Техническая информация
- volume{c693706d-3f85-11ed-82a9-806e6f6e6963}\system volume information\tracking.log.tmp
- volume{c693706e-3f85-11ed-82a9-806e6f6e6963}\system volume information\tracking.log.tmp
- nul
- <SYSTEM32>\catroot2\dberr.txt
- %WINDIR%\softwaredistribution\DataStore\logs\edb.chk
- %WINDIR%\temp\ts_996d.tmp
- %WINDIR%\temp\ts_947a.tmp
- %WINDIR%\temp\ts_6d1b.tmp
- %WINDIR%\temp\ts_6ab9.tmp
- %WINDIR%\temp\ts_67ca.tmp
- %WINDIR%\temp\ts_624b.tmp
- %WINDIR%\temp\ts_5b54.tmp
- %WINDIR%\temp\ts_5a4a.tmp
- %WINDIR%\temp\ts_548c.tmp
- %WINDIR%\Temp\fwtsqmfile00.sqm
- %WINDIR%\temp\dmiacf5.tmp
- %WINDIR%\serviceprofiles\localservice\appdata\local\microsoft\windows\windowsupdate.log
- %WINDIR%\windowsupdate.log
- %WINDIR%\win.ini
- %WINDIR%\inf\netavpna.pnf
- %WINDIR%\inf\netrasa.pnf
- %WINDIR%\inf\keyboard.pnf
- <SYSTEM32>\restore\machineguid.txt
- %WINDIR%\softwaredistribution\DataStore\logs\edb.log
- %WINDIR%\softwaredistribution\DataStore\logs\edb00006.log
- volume{c693706d-3f85-11ed-82a9-806e6f6e6963}\system volume information\tracking.log.tmp в volume{c693706d-3f85-11ed-82a9-806e6f6e6963}\system volume information\tracking.log
- volume{c693706e-3f85-11ed-82a9-806e6f6e6963}\system volume information\tracking.log.tmp в volume{c693706e-3f85-11ed-82a9-806e6f6e6963}\system volume information\tracking.log
- '<SYSTEM32>\cmd.exe' /c Color 0a
- '<SYSTEM32>\sc.exe' stop XblAuthManager
- '<SYSTEM32>\cmd.exe' /c sc stop XblGameSave >nul 2>&1
- '<SYSTEM32>\sc.exe' stop XblGameSave
- '<SYSTEM32>\cmd.exe' /c sc stop XboxNetApiSvc >nul 2>&1
- '<SYSTEM32>\sc.exe' stop XboxNetApiSvc
- '<SYSTEM32>\cmd.exe' /c sc stop XboxGipSvc >nul 2>&1
- '<SYSTEM32>\sc.exe' stop XboxGipSvc
- '<SYSTEM32>\cmd.exe' /c del /s /q %system(_xor_drive%\desktop.ini
- '<SYSTEM32>\cmd.exe' /c sc stop XblAuthManager >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c sc stop HTTPDebuggerPro >nul 2>&1
- '<SYSTEM32>\sc.exe' delete HTTPDebuggerPro
- '<SYSTEM32>\cmd.exe' /c sc stop BEService >nul 2>&1
- '<SYSTEM32>\sc.exe' stop BEService
- '<SYSTEM32>\cmd.exe' /c sc delete BEService >nul 2>&1
- '<SYSTEM32>\sc.exe' delete BEService
- '<SYSTEM32>\cmd.exe' /c sc stop BEDaisy >nul 2>&1
- '<SYSTEM32>\sc.exe' stop BEDaisy
- '<SYSTEM32>\sc.exe' stop HTTPDebuggerPro
- '<SYSTEM32>\cmd.exe' /c sc delete HTTPDebuggerPro >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c del /s /q %system(_xor_drive%\Recovery\ntser.sys
- '<SYSTEM32>\cmd.exe' /c del /s /q %system(_xor_drive%\ProgramData\ntser.pol
- '<SYSTEM32>\sc.exe' delete BEDaisy
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %ALLUSERSPROFILE%\NVIDIA Corporation\NV_Cache
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %ALLUSERSPROFILE%\NVIDIA Corporation\Drs\nvAppTimestamps
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %ALLUSERSPROFILE%\Microsoft\Windows\WER
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\PerfLogs
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Documents and Settings\%username%\AppData\Local\Application Data\Microsoft\Windows\Caches
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %localappdata%\Microsoft\Windows\Caches
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\system(_xor_32\restore\MachineGuid.txt
- '<SYSTEM32>\cmd.exe' /c del /s /q %system(_xor_drive%\Users\Public\Libraries\collection.dat
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %system(_xor_drive%\system(_xor_ Volume Information\IndexerVolumeGuid
- '<SYSTEM32>\cmd.exe' /c del /s /q %system(_xor_drive%\system(_xor_ Volume Information\WPSettings.dat
- '<SYSTEM32>\cmd.exe' /c del /s /q %system(_xor_drive%\system(_xor_ Volume Information\tracking.log
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %system(_xor_drive%\ProgramData\Microsoft\Windows\WER
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %system(_xor_drive%\Users\Public\Shared Files
- '<SYSTEM32>\cmd.exe' /c del /s /q %system(_xor_drive%\Windows\INF\setpapi.dev.log
