Техническая информация
- [HKLM\System\CurrentControlSet\Services\defser] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\defser] 'ImagePath' = '<Полный путь к файлу>'
- 'defser' <Полный путь к файлу>
- <Имя диска съемного носителя>:\darkboard\s67958519413
- <Имя диска съемного носителя>:\darkboard\o52311212105
- <Текущая директория>\netframwork.dll
- %ALLUSERSPROFILE%\board\ids
- %WINDIR%\logg.bat
- %ALLUSERSPROFILE%\board\runs.txt
- %ALLUSERSPROFILE%\board\posi.txt
- %ALLUSERSPROFILE%\board\st
- C:\darkboard\s67958519413
- D:\darkboard\s67958519413
- %ALLUSERSPROFILE%\board\s67958519413
- C:\darkboard\o52311212105
- D:\darkboard\o52311212105
- %ALLUSERSPROFILE%\board\o52311212105
- C:\darkboard\readme.txt
- %WINDIR%\debug\wwfamwo3c\system volume information\tracking.log
- C:\system volume information\mountpointmanagerremotedatabase
- <Имя диска съемного носителя>:\delete.avi
- <Имя диска съемного носителя>:\000814251_video_01.avi
- <Имя диска съемного носителя>:\toolbar.bmp
- <Имя диска съемного носителя>:\dialmap.bmp
- <Имя диска съемного носителя>:\sdksampleunprivdeveloper.cer
- <Имя диска съемного носителя>:\contoso.cer
- <Имя диска съемного носителя>:\correct.avi
- 'localhost':49186
- '<LOCALNET>.75.161':445
- '<LOCALNET>.75.163':445
- '<LOCALNET>.75.165':445
- '<LOCALNET>.75.169':445
- '<LOCALNET>.75.167':445
- '<LOCALNET>.75.171':445
- '<LOCALNET>.75.173':445
- '<LOCALNET>.75.175':445
- '<LOCALNET>.75.177':445
- '<LOCALNET>.75.178':445
- '<LOCALNET>.75.180':445
- '<LOCALNET>.75.179':445
- '<LOCALNET>.75.181':445
- '<LOCALNET>.75.123':445
- '<LOCALNET>.75.182':445
- '<LOCALNET>.75.186':445
- '<LOCALNET>.75.188':445
- '<LOCALNET>.75.190':445
- '<LOCALNET>.75.192':445
- '<LOCALNET>.75.194':445
- '<LOCALNET>.75.196':445
- '<LOCALNET>.75.198':445
- '<LOCALNET>.75.200':445
- '<LOCALNET>.75.202':445
- '<LOCALNET>.75.204':445
- '<LOCALNET>.75.206':445
- '<LOCALNET>.75.208':445
- '<LOCALNET>.75.210':445
- '<LOCALNET>.75.157':445
- '<LOCALNET>.75.159':445
- '<LOCALNET>.75.155':445
- '<LOCALNET>.75.153':445
- '<LOCALNET>.75.151':445
- '<LOCALNET>.75.95':445
- '<LOCALNET>.75.97':445
- '<LOCALNET>.75.99':445
- '<LOCALNET>.75.101':445
- '<LOCALNET>.75.103':445
- '<LOCALNET>.75.105':445
- '<LOCALNET>.75.107':445
- '<LOCALNET>.75.109':445
- '<LOCALNET>.75.111':445
- '<LOCALNET>.75.113':445
- '<LOCALNET>.75.117':445
- '<LOCALNET>.75.115':445
- '<LOCALNET>.75.119':445
- '<LOCALNET>.75.212':445
- '<LOCALNET>.75.184':445
- '<LOCALNET>.75.121':445
- '<LOCALNET>.75.127':445
- '<LOCALNET>.75.129':445
- '<LOCALNET>.75.131':445
- '<LOCALNET>.75.133':445
- '<LOCALNET>.75.135':445
- 'ch####p.dyndns.org':80
- '<LOCALNET>.75.137':445
- '<LOCALNET>.75.139':445
- '<LOCALNET>.75.141':445
- '<LOCALNET>.75.143':445
- '<LOCALNET>.75.145':445
- '<LOCALNET>.75.147':445
- '<LOCALNET>.75.149':445
- '<LOCALNET>.75.93':445
- '<LOCALNET>.75.125':445
- '<LOCALNET>.75.250':445
- 'localhost':49720
- '<LOCALNET>.75.218':445
- '<LOCALNET>.75.217':445
- '<LOCALNET>.75.219':445
- '<LOCALNET>.75.221':445
- '<LOCALNET>.75.223':445
- '<LOCALNET>.75.225':445
- '<LOCALNET>.75.227':445
- 'localhost':49430
- '<LOCALNET>.75.229':445
- '<LOCALNET>.75.231':445
- '<LOCALNET>.75.233':445
- '<LOCALNET>.75.235':445
- '<LOCALNET>.75.237':445
- '<LOCALNET>.75.239':445
- '<LOCALNET>.75.214':445
- '<LOCALNET>.75.241':445
- '<LOCALNET>.75.251':445
- '<LOCALNET>.75.247':445
- '<LOCALNET>.75.249':445
- '<LOCALNET>.75.245':445
- '<LOCALNET>.75.255':445
- '<LOCALNET>.75.253':445
- 'ap#.##legram.org':443
- 'localhost':49447
- 'localhost':49450
- 'localhost':49562
- 'localhost':49711
- 'localhost':49714
- 'localhost':49717
- '<LOCALNET>.75.213':445
- '<LOCALNET>.75.215':445
- '<LOCALNET>.75.211':445
- '<LOCALNET>.75.209':445
- '<LOCALNET>.75.207':445
- '<LOCALNET>.75.228':445
- '<LOCALNET>.75.226':445
- '<LOCALNET>.75.224':445
- '<LOCALNET>.75.222':445
- '<LOCALNET>.75.230':445
- '<LOCALNET>.75.232':445
- '<LOCALNET>.75.234':445
- '<LOCALNET>.75.236':445
- '<LOCALNET>.75.238':445
- '<LOCALNET>.75.240':445
- '<LOCALNET>.75.242':445
- '<LOCALNET>.75.244':445
- '<LOCALNET>.75.246':445
- '<LOCALNET>.75.216':445
- '<LOCALNET>.75.91':445
- '<LOCALNET>.75.248':445
- '<LOCALNET>.75.254':445
- '<LOCALNET>.75.183':445
- '<LOCALNET>.75.185':445
- '<LOCALNET>.75.187':445
- '<LOCALNET>.75.189':445
- '<LOCALNET>.75.191':445
- '<LOCALNET>.75.193':445
