Technical Information
- [<HKLM>\System\CurrentControlSet\Services\OCS Inventory Service] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\OCS Inventory Service] 'ImagePath' = '"%ProgramFiles%\OCS Inventory Agent\OcsService.exe"'
- 'OCS Inventory Service' "%ProgramFiles%\OCS Inventory Agent\OcsService.exe"
- 'OCS Inventory Service' %ProgramFiles%\OCS Inventory Agent\OcsService.exe
- %TEMP%\ocspackage.log
- %ProgramFiles%\ocs inventory agent\vcruntime140.dll
- %ProgramFiles%\ocs inventory agent\vcomp140.dll
- %ProgramFiles%\ocs inventory agent\vcruntime140_1.dll
- %ProgramFiles%\ocs inventory agent\vcamp140.dll
- %ProgramFiles%\ocs inventory agent\ucrtbase.dll
- %ProgramFiles%\ocs inventory agent\ziparchive.dll
- %ProgramFiles%\ocs inventory agent\zlib1.dll
- %ProgramFiles%\ocs inventory agent\comhttp.dll
- %ProgramFiles%\ocs inventory agent\ocswmi.dll
- %ProgramFiles%\ocs inventory agent\sysinfo.dll
- %ProgramFiles%\ocs inventory agent\ocsinventory front.dll
- %ProgramFiles%\ocs inventory agent\ocsinventory.exe
- %ProgramFiles%\ocs inventory agent\download.exe
- %ProgramFiles%\ocs inventory agent\ocssystray.exe
- %ALLUSERSPROFILE%\ocs inventory ng\agent\sysinfo.log.bak
- %ProgramFiles%\ocs inventory agent\ocsnotifyuser.exe
- %ProgramFiles%\ocs inventory agent\ocs-transform.xsl
- %ProgramFiles%\ocs inventory agent\plugins\saas.ps1
- %ALLUSERSPROFILE%\ocs inventory ng\agent\ocsinventory.log
- %ALLUSERSPROFILE%\ocs inventory ng\agent\ocsinventory.dat
- %ALLUSERSPROFILE%\ocs inventory ng\agent\sysinfo.log
- %ALLUSERSPROFILE%\ocs inventory ng\agent\saas.ps1.xml
- %ALLUSERSPROFILE%\ocs inventory ng\agent\last_state
- %ALLUSERSPROFILE%\ocs inventory ng\agent\download\ocsinventory.ini
- %ALLUSERSPROFILE%\ocs inventory ng\agent\download.log
- %ALLUSERSPROFILE%\ocs inventory ng\agent\rand
- %ALLUSERSPROFILE%\ocs inventory ng\agent\download.log.bak
- %ALLUSERSPROFILE%\ocs inventory ng\agent\ocsinventory.log.bak
- %ProgramFiles%\ocs inventory agent\mfcm140u.dll
- %ProgramFiles%\ocs inventory agent\ocsservice.exe
- %ProgramFiles%\ocs inventory agent\mfcm140.dll
- %TEMP%\nsi7994.tmp\agent.ini
- %TEMP%\nss6e8b.tmp\system.dll
- %TEMP%\nss6e8b.tmp\instocs.exe
- %TEMP%\nss6e8b.tmp\ocssetup.exe
- %TEMP%\nss6e8b.tmp\ocsdata\label
- %TEMP%\nss6e8b.tmp\ocsdat.ini
- %TEMP%\nss6e8b.tmp\userinfo.dll
- %TEMP%\nss7455.tmp\system.dll
- %ALLUSERSPROFILE%\ocs inventory ng\agent\label
- %TEMP%\nss7983.tmp
- %TEMP%\nsi7994.tmp\system.dll
- %TEMP%\nss6e8b.tmp\ocs-windows-agent-setup-x64.log
- %TEMP%\nsi7994.tmp\server.ini
- %TEMP%\nsi7994.tmp\proxy.ini
- %TEMP%\nsi7994.tmp\local.ini
- %ProgramFiles%\ocs inventory agent\mfc140.dll
- %TEMP%\nsi7994.tmp\splash.bmp
- %TEMP%\nsi7994.tmp\setacl.exe
- %TEMP%\nsi7994.tmp\userinfo.dll
- %TEMP%\nsi7994.tmp\nsexec.dll
- %TEMP%\nsi7994.tmp\services.dll
- %TEMP%\nsi7994.tmp\nsprocess.dll
- %TEMP%\nsi7994.tmp\killprocdll.dll
- %ALLUSERSPROFILE%\ocs inventory ng\agent\ocsinventory.ini
- %ProgramFiles%\ocs inventory agent\libcurl.dll
- %ProgramFiles%\ocs inventory agent\libeay32.dll
- %ProgramFiles%\ocs inventory agent\ssleay32.dll
- %ProgramFiles%\ocs inventory agent\msvcp140.dll
- %ProgramFiles%\ocs inventory agent\msvcr120.dll
- %ProgramFiles%\ocs inventory agent\mfc140u.dll
- %ProgramFiles%\ocs inventory agent\uninst.exe
- %ALLUSERSPROFILE%\ocs inventory ng\agent\label
- %TEMP%\nss6e8b.tmp\ocssetup.exe
- %TEMP%\nss6e8b.tmp\ocsdata\label
- %TEMP%\nss6e8b.tmp\ocsdat.ini
- %TEMP%\nss6e8b.tmp\ocs-windows-agent-setup-x64.log
- %TEMP%\nss6e8b.tmp\instocs.exe
- %TEMP%\nss7455.tmp\system.dll
- %TEMP%\nsi7994.tmp\userinfo.dll
- %TEMP%\nsi7994.tmp\system.dll
- %TEMP%\nsi7994.tmp\splash.bmp
- %TEMP%\nsi7994.tmp\setacl.exe
- %TEMP%\nsi7994.tmp\services.dll
- %TEMP%\nsi7994.tmp\server.ini
- %TEMP%\nsi7994.tmp\proxy.ini
- %TEMP%\nsi7994.tmp\nsprocess.dll
- %TEMP%\nsi7994.tmp\nsexec.dll
- %TEMP%\nsi7994.tmp\local.ini
- %TEMP%\nsi7994.tmp\killprocdll.dll
- %TEMP%\nsi7994.tmp\agent.ini
- %ALLUSERSPROFILE%\ocs inventory ng\agent\sysinfo.log
- %ALLUSERSPROFILE%\ocs inventory ng\agent\ocsinventory.log
- %ALLUSERSPROFILE%\ocs inventory ng\agent\download.log
- %ALLUSERSPROFILE%\ocs inventory ng\agent\rand
- %ALLUSERSPROFILE%\ocs inventory ng\agent\saas.ps1.xml
- %TEMP%\nss6e8b.tmp\system.dll
- %TEMP%\nss6e8b.tmp\userinfo.dll
- %ALLUSERSPROFILE%\ocs inventory ng\agent\rand
- %ALLUSERSPROFILE%\ocs inventory ng\agent\ocsinventory.log
- %ALLUSERSPROFILE%\ocs inventory ng\agent\label
- %ALLUSERSPROFILE%\ocs inventory ng\agent\sysinfo.log
- 'in#####ire.progetech.fr':80
- http://in#####ire.progetech.fr/ocsinventory/deploy/label
- http://in#####ire.progetech.fr/ocsinventory
- DNS ASK in#####ire.progetech.fr
- DNS ASK microsoft.com
- '%TEMP%\nss6e8b.tmp\instocs.exe'
- '%TEMP%\nss6e8b.tmp\ocssetup.exe' /SSL=0 /PACKAGER /GPO /SERVER=http://in#####ire.progetech.fr/ocsinventory /S /NOW /NOSPLASH /NO_SYSTRAY /FORCE /DEBUG=2 /HKCU /DEPLOY
- '%ProgramFiles%\ocs inventory agent\ocsinventory.exe' /SAVE_CONF /SERVER=http://in#####ire.progetech.fr/ocsinventory /USER= /PWD= /SSL=0 /CA="cacert.pem" /PROXY_TYPE=0 /PROXY= /PROXY_PORT= /PROXY_USER= /PROXY_PWD= /DEBUG=2 /TAG="" /NO_SYSTRAY
- '%ProgramFiles%\ocs inventory agent\ocsinventory.exe'
- '%ProgramFiles%\ocs inventory agent\download.exe'
- '%ProgramFiles%\ocs inventory agent\ocsservice.exe' -install
- '%ProgramFiles%\ocs inventory agent\ocsservice.exe'
- '%ProgramFiles%\ocs inventory agent\ocsinventory.exe' /SAVE_CONF /SERVER=http://in#####ire.progetech.fr/ocsinventory /USER= /PWD= /SSL=0 /CA="cacert.pem" /PROXY_TYPE=0 /PROXY= /PROXY_PORT= /PROXY_USER= /PROXY_PWD= /DEBUG=2 /TAG="" /NO_SYSTRAY' (with hidden window)
- '%ProgramFiles%\ocs inventory agent\ocsinventory.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Bypass -Command "& {& '%ProgramFiles%\OCS Inventory Agent\plugins\Saas.ps1'; [Environment]::Exit(1)}"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%ProgramFiles%\OCS Inventory Agent\download.exe"' (with hidden window)
- '%ProgramFiles%\ocs inventory agent\ocsservice.exe' -install' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%ProgramFiles%\OCS Inventory Agent\ocsinventory.exe"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Bypass -Command "& {& '%ProgramFiles%\OCS Inventory Agent\plugins\Saas.ps1'; [Environment]::Exit(1)}"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -Command "& {& '%ProgramFiles%\OCS Inventory Agent\plugins\Saas.ps1'; [Environment]::Exit(1)}"
- '<SYSTEM32>\ipconfig.exe' /displaydns
- '<SYSTEM32>\cmd.exe' /c "%ProgramFiles%\OCS Inventory Agent\download.exe"
- '<SYSTEM32>\cmd.exe' /c "%ProgramFiles%\OCS Inventory Agent\ocsinventory.exe"