Technical Information
- file extensions
- '<SYSTEM32>\net.exe' stop wsearch /y
- '<SYSTEM32>\taskkill.exe' /f /im ccleaner.exe
- '<SYSTEM32>\taskkill.exe' /f /im ccleaner64.exe
- <Current directory>\$nullf
- <Current directory>\temp2188.edb
- <Current directory>\tempdfrg2188.edb
- <Current directory>\tempdfrg2188.edb
- '<SYSTEM32>\cmd.exe' /c cls
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Piriform\CCleaner" /v "CheckTrialOffer" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Piriform\CCleaner" /v "(Cfg)HealthCheck" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Piriform\CCleaner" /v "(Cfg)HealthCheck" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Piriform\CCleaner" /v "(Cfg)QuickClean" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Piriform\CCleaner" /v "(Cfg)QuickClean" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Piriform\CCleaner" /v "(Cfg)QuickCleanIpm" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Piriform\CCleaner" /v "(Cfg)QuickCleanIpm" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Piriform\CCleaner" /v "(Cfg)SoftwareUpdater" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Piriform\CCleaner" /v "(Cfg)SoftwareUpdater" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Piriform\CCleaner" /v "(Cfg)SoftwareUpdaterIpm" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Piriform\CCleaner" /v "(Cfg)SoftwareUpdaterIpm" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Tracing\WPPMediaPerApp\Skype\ETW" /v "TraceLevelThreshold" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Tracing\WPPMediaPerApp\Skype\ETW" /v "TraceLevelThreshold" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Tracing\WPPMediaPerApp\Skype" /v "EnableTracing" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Tracing\WPPMediaPerApp\Skype" /v "EnableTracing" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Piriform\CCleaner" /v "CheckTrialOffer" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Google\Chrome" /v "MetricsReportingEnabled" /t REG_SZ /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Piriform\CCleaner" /v "UpdateCheck" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Piriform\CCleaner" /v "UpdateAuto" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Google\Chrome" /v "ChromeCleanupEnabled" /t REG_SZ /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Google\Chrome" /v "ChromeCleanupEnabled" /t REG_SZ /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Google\Chrome" /v "ChromeCleanupReportingEnabled" /t REG_SZ /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Google\Chrome" /v "ChromeCleanupReportingEnabled" /t REG_SZ /d 0 /f
- '<SYSTEM32>\cmd.exe' /c taskkill /f /im ccleaner.exe >nul 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /f /im ccleaner64.exe >nul 2>nul
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Piriform\CCleaner" /v "HomeScreen" /t REG_SZ /d 2 /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Piriform\CCleaner" /v "HomeScreen" /t REG_SZ /d 2 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Piriform\CCleaner" /v "Monitoring" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Piriform\CCleaner" /v "Monitoring" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Piriform\CCleaner" /v "HelpImproveCCleaner" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Piriform\CCleaner" /v "HelpImproveCCleaner" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Piriform\CCleaner" /v "SystemMonitoring" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Piriform\CCleaner" /v "SystemMonitoring" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Piriform\CCleaner" /v "UpdateAuto" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Piriform\CCleaner" /v "UpdateCheck" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Google\Chrome" /v "MetricsReportingEnabled" /t REG_SZ /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Tracing\WPPMediaPerApp\Skype\ETW" /v "EnableTracing" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Tracing\WPPMediaPerApp\Skype\ETW" /v "WPPFilePath" /t REG_SZ /d "%%SYSTEMDRIVE%%\TEMP\WPPMedia" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\InputPersonalization" /v RestrictImplicitTextCollection /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Reporting" /v "DisableGenericReports" /t REG_DWORD /d 2 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Reporting" /v "DisableGenericReports" /t REG_DWORD /d 2 