Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -Command Add-MpPreference -ExclusionPath '%APPDATA%\syshlp.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -Command Add-MpPreference -ExclusionPath '%APPDATA%'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -Command Add-MpPreference -ExclusionPath '<Текущая директория>'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath <Текущая директория>
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath %APPDATA%\syshlp.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath %APPDATA%
- ClassName: '桓汥彬牔祡湗d' WindowName: ''
- '<SYSTEM32>\net.exe' localgroup Administrators user /delete
- '<SYSTEM32>\net1.exe' localgroup Administrators user /delete