Техническая информация
- <SYSTEM32>\tasks\gpuukycozfg
- %WINDIR%\tasks\ttxwlyanhitqknu.job
- <SYSTEM32>\tasks\ttxwlyanhitqknu
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\DORqCDMephUn' = '0'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\YXTlNYiNhesucWgmxwR' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\YXTlNYiNhesucWgmxwR' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\tEBwciEeeTWU2' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\tEBwciEeeTWU2' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\tEBwciEeeTWU2' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\zzCFkPQJwPsBC' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\WazeeBRsvIE' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\YXTlNYiNhesucWgmxwR' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\zzCFkPQJwPsBC' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%PROGRAMDATA%\ozuvCoiKxQipFEVB' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\ViNtTJGefsWPC' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%PROGRAMDATA%\ozuvCoiKxQipFEVB' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\ViNtTJGefsWPC' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\DSCUdIANHlLVrqpDH' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\ViNtTJGefsWPC' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\zzCFkPQJwPsBC' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%PROGRAMDATA%\ozuvCoiKxQipFEVB' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\WazeeBRsvIE' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\WazeeBRsvIE' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\LxSngtEsU' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\WazeeBRsvIE' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\YXTlNYiNhesucWgmxwR' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\tEBwciEeeTWU2' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\zzCFkPQJwPsBC' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%PROGRAMDATA%\ozuvCoiKxQipFEVB' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\ViNtTJGefsWPC' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\DSCUdIANHlLVrqpDH' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\LxSngtEsU' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\EzqMTPeUcxhCvtAv' = '0'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\EzqMTPeUcxhCvtAv' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\EzqMTPeUcxhCvtAv' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\DORqCDMephUn' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\DORqCDMephUn' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\DORqCDMephUn' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\LxSngtEsU' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\LxSngtEsU' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\EzqMTPeUcxhCvtAv' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\DSCUdIANHlLVrqpDH' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\DSCUdIANHlLVrqpDH' = '00000000'
- '%WINDIR%\temp\ctdtnwctsprivpou\khshfeesa.exe' /S /UPDATE
- %WINDIR%\temp\ctdtnwctsprivpou\khshfeesa.exe
- %WINDIR%\temp\ezqmtpeucxhcvtav\fcizwchhadssjklw.vbs
- %ProgramFiles(x86)%\lxsngtesu\bpmjzq.dll
- %ProgramFiles(x86)%\dorqcdmephun\rgyfzanbtn.dll
- %WINDIR%\temp\ezqmtpeucxhcvtav\fcizwchhadssjklw.vbs
- <SYSTEM32>\tasks\gpuukycozfg
- %PROGRAMDATA%\ntuser.pol
- %PROGRAMDATA%\tempntuser.pol
- http://www.te###pdate.info/updates/ya/ytab_3/win/version.txt
- http://www.te###pdate.info/updates/ya/ytab_3/win/update_e.jpg
- DNS ASK te###pdate.info
- '%WINDIR%\syswow64\wscript.exe' "%WINDIR%\Temp\EzqMTPeUcxhCvtAv\FCiZWcHHADsSjklW.vbs"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\zzCFkPQJwPsBC" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\zzCFkPQJwPsBC" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\zzCFkPQJwPsBC" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\ozuvCoiKxQipFEVB" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\ozuvCoiKxQipFEVB" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\ozuvCoiKxQipFEVB" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\ozuvCoiKxQipFEVB" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\ViNtTJGefsWPC" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\ViNtTJGefsWPC" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\ViNtTJGefsWPC" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\ViNtTJGefsWPC" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\DSCUdIANHlLVrqpDH" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\DSCUdIANHlLVrqpDH" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\DSCUdIANHlLVrqpDH" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\DSCUdIANHlLVrqpDH" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\EzqMTPeUcxhCvtAv" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\EzqMTPeUcxhCvtAv" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\zzCFkPQJwPsBC" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\EzqMTPeUcxhCvtAv" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\tEBwciEeeTWU2" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\tEBwciEeeTWU2" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DORqCDMephUn" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DORqCDMephUn" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DORqCDMephUn" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DORqCDMephUn" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\LxSngtEsU" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\LxSngtEsU" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\LxSngtEsU" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\LxSngtEsU" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\WazeeBRsvIE" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\WazeeBRsvIE" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\WazeeBRsvIE" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\WazeeBRsvIE" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\YXTlNYiNhesucWgmxwR" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\YXTlNYiNhesucWgmxwR" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\YXTlNYiNhesucWgmxwR" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\YXTlNYiNhesucWgmxwR" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\tEBwciEeeTWU2" /t REG_DWORD /d 0 /reg:32' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\tEBwciEeeTWU2" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\EzqMTPeUcxhCvtAv" /t REG_DWORD /d 0 /reg:64' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\EzqMTPeUcxhCvtAv" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "GJQYLzkwMgBEAgSmnAn"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "zdYLYCNnyRGhLtqHAWg2" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "zdYLYCNnyRGhLtqHAWg2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "zdYLYCNnyRGhLtqHAWg" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "zdYLYCNnyRGhLtqHAWg"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "mFcfVcteWhwXJLMHF2" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "mFcfVcteWhwXJLMHF2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "mFcfVcteWhwXJLMHF" /F