- '<LOCALNET>.75.195':445
- '<LOCALNET>.75.197':445
- '<LOCALNET>.75.199':445
- '<LOCALNET>.75.201':445
- '<LOCALNET>.75.203':445
- '<LOCALNET>.75.205':445
- '<LOCALNET>.75.220':445
- '<LOCALNET>.75.252':445
- '<LOCALNET>.75.243':445
- '<LOCALNET>.75.89':445
- '<LOCALNET>.75.56':445
- '<LOCALNET>.75.70':445
- '<LOCALNET>.75.72':445
- '<LOCALNET>.75.74':445
- '<LOCALNET>.75.76':445
- '<LOCALNET>.75.78':445
- '<LOCALNET>.75.80':445
- '<LOCALNET>.75.82':445
- '<LOCALNET>.75.84':445
- '<LOCALNET>.75.86':445
- '<LOCALNET>.75.88':445
- '<LOCALNET>.75.90':445
- '<LOCALNET>.75.92':445
- '<LOCALNET>.75.94':445
- '<LOCALNET>.75.29':445
- '<LOCALNET>.75.96':445
- '<LOCALNET>.75.98':445
- '<LOCALNET>.75.102':445
- '<LOCALNET>.75.104':445
- '<LOCALNET>.75.106':445
- '<LOCALNET>.75.108':445
- '<LOCALNET>.75.110':445
- '<LOCALNET>.75.112':445
- '<LOCALNET>.75.114':445
- '<LOCALNET>.75.116':445
- '<LOCALNET>.75.118':445
- '<LOCALNET>.75.120':445
- '<LOCALNET>.75.122':445
- '<LOCALNET>.75.124':445
- '<LOCALNET>.75.66':445
- '<LOCALNET>.75.68':445
- '<LOCALNET>.75.64':445
- '<LOCALNET>.75.62':445
- '<LOCALNET>.75.59':445
- '<LOCALNET>.75.2':445
- '<LOCALNET>.75.4':445
- '<LOCALNET>.75.6':445
- '<LOCALNET>.75.8':445
- '<LOCALNET>.75.10':445
- '<LOCALNET>.75.12':445
- '<LOCALNET>.75.13':445
- '<LOCALNET>.75.15':445
- '<LOCALNET>.75.17':445
- '<LOCALNET>.75.19':445
- '<LOCALNET>.75.21':445
- '<LOCALNET>.75.23':445
- '<LOCALNET>.75.25':445
- '<LOCALNET>.75.126':445
- '<LOCALNET>.75.100':445
- '<LOCALNET>.75.27':445
- '<LOCALNET>.75.33':445
- '<LOCALNET>.75.35':445
- '<LOCALNET>.75.37':445
- '<LOCALNET>.75.39':445
- '<LOCALNET>.75.41':445
- '<LOCALNET>.75.43':445
- '<LOCALNET>.75.45':445
- '<LOCALNET>.75.47':445
- '<LOCALNET>.75.49':445
- '<LOCALNET>.75.51':445
- '<LOCALNET>.75.53':445
- '<LOCALNET>.75.55':445
- '<LOCALNET>.75.57':445
- '<LOCALNET>.75.0':445
- '<LOCALNET>.75.31':445
- '<LOCALNET>.75.164':445
- '<LOCALNET>.75.85':445
- '<LOCALNET>.75.132':445
- '<LOCALNET>.75.28':445
- '<LOCALNET>.75.30':445
- '<LOCALNET>.75.32':445
- '<LOCALNET>.75.34':445
- '<LOCALNET>.75.36':445
- '<LOCALNET>.75.38':445
- '<LOCALNET>.75.40':445
- '<LOCALNET>.75.42':445
- '<LOCALNET>.75.44':445
- '<LOCALNET>.75.46':445
- '<LOCALNET>.75.48':445
- '<LOCALNET>.75.50':445
- '<LOCALNET>.75.52':445
- '<LOCALNET>.75.128':445
- '<LOCALNET>.75.54':445
- '<LOCALNET>.75.58':445
- '<LOCALNET>.75.63':445
- '<LOCALNET>.75.60':445
- '<LOCALNET>.75.65':445
- '<LOCALNET>.75.67':445
- '<LOCALNET>.75.69':445
- '<LOCALNET>.75.71':445
- '<LOCALNET>.75.73':445
- '<LOCALNET>.75.75':445
- '<LOCALNET>.75.77':445
- '<LOCALNET>.75.79':445
- '<LOCALNET>.75.81':445
- '<LOCALNET>.75.83':445
- '<LOCALNET>.75.24':445
- '<LOCALNET>.75.26':445
- '<LOCALNET>.75.22':445
- '<LOCALNET>.75.20':445
- '<LOCALNET>.75.18':445
- '<LOCALNET>.75.136':445
- '<LOCALNET>.75.138':445
- '<LOCALNET>.75.140':445
- '<LOCALNET>.75.142':445
- '<LOCALNET>.75.144':445
- '<LOCALNET>.75.146':445
- '<LOCALNET>.75.148':445
- '<LOCALNET>.75.150':445
- '<LOCALNET>.75.152':445
- '<LOCALNET>.75.154':445
- '<LOCALNET>.75.156':445
- '<LOCALNET>.75.158':445
- '<LOCALNET>.75.160':445
- '<LOCALNET>.75.130':445
- '<LOCALNET>.75.87':445
- '<LOCALNET>.75.162':445
- '<LOCALNET>.75.168':445
- '<LOCALNET>.75.170':445
- '<LOCALNET>.75.172':445
- '<LOCALNET>.75.174':445
- '<LOCALNET>.75.176':445
- '<LOCALNET>.75.1':445
- '<LOCALNET>.75.3':445
- '<LOCALNET>.75.5':445
- '<LOCALNET>.75.7':445
- '<LOCALNET>.75.9':445
- '<LOCALNET>.75.11':445
- '<LOCALNET>.75.14':445
- '<LOCALNET>.75.16':445
- '<LOCALNET>.75.134':445
- '<LOCALNET>.75.166':445
- 'localhost':49723
- http://ch####p.dyndns.org/
- 'localhost':49186
- 'localhost':49721
- 'localhost':49720
- 'localhost':49718
- 'localhost':49717
- 'localhost':49715
- 'localhost':49714
- 'localhost':49712
- 'localhost':49711
- 'localhost':49723
- 'localhost':49563
- 'localhost':49451
- 'localhost':49450
- 'localhost':49448
- 'localhost':49447
- 'ap#.##legram.org':443
- 'localhost':49431
- 'localhost':49430
- 'localhost':49187
- 'localhost':49562
- 'localhost':49724
- DNS ASK ch####p.dyndns.org
- DNS ASK ap#.##legram.org
- '<SYSTEM32>\sc.exe' create defser binpath= "<Полный путь к файлу>" start= auto' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\logg.bat' (со скрытым окном)
