Technical Information
- [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001] 'PackedCatalogItem' = '{25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,3...
- [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002] 'PackedCatalogItem' = '{25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,3...
- [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003] 'PackedCatalogItem' = '{25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,3...
- [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004] 'PackedCatalogItem' = '{25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,3...
- [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005] 'PackedCatalogItem' = '{25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,3...
- [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006] 'PackedCatalogItem' = '{25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,3...
- [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007] 'PackedCatalogItem' = '{25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,3...
- [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008] 'PackedCatalogItem' = '{25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,3...
- [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009] 'PackedCatalogItem' = '{25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,3...
- [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010] 'PackedCatalogItem' = '{25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,3...
- '<SYSTEM32>\net.exe' stop winmgmt /y
- nul
- %WINDIR%\temp\fwtsqmfile02.sqm
- %WINDIR%\inf\setupapi.dev.log
- %WINDIR%\Prefetch\SETUP.EXE-EA68F294.pf
- %WINDIR%\Prefetch\SETUP.EXE-F9915F9F.pf
- %WINDIR%\Prefetch\SETUPUTILITY.EXE-81395DE3.pf
- %WINDIR%\Prefetch\SETX.EXE-A7E52BF4.pf
- %WINDIR%\Prefetch\SHUTDOWN.EXE-E7D5C9CC.pf
- %WINDIR%\Prefetch\SETUP.EXE-B4850DF7.pf
- %WINDIR%\Prefetch\SETUP.EXE-D498D406.pf
- %WINDIR%\Prefetch\SPPSVC.EXE-B0F8131B.pf
- %WINDIR%\Prefetch\SVCHOST.EXE-007FEA55.pf
- %WINDIR%\Prefetch\SVCHOST.EXE-05F624AB.pf
- %WINDIR%\Prefetch\SVCHOST.EXE-7CFEDEA3.pf
- %WINDIR%\Prefetch\TASKHOST.EXE-7238F31D.pf
- %WINDIR%\Prefetch\THUNDERBIRD SETUP 78.9.1 (X64-07C878F8.pf
- %WINDIR%\Prefetch\STEAMSERVICE.EXE-57E215D3.pf
- %WINDIR%\Prefetch\STEAMSETUP_2.10.91.91.EXE-91D3EED3.pf
- %WINDIR%\Prefetch\SETUP.EXE-7C026C7F.pf
- %WINDIR%\Prefetch\SETUP.EXE-77FE9137.pf
- %WINDIR%\Prefetch\SETUP.EXE-0A445B9B.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-36DAC103.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-7438E4D5.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-860C49A4.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-DB187FD1.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-E6258EDF.pf
- %WINDIR%\Prefetch\RUNONCE.EXE-0E293DD6.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-038E6267.pf
- %WINDIR%\Prefetch\RUNONCE.EXE-D0649312.pf
- %WINDIR%\Prefetch\SEARCHFILTERHOST.EXE-77482212.pf
- %WINDIR%\Prefetch\SEARCHINDEXER.EXE-4A6353B9.pf
- %WINDIR%\Prefetch\SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf
- %WINDIR%\Prefetch\SERVICEMODELREG.EXE-1F42B3E3.pf
- %WINDIR%\Prefetch\SERVICEMODELREG.EXE-AFDDD121.pf
- %WINDIR%\Prefetch\SETUP.EXE-04541C92.pf
- %WINDIR%\Prefetch\SC.EXE-945D79AE.pf
- %WINDIR%\Prefetch\THUNDERBIRD.EXE-5119524C.pf
- %WINDIR%\Prefetch\TRUSTEDINSTALLER.EXE-3CC531E5.pf
- %WINDIR%\Prefetch\TSETUP.1.4.3.EXE-EF3D6F27.pf
- %WINDIR%\Prefetch\TSETUP.1.4.3.TMP-D1AA1547.pf
- %WINDIR%\Prefetch\VC_REDIST.X86.EXE-1DCB7807.pf
- %WINDIR%\Prefetch\VC_REDIST.X86.EXE-35B8AF5D.pf
- %WINDIR%\Prefetch\VC_REDIST.X86.EXE-4DA5E6B3.pf
- %WINDIR%\Prefetch\VC_REDIST.X86.EXE-92EB15BB.pf
- %WINDIR%\Prefetch\VC_REDIST.X86.EXE-D6410970.pf
- %WINDIR%\Prefetch\VC_REDIST.X86.EXE-E8257B7C.pf
- %WINDIR%\Prefetch\VSSVC.EXE-B8AFC319.pf
- %WINDIR%\Prefetch\WERMGR.EXE-0F2AC88C.pf
- %WINDIR%\Prefetch\WEVTUTIL.EXE-400D93E8.pf
- %WINDIR%\Prefetch\WEVTUTIL.EXE-EF5861C4.pf
- %WINDIR%\Prefetch\WINRAR-X64-531.EXE-91D4B934.pf
