Technical Information
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WaaSMedic.exe] 'Debugger' = '/'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WaasMedicAgent.exe] 'Debugger' = '/'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Windows10Upgrade.exe] 'Debugger' = '/'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Windows10UpgraderApp.exe] 'Debugger' = '/'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UpdateAssistant.exe] 'Debugger' = '/'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UsoClient.exe] 'Debugger' = '/'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\remsh.exe] 'Debugger' = '/'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EOSnotify.exe] 'Debugger' = '/'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SihClient.exe] 'Debugger' = '/'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\upfc.exe] 'Debugger' = '/'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\InstallAgent.exe] 'Debugger' = '/'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MusNotification.exe] 'Debugger' = '/'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MusNotificationUx.exe] 'Debugger' = '/'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MoNotificationUx.exe] 'Debugger' = '/'
- [HKLM\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'EnableFirewall' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- Windows Firewall
- Windows Update
- Windows Defender
- System Restore (SR)
- '<SYSTEM32>\netsh.exe' advfirewall set allprofiles state off
- '<SYSTEM32>\net.exe' stop HomeGroupListener
- '<SYSTEM32>\net.exe' stop HomeGroupProvider
- '<SYSTEM32>\net.exe' stop PcaSvc
- '<SYSTEM32>\net.exe' stop diagsvc
- '<SYSTEM32>\net.exe' stop DPS
- '<SYSTEM32>\net.exe' stop WdiServiceHost
- '<SYSTEM32>\net.exe' stop WdiSystemHost
- '<SYSTEM32>\net.exe' stop SDRSVC
- '<SYSTEM32>\net.exe' stop WerSvc
- '<SYSTEM32>\net.exe' stop RemoteRegistry
- '<SYSTEM32>\net.exe' stop edgeupdate
- %TEMP%\40wg5en7.bat
- %TEMP%\1c6t7r6m.tmp
- %TEMP%\aut20a9.tmp
- %TEMP%\auteb1.tmp
- %TEMP%\aute91.tmp
- %TEMP%\2m5s4g4g.tmp
- %TEMP%\aute61.tmp
- %WINDIR%\temp\axombhb
- %WINDIR%\temp\aut51e.tmp
- %TEMP%\aut20e9.tmp
- %TEMP%\umtkrlu
- nul
- %TEMP%\qb0c0000.11\wub_x64.exe
- %TEMP%\qb0c0000.11\wub.ini
- %TEMP%\qb0c0000.11\wub.exe
- %TEMP%\qb0c0000.11\rexplorer_x64.exe
- %TEMP%\qb0c0000.11\rexplorer.exe
- %TEMP%\qb0c0000.11\defendercontrol.ini
- %TEMP%\qb0c0000.11\defendercontrol.exe
- %TEMP%\autfdce.tmp
- %TEMP%\aut2138.tmp
- %TEMP%\autfdce.tmp
- %TEMP%\umtkrlu
- %WINDIR%\temp\aut51e.tmp
- %WINDIR%\temp\axombhb
- %TEMP%\aute61.tmp
- %TEMP%\aute91.tmp
- %TEMP%\auteb1.tmp
- %TEMP%\2m5s4g4g.tmp
- %TEMP%\aut20a9.tmp
- %TEMP%\aut20e9.tmp
- %TEMP%\aut2138.tmp
- %TEMP%\1c6t7r6m.tmp
- %TEMP%\qb0c0000.11\wub.exe
- %TEMP%\qb0c0000.11\wub.ini
- %TEMP%\qb0c0000.11\wub_x64.exe
- %TEMP%\40wg5en7.bat
- %HOMEPATH%\Favorites\Links\desktop.ini
- %ALLUSERSPROFILE%\ntuser.pol
- %HOMEPATH%\ntuser.pol
- %ALLUSERSPROFILE%\tempntuser.pol
- %HOMEPATH%\tempntuser.pol
- '%TEMP%\qb0c0000.11\defendercontrol.exe' /D
- '%TEMP%\qb0c0000.11\defendercontrol.exe' /SYS 1
- '%TEMP%\qb0c0000.11\wub_x64.exe' /D /P
- '%TEMP%\qb0c0000.11\rexplorer_x64.exe' /I /F
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\40WG5EN7.BAT" "<Full path to file>" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\40WG5EN7.BAT" "<Full path to file>" "
- '<SYSTEM32>\powercfg.exe' -change -disk-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' -change -disk-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' -change -monitor-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' -change -monitor-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' -setactive 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c