- '<SYSTEM32>\vssadmin.exe' Delete Shadows /All /Quiet' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c powercfg /setactive 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c' (со скрытым окном)
- '<SYSTEM32>\sc.exe' delete defser' (со скрытым окном)
- '<SYSTEM32>\sc.exe' start defser' (со скрытым окном)
- '<SYSTEM32>\sc.exe' create defser binpath= "<Полный путь к файлу>" start= auto
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnostics-Networking/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnostics-PerfTrack-Counters/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnostics-PerfTrack/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnostics-Performance/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnostics-Performance/Diagnostic/Loopback"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnostics-Performance/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DirectShow-KernelSupport/Performance"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DirectSound/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DirectWrite-FontCache/Tracing"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DiskDiagnostic/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DxpTaskRingtone/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DiskDiagnosticDataCollector/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DiskDiagnosticResolver/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DisplayColorCalibration/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DisplayColorCalibration/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DisplaySwitch/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Documents/Performance"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DriverFrameworks-UserMode/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DxgKrnl/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DxgKrnl/Performance"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnostics-Networking/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Disk/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-WDI/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-PCW/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Dhcpv6-Client/Admin"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Dhcpv6-Client/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DiagCpl/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-DPS/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-DPS/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-DPS/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-MSDE/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-PCW/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-PCW/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-PLA/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-TaskManager/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-PLA/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-Perfhost/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-Scheduled/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-Scripted/Admin"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-Scripted/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-Scripted/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-Scripted/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Diagnosis-WDC/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-FMS/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Kernel-EventTracing/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-EapHost/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-HealthCenterCPL/Performance"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Help/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-HomeGroup"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-HomeGroup-ListenerService"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-HotStart/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-HttpService/Trace"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-IKE/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-IKEDBG/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-IPBusEnum/Tracing"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-International-RegionalOptionsControlPanel/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-EFS/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-International/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