- %WINDIR%\Prefetch\WMIADAP.EXE-F8DFDFA2.pf
- %WINDIR%\Prefetch\WMIPRVSE.EXE-1628051C.pf
- %WINDIR%\Prefetch\WUAUCLT.EXE-70318591.pf
- %WINDIR%\Prefetch\WUSA.EXE-A8D5906C.pf
- %WINDIR%\Prefetch\VC_REDIST.X86.EXE-1C5672A5.pf
- %WINDIR%\Prefetch\VC_REDIST.X64.EXE-C0CD3F70.pf
- %WINDIR%\Prefetch\VC_REDIST.X64.EXE-D3A3C549.pf
- %WINDIR%\Prefetch\VC_REDIST.X64.EXE-B0C890FD.pf
- %WINDIR%\Prefetch\UNINSTALL.EXE-A11D6B07.pf
- %WINDIR%\Prefetch\UNLODCTR.EXE-531FACC7.pf
- %WINDIR%\Prefetch\UNLODCTR.EXE-A3D4DEEB.pf
- %WINDIR%\Prefetch\UNPACK200.EXE-BB96DA5F.pf
- %WINDIR%\Prefetch\VCREDIST_X64.EXE-24AEA5D8.pf
- %WINDIR%\Prefetch\VCREDIST_X64.EXE-8227A7EF.pf
- %WINDIR%\Prefetch\VCREDIST_X64.EXE-A53F124B.pf
- %WINDIR%\Prefetch\VCREDIST_X86.EXE-163EFD5C.pf
- %WINDIR%\Prefetch\VCREDIST_X86.EXE-73B7FF73.pf
- %WINDIR%\Prefetch\VCREDIST_X86.EXE-96CF69CF.pf
- %WINDIR%\Prefetch\VCREDIST_X86.EXE-C622F3EF.pf
- %WINDIR%\Prefetch\VC_REDIST.X64.EXE-2C3B2083.pf
- %WINDIR%\Prefetch\VC_REDIST.X64.EXE-442857D9.pf
- %WINDIR%\Prefetch\VC_REDIST.X64.EXE-5C158F2F.pf
- %WINDIR%\Prefetch\VC_REDIST.X64.EXE-89C170F2.pf
- %WINDIR%\Prefetch\WUSA.EXE-F04B35C8.pf
- %WINDIR%\Prefetch\REGTLIBV12.EXE-D3A27E55.pf
- %WINDIR%\Prefetch\REGTLIBV12.EXE-B7C4F383.pf
- %WINDIR%\Prefetch\REGSVR32.EXE-8461DBEE.pf
- %WINDIR%\Prefetch\ASPNET_REGIIS.EXE-86915B5A.pf
- %WINDIR%\Prefetch\BCSSYNC.EXE-3F6C64A2.pf
- %WINDIR%\Prefetch\BFSVC.EXE-9C7A4DEE.pf
- %WINDIR%\Prefetch\BSPATCH.EXE-DD9E5E46.pf
- %WINDIR%\Prefetch\CHROME.EXE-5617A1BF.pf
- %WINDIR%\prefetch\agrobust.db
- %WINDIR%\Prefetch\ASPNET_REGIIS.EXE-75651A3C.pf
- %WINDIR%\Prefetch\CLRGC.EXE-5D5B90F5.pf
- %WINDIR%\Prefetch\CONHOST.EXE-1F3E9D7E.pf
- %WINDIR%\Prefetch\DEFAULT-BROWSER-AGENT.EXE-01C82E17.pf
- %WINDIR%\Prefetch\DLLHOST.EXE-5E46FA0D.pf
- %WINDIR%\Prefetch\DLLHOST.EXE-766398D2.pf
- %WINDIR%\Prefetch\DLLHOST.EXE-B2EB1806.pf
- %WINDIR%\Prefetch\CMD.EXE-4A81B364.pf
- %WINDIR%\Prefetch\CMD.EXE-AC113AA8.pf
- %WINDIR%\Prefetch\AgGlGlobalHistory.db
- %WINDIR%\Prefetch\AgGlFgAppHistory.db
- %WINDIR%\Prefetch\AgGlFaultHistory.db
- %WINDIR%\Temp\fwtsqmfile00.sqm
- %WINDIR%\Temp\fwtsqmfile01.sqm
- %WINDIR%\temp\ts_20dd.tmp
- %WINDIR%\temp\ts_235f.tmp
- %WINDIR%\temp\ts_23ec.tmp
- %WINDIR%\temp\ts_2862.tmp
- %WINDIR%\temp\dmi3ddf.tmp
- %WINDIR%\temp\ts_2b9f.tmp
- %WINDIR%\temp\ts_2eed.tmp
- %WINDIR%\temp\ts_3595.tmp
- %WINDIR%\temp\ts_3622.tmp
- %WINDIR%\Prefetch\42.0.2311.135_CHROME_INSTALLE-7FD75326.pf
- %WINDIR%\Prefetch\ACRORDRDC1501020056_EN_US.EXE-3B58C109.pf
- %WINDIR%\Prefetch\AgAppLaunch.db
- %WINDIR%\temp\ts_2da4.tmp
- %WINDIR%\Prefetch\DOTNETFX35.EXE-852DD91F.pf
- %WINDIR%\Prefetch\DOTNETFX35SETUP.EXE-506819A6.pf
- %WINDIR%\Prefetch\DOTNETFX40_FULL_X86_X64.EXE-D34AC1BF.pf
- %WINDIR%\Prefetch\DRVINST.EXE-4CB4314A.pf
- %WINDIR%\Prefetch\MSIEXEC.EXE-A2D55CB6.pf
- %WINDIR%\Prefetch\MSIEXEC.EXE-E09A077A.pf
- %WINDIR%\Prefetch\NDP48-X86-X64-ALLOS-ENU.EXE-54656820.pf
- %WINDIR%\Prefetch\NETSH.EXE-F1B6DA12.pf
- %WINDIR%\Prefetch\NGEN.EXE-AE594A6B.pf
- %WINDIR%\Prefetch\NGEN.EXE-EC3F9239.pf
- %WINDIR%\Prefetch\NTOSBOOT-B00DFAAD.pf
- %WINDIR%\Prefetch\OPERA_29.0.1795.47_SETUP.EXE-839F60FD.pf
- %WINDIR%\Prefetch\OPERA_29.0.1795.47_SETUP.EXE-9C628850.pf
- %WINDIR%\Prefetch\OSE.EXE-51C16F0E.pf
- %WINDIR%\Prefetch\OSE00000.EXE-2A4EFDBF.pf
- %WINDIR%\Prefetch\PfSvPerfStats.bin
- %WINDIR%\Prefetch\PING.EXE-7E94E73E.pf
- %WINDIR%\Prefetch\RDRSERVICESUPDATER.EXE-3D26E665.pf
- %WINDIR%\Prefetch\ReadyBoot\Trace1.fx
- %WINDIR%\Prefetch\MSCORSVW.EXE-C3C515BD.pf
- %WINDIR%\Prefetch\MSCORSVW.EXE-57D17DAF.pf
- %WINDIR%\Prefetch\MSCORSVW.EXE-90526FAC.pf
- %WINDIR%\Prefetch\MSCORSVW.EXE-245ED79E.pf
- %WINDIR%\Prefetch\FIREFOX SETUP 78.0.2 (X64).EX-D6C4EFE8.pf
- %WINDIR%\Prefetch\FIREFOX.EXE-A606B53C.pf
- %WINDIR%\Prefetch\IE4UINIT.EXE-8B333E8B.pf
- %WINDIR%\Prefetch\INSTALL.EXE-3B270E29.pf
- %WINDIR%\Prefetch\INSTALLER.EXE-58BA519F.pf
- %WINDIR%\Prefetch\INSTALLER.EXE-6C3AB888.pf
- %WINDIR%\Prefetch\JAUREG.EXE-2358F266.pf
