WriteConsoleW
|
buffer:
Get-Process : Cannot find a process with the name "sysupdate". Verify the proce
console_handle:
0x00000023
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ss name and call the cmdlet again.
console_handle:
0x0000002f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\1.ps1:18 char:16
console_handle:
0x0000003b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ Get-Process <<<< -Name $proc_name | Stop-Process
console_handle:
0x00000047
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : ObjectNotFound: (sysupdate:String) [Get-Process]
console_handle:
0x00000053
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
, ProcessCommandException
console_handle:
0x0000005f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : NoProcessFoundForGivenName,Microsoft.PowerShell.
console_handle:
0x0000006b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Commands.GetProcessCommand
console_handle:
0x00000077
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Remove-Item : Cannot find path 'C:\Users\test22\AppData\Local\Temp\sysupdate.ex
console_handle:
0x00000097
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
e' because it does not exist.
console_handle:
0x000000a3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\1.ps1:19 char:16
console_handle:
0x000000af
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ Remove-Item <<<< $path
console_handle:
0x000000bb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : ObjectNotFound: (C:\Users\test22...p\sysupdate.e
console_handle:
0x000000c7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
xe:String) [Remove-Item], ItemNotFoundException
console_handle:
0x000000d3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.Remov
console_handle:
0x000000df
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
eItemCommand
console_handle:
0x000000eb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Get-Process : Cannot find a process with the name "config.json". Verify the pro
console_handle:
0x00000023
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
cess name and call the cmdlet again.
console_handle:
0x0000002f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\1.ps1:18 char:16
console_handle:
0x0000003b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ Get-Process <<<< -Name $proc_name | Stop-Process
console_handle:
0x00000047
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : ObjectNotFound: (config.json:String) [Get-Proces
console_handle:
0x00000053
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
s], ProcessCommandException
console_handle:
0x0000005f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : NoProcessFoundForGivenName,Microsoft.PowerShell.
console_handle:
0x0000006b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Commands.GetProcessCommand
console_handle:
0x00000077
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Remove-Item : Cannot find path 'C:\Users\test22\AppData\Local\Temp\config.json'
console_handle:
0x00000097
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
because it does not exist.
console_handle:
0x000000a3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\1.ps1:19 char:16
console_handle:
0x000000af
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ Remove-Item <<<< $path
console_handle:
0x000000bb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : ObjectNotFound: (C:\Users\test22...emp\config.js
console_handle:
0x000000c7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
on:String) [Remove-Item], ItemNotFoundException
console_handle:
0x000000d3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.Remov
console_handle:
0x000000df
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
eItemCommand
console_handle:
0x000000eb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Remove-Item : Cannot find path 'C:\Users\test22\AppData\Local\Temp\update.ps1'
console_handle:
0x0000010b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
because it does not exist.
console_handle:
0x00000117
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\1.ps1:56 char:12
console_handle:
0x00000123
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ Remove-Item <<<< $payload_path
console_handle:
0x0000012f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : ObjectNotFound: (C:\Users\test22...Temp\update.p
console_handle:
0x0000013b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
s1:String) [Remove-Item], ItemNotFoundException
console_handle:
0x00000147
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.Remov
console_handle:
0x00000153
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
eItemCommand
console_handle:
0x0000015f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Remove-Item : Cannot find path 'C:\Users\test22\update.ps1' because it does not
console_handle:
0x0000017f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
exist.
console_handle:
0x0000018b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\1.ps1:57 char:12
console_handle:
0x00000197
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ Remove-Item <<<< $HOME\update.ps1
console_handle:
0x000001a3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : ObjectNotFound: (C:\Users\test22\update.ps1:Stri
console_handle:
0x000001af
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ng) [Remove-Item], ItemNotFoundException
console_handle:
0x000001bb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.Remov
console_handle:
0x000001c7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
eItemCommand
console_handle:
0x000001d3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
download with backurl
console_handle:
0x000001e3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Exception calling "DownloadFile" with "2" argument(s): "Value cannot be null.
console_handle:
0x000001f7
|
1
|
1 |
0
|