Technical Information
- Windows Update
- '<SYSTEM32>\net.exe' stop wuauserv
- <SYSTEM32>\cmd.exe
- %TEMP%\d8f0.tmp\d8f1.bat
- nul
- %WINDIR%\Prefetch\42.0.2311.135_CHROME_INSTALLE-7FD75326.pf
- %WINDIR%\Prefetch\SVCHOST.EXE-007FEA55.pf
- %WINDIR%\Prefetch\SVCHOST.EXE-05F624AB.pf
- %WINDIR%\Prefetch\SVCHOST.EXE-63699C7D.pf
- %WINDIR%\Prefetch\SVCHOST.EXE-7CFEDEA3.pf
- %WINDIR%\Prefetch\SVCHOST.EXE-95B0C790.pf
- %WINDIR%\Prefetch\SVCHOST.EXE-CF79EE4C.pf
- %WINDIR%\Prefetch\TASKHOST.EXE-7238F31D.pf
- %WINDIR%\Prefetch\SETUP.EXE-BED2EC70.pf
- %WINDIR%\Prefetch\THUNDERBIRD SETUP 78.9.1 (X64-07C878F8.pf
- %WINDIR%\Prefetch\THUNDERBIRD.EXE-5119524C.pf
- %WINDIR%\Prefetch\TRUSTEDINSTALLER.EXE-3CC531E5.pf
- %WINDIR%\Prefetch\TSETUP.1.4.3.EXE-EF3D6F27.pf
- %WINDIR%\Prefetch\TSETUP.1.4.3.TMP-56512EE9.pf
- %WINDIR%\Prefetch\UNINSTALL.EXE-A11D6B07.pf
- %WINDIR%\Prefetch\STEAMSETUP_2.10.91.91.EXE-91D3EED3.pf
- %WINDIR%\Prefetch\STEAMSERVICE.EXE-57E215D3.pf
- %WINDIR%\Prefetch\SPPSVC.EXE-B0F8131B.pf
- %WINDIR%\Prefetch\SPOOLSV.EXE-D1F6B8B6.pf
- %WINDIR%\Prefetch\SMSS.EXE-E9C28FC6.pf
- %WINDIR%\Prefetch\SIDEBAR.EXE-FA75EA61.pf
- %WINDIR%\Prefetch\SHUTDOWN.EXE-E7D5C9CC.pf
- %WINDIR%\Prefetch\SETX.EXE-A7E52BF4.pf
- %WINDIR%\Prefetch\SETUP.EXE-D38BBFDE.pf
- %WINDIR%\Prefetch\SVCHOST.EXE-FEDB32D0.pf
- %WINDIR%\Prefetch\SETUP.EXE-7C026C7F.pf
- %WINDIR%\Prefetch\SETUP.EXE-663C249B.pf
- %WINDIR%\Prefetch\SETUP.EXE-421F8E21.pf
- %WINDIR%\Prefetch\SETUP.EXE-2EF91A4E.pf
- %WINDIR%\Prefetch\SETUP.EXE-2D9F1C3B.pf
- %WINDIR%\Prefetch\SETUP.EXE-2078B256.pf
- %WINDIR%\Prefetch\SETUP.EXE-04541C92.pf
- %WINDIR%\Prefetch\UNPACK200.EXE-BB96DA5F.pf
- %WINDIR%\Prefetch\UNREGMP2.EXE-2294B148.pf
- %WINDIR%\Prefetch\VCREDIST_X64.EXE-24AEA5D8.pf
- %WINDIR%\Prefetch\VCREDIST_X64.EXE-8227A7EF.pf
- %WINDIR%\Prefetch\VC_REDIST.X86.EXE-4DA5E6B3.pf
- %WINDIR%\Prefetch\VC_REDIST.X86.EXE-92EB15BB.pf
- %WINDIR%\Prefetch\VSSVC.EXE-B8AFC319.pf
- %WINDIR%\Prefetch\WERMGR.EXE-0F2AC88C.pf
- %WINDIR%\Prefetch\WEVTUTIL.EXE-400D93E8.pf
- %WINDIR%\Prefetch\WEVTUTIL.EXE-EF5861C4.pf
- %WINDIR%\Prefetch\WINLOGON.EXE-B020DC41.pf
- %WINDIR%\Prefetch\SERVICES.EXE-511D36F4.pf
- %WINDIR%\Prefetch\WINMAIL.EXE-1092D371.pf
- %WINDIR%\Prefetch\WINMAIL.EXE-F551299C.pf
- %WINDIR%\Prefetch\WINRAR-X64-531.EXE-91D4B934.pf
- %WINDIR%\Prefetch\WMIADAP.EXE-F8DFDFA2.pf