- %WINDIR%\Prefetch\JAVAW.EXE-DCCF0AB8.pf
- %WINDIR%\Prefetch\JAVAWS.EXE-ED58C697.pf
- %WINDIR%\Prefetch\JP2LAUNCHER.EXE-7DCCD1B9.pf
- %WINDIR%\Prefetch\JRE-8U45-WINDOWS-X64.EXE-61CC34B3.pf
- %WINDIR%\Prefetch\LODCTR.EXE-3CCE0534.pf
- %WINDIR%\Prefetch\LODCTR.EXE-72CD50D0.pf
- %WINDIR%\Prefetch\MOFCOMP.EXE-8FE3D558.pf
- %WINDIR%\Prefetch\MOFCOMP.EXE-FDE76EFC.pf
- %WINDIR%\Prefetch\ReadyBoot\Trace2.fx
- %WINDIR%\Prefetch\XCOPY.EXE-41E6513F.pf
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName /v ComputerName /t REG_SZ /d %Random% /f >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /CSK "Default string" >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /CM "Default string" >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /SP "MS-7D22" >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /SM "Micro-Star International Co., Ltd." >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /SK "Default string" >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /SF "Default string" >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /BM "Micro-Star International Co., Ltd." >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\Disk1.exe F: D93D-3309
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /BP "H510M-A PRO (MS-7D22)" >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /BT "Default string" >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /BLC "Default string" >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /PSN "To Be Filled By O.E.M." >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /PAT "To Be Filled By O.E.M." >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /PPN "To Be Filled By O.E.M." >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /CS "Default string" >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /CV "1.0" >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /SS "Default string" >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /SV "1.0" >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /SU AUTO >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\Disk1.exe E: 37C4-6081
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /CA "Default string" >nul
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\CurrentControlSet\Services\mssmbios\Data /v AcpiData /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\CurrentControlSet\Services\mssmbios\Data /v BiosData /f
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\CurrentControlSet\Services\mssmbios\Data /v BiosData /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\CurrentControlSet\Services\mssmbios\Data /v RegistersData /f
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\CurrentControlSet\Services\mssmbios\Data /v RegistersData /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\CurrentControlSet\Services\mssmbios\Data /v SMBiosData /f
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /CM "Micro-Star International Co., Ltd." >nul
- '<SYSTEM32>\reg.exe' DELETE HKLM\SOFTWARE\Microsoft\Dfrg\Statistics /f
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /BV "1.0" >nul
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\CurrentControlSet\Services\mssmbios\Data /v SMBiosData /f
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet001\Services\BEService /f
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet001\Services\BEService /f
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\Mac.bat >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\Disk1.exe C: 4023-372A
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\Disk1.exe D: F316-3FBA
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\0 /f
- '<SYSTEM32>\reg.exe' DELETE HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\0 /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SYSTEM\Software\Microsoft /v BuildLabEx /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /CO "0000 0000h" >nul
- '<SYSTEM32>\cmd.exe' /c powershell vssadmin delete shadows /all >nul