Iphlpsvc/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Iphlpsvc/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Iphlpsvc/Trace"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Kernel-Acpi/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Kernel-Boot/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Kernel-BootDiagnostics/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Kernel-Disk/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Kernel-EventTracing/Admin"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-HealthCenter/Performance"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DhcpNap/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-HealthCenter/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-FMS/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-EapHost/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-EapHost/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-EaseOfAccess/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-EventCollector/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-EventCollector/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-EventLog-WMIProvider/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-EventLog/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-EventLog/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-FMS/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DxpTaskSyncProvider/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-GroupPolicy/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-FailoverClustering-Client/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Fault-Tolerant-Heap/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Feedback-Service-TriggerProvider"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-FileInfoMinifilter/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Firewall-CPL/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Folder"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Forwarding/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Forwarding/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-GettingStarted/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-HAL/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-IPSEC-SRV/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DhcpNap/Admin"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DUI/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-IEFRAME/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-PerfTrack-IEFRAME/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-PerfTrack-MSHTML/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-ADSI/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-API-Tracing/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-ATAPort/General"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-ATAPort/SATA-LPM"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-ActionQueue/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-AltTab/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-AppLocker/EXE"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Audio/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-AppLocker/MSI"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Application"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Application-Experience/Problem-Steps-Recorder"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Application-Experience/Program-Compatibility-Assistant"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Application-Experience/Program-Compatibility-Troubleshooter"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Application-Experience/Program-Inventory"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Application-Experience/Program-Inventory/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Application-Experience/Program-Telemetry"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Audio/CaptureMonitor"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-IE/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-AppID/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "MediaFoundationPlatform"
- '<SYSTEM32>\wevtutil.exe' cl "DirectShowPluginControl"
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\logg.bat
- '<SYSTEM32>\cmd.exe' /c powercfg /setactive 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c