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\MRT" /v "DontReportInfectionInformation" /t REG_DWORD /d 2 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\MRT" /v "DontReportInfectionInformation" /t REG_DWORD /d 2 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v "LocalSettingOverrideSpynetReporting" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\Software\Microsoft\VisualStudio\Telemetry" /v "TurnOffSwitch" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v "LocalSettingOverrideSpynetReporting" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v "SpynetReporting" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCUSOFTWARE\Microsoft\Personalization\Settings" /v AcceptedPrivacyPolicy /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCUSOFTWARE\Microsoft\Personalization\Settings" /v AcceptedPrivacyPolicy /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore" /v HarvestContacts /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore" /v HarvestContacts /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Search" /v "AllowCortana" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\InputPersonalization" /v RestrictImplicitInkCollection /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\InputPersonalization" /v RestrictImplicitTextCollection /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Tracing\WPPMediaPerApp\Skype" /v "WPPFilePath" /t REG_SZ /d "%%SYSTEMDRIVE%%\TEMP\Tracing\WPPMedia" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Tracing\WPPMediaPerApp\Skype\ETW" /v "EnableTracing" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Input\TIPC" /v Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Tracing\WPPMediaPerApp\Skype\ETW" /v "WPPFilePath" /t REG_SZ /d "%C:%\TEMP\WPPMedia" /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\MediaPlayer\Preferences" /v "UsageTracking" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\MediaPlayer\Preferences" /v "UsageTracking" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Mozilla\Firefox" /v "DisableTelemetry" /t REG_DWORD /d 2 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Mozilla\Firefox" /v "DisableTelemetry" /t REG_DWORD /d 2 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\AdvertisingInfo" /v Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\AdvertisingInfo" /v Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\CPSS\Store\AdvertisingInfo" /v "Value" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Microsoft\Windows\CurrentVersion\CPSS\Store\AdvertisingInfo" /v "Value" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\Software\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\appDiagnostics" /v "Value" /t REG_SZ /d "Deny" /f
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\appDiagnostics" /v "Value" /t REG_SZ /d "Deny" /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\appDiagnostics" /v "Value" /t REG_SZ /d "Deny" /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\appDiagnostics" /v "Value" /t REG_SZ /d "Deny" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Input\TIPC" /v Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Tracing\WPPMediaPerApp\Skype" /v "WPPFilePath" /t REG_SZ /d "%C:%\TEMP\Tracing\WPPMedia" /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\InputPersonalization" /v RestrictImplicitInkCollection /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Microsoft\VisualStudio\Telemetry" /v "TurnOffSwitch" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Wow6432Node\Microsoft\VSCommon\14.0\SQM" /v "OptIn" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Feeds" /v EnableFeeds /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\Control\WMI\AutoLogger\AutoLogger-Diagtrack-Listener" /v "Start" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SYSTEM\CurrentControlSet\Control\WMI\AutoLogger\SQMLogger" /v "Start" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\Control\WMI\AutoLogger\SQMLogger" /v "Start" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\Software\Microsoft\Windows\CurrentVersion\Privacy" /v "TailoredExperiencesWithDiagnosticDataEnabled" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Microsoft\Windows\CurrentVersion\Privacy" /v "TailoredExperiencesWithDiagnosticDataEnabled" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SYSTEM\ControlSet001\Control\WMI\Autologger\AutoLogger-Diagtrack-Listener" /v "Start" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\ControlSet001\Control\WMI\Autologger\AutoLogger-Diagtrack-Listener" /v "Start" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SYSTEM\ControlSet001\Services\dmwappushservice" /v "Start" /t REG_DWORD /d 4 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\ControlSet001\Services\dmwappushservice" /v "Start" /t REG_DWORD /d 4 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SYSTEM\ControlSet001\Services\DiagTrack" /v "Start" /t REG_DWORD /d 4 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\ControlSet001\Services\DiagTrack" /v "Start" /t REG_DWORD /d 4 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Office\Common\ClientTelemetry" /v "DisableTelemetry" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Office\Common\ClientTelemetry" /v "DisableTelemetry" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppCompat" /v "DisableUAR" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppCompat" /v "AITEnable" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SYSTEM\CurrentControlSet\Control\WMI\AutoLogger\AutoLogger-Diagtrack-Listener" /v "Start" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Office\17.0\Common\ClientTelemetry" /v "DisableTelemetry" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Office\16.0\Common\ClientTelemetry" /v "DisableTelemetry" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Office\16.0\Common\ClientTelemetry" /v "DisableTelemetry" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CompatTelRunner.exe" /v Debugger /t REG_SZ /d "<SYSTEM32>\taskkill.exe" /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CompatTelRunner.exe" /v Debugger /t REG_SZ /d "<SYSTEM32>\taskkill.exe" /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DeviceCensus.exe" /v Debugger /t REG_SZ /d "<SYSTEM32>\taskkill.exe" /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DeviceCensus.exe" /v Debugger /t REG_SZ /d "<SYSTEM32>\taskkill.exe" /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Device Metadata" /v PreventDeviceMetadataFromNetwork /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Device Metadata" /v PreventDeviceMetadataFromNetwork /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection" /v "AllowTelemetry" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection" /v "AllowTelemetry" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\Software\Policies\Microsoft\Windows\DataCollection" /v "AllowTelemetry" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Policies\Microsoft\Windows\DataCollection" /v "AllowTelemetry" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\MRT" /v DontOfferThroughWUAU /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\MRT" /v DontOfferThroughWUAU /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\SQMClient\Windows" /v "CEIPEnable" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppCompat" /v "AITEnable" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl\StorageTelemetry" /v DeviceDumpEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\SQMClient\Windows" /v "CEIPEnable" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Office\17.0\Common\ClientTelemetry" /v "DisableTelemetry" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Policies\Microsoft\Office\16.0\OSM" /v "EnableLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Office\16.0\Common\ClientTelemetry" /v "VerboseLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Policies\Microsoft\Office\15.0\OSM" /v "EnableUpload" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Policies\Microsoft\Office\16.0\OSM" /v "EnableUpload" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Policies\Microsoft\Office\16.0\OSM" /v "EnableUpload" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Policies\Microsoft\Office\17.0\OSM" /v "EnableUpload" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Policies\Microsoft\Office\17.0\OSM" /v "EnableUpload" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows\AppCompat" /v "DisableUAR" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c sc stop VSStandardCollectorService150
- '<SYSTEM32>\sc.exe' stop VSStandardCollectorService150
- '<SYSTEM32>\cmd.exe' /c cmd /c sc config VSStandardCollectorService150 start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config VSStandardCollectorService150 start= disabled
- '<SYSTEM32>\sc.exe' config VSStandardCollectorService150 start= disabled