- '<SYSTEM32>\reg.exe' delete "HKCR\.zip\ShellNew" /f
- '<SYSTEM32>\reg.exe' delete "HKCR\.jnt\jntfile\ShellNew" /f
- '<SYSTEM32>\reg.exe' delete "HKCR\.zip\CompressedFolder\ShellNew" /f
- '<SYSTEM32>\reg.exe' delete "HKCR\.library-ms\ShellNew" /f
- '<SYSTEM32>\reg.exe' delete "HKCR\.rtf\ShellNew" /f
- '<SYSTEM32>\reg.exe' delete "HKCR\.rar\ShellNew" /f
- '<SYSTEM32>\reg.exe' delete "HKCR\.contact\ShellNew" /f
- '<SYSTEM32>\reg.exe' delete "HKCR\.bmp\ShellNew" /f
- '<SYSTEM32>\sc.exe' config edgeupdate start= DISABLED
- '<SYSTEM32>\net1.exe' stop edgeupdate
- '<SYSTEM32>\sc.exe' config RemoteRegistry start= DISABLED
- '<SYSTEM32>\net1.exe' stop RemoteRegistry
- '<SYSTEM32>\sc.exe' config WerSvc start= DISABLED
- '<SYSTEM32>\net1.exe' stop WerSvc
- '<SYSTEM32>\sc.exe' config SDRSVC start= DISABLED
- '<SYSTEM32>\net1.exe' stop SDRSVC
- '<SYSTEM32>\sc.exe' config WdiSystemHost start= DISABLED
- '<SYSTEM32>\sc.exe' config WdiServiceHost start= DISABLED
- '<SYSTEM32>\sc.exe' config DPS start= DISABLED
- '<SYSTEM32>\sc.exe' config diagsvc start= DISABLED
- '<SYSTEM32>\net1.exe' stop WdiSystemHost
- '<SYSTEM32>\net1.exe' stop WdiServiceHost
- '<SYSTEM32>\net1.exe' stop DPS
- '<SYSTEM32>\net1.exe' stop diagsvc
- '<SYSTEM32>\net1.exe' stop PcaSvc
- '<SYSTEM32>\sc.exe' config PcaSvc start= DISABLED
- '<SYSTEM32>\powercfg.exe' -change -standby-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' -change -standby-timeout-dc 0
- '<SYSTEM32>\gpscript.exe' /RefreshSystemParam
- '<SYSTEM32>\svchost.exe' -k secsvcs
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag" /v "ThisPCPolicy" /t REG_SZ /d "Hide" /f /reg:32
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag" /v "ThisPCPolicy" /t REG_SZ /d "Hide" /f /reg:32
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag" /v "ThisPCPolicy" /t REG_SZ /d "Hide" /f /reg:32
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag" /v "ThisPCPolicy" /t REG_SZ /d "Hide" /f /reg:32
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag" /v "ThisPCPolicy" /t REG_SZ /d "Hide" /f /reg:32
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag" /v "ThisPCPolicy" /t REG_SZ /d "Hide" /f /reg:32
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\PropertyBag" /v "ThisPCPolicy" /t REG_SZ /d "Hide" /f /reg:32
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{f42ee2d3-909f-4907-8871-4c22fc0bf756}\PropertyBag" /v "ThisPCPolicy" /t REG_SZ /d "Hide" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{a0c69a99-21c8-4671-8703-7934162fcf1d}\PropertyBag" /v "ThisPCPolicy" /t REG_SZ /d "Hide" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7d83ee9b-2244-4e70-b1f5-5393042af1e4}\PropertyBag" /v "ThisPCPolicy" /t REG_SZ /d "Hide" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{35286a68-3c57-41a1-bbb1-0eae73d76c95}\PropertyBag" /v "ThisPCPolicy" /t REG_SZ /d "Hide" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0ddd015d-b06c-45d5-8c4c-f59713854639}\PropertyBag" /v "ThisPCPolicy" /t REG_SZ /d "Hide" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{31C0DD25-9439-4F12-BF41-7FF4EDA38722}\PropertyBag" /v "ThisPCPolicy" /t REG_SZ /d "Hide" /f
- '<SYSTEM32>\reg.exe' add "HKCR\Directory\shell\runas\command" /v "IsolatedCommand" /t REG_SZ /d "cmd.exe /c takeown /f \"%1\" /r /d y && icacls \"%1\" /grant administrators:F /t" /f
- '<SYSTEM32>\schtasks.exe' /Change /DISABLE /TN "\Microsoft\Office\Office 15 Subscription Heartbeat"
- '<SYSTEM32>\schtasks.exe' /Change /DISABLE /TN "\AdobeAAMUpdater-1.0-xuecudzmj-user"
- '<SYSTEM32>\schtasks.exe' /Change /DISABLE /TN "\Microsoft\Office\OfficeTelemetryAgentLogOn"
- '<SYSTEM32>\schtasks.exe' /Change /DISABLE /TN "\Microsoft\Office\OfficeTelemetryAgentFallBack"
- '<SYSTEM32>\schtasks.exe' /Change /DISABLE /TN "\GoogleUpdateTaskMachineCore"
- '<SYSTEM32>\schtasks.exe' /Change /DISABLE /TN "\GoogleUpdateTaskMachineUA"
- '<SYSTEM32>\schtasks.exe' /Change /DISABLE /TN "\Microsoft\Windows\Diagnosis\Scheduled"
- '<SYSTEM32>\schtasks.exe' /Change /DISABLE /TN "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector"
- '<SYSTEM32>\schtasks.exe' /Change /DISABLE /TN "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver"
- '<SYSTEM32>\schtasks.exe' /Change /DISABLE /TN "\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task"
- '<SYSTEM32>\schtasks.exe' /Change /DISABLE /TN "\Microsoft\Windows\SkyDrive\Routine Maintenance Task"
- '<SYSTEM32>\schtasks.exe' /Change /DISABLE /TN "\Microsoft\Windows\Windows Error Reporting\QueueReporting"
- '<SYSTEM32>\powercfg.exe' -change -hibernate-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' -change -hibernate-timeout-ac 0
- '<SYSTEM32>\sc.exe' config HomeGroupProvider start= DISABLED
- '<SYSTEM32>\sc.exe' config HomeGroupListener start= DISABLED
- '<SYSTEM32>\net1.exe' stop HomeGroupProvider
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP\Clients" /va /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore" /v "RPSessionInterval" /t REG_DWORD /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\Control\Remote Assistance" /v "fAllowToGetHelp" /t REG_DWORD /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers" /v "DisableAutoplay" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\WinRAR\General\Toolbar" /v "Lock" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\WinRAR\Setup\MenuItems" /v "EmailOpt" /t REG_DWORD /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\WinRAR\Setup\MenuItems" /v "EmailArc" /t REG_DWORD /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKCU\Control Panel\International" /v "sShortDate" /t REG_SZ /d "yyyy/M/d dddd" /f
- '<SYSTEM32>\reg.exe' add "HKCU\Control Panel\Desktop" /v "WindowArrangementActive" /t REG_SZ /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Search" /v "AllowCortana" /t REG_DWORD /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Windows Feeds" /v "EnableFeeds" /t REG_DWORD /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Policies\Microsoft\Windows\Explorer" /v "HidePeopleBar" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Search" /v "SearchboxTaskbarMode" /t REG_DWORD /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v "DisableNotificationCenter" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\MicrosoftEdge" /v "PreventFirstRunPage" /t REG_DWORD /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows\HomeGroup" /v "DisableHomeGroup" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Associations" /v "ModRiskFileTypes" /t REG_SZ /d ".bat;.exe;.reg;.vbs;.chm;.msi;.js;.cmd" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer" /v "link" /t REG_BINARY /d "00000000" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "ConfirmFileDelete" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Policies\Microsoft\Windows\AppCompat" /v "DisablePCA" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\Services\mpssvc" /v "Start" /t REG_DWORD /d "4" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Personalization" /v "NoLockScreen" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKCU\Control Panel\Desktop" /v "ScreenSaverIsSecure" /t REG_SZ /d "0" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\Control Panel\Desktop" /v "SCRNSAVE.EXE" /f
- '<SYSTEM32>\powercfg.exe' -h off
- '<SYSTEM32>\bcdedit.exe' /set {current} bootmenupolicy legacy
- '<SYSTEM32>\chkntfs.exe' /t:0
- '<SYSTEM32>\mode.com' 31,4
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows\ScheduledDiagnostics" /v "EnabledExecution" /t REG_DWORD /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\SQMClient\Windows" /v "CEIPEnable" /t REG_DWORD /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore" /v "DisableSR" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "OneDrive" /f
- '<SYSTEM32>\net1.exe' stop HomeGroupListener
- '<SYSTEM32>\reg.exe' delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "OneDriveSetup" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A}" /v "AutoStart" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\Control" /v "WaitToKillServiceTimeout" /t REG_SZ /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer" /v "SmartScreenEnabled" /t REG_SZ /d "Off" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanWorkstation" /v "AllowInsecureGuestAuth" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "ConsentPromptBehaviorAdmin" /t REG_DWORD /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel" /v "{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel" /v "{59031a47-3f72-44a7-89c5-5595fe6b30ee}" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel" /v "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel" /v "{20D04FE0-3AEA-1069-A2D8-08002B30309D}" /t REG_DWORD /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "ListviewShadow" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "IconsOnly" /t REG_DWORD /d "0" /f
- '<SYSTEM32>\reg.exe' add "HKCU\Control Panel\Desktop" /v "FontSmoothing" /t REG_SZ /d "2" /f
- '<SYSTEM32>\schtasks.exe' /Change /DISABLE /TN "\Microsoft\Windows\Maintenance\WinSAT"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag" /v "ThisPCPolicy" /t REG_SZ /d "Hide" /f
- '<SYSTEM32>\raserver.exe' /offerraupdate
- '<SYSTEM32>\reg.exe' add "HKCR\Directory\shell\runas\command" /ve /t REG_SZ /d "cmd.exe /c takeown /f \"%1\" /r /d y && icacls \"%1\" /grant administrators:F /t" /f
- '<SYSTEM32>\reg.exe' add "HKCR\Directory\shell\runas" /v "NoWorkingDirectory" /t REG_SZ /d "" /f
- '<SYSTEM32>\reg.exe' add "HKCR\Directory\shell\runas" /ve /t REG_SZ /d "╣▄└φ╘▒╚Г╡├╦∙╙╨╚Вї" /f
- '<SYSTEM32>\reg.exe' add "HKCR\exefile\shell\runas2\command" /v "IsolatedCommand" /t REG_SZ /d "cmd.exe /c takeown /f \"%1\" && icacls \"%1\" /grant administrators:F" /f
- '<SYSTEM32>\reg.exe' add "HKCR\exefile\shell\runas2\command" /ve /t REG_SZ /d "cmd.exe /c takeown /f \"%1\" && icacls \"%1\" /grant administrators:F" /f
- '<SYSTEM32>\reg.exe' add "HKCR\exefile\shell\runas2" /v "NoWorkingDirectory" /t REG_SZ /d "" /f
- '<SYSTEM32>\reg.exe' add "HKCR\exefile\shell\runas2" /ve /t REG_SZ /d "╣▄└φ╘▒╚Г╡├╦∙╙╨╚Вї" /f
- '<SYSTEM32>\reg.exe' add "HKCR\*\shell\runas\command" /v "IsolatedCommand" /t REG_SZ /d "cmd.exe /c takeown /f \"%1\" && icacls \"%1\" /grant administrators:F" /f
- '<SYSTEM32>\reg.exe' add "HKCR\*\shell\runas\command" /ve /t REG_SZ /d "cmd.exe /c takeown /f \"%1\" && icacls \"%1\" /grant administrators:F" /f
- '<SYSTEM32>\reg.exe' add "HKCR\*\shell\runas" /v "NoWorkingDirectory" /t REG_SZ /d "" /f
- '<SYSTEM32>\reg.exe' add "HKCR\*\shell\runas" /ve /t REG_SZ /d "╣▄└φ╘▒╚Г╡├╦∙╙╨╚Вї" /f
- '<SYSTEM32>\reg.exe' add "HKCR\*\shell\Notepad\Command" /ve /t REG_SZ /d "notepad %1" /f
- '<SYSTEM32>\reg.exe' add "HKCR\*\shell\Notepad" /ve /t REG_SZ /d "╙├╝╟╩┬▒╛┤≥┐В¬╕├╬─╝■" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows\OneDrive" /v "DisableFileSyncNGSC" /t REG_DWORD /d "1" /f
- '<SYSTEM32>\schtasks.exe' /Change /DISABLE /TN "\Microsoft\Windows\Defrag\ScheduledDefrag"
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 2