- %WINDIR%\Prefetch\WMIPRVSE.EXE-1628051C.pf
- %WINDIR%\Prefetch\WUAUCLT.EXE-70318591.pf
- %WINDIR%\Prefetch\VC_REDIST.X86.EXE-473D0913.pf
- %WINDIR%\Prefetch\VC_REDIST.X64.EXE-2C3B2083.pf
- %WINDIR%\Prefetch\VC_REDIST.X86.EXE-380848FE.pf
- %WINDIR%\Prefetch\VC_REDIST.X64.EXE-26342EFB.pf
- %WINDIR%\Prefetch\VCREDIST_X64.EXE-A53F124B.pf
- %WINDIR%\Prefetch\VCREDIST_X64.EXE-D4929C6B.pf
- %WINDIR%\Prefetch\VCREDIST_X86.EXE-163EFD5C.pf
- %WINDIR%\Prefetch\VCREDIST_X86.EXE-73B7FF73.pf
- %WINDIR%\Prefetch\VCREDIST_X86.EXE-96CF69CF.pf
- %WINDIR%\Prefetch\VCREDIST_X86.EXE-C622F3EF.pf
- %WINDIR%\Prefetch\WUSA.EXE-F04B35C8.pf
- %WINDIR%\Prefetch\VC_REDIST.X86.EXE-1DCB7807.pf
- %WINDIR%\Prefetch\VC_REDIST.X64.EXE-442857D9.pf
- %WINDIR%\Prefetch\VC_REDIST.X64.EXE-5C158F2F.pf
- %WINDIR%\Prefetch\VC_REDIST.X64.EXE-625F2779.pf
- %WINDIR%\Prefetch\VC_REDIST.X64.EXE-B0C890FD.pf
- %WINDIR%\Prefetch\VC_REDIST.X64.EXE-D3A3C549.pf
- %WINDIR%\Prefetch\VC_REDIST.X86.EXE-1C5672A5.pf
- %WINDIR%\Prefetch\VC_REDIST.X86.EXE-35B8AF5D.pf
- %WINDIR%\Prefetch\WININIT.EXE-5322684A.pf
- %WINDIR%\Prefetch\SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-46A5F75F.pf
- %WINDIR%\Prefetch\DEFAULT-BROWSER-AGENT.EXE-91AA6C8A.pf
- %WINDIR%\Prefetch\DLLHOST.EXE-5E46FA0D.pf
- %WINDIR%\Prefetch\DLLHOST.EXE-766398D2.pf
- %WINDIR%\Prefetch\DLLHOST.EXE-B2EB1806.pf
- %WINDIR%\Prefetch\DRVINST.EXE-4CB4314A.pf
- %WINDIR%\Prefetch\FIREFOX SETUP 78.0.2.EXE-691327D9.pf
- %WINDIR%\Prefetch\IE4UINIT.EXE-3A7E0C67.pf
- %WINDIR%\prefetch\agrobust.db
- %WINDIR%\Prefetch\IE4UINIT.EXE-8B333E8B.pf
- %WINDIR%\Prefetch\INSTALL.EXE-7D6E11A9.pf
- %WINDIR%\Prefetch\INSTALLER.EXE-5857FAFB.pf
- %WINDIR%\Prefetch\INSTALLER.EXE-6C3AB888.pf
- %WINDIR%\Prefetch\JAUREG.EXE-2358F266.pf
- %WINDIR%\Prefetch\JAVAW.EXE-DCCF0AB8.pf
- %WINDIR%\Prefetch\CSRSS.EXE-3FE41F7E.pf
- %WINDIR%\Prefetch\CONHOST.EXE-1F3E9D7E.pf
- %WINDIR%\Prefetch\CMD.EXE-AC113AA8.pf
- %WINDIR%\Prefetch\CMD.EXE-4A81B364.pf
- %WINDIR%\Prefetch\CLRGC.EXE-5D5B90F5.pf
- %WINDIR%\Prefetch\CHROME.EXE-5617A1BF.pf
- %WINDIR%\Prefetch\BSPATCH.EXE-DD9E5E46.pf
- %WINDIR%\Prefetch\BFSVC.EXE-9C7A4DEE.pf
- %WINDIR%\Prefetch\AUDIODG.EXE-BDFD3029.pf
- %WINDIR%\Prefetch\FIREFOX.EXE-18ACFCFF.pf
- %WINDIR%\Prefetch\AgGlUAD_S-1-5-21-1238866942-1249195528-555854008-1000.db
- %WINDIR%\Prefetch\AgGlUAD_P_S-1-5-21-1238866942-1249195528-555854008-1000.db