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\Software\Wow6432Node\Microsoft\VSCommon\14.0\SQM" /v "OptIn" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Policies\Microsoft\Office\15.0\OSM" /v "EnableLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Policies\Microsoft\Office\15.0\OSM" /v "EnableLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c sc stop VSStandardCollectorService150
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Policies\Microsoft\Office\15.0\OSM" /v "EnableUpload" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Policies\Microsoft\Office\16.0\OSM" /v "EnableLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Office\17.0\Word\Options" /v "EnableLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Office\17.0\Word\Options" /v "EnableLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Office\16.0\Common\ClientTelemetry" /v "VerboseLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Office\15.0\Outlook\Options\Mail" /v "EnableLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Office\15.0\Outlook\Options\Mail" /v "EnableLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Options\Mail" /v "EnableLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Search" /v "AllowCortana" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Options\Mail" /v "EnableLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Office\15.0\Outlook\Options\Calendar" /v "EnableCalendarLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v "SpynetReporting" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Options\Calendar" /v "EnableCalendarLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Office\15.0\Word\Options" /v "EnableLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Office\15.0\Word\Options" /v "EnableLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Office\16.0\Word\Options" /v "EnableLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Office\16.0\Word\Options" /v "EnableLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Office\15.0\Outlook\Options\Calendar" /v "EnableCalendarLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Office\Common\ClientTelemetry" /v "VerboseLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Office\Common\ClientTelemetry" /v "VerboseLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Options\Calendar" /v "EnableCalendarLogging" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKLM\Software\Policies\Microsoft\PushToInstall /v DisablePushToInstall /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Feeds" /v EnableFeeds /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c ipconfig /flushdns >NUL
- '<SYSTEM32>\ipconfig.exe' /flushdns
- '<SYSTEM32>\cmd.exe' /c netsh interface ipv4 add dnsservers "Ethernet" address=1.1.1.1 index=1 >NUL
- '<SYSTEM32>\netsh.exe' interface ipv4 add dnsservers "Ethernet" address=1.1.1.1 index=1
- '<SYSTEM32>\cmd.exe' /c netsh interface ipv4 add dnsservers "Ethernet" address=8.8.8.8 index=2 >NUL
- '<SYSTEM32>\netsh.exe' interface ipv4 add dnsservers "Ethernet" address=8.8.8.8 index=2
- '<SYSTEM32>\cmd.exe' /c netsh interface ipv4 add dnsservers "Wi-Fi" address=1.1.1.1 index=1 >NUL
- '<SYSTEM32>\netsh.exe' interface ipv4 add dnsservers "Wi-Fi" address=1.1.1.1 index=1
- '<SYSTEM32>\cmd.exe' /c netsh interface ipv4 add dnsservers "Wi-Fi" address=8.8.8.8 index=2 >NUL
- '<SYSTEM32>\netsh.exe' interface ipv4 add dnsservers "Wi-Fi" address=8.8.8.8 index=2
- '<SYSTEM32>\cmd.exe' /c wget https://downloads.malwarebytes.com/file/adwcleaner -O %ProgramData%\adwcleaner.exe >NUL
- '<SYSTEM32>\cmd.exe' /c cmd /c if exist %ProgramData%\adwcleaner.exe start /WAIT %ProgramData%\adwcleaner.exe /eula /clean /noreboot >NUL
- '<SYSTEM32>\cmd.exe' /c if exist %ALLUSERSPROFILE%\adwcleaner.exe start /WAIT %ALLUSERSPROFILE%\adwcleaner.exe /eula /clean /noreboot
- '<SYSTEM32>\cmd.exe' /c del %ProgramData%\adwcleaner.exe >NUL
- '<SYSTEM32>\cmd.exe' /c arp -d *
- '<SYSTEM32>\cmd.exe' /c cmd /c Del "%ProgramData%\Microsoft\Windows Defender\Scans\History\Results\Resource" /F /Q /S >$null 2>$null
- '<SYSTEM32>\arp.exe' -d *
- '<SYSTEM32>\cmd.exe' /c cmd /c Del "%ProgramData%\Microsoft\Windows Defender\Scans\History\Results\Quick" /F /Q /S >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c Del "%ProgramData%\Microsoft\Windows Defender\Scans\MetaStore" /F /Q /S >$null 2>$null
- '<SYSTEM32>\sc.exe' config AJRouter start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop amdfendr
