WriteConsoleW
|
buffer:
Mode LastWriteTime Length Name
console_handle:
0x0000001b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
d---- 2021-08-01 오전 9:11 Google
console_handle:
0x00000023
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Remove-Item : Cannot find path 'C:\Users\Public\OneDrive.vbs' because it does n
console_handle:
0x00000023
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ot exist.
console_handle:
0x0000002f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\link.jpg.ps1:248 char:14
console_handle:
0x0000003b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ Remove-Item <<<< -Path C:\Users\Public\OneDrive.vbs -Force
console_handle:
0x00000047
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : ObjectNotFound: (C:\Users\Public\OneDrive.vbs:St
console_handle:
0x00000053
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ring) [Remove-Item], ItemNotFoundException
console_handle:
0x0000005f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.Remov
console_handle:
0x0000006b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
eItemCommand
console_handle:
0x00000077
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Directory: C:\Users\Public
console_handle:
0x00000097
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Mode LastWriteTime Length Name
console_handle:
0x000000a3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
-a--- 2021-08-01 오전 9:11 0 alosh.ps1
console_handle:
0x000000ab
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Windows Registry Editor Version 5.00
console_handle:
0x00000013
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Security and Maint
console_handle:
0x00000017
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
enance\Checks]
console_handle:
0x00000017
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Security and Maint
console_handle:
0x0000000f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
enance\Checks\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.100]
console_handle:
0x0000000f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
"CheckSetting"=hex:01,00,00,00,d0,8c,9d,df,01,15,d1,11,8c,7a,00,c0,4f,c2,97,eb,
console_handle:
0x00000017
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
01,00,00,00,c5,b3,6a,e4,0c,03,21,45,ac,98,0c,b7,4e,27,27,e1,00,00,00,00,02,\
console_handle:
0x0000001b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
00,00,00,00,00,10,66,00,00,00,01,00,00,20,00,00,00,72,95,d4,76,21,15,a1,34,\
console_handle:
0x0000001f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
a9,81,1e,14,d6,bd,b3,91,0b,23,5c,74,61,4a,e3,08,58,8a,0d,46,c5,57,0d,b4,00,\
console_handle:
0x00000023
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
00,00,00,0e,80,00,00,00,02,00,00,20,00,00,00,23,8f,17,7c,83,ae,0c,12,38,b9,\
console_handle:
0x00000027
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
93,b7,cf,05,50,6d,3e,e1,2b,ef,50,06,5c,85,61,04,6e,56,32,43,f0,72,30,00,00,\
console_handle:
0x0000002b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
00,71,47,f8,00,73,33,f6,8f,5a,e6,09,3d,96,1a,c9,f5,52,ae,c3,db,52,45,f4,ed,\
console_handle:
0x0000002f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
34,b3,2e,a4,30,00,ae,d3,b3,8f,f2,9d,c5,59,ac,b1,18,76,e1,e8,79,5b,bf,32,40,\
console_handle:
0x00000033
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
00,00,00,10,3f,ef,37,f4,d9,cb,74,f6,17,ab,cb,21,4f,31,99,d2,c9,14,be,cb,ce,\
console_handle:
0x00000037
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
19,75,40,8e,0f,bb,fd,1f,af,29,e9,e5,92,40,35,30,ac,01,11,f8,f2,06,9d,af,30,\
console_handle:
0x0000003b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
bd,7f,42,c3,d6,15,f3,d6,a2,65,17,e9,1f,2a,15,1e,ad
console_handle:
0x0000003f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Security and Maint
console_handle:
0x00000043
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
enance\Checks\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.101]
console_handle:
0x00000043
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Security and Maint
console_handle:
0x00000047
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
enance\Checks\{088E8DFB-2464-4C21-BAD2-F0AA6DB5D4BC}.check.0]
console_handle:
0x00000047
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
"CheckSetting"=hex:23,00,41,00,43,00,42,00,6c,00,6f,00,62,00,00,00,00,00,00,00,
console_handle:
0x0000004b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
01,00,00,00,80,00,00,00,61,70,70,6c,26,ca,50,b3,15,dc,d0,01,01,00,00,00,7b,\
console_handle:
0x0000004f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
00,30,00,38,00,38,00,45,00,38,00,44,00,46,00,42,00,2d,00,32,00,34,00,36,00,\
console_handle:
0x00000053
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
34,00,2d,00,34,00,43,00,32,00,31,00,2d,00,42,00,41,00,44,00,32,00,2d,00,46,\
console_handle:
0x00000057
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
00,30,00,41,00,41,00,36,00,44,00,42,00,35,00,44,00,34,00,42,00,43,00,7d,00,\
console_handle:
0x0000005b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
2e,00,6e,00,6f,00,74,00,69,00,66,00,69,00,63,00,61,00,74,00,69,00,6f,00,6e,\
console_handle:
0x0000005f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
00,2e,00,31,00,00,00,73,68,3a,6e,61,6d,65,3e,40,73,68
console_handle:
0x00000063
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Security and Maint
console_handle:
0x00000067
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
enance\Checks\{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}.check.101]
console_handle:
0x00000067
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Security and Maint
console_handle:
0x0000006b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
enance\Checks\{134EA407-755D-4A93-B8A6-F290CD155023}.check.8001]
console_handle:
0x0000006b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
"CheckSetting"=hex:01,00,00,00,d0,8c,9d,df,01,15,d1,11,8c,7a,00,c0,4f,c2,97,eb,
console_handle:
0x0000006f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
01,00,00,00,c5,b3,6a,e4,0c,03,21,45,ac,98,0c,b7,4e,27,27,e1,00,00,00,00,02,\
console_handle:
0x00000073
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
00,00,00,00,00,10,66,00,00,00,01,00,00,20,00,00,00,20,c1,9f,91,55,f3,43,a3,\
console_handle:
0x00000077
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
4e,1b,3b,9a,91,ec,fa,19,17,cb,45,43,f9,15,4b,ce,6a,c6,aa,b4,63,63,5f,36,00,\
console_handle:
0x0000007b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
00,00,00,0e,80,00,00,00,02,00,00,20,00,00,00,84,22,14,42,cb,c8,72,1f,61,57,\
console_handle:
0x0000007f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
06,0c,34,d9,7e,b9,89,19,34,ab,b6,b9,ee,86,0e,5c,a1,6c,ae,14,08,48,30,00,00,\
console_handle:
0x00000083
|
1
|
1 |
0
|