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "GJQYLzkwMgBEAgSmnAn" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "mFcfVcteWhwXJLMHF"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "GrseccuGQFPPOJfRM2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "GrseccuGQFPPOJfRM" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "GrseccuGQFPPOJfRM"
- '<SYSTEM32>\taskeng.exe' {0B93F811-394D-44F6-97D3-C3A84855E7E6} S-1-5-21-1960123792-2022915161-3775307078-1001:zzmihg\user:Interactive:[1]
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "gpuukycozFG" /F
- '%WINDIR%\syswow64\schtasks.exe' /run /tn "gpuukycozFG"
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "gpuukycozFG" /SC once /ST 17:38:04 /F /RU "user" /TR "rundll32 Userenv.dll,RefreshPolicy 1"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\DSCUdIANHlLVrqpDH" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "GrseccuGQFPPOJfRM2" /F
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "FhGKsTjqwlxjgY" /F
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "mIjawppuepyPT2" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "FpBRrqTIZBTkMOW"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "mIjawppuepyPT2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "mIjawppuepyPT" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "mIjawppuepyPT"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "nAygqKKUJCMQx2" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "nAygqKKUJCMQx2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "nAygqKKUJCMQx" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "nAygqKKUJCMQx"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "qiZiFplQVElkeT" /F
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\DSCUdIANHlLVrqpDH" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qiZiFplQVElkeT"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "FhGKsTjqwlxjgY"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "tTxwLyANHITqKNu2" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "tTxwLyANHITqKNu2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "tTxwLyANHITqKNu" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "tTxwLyANHITqKNu"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "FpBRrqTIZBTkMOW2" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "FpBRrqTIZBTkMOW2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "FpBRrqTIZBTkMOW" /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "GJQYLzkwMgBEAgSmnAn2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /TN "GJQYLzkwMgBEAgSmnAn2" /F
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\DSCUdIANHlLVrqpDH" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\YXTlNYiNhesucWgmxwR" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\WazeeBRsvIE" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\WazeeBRsvIE" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\LxSngtEsU" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\LxSngtEsU" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\LxSngtEsU" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\LxSngtEsU" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DORqCDMephUn" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DORqCDMephUn" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\WazeeBRsvIE" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DORqCDMephUn" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\cmd.exe' /C mkdir "%WINDIR%\Temp\EzqMTPeUcxhCvtAv" && copy nul "%WINDIR%\Temp\EzqMTPeUcxhCvtAv\FCiZWcHHADsSjklW.vbs"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\EzqMTPeUcxhCvtAv" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\EzqMTPeUcxhCvtAv" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\EzqMTPeUcxhCvtAv" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\EzqMTPeUcxhCvtAv" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\EzqMTPeUcxhCvtAv" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\EzqMTPeUcxhCvtAv" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\EzqMTPeUcxhCvtAv" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\DORqCDMephUn" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\zzCFkPQJwPsBC" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\ViNtTJGefsWPC" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\YXTlNYiNhesucWgmxwR" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\ViNtTJGefsWPC" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\ViNtTJGefsWPC" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\ViNtTJGefsWPC" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\ozuvCoiKxQipFEVB" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\ozuvCoiKxQipFEVB" /t REG_DWORD /d 0 /reg:64
- '<SYSTEM32>\raserver.exe' /offerraupdate
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\ozuvCoiKxQipFEVB" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\ozuvCoiKxQipFEVB" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\DSCUdIANHlLVrqpDH" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\zzCFkPQJwPsBC" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\zzCFkPQJwPsBC" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\zzCFkPQJwPsBC" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\tEBwciEeeTWU2" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\tEBwciEeeTWU2" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\tEBwciEeeTWU2" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\tEBwciEeeTWU2" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\YXTlNYiNhesucWgmxwR" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\YXTlNYiNhesucWgmxwR" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\WazeeBRsvIE" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TR "rundll32 \"%ProgramFiles(x86)%\LxSngtEsU\BpMJZq.dll\",#1" /RU "SYSTEM" /SC ONLOGON /TN "tTxwLyANHITqKNu" /V1 /F