Техническая информация
- <SYSTEM32>\tasks\gfmkfqjkk
- %WINDIR%\tasks\bguvhccqtxqwxjc.job
- <SYSTEM32>\tasks\bguvhccqtxqwxjc
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\AaavntqHU' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\AaavntqHU' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\GCCewQuGoIE' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\GCCewQuGoIE' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\IBOeaiVJaQNeushXXNR' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\IBOeaiVJaQNeushXXNR' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\RQlLCJGgNJhU2' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\dzeaLDZKMHCxtpiUO' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\AaavntqHU' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\RQlLCJGgNJhU2' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\cufjJoOUspeIC' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\cufjJoOUspeIC' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ALLUSERSPROFILE%\smWEKOSdLiGSaNVB' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ALLUSERSPROFILE%\smWEKOSdLiGSaNVB' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\zqfhnbqOWhQDs' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\zqfhnbqOWhQDs' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\VVPByIQdrCUn' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\VVPByIQdrCUn' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\zqfhnbqOWhQDs' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ALLUSERSPROFILE%\smWEKOSdLiGSaNVB' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\cufjJoOUspeIC' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\IBOeaiVJaQNeushXXNR' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\RQlLCJGgNJhU2' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\VVPByIQdrCUn' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\cufjJoOUspeIC' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ALLUSERSPROFILE%\smWEKOSdLiGSaNVB' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\zqfhnbqOWhQDs' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\dzeaLDZKMHCxtpiUO' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\GCCewQuGoIE' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\SlydqQJkrlmQBxer' = '0'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\SlydqQJkrlmQBxer' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\SlydqQJkrlmQBxer' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\AaavntqHU' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\GCCewQuGoIE' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\IBOeaiVJaQNeushXXNR' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\RQlLCJGgNJhU2' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\VVPByIQdrCUn' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\SlydqQJkrlmQBxer' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\dzeaLDZKMHCxtpiUO' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\dzeaLDZKMHCxtpiUO' = '00000000'
- %WINDIR%\temp\slydqqjkrlmqbxer\vvycnrhf\lxifwtvamcyuphas.wsf
- %ProgramFiles(x86)%\aaavntqhu\iekzea.dll
- <SYSTEM32>\tasks\gfmkfqjkk
- %WINDIR%\temp\slydqqjkrlmqbxer\vvycnrhf\lxifwtvamcyuphas.wsf
- %ALLUSERSPROFILE%\ntuser.pol
- %HOMEPATH%\ntuser.pol
- '%WINDIR%\syswow64\wscript.exe' "%WINDIR%\Temp\SlydqQJkrlmQBxer\VVycnRhf\LXIFwTVamcyuPHAS.wsf"
- '<SYSTEM32>\gpupdate.exe' /force' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -EncodedCommand cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIABnAHAAdQBwAGQAYQB0AGUALgBlAHgAZQAgAC8AZgBvAHIAYwBlAA==' (со скрытым окном)
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "gFMkfQJKk" /SC once /ST 02:29:38 /F /RU "user" /TR "powershell -WindowStyle Hidden -EncodedCommand cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZ...
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TR "rundll32 \"%ProgramFiles(x86)%\AaavntqHU\iEkZeA.dll\",#1" /RU "SYSTEM" /SC ONLOGON /TN "BgUVhCCQtXQWXjc" /V1 /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "JTIdRkBQBzAnfAu"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "JTIdRkBQBzAnfAu"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "JTIdRkBQBzAnfAu2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "JTIdRkBQBzAnfAu2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "mNQxwWwwMbWdlKd"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "mNQxwWwwMbWdlKd"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "TNgDDIIVToIGXNR"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "mNQxwWwwMbWdlKd2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "PxzTnHvNZZrARoI"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "PxzTnHvNZZrARoI"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "PxzTnHvNZZrARoI2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "PxzTnHvNZZrARoI2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BnUDMHVemBvEUfF"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BnUDMHVemBvEUfF"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BnUDMHVemBvEUfF2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "MmoQqqWIeyoMSYJuQzf2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "MmoQqqWIeyoMSYJuQzf2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "mNQxwWwwMbWdlKd2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BnUDMHVemBvEUfF2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "CGxxCVoDCZotubRKLwR2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "xAoBytsqYTCZquMHCHO"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "xAoBytsqYTCZquMHCHO"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "xAoBytsqYTCZquMHCHO2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "xAoBytsqYTCZquMHCHO2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "PPgouSZKhhbokpnohSH"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "PPgouSZKhhbokpnohSH"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "PPgouSZKhhbokpnohSH2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "PPgouSZKhhbokpnohSH2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "GQgazEIzGUGJOZGIMhC"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "GQgazEIzGUGJOZGIMhC"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "GQgazEIzGUGJOZGIMhC2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "GQgazEIzGUGJOZGIMhC2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "CGxxCVoDCZotubRKLwR"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "CGxxCVoDCZotubRKLwR"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "CGxxCVoDCZotubRKLwR2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "MmoQqqWIeyoMSYJuQzf"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "LZgTwtlRaTVtWXcRhiM2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "MmoQqqWIeyoMSYJuQzf"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "fCZWDhtewbKGfmYyc"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "TNgDDIIVToIGXNR"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "eZXdVaWusKJEH"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "eZXdVaWusKJEH2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "NrPntGMabYTvI"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "NrPntGMabYTvI"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "NrPntGMabYTvI2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "NrPntGMabYTvI2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qxSVTIIqATCBX"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "qxSVTIIqATCBX"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "TNgDDIIVToIGXNR2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qxSVTIIqATCBX2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "FQYYBuVWtnosI"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "FQYYBuVWtnosI"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "FQYYBuVWtnosI2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "FQYYBuVWtnosI2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "UbakGstaoNGBT"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "UbakGstaoNGBT"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "eZXdVaWusKJEH"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "QXvIfWwobcdOc2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "eZXdVaWusKJEH2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "QXvIfWwobcdOc2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "QXvIfWwobcdOc"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "TNgDDIIVToIGXNR2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "SNebaMeMmgDOeyB"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "SNebaMeMmgDOeyB2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "SNebaMeMmgDOeyB2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "TtqYqQdLuVIeHH"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "TtqYqQdLuVIeHH"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "YDzqBOZZgJWtiz"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "LZgTwtlRaTVtWXcRhiM"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "YDzqBOZZgJWtiz"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "LZgTwtlRaTVtWXcRhiM2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ztevstSteaamso"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "xcUuTsKowokViP"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "gyGMQlIHRLUEfy"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "gyGMQlIHRLUEfy"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "EhNfIIHOJNdJfE"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "EhNfIIHOJNdJfE"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "QXvIfWwobcdOc"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ztevstSteaamso"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "SNebaMeMmgDOeyB"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "xcUuTsKowokViP"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "LZgTwtlRaTVtWXcRhiM"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "wGeREkCGxqMQeeNNoyX2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "wGeREkCGxqMQeeNNoyX2"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\VVPByIQdrCUn" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\cufjJoOUspeIC" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\cufjJoOUspeIC" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ALLUSERSPROFILE%\smWEKOSdLiGSaNVB" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ALLUSERSPROFILE%\smWEKOSdLiGSaNVB" /t REG_DWORD /d 0 /reg:64
- '<SYSTEM32>\raserver.exe' /offerraupdate
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\zqfhnbqOWhQDs" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\zqfhnbqOWhQDs" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\dzeaLDZKMHCxtpiUO" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\dzeaLDZKMHCxtpiUO" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\AaavntqHU" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\AaavntqHU" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\GCCewQuGoIE" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\GCCewQuGoIE" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\IBOeaiVJaQNeushXXNR" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\RQlLCJGgNJhU2" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\IBOeaiVJaQNeushXXNR" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\VVPByIQdrCUn" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\IBOeaiVJaQNeushXXNR" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\GCCewQuGoIE" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\SlydqQJkrlmQBxer" /t REG_DWORD /d 0 /reg:64
- '<SYSTEM32>\taskeng.exe' {58FEC182-6BB5-4A2B-B920-4D7FEB835750} S-1-5-21-1960123792-2022915161-3775307078-1001:fbaalb\user:Interactive:[1]
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -EncodedCommand cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIABnAHAAdQBwAGQAYQB0AGUALgBlAHgAZQAgAC8AZgBvAHIAYwBlAA==
- '<SYSTEM32>\gpupdate.exe' /force
- '<SYSTEM32>\gpscript.exe' /RefreshSystemParam
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "gFMkfQJKk"
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\SlydqQJkrlmQBxer" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\SlydqQJkrlmQBxer" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\IBOeaiVJaQNeushXXNR" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "UbakGstaoNGBT2"
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\SlydqQJkrlmQBxer" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\SlydqQJkrlmQBxer" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\SlydqQJkrlmQBxer" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\SlydqQJkrlmQBxer" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\cmd.exe' /C copy nul "%WINDIR%\Temp\SlydqQJkrlmQBxer\VVycnRhf\LXIFwTVamcyuPHAS.wsf"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\AaavntqHU" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\AaavntqHU" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\GCCewQuGoIE" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\schtasks.exe' /run /I /tn "gFMkfQJKk"
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\SlydqQJkrlmQBxer" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "qxSVTIIqATCBX2"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\RQlLCJGgNJhU2" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\cufjJoOUspeIC" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "rCQFPmQfSCisWCAcZ2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "NuCDgTdvxWpStJwkO"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "NuCDgTdvxWpStJwkO"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "NuCDgTdvxWpStJwkO2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "NuCDgTdvxWpStJwkO2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ETerTIfigFzysLrKO"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\RQlLCJGgNJhU2" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ETerTIfigFzysLrKO"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ETerTIfigFzysLrKO2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "gBsoyUzXJSVNRBfbz"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "gBsoyUzXJSVNRBfbz"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "gBsoyUzXJSVNRBfbz2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "gBsoyUzXJSVNRBfbz2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "wGeREkCGxqMQeeNNoyX"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "wGeREkCGxqMQeeNNoyX"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "rCQFPmQfSCisWCAcZ"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ETerTIfigFzysLrKO2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "rCQFPmQfSCisWCAcZ2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "rCQFPmQfSCisWCAcZ"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "AOxXtICYJTrsmvvkw2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "AOxXtICYJTrsmvvkw2"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\cufjJoOUspeIC" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ALLUSERSPROFILE%\smWEKOSdLiGSaNVB" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ALLUSERSPROFILE%\smWEKOSdLiGSaNVB" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\zqfhnbqOWhQDs" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\zqfhnbqOWhQDs" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\dzeaLDZKMHCxtpiUO" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\RQlLCJGgNJhU2" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\dzeaLDZKMHCxtpiUO" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\VVPByIQdrCUn" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "fCZWDhtewbKGfmYyc"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "fCZWDhtewbKGfmYyc2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "mYeBfOlyCcPsocaqV"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "mYeBfOlyCcPsocaqV"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "mYeBfOlyCcPsocaqV2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "mYeBfOlyCcPsocaqV2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "AOxXtICYJTrsmvvkw"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\VVPByIQdrCUn" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "AOxXtICYJTrsmvvkw"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "fCZWDhtewbKGfmYyc2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "UbakGstaoNGBT2"