagementClientPerf /tr \"<Полный путь к файлу>\" /sc MINUTE /mo 5 /rl HIGHEST /f (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c net use (со скрытым окном)
- '<SYSTEM32>\net.exe' use
- '<SYSTEM32>\schtasks.exe' /create /tn MicrosoftWindowsManagementHostSystem /tr "\"%ALLUSERSPROFILE%\Microsoft\Windows\WmiPrvSE.exe\" --watch --exe \"%ALLUSERSPROFILE%\Microsoft\Windows\<Имя файла>.exe\"" /sc ONLOGON /ru... (со скрытым окном)
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\subscription PATH __EventFilter CREATE Name=\"MicrosoftWindowsFilter\" EventNameSpace=\"root\cimv2\" QueryLanguage=\"WQL\" "Query=\"SELECT * FROM __InstanceModificationEvent W... (со скрытым окном)
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\subscription PATH CommandLineEventConsumer CREATE Name=\"MicrosoftWindowsConsumer\" ExecutablePath=\"%ALLUSERSPROFILE%\Microsoft\Windows\<Имя файла>.exe\" (со скрытым окном)
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\subscription PATH __FilterToConsumerBinding CREATE Filter=\"__EventFilter.Name=\\\"MicrosoftWindowsFilter\\\"\" Consumer=\"CommandLineEventConsumer.Name=\\\"MicrosoftWindowsCo... (со скрытым окном)
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule "name=RemoteX Client" dir=out action=allow program=<Полный путь к файлу> (со скрытым окном)
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule "name=RemoteX Client In" dir=in action=allow program=<Полный путь к файлу> (со скрытым окном)
- '%LOCALAPPDATA%\microsoft\windows\wmiprvse.exe' --guard --pid 3404 --exe <Полный путь к файлу> (со скрытым окном)
- '%TEMP%\rxinj1208896096\chrome_injector.exe' -f all (со скрытым окном)
- '%TEMP%\rxlss2494495181\lss.exe' (со скрытым окном)