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' vssadmin delete shadows /all
- '<SYSTEM32>\cmd.exe' /c powershell Reset-PhysicalDisk * >nul
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Reset-PhysicalDisk *
- '<SYSTEM32>\cmd.exe' /c fsutil usn deletejournal /n C: >nul
- '<SYSTEM32>\fsutil.exe' usn deletejournal /n C
- '<SYSTEM32>\cmd.exe' /c fsutil usn deletejournal /n D: >nul
- '<SYSTEM32>\fsutil.exe' usn deletejournal /n D
- '<SYSTEM32>\netsh.exe' winsock reset
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SOFTWARE\Microsoft\Dfrg\Statistics /f
- '<SYSTEM32>\cmd.exe' /c netsh winsock reset >nul
- '<SYSTEM32>\fsutil.exe' usn deletejournal /n F
- '<SYSTEM32>\cmd.exe' /c del /s /f /q <SYSTEM32>\restore\MachineGuid.txt >nul
- '<SYSTEM32>\cmd.exe' /c del /s /f /q C:\System Volume Information\IndexerVolumeGuid >nul
- '<SYSTEM32>\cmd.exe' /c del /s /f /q C:\System Volume Information\tracking.log >nul
- '<SYSTEM32>\cmd.exe' /c del /s /f /q %WINDIR%\INF\setupapi.dev.log >nul
- '<SYSTEM32>\cmd.exe' /c del /s /f /q %WINDIR%\INF\setupapi.setup.log >nul
- '<SYSTEM32>\cmd.exe' /c rmdir /s /q %WINDIR%\temp >nul
- '<SYSTEM32>\fsutil.exe' usn deletejournal /n E
- '<SYSTEM32>\cmd.exe' /c fsutil usn deletejournal /n E: >nul
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\CurrentControlSet\Services\mssmbios\Data /v AcpiData /f
- '<SYSTEM32>\cmd.exe' /c netsh int ipv6 reset >nul
- '<SYSTEM32>\net.exe' start winmgmt /y
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /IVN "American Megatrends International, LLC." >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /BS %random%%random%%random%%random% >nul
- '<SYSTEM32>\cmd.exe' /c sc stop winmgmt >nul
- '<SYSTEM32>\sc.exe' stop winmgmt
- '<SYSTEM32>\cmd.exe' /c sc start winmgmt >nul
- '<SYSTEM32>\sc.exe' start winmgmt
- '<SYSTEM32>\cmd.exe' /c net stop winmgmt /y >nul
- '<SYSTEM32>\netsh.exe' int ipv6 reset
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /CT "03h" >nul
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\GameBarPresenceWriter\2.exe /IV "3.80" >nul
- '<SYSTEM32>\net1.exe' start winmgmt /y
- '<SYSTEM32>\cmd.exe' /c ipconfig /flushdns >nul
- '<SYSTEM32>\ipconfig.exe' /flushdns
- '<SYSTEM32>\cmd.exe' /c netsh int reset all >nul
- '<SYSTEM32>\netsh.exe' int reset all
- '<SYSTEM32>\cmd.exe' /c netsh int ipv4 reset >nul
- '<SYSTEM32>\netsh.exe' int ipv4 reset
- '<SYSTEM32>\cmd.exe' /c net start winmgmt /y >nul
- '<SYSTEM32>\net1.exe' stop winmgmt /y
- '<SYSTEM32>\reg.exe' DELETE HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket /v LastEnum /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket /v LastEnum /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global /v ClientUUID /t REG_SZ /d 15623401-194298517-203515999 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global /v PersistenceIdentifier /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global /v PersistenceIdentifier /t REG_SZ /d 15623401-194298517-203515999 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global\CoProcManager /v ChipsetMatchID /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global\CoProcManager /v ChipsetMatchID /t REG_SZ /d 1562611149-452532581-306659926 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi" "Port" "0\Scsi" "Bus" "0\Target" "Id" "0\Logical" "Unit" "Id" "0 /v Identifier /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SYSTEM\HardwareConfig /v LastConfig /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\SQMClient /v MachineId /t REG_SZ /d {%Random%%Random%-%Random%%Random%-%Random%%Random%} /f >nul
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\NVIDIA" "Corporation\Global /v ClientUUID /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi" "Port" "0\Scsi" "Bus" "0\Target" "Id" "0\Logical" "Unit" "Id" "0 /v Identifier /t REG_SZ /d 1562611149-452532581-306659926 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\0 /v Identifier /t REG_SZ /d 1562921898-2238923876-821213852 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\1 /v Identifier /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\1 /v Identifier /t REG_SZ /d 1562921898-2238923876-821213852 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SYSTEM\ControlSet001\Services\BasicDisplay\Video /v VideoID /t REG_SZ /d {%Random%%Random%-%Random%%Random%-%Random%%Random%} /f >nul
- '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\ControlSet001\Services\BasicDisplay\Video /v VideoID /t REG_SZ /d {1562921898-2238923876-821213852} /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v Hostname /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f >nul
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi" "Port" "1\Scsi" "Bus" "0\Target" "Id" "0\Logical" "Unit" "Id" "0 /v Identifier /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi" "Port" "1\Scsi" "Bus" "0\Target" "Id" "0\Logical" "Unit" "Id" "0 /v Identifier /t REG_SZ /d 1562611149-452532581-306659926 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\HARDWARE\DESCRIPTION\System\MultifunctionAdapter\0\DiskController\0\DiskPeripheral\0 /v Identifier /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\cmd.exe' /c rmdir /s /q C:\Users\%username%\AppData\Local\Temp >nul
- '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v Hostname /t REG_SZ /d 1563332646-748515171-1852717779 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d 1562022420-156417222-100362072 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName /v ComputerName /t REG_SZ /d %Random% /f >nul
- '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName /v ComputerName /t REG_SZ /d 15610 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {%Random%%Random%-%Random%%Random%-%Random%%Random%} /f >nul
- '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareId /t REG_SZ /d {1561022943-1350810568-1186123060} /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareIds /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\SystemInformation /v ComputerHardwareIds /t REG_SZ /d 15613924-313721863-2217526987 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v HwProfileGuid /t REG_SZ /d {%Random%%Random%-%Random%%Random%-%Random%%Random%} /f >nul
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f >nul
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Cryptography /v GUID /t REG_SZ /d 1562022420-156417222-100362072 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\IDConfigDB\Hardware" "Profiles\0001 /v HwProfileGuid /t REG_SZ /d {15613924-313721863-2217526987} /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\SQMClient /v WinSqmFirstSessionStartTime /t REG_QWORD /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\SQMClient /v WinSqmFirstSessionStartTime /t REG_QWORD /d 1561611672-1646825927-3249030913 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallTime /t REG_QWORD /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallTime /t REG_QWORD /d 1561611672-1646825927-3249030913 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallDate /t REG_QWORD /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v InstallDate /t REG_QWORD /d 1562022420-156417222-100362072 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f >nul
- '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName /v ComputerName /t REG_SZ /d 15610 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\SQMClient /v MachineId /t REG_SZ /d {1561611672-1646825927-3249030913} /f
- '<SYSTEM32>\cmd.exe' /c fsutil usn deletejournal /n F: >nul
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\Tcpip\Parameters /v Domain /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f >nul
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Control\DevQuery\6 /v UUID /t REG_SZ /d1563610626-253496466-2884121706 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildBranch /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildBranch /t REG_SZ /d 1564920852-312704416-45634645 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v DigitalProductId /t REG_BINARY /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v DigitalProductId /t REG_BINARY /d 1564920852-312704416-45634645 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v DigitalProductId4 /t REG_BINARY /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v DigitalProductId4 /t REG_BINARY /d 1565231600-1636628479-148788571 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SYSTEM\ControlSet001\Services\kbdclass\Parameters /v WppRecorder_TraceGuid /t REG_SZ /d {%Random%%Random%-%Random%%Random%-%Random%%Random%} /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\Tcpip\Parameters /v Domain /t REG_SZ /d 1563332646-748515171-1852717779 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOrganization /t REG_SZ /d 1564920852-312704416-45634645 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOrganization /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\MountedDevices /f
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\MountedDevices /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\ControlSet001\Services\kbdclass\Parameters /v WppRecorder_TraceGuid /t REG_SZ /d {1565231600-1636628479-148788571} /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\ControlSet001\Services\mouhid\Parameters /v WppRecorder_TraceGuid /t REG_SZ /d {1565231600-1636628479-148788571} /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\System\CurrentControlSet\Control\DevQuery\6 /v UUID /t REG_SZ /d%Random%%Random%-%Random%%Random%-%Random%%Random% /f >nul
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SYSTEM\ControlSet001\Services\mouhid\Parameters /v WppRecorder_TraceGuid /t REG_SZ /d {%Random%%Random%-%Random%%Random%-%Random%%Random%} /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\HardwareConfig /v LastConfig /t REG_SZ /d 15623401-194298517-203515999 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v NV" "Hostname /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters /v NV" "Hostname /t REG_SZ /d 1563610626-253496466-2884121706 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v ProductId /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f >nul
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v ProductId /t REG_SZ /d 1563610626-253496466-2884121706 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f >nul
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v BuildGUID /t REG_SZ /d 1563921375-1044530530-638825633 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SYSTEM\Software\Microsoft /v BuildLab /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\Tracing\Microsoft\Profile\Profile /v Guid /t REG_SZ /d 1564610104-1340613120-27017718 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOwner /t REG_SZ /d 1564610104-1340613120-27017718 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion /v RegisteredOwner /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v AccountDomainSid /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v AccountDomainSid /t REG_SZ /d 1564332123-2831021825-1670229559 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v PingID /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v PingID /t REG_SZ /d 1564332123-2831021825-1670229559 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientId /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientId /t REG_SZ /d 1564332123-2831021825-1670229559 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\SOFTWARE\Microsoft\Windows" "NT\CurrentVersion\Tracing\Microsoft\Profile\Profile /v Guid /t REG_SZ /d %Random%%Random%-%Random%%Random%-%Random%%Random% /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\Software\Microsoft /v BuildLab /t REG_SZ /d 1563921375-1044530530-638825633 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SYSTEM\Software\Microsoft /v BuildLabEx /t REG_SZ /d 1563921375-1044530530-638825633 /f
- '<SYSTEM32>\cmd.exe' /c rmdir /s /q %WINDIR%\Prefetch >nul