- '<SYSTEM32>\sc.exe' stop amdfendr
- '<SYSTEM32>\cmd.exe' /c sc config amdfendr start= disabled
- '<SYSTEM32>\sc.exe' config amdfendr start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop amdfendrmgr
- '<SYSTEM32>\sc.exe' stop amdfendrmgr
- '<SYSTEM32>\cmd.exe' /c sc config amdfendrmgr start= disabled
- '<SYSTEM32>\sc.exe' config amdfendrmgr start= disabled
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ndu" /v "Start" /t REG_DWORD /d 4 /f
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Ndu" /v "Start" /t REG_DWORD /d 4 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c Del "%ProgramData%\Microsoft\Windows Defender\Network Inspection System\Support\*.log" /F /Q /S >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c Del "%ProgramData%\Microsoft\Windows Defender\Scans\History\CacheManager" /F /Q /S >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c Del "%ProgramData%\Microsoft\Windows Defender\Scans\History\ReportLatencyLatency" /F /Q /S >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c Del "%ProgramData%\Microsoft\Windows Defender\Scans\History\Service\*.log" /F /Q /S >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c Del "%ProgramData%\Microsoft\Windows Defender\Support" /F /Q /S >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c route -f
- '<SYSTEM32>\route.exe' -f
- '<SYSTEM32>\cmd.exe' /c nbtstat -R
- '<SYSTEM32>\netsh.exe' winsock reset catalog
- '<SYSTEM32>\netsh.exe' advfirewall reset
- '<SYSTEM32>\cmd.exe' /c netsh int reset all
- '<SYSTEM32>\netsh.exe' int reset all
- '<SYSTEM32>\cmd.exe' /c netsh int ipv4 reset
- '<SYSTEM32>\netsh.exe' int ipv4 reset
- '<SYSTEM32>\cmd.exe' /c netsh int ipv6 reset
- '<SYSTEM32>\sc.exe' stop AJRouter
- '<SYSTEM32>\netsh.exe' int ipv6 reset
- '<SYSTEM32>\ipconfig.exe' / release
- '<SYSTEM32>\cmd.exe' /c ipconfig / /flushdns
- '<SYSTEM32>\ipconfig.exe' / /flushdns
- '<SYSTEM32>\cmd.exe' /c ipconfig / flushdns
- '<SYSTEM32>\ipconfig.exe' / flushdns
- '<SYSTEM32>\cmd.exe' /c netsh winsock reset catalog
- '<SYSTEM32>\netsh.exe' winsock reset
- '<SYSTEM32>\cmd.exe' /c netsh advfirewall reset
- '<SYSTEM32>\cmd.exe' /c netsh winsock reset
- '<SYSTEM32>\netsh.exe' int tcp reset all
- '<SYSTEM32>\nbtstat.exe' -R
- '<SYSTEM32>\nbtstat.exe' -RR
- '<SYSTEM32>\cmd.exe' /c netcfg -d
- '<SYSTEM32>\netcfg.exe' -d
- '<SYSTEM32>\cmd.exe' /c netsh int httpstunnel reset all
- '<SYSTEM32>\netsh.exe' int httpstunnel reset all
- '<SYSTEM32>\cmd.exe' /c sc config AJRouter start= disabled
- '<SYSTEM32>\cmd.exe' /c netsh int ip reset
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Assistance\Client\1.0" /v NoActiveHelp /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c netsh int isatap reset all
- '<SYSTEM32>\cmd.exe' /c netsh int portproxy reset all
- '<SYSTEM32>\netsh.exe' int portproxy reset all
- '<SYSTEM32>\cmd.exe' /c netsh int teredo reset all
- '<SYSTEM32>\netsh.exe' int teredo reset all
- '<SYSTEM32>\cmd.exe' /c netsh int tcp reset all
- '<SYSTEM32>\netsh.exe' int ip reset
- '<SYSTEM32>\cmd.exe' /c nbtstat -RR
- '<SYSTEM32>\netsh.exe' int isatap reset all
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl\StorageTelemetry" /v DeviceDumpEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\sc.exe' config diagsvc start= disabled
- '<SYSTEM32>\sc.exe' stop SEMgrSvc
- '<SYSTEM32>\cmd.exe' /c sc config RemoteAccess start= disabled
- '<SYSTEM32>\sc.exe' config RemoteAccess start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop SCardSvr
- '<SYSTEM32>\sc.exe' stop SCardSvr
- '<SYSTEM32>\cmd.exe' /c sc config SCardSvr start= disabled
- '<SYSTEM32>\sc.exe' config SCardSvr start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop SCPolicySvc
- '<SYSTEM32>\sc.exe' stop SCPolicySvc
- '<SYSTEM32>\cmd.exe' /c sc config SCPolicySvc start= disabled
- '<SYSTEM32>\sc.exe' config SCPolicySvc start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop fax
- '<SYSTEM32>\sc.exe' stop fax
- '<SYSTEM32>\cmd.exe' /c sc config fax start= disabled
- '<SYSTEM32>\sc.exe' config fax start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop RemoteAccess
- '<SYSTEM32>\cmd.exe' /c sc stop WerSvc
- '<SYSTEM32>\sc.exe' config RemoteRegistry start= disabled
- '<SYSTEM32>\sc.exe' stop RemoteRegistry
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v TaskbarDa /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c winget uninstