Technical Information
- <SYSTEM32>\tasks\microsoft\windows\autochk\proxy
- <SYSTEM32>\tasks\microsoft\windows\location\notifications
- User Account Control (UAC)
- '<SYSTEM32>\taskkill.exe' /f /im OneDrive.exe
- %TEMP%\c89b.tmp\c89c.bat
- nul
- %TEMP%\~import.reg
- %HOMEPATH%\desktop\remove_3dprint_context.reg
- %TEMP%\~import.reg
- %HOMEPATH%\desktop\remove_3dprint_context.reg
- %TEMP%\~import.reg
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\C89B.tmp\C89C.bat <Full path to file>"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\C89B.tmp\C89C.bat <Full path to file>"
- '<SYSTEM32>\find.exe' /C /I "choice.microsoft.com.nstac.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "settings-win.data.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "vortex-bn2.metron.live.com.nsatc.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "vortex-cy2.metron.live.com.nsatc.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "a.ads1.msn.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "a.ads2.msads.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "ac3.msn.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "feedback.search.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "feedback.microsoft-hohm.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "a-0004.a-msedge.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "a-0005.a-msedge.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "a-0006.a-msedge.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "a-0007.a-msedge.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "a-0008.a-msedge.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "a-0009.a-msedge.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "a.ads2.msn.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "a-0002.a-msedge.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "settings-sandbox.data.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "a.rad.msn.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "a-0001.a-msedge.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "watson.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "survey.watson.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "watson.live.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "statsfe2.ws.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "corpext.msitadfs.glbdns2.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "compatexchange.cloudapp.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "i1.services.social.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "feedback.windows.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "i1.services.social.microsoft.com.nsatc.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "statsfe2.update.microsoft.com.akadns.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "sls.update.microsoft.com.akadns.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "diagnostics.support.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "corp.sts.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "statsfe1.ws.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "pre.footprintpredict.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "cs1.wpc.v0cdn.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "fe2.update.microsoft.com.akadns.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "vortex-sandbox.data.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "ad.doubleclick.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "ads1.msn.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "m.adnxs.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "m.hotmail.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "msedge.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "msftncsi.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "msnbot-65-55-108-23.search.msn.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "msntest.serving-sys.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "lb1.www.ms.##adns.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "live.rads.msn.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "pricelist.skype.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "s0.2mdn.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "schemas.microsoft.akadns.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "secure.adnxs.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "secure.flashtalking.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "static.2mdn.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "view.atdmt.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "rad.live.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "s.gateway.messenger.live.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "ads.msn.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "adnexus.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "flex.msn.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "aidps.atdmt.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "aka-cdn-ns.adtech.de" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "a-msedge.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "apps.skype.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "b.ads1.msn.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "g.msn.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "ads1.msads.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "h1.msn.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "b.ads2.msads.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "c.msn.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "cdn.atdmt.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "cds26.ams9.msecn.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "db3aqu.atdmt.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "ec.atdmt.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "b.rad.msn.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "bs.serving-sys.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "c.atdmt.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "telemetry.appex.bing.net:443" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "telemetry.urs.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "telemetry.appex.bing.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\PushToInstall\Registration" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\PushToInstall\LoginCheck" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Feedback\Siuf\DmClient" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\InstallService\ScanForUpdates" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Location\WindowsActionDialog" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Location\Notifications" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\InstallService\WakeUpAndScanForUpdates" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "MicrosoftEdgeUpdateTaskMachineCore" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "MicrosoftEdgeUpdateTaskMachineUA" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Maps\MapsUpdateTask" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\User Profile Service\HiveUploadTask" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Windows Error Reporting\QueueReporting" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\InstallService\SmartRetry" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\InstallService\ScanForUpdatesAsUser" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\InstallService\WakeUpAndContinueUpdates" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Windows Defender\Windows Defender Verification" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip" /Disable
- '%WINDIR%\regedit.exe' /S "%TEMP%\~import.reg"
- '<SYSTEM32>\timeout.exe' /t 1
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser" /Disable
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Application Experience\PcaPatchDbTask" /Disable
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Application Experience\ProgramDataUpdater" /Disable
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Application Experience\StartupAppTask" /Disable
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\RetailDemo\CleanupOfflineContent" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval" /DISABLE
- '<SYSTEM32>\openfiles.exe'
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector" /Disable
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver" /Disable
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Maintenance\WinSAT" /Disable
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Customer Experience Improvement Program\Consolidator" /Disable
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Autochk\Proxy" /Disable
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\Maps\MapsToastTask" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\UpdateOrchestrator\Reboot_AC" /DISABLE
- '<SYSTEM32>\find.exe' /C /I "telecommand.telemetry.microsoft.com.nsatc.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "oca.telemetry.microsoft.com.nsatc.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "sqm.telemetry.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "sqm.telemetry.microsoft.com.nsatc.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "watson.telemetry.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "watson.telemetry.microsoft.com.nsatc.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "telecommand.telemetry.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "vortex.data.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "oca.telemetry.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "redir.metaservices.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "wes.df.telemetry.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "reports.wes.df.telemetry.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "services.wes.df.telemetry.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "sqm.df.telemetry.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "watson.ppe.telemetry.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "choice.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "choice.microsoft.com.nsatc.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "df.telemetry.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "vortex-win.data.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "telemetry.microsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery" /DISABLE
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\UNP\RunUpdateNotificationMgr" /DISABLE
- '<SYSTEM32>\reg.exe' DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{088e3905-0323-4b02-9826-5d99428e115f}" /f
- '<SYSTEM32>\reg.exe' DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{1CF1260C-4DD0-4ebb-811F-33C572699FDE}" /f
- '<SYSTEM32>\reg.exe' DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{24ad3ad4-a569-4530-98e1-ab02f9417aa8}" /f
- '<SYSTEM32>\reg.exe' DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{374DE290-123F-4565-9164-39C4925E467B}" /f
- '<SYSTEM32>\reg.exe' DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA}" /f
- '<SYSTEM32>\reg.exe' DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{3dfdf296-dbec-4fb4-81d1-6a3438bcf4de}" /f
- '<SYSTEM32>\schtasks.exe' /change /TN "\Microsoft\Windows\WindowsUpdate\Scheduled Start" /DISABLE
- '<SYSTEM32>\reg.exe' DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{A0953C92-50DC-43bf-BE83-3742FED03C9C}" /f
- '<SYSTEM32>\reg.exe' DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}" /f
- '<SYSTEM32>\reg.exe' DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{d3162b92-9365-467a-956b-92703aca08af}" /f
- '<SYSTEM32>\reg.exe' DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{f86fa3ab-70d2-4fc7-9c99-fcbf05467f3a}" /f
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 5
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 8
- '<SYSTEM32>\reg.exe' DELETE "HKEY_CLASSES_ROOT\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}" /f
- '<SYSTEM32>\reg.exe' DELETE "HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}" /f
- '<SYSTEM32>\reg.exe' DELETE "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}" /f
- '%WINDIR%\regedit.exe' /s "%HOMEPATH%\Desktop\remove_3dprint_context.reg"
- '<SYSTEM32>\timeout.exe' /t 5