- '<SYSTEM32>\cmd.exe' /c del /s /q %system(_xor_drive%\Windows\INF\setpapi.setp.log
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %system(_xor_drive%\Users\Public\Libraries
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %system(_xor_drive%\MSOCache
- '<SYSTEM32>\cmd.exe' /c sc delete BEDaisy >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\CrashDmps
- '<SYSTEM32>\cmd.exe' /c del /s /q %system(_xor_drive%\Users\Defalt\NTSER.DAT
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %WINDIR%\system(_xor_32\config\system(_xor_profile\AppData\Local\ScreenTime
- '<SYSTEM32>\cmd.exe' /c sc stop EasyAntiCheat >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c netsh winsock reset
- '<SYSTEM32>\netsh.exe' winsock reset
- '<SYSTEM32>\cmd.exe' /c netsh winsock reset catalog
- '<SYSTEM32>\netsh.exe' winsock reset catalog
- '<SYSTEM32>\cmd.exe' /c netsh int ip reset
- '<SYSTEM32>\netsh.exe' int ip reset
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall reset
- '<SYSTEM32>\netsh.exe' advfirewall reset
- '<SYSTEM32>\cmd.exe' /c netsh int reset all
- '<SYSTEM32>\netsh.exe' int reset all
- '<SYSTEM32>\cmd.exe' /c netsh int ipv4 reset
- '<SYSTEM32>\netsh.exe' int ipv4 reset
- '<SYSTEM32>\cmd.exe' /c netsh int ipv6 reset
- '<SYSTEM32>\netsh.exe' int ipv6 reset
- '<SYSTEM32>\cmd.exe' /c ipconfig / release
- '<SYSTEM32>\ipconfig.exe' / release
- '<SYSTEM32>\cmd.exe' /c ipconfig / renew
- '<SYSTEM32>\ipconfig.exe' / renew
- '<SYSTEM32>\cmd.exe' /c ipconfig / flushdns
- '<SYSTEM32>\reg.exe' delete HKLM\SYSTEM\ControlSet001\Services\BEService /f
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\D3DSCache
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\ConnectedDevicesPlatform
- '<SYSTEM32>\cmd.exe' /c reg delete HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat /f
- '<SYSTEM32>\cmd.exe' /c sc stop EasyAntiCheatSys >nul 2>&1
- '<SYSTEM32>\sc.exe' stop EasyAntiCheatSys
- '<SYSTEM32>\cmd.exe' /c sc delete EasyAntiCheat >nul 2>&1
- '<SYSTEM32>\sc.exe' delete EasyAntiCheat
- '<SYSTEM32>\cmd.exe' /c sc delete EasyAntiCheatSys >nul 2>&1
- '<SYSTEM32>\sc.exe' delete EasyAntiCheatSys
- '<SYSTEM32>\cmd.exe' /c reg delete HKEY_LOCAL_MACHINE\system(_xor_ing\CurrentControlSet\Services\vgk\Security /f
- '<SYSTEM32>\reg.exe' delete HKEY_LOCAL_MACHINE\system(_xor_ing\CurrentControlSet\Services\vgk\Security /f
- '<SYSTEM32>\cmd.exe' /c reg delete HKEY_LOCAL_MACHINE\system(_xor_ing\CurrentControlSet\Services\vgc\Security /f
- '<SYSTEM32>\reg.exe' delete HKEY_LOCAL_MACHINE\system(_xor_ing\CurrentControlSet\Services\vgc\Security /f
- '<SYSTEM32>\cmd.exe' /c @del /q %systemdrive%\Users\%username%\AppData\Local\DigitalEntitlements
- '<SYSTEM32>\cmd.exe' /c @del /q %systemdrive%:\Users\%username%\AppData\Roaming\CitizenFX
- '<SYSTEM32>\cmd.exe' /c @del /q D:\Users\%username%\AppData\Local\DigitalEntitlements
- '<SYSTEM32>\cmd.exe' /c @del /q <Имя диска съемного носителя>:\Users\%username%\AppData\Local\DigitalEntitlements
- '<SYSTEM32>\cmd.exe' /c @del /q <Имя диска съемного носителя>:\Users\%username%\AppData\Roaming\CitizenFX
- '<SYSTEM32>\cmd.exe' /c @del /q E:\Users\%username%\AppData\Local\DigitalEntitlements
- '<SYSTEM32>\cmd.exe' /c @del /q E:\Users\%username%\AppData\Roaming\CitizenFX
- '<SYSTEM32>\cmd.exe' /c reg delete HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat /f
- '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat /f
- '<SYSTEM32>\reg.exe' delete HKLM\SYSTEM\ControlSet001\Services\EasyAntiCheat /f
- '<SYSTEM32>\sc.exe' stop EasyAntiCheat
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\Microsoft\Internet Explorer\CacheStorage
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\Microsoft\Terminal Server Client\Cache
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\Microsoft\Windows\Caches
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\Local Settings\Riot Games