- %WINDIR%\Prefetch\AgGlGlobalHistory.db
- %WINDIR%\Prefetch\AgGlFgAppHistory.db
- %WINDIR%\Prefetch\AgGlFaultHistory.db
- %WINDIR%\Prefetch\AgAppLaunch.db
- %WINDIR%\Prefetch\ACRORDRDC1501020056_EN_US.EXE-3B58C109.pf
- %WINDIR%\Prefetch\JAVAWS.EXE-ED58C697.pf
- %WINDIR%\Prefetch\JP2LAUNCHER.EXE-7DCCD1B9.pf
- %WINDIR%\Prefetch\JRE-8U45-WINDOWS-X64.EXE-61CC34B3.pf
- %WINDIR%\Prefetch\LSASS.EXE-419F2D06.pf
- %WINDIR%\Prefetch\ReadyBoot\Trace4.fx
- %WINDIR%\Prefetch\REG.EXE-E7E8BD26.pf
- %WINDIR%\Prefetch\REGSVR32.EXE-8461DBEE.pf
- %WINDIR%\Prefetch\REGSVR32.EXE-D5170E12.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-038E6267.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-36DAC103.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-685A8F09.pf
- %WINDIR%\Prefetch\SEARCHINDEXER.EXE-4A6353B9.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-7438E4D5.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-860C49A4.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-9CC17D45.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-A148E651.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-C211633D.pf
- %WINDIR%\Prefetch\RUNDLL32.EXE-E6258EDF.pf
- %WINDIR%\Prefetch\ReadyBoot\Trace3.fx
- %WINDIR%\Prefetch\NETSH.EXE-F1B6DA12.pf
- %WINDIR%\prefetch\ReadyBoot\trace2.fx
- %WINDIR%\Prefetch\NDP48-X86-X64-ALLOS-ENU.EXE-54656820.pf
- %WINDIR%\Prefetch\LSM.EXE-E22FF25C.pf
- %WINDIR%\Prefetch\MCTADMIN.EXE-C9CFA3B9.pf
- %WINDIR%\Prefetch\MSCORSVW.EXE-245ED79E.pf
- %WINDIR%\Prefetch\MSCORSVW.EXE-90526FAC.pf
- %WINDIR%\Prefetch\MSIEXEC.EXE-A2D55CB6.pf
- %WINDIR%\Prefetch\MSIEXEC.EXE-E09A077A.pf
- %WINDIR%\Prefetch\SEARCHFILTERHOST.EXE-77482212.pf
- %WINDIR%\Prefetch\RDRSERVICESUPDATER.EXE-3D26E665.pf
- %WINDIR%\Prefetch\NTOSBOOT-B00DFAAD.pf
- %WINDIR%\Prefetch\OPERA_29.0.1795.47_SETUP.EXE-839F60FD.pf
- %WINDIR%\Prefetch\OPERA_29.0.1795.47_SETUP.EXE-9C628850.pf
- %WINDIR%\Prefetch\OSE.EXE-51C16F0E.pf
- %WINDIR%\Prefetch\OSE00000.EXE-2A4EFDBF.pf
- %WINDIR%\Prefetch\PfSvPerfStats.bin
- %WINDIR%\Prefetch\ReadyBoot\Trace1.fx
- %WINDIR%\Prefetch\XCOPY.EXE-41E6513F.pf
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\D8F0.tmp\D8F1.bat <Full path to file>"
- '<SYSTEM32>\net1.exe' stop wuauserv
- '<SYSTEM32>\sc.exe' config wuauserv start= disabled error= ignore