- '<SYSTEM32>\powercfg.exe' /setactive 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c
- '<SYSTEM32>\cmd.exe' /c wevtutil el
- '<SYSTEM32>\wevtutil.exe' el
- '<SYSTEM32>\wevtutil.exe' cl "Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Application"
- '<SYSTEM32>\wevtutil.exe' cl "DebugChannel"
- '<SYSTEM32>\wevtutil.exe' cl "DirectShowFilterGraph"
- '<SYSTEM32>\wevtutil.exe' cl "EndpointMapper"
- '<SYSTEM32>\wevtutil.exe' cl "MediaFoundationPipeline"
- '<SYSTEM32>\wevtutil.exe' cl "ForwardedEvents"
- '<SYSTEM32>\wevtutil.exe' cl "HardwareEvents"
- '<SYSTEM32>\wevtutil.exe' cl "Internet"
- '<SYSTEM32>\wevtutil.exe' cl "Key"
- '<SYSTEM32>\sc.exe' delete defser
- '<SYSTEM32>\wevtutil.exe' cl "MF_MediaFoundationDeviceProxy"
- '<SYSTEM32>\wevtutil.exe' cl "Media"
- '<SYSTEM32>\wevtutil.exe' cl "MediaFoundationDeviceProxy"
- '<SYSTEM32>\wevtutil.exe' cl "MediaFoundationPerformance"
- '<SYSTEM32>\sc.exe' start defser
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-BranchCacheEventProvider/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Dhcp-Client/Admin"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Authentication"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-CodeIntegrity/Verbose"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-ComDlg32/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-ComDlg32/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-CorruptedFileRecovery-Client/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-CorruptedFileRecovery-Server/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-CredUI/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Crypto-RNG/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DCLocator/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DNS-Client/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DUSER/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Audit/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DXP/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DateTimeControlPanel/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DateTimeControlPanel/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DateTimeControlPanel/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Deplorch/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DeviceSync/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DeviceSync/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DeviceUx/Informational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-DeviceUx/Performance"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-CodeIntegrity/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Dhcp-Client/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-CmiSetup/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-BranchCacheClientEventProvider/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-AxInstallService/Log"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Backup"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Biometrics/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-BitLocker-DrivePreparationTool/Admin"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-BitLocker-DrivePreparationTool/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Bits-Client/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Bits-Client/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Bluetooth-MTPEnum/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-BranchCache/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Audio/Performance"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-CertificateServicesClient-CredentialRoaming/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-BranchCacheSMB/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-BranchCacheSMB/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-CAPI2/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-CDROM/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-COM/Analytic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-COMRuntime/Tracing"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Calculator/Debug"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Calculator/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-CertPoleEng/Operational"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-ClearTypeTextTuner/Diagnostic"
- '<SYSTEM32>\wevtutil.exe' cl "Microsoft-Windows-Kernel-File/Analytic"