- '<SYSTEM32>\cmd.exe' /c del /f /q %ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Riot Games\VALORANT.lnk
- '<SYSTEM32>\cmd.exe' /c del C:\Riot Games\VALORANT\live\Manifest_NonFSFiles_Win64.txt /f /q
- '<SYSTEM32>\cmd.exe' /c del C:\Riot Games\VALORANT\live\Engine\Binaries\ThirdParty\CEF3\Win64\icdtl.dat /f /q
- '<SYSTEM32>\cmd.exe' /c del C:\Riot Games\Riot Client\X\natives_blob.bin /f /q
- '<SYSTEM32>\cmd.exe' /c del C:\Riot Games\Riot Client\X\icdtl.dat /f /q
- '<SYSTEM32>\cmd.exe' /c del C:\Riot Games\Riot Client\X\Plgins\plgin - manifest.json /f /q
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\vgkbootstats.dat
- '<SYSTEM32>\cmd.exe' /c reg delete HKEY_LOCAL_MACHINE\system(_xor_\HardwareConfig /f
- '<SYSTEM32>\reg.exe' delete HKEY_LOCAL_MACHINE\system(_xor_\HardwareConfig /f
- '<SYSTEM32>\cmd.exe' /c del /s /q /f %system(_xor_drive%\$Recycle.bin
- '<SYSTEM32>\cmd.exe' /c del /s /q D:\system(_xor_ Volume Information\tracking.log
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\win.ini
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\memory.dmp
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\WindowsUpdate.log
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\system(_xor_32\LogFiles\WMI\Wifi.etl
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\system(_xor_32\LogFiles\WMI\RadioMgr.etl
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %ProgramFiles%\Riot Games
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %ALLUSERSPROFILE%\Application Data\Riot Games
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Riot Games
- '<SYSTEM32>\ipconfig.exe' / flushdns
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\system(_xor_32\LogFiles\WMI\NtfsLog.etl
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %ALLUSERSPROFILE%\Riot Games
- '<SYSTEM32>\cmd.exe' /c del /s /q C:\Users\%username%\AppData\Local\Riot Games
- '<SYSTEM32>\cmd.exe' /c del /s /q %ALLUSERSPROFILE%\Riot Games
- '<SYSTEM32>\cmd.exe' /c reg delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ExplorerHKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Riot Game valorant.live
- '<SYSTEM32>\reg.exe' delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ExplorerHKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Riot Game valorant.live
- '<SYSTEM32>\cmd.exe' /c reg delete HKEY_LOCAL_MACHINE\system(_xor_\CurrentControlSet\Services\vgk\Security /f
- '<SYSTEM32>\reg.exe' delete HKEY_LOCAL_MACHINE\system(_xor_\CurrentControlSet\Services\vgk\Security /f
- '<SYSTEM32>\cmd.exe' /c reg delete HKEY_LOCAL_MACHINE\system(_xor_\CurrentControlSet\Services\vgc\Security /f
- '<SYSTEM32>\reg.exe' delete HKEY_LOCAL_MACHINE\system(_xor_\CurrentControlSet\Services\vgc\Security /f
- '<SYSTEM32>\cmd.exe' /c del /s /q C:\Users\%username%\AppData\Local\VALORANT
- '<SYSTEM32>\cmd.exe' /c reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Riot Vangard /f
- '<SYSTEM32>\cmd.exe' /c reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\VALORANT - Win64 - Shipping.ex /f
- '<SYSTEM32>\reg.exe' delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\VALORANT - Win64 - Shipping.ex /f
- '<SYSTEM32>\cmd.exe' /c reg delete HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist /f
- '<SYSTEM32>\reg.exe' delete HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\UserAssist /f
- '<SYSTEM32>\cmd.exe' /c reg delete HKEY_CLASSES_ROOT\riotclient /f
- '<SYSTEM32>\reg.exe' delete HKEY_CLASSES_ROOT\riotclient /f
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\VALORANT
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Riot Games
- '<SYSTEM32>\reg.exe' delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Riot Vangard /f
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %ProgramFiles%\Riot Vangard
- '<SYSTEM32>\cmd.exe' /c reg delete HKLM\SYSTEM\ControlSet001\Services\BEService /f
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\system(_xor_32\LogFiles\WMI\NetCore.etl
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\UserviceProfiles\NetworkService\NTSER.DAT
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %WINDIR%\system(_xor_32\WDI\LogFiles\StartpInfo
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %WINDIR%\system(_xor_32\WDI\LogFiles
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %WINDIR%\SoftwareDistribution
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %WINDIR%\UserviceProfiles\NetworkService\AppData\Local\Microsoft\Windows\deliveryOptimization\Logs
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %WINDIR%\UserviceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Roaming\Microsoft\Protect
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\VirtalStore
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\UnrealEngine
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\Temp
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\Microsoft\Windows\WebCache
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\Microsoft\Windows\WER
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\Microsoft\Windows\INetCookies
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\Microsoft\Windows\INetCache
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\Microsoft\Windows\IEDownloadHistory
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\Microsoft\Windows\IECompataCache
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\Microsoft\Windows\IECompatCache
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\system(_xor_32\LogFiles\WMI\Microsoft - Windows - Rdp - Graphics - RdpIdd - Trace.etl
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %WINDIR%\system(_xor_32\config\TxR
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\system(_xor_32\LogFiles\WMI\LwtNetLog.etl
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %WINDIR%\system(_xor_32\config\system(_xor_profile\AppData\Local\D3DSCache
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Documents and Settings\All Users\Riot Games
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\UserviceProfiles\LocalService\AppData\Local\Microsoft\Windows\qwavecache.dat
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\Logs\DISM\dism.log
- '<SYSTEM32>\cmd.exe' /c del /s /q %WINDIR%\DirectX.log
- '<SYSTEM32>\cmd.exe' /c del /s /q C:\Users\Public\Desktop\VALORANT.lnk
- '<SYSTEM32>\cmd.exe' /c del /s /q C:\Users\%username%\ntser.dat.LOG2
- '<SYSTEM32>\cmd.exe' /c del /s /q C:\Users\%username%\ntser.dat.LOG1
- '<SYSTEM32>\cmd.exe' /c del /s /q C:\Users\%username%\AppData\Local\Microsoft\Windows\INetCache\IE\container.dat
- '<SYSTEM32>\cmd.exe' /c del /s /q C:\Users\%username%\NTSER.DAT
- '<SYSTEM32>\cmd.exe' /c del /s /q C:\Users\%username%\AppData\Local\UnrealEngine\4.23\Saved\Config\WindowsClient\Manifest.ini
- '<SYSTEM32>\cmd.exe' /c del /s /q C:\Users\%username%\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
- '<SYSTEM32>\cmd.exe' /c del /s /q C:\Users\%username%\AppData\Local\Microsoft\OneDrive\logs\Common\DeviceHealthSummaryConfigration.ini
- '<SYSTEM32>\cmd.exe' /c del /s /q C:\Users\%username%\AppData\Local\IconCache.db
- '<SYSTEM32>\cmd.exe' /c del /s /q C:\Users\%username%\AppData\Local\AC\INetCookies\ESE\container.dat
- '<SYSTEM32>\cmd.exe' /c del /s /q C:\system(_xor_ Volume Information\tracking.log
- '<SYSTEM32>\cmd.exe' /c del /s /q %ALLUSERSPROFILE%\Microsoft\Windows\DeviceMetadataCache\dmrc.idx
- '<SYSTEM32>\cmd.exe' /c del /s /q C:\Config.Msi
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q C:\Users\%username%\AppData\Local\Microsoft\Windows\<INETFILES>
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %WINDIR%\logs\CBS
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %WINDIR%\Temp
- '<SYSTEM32>\cmd.exe' /c RMDIR /S /Q %WINDIR%\system(_xor_32\config\system(_xor_profile\AppData\Local\Microsoft\Vault\UserProfileRoaming
- '<SYSTEM32>\cmd.exe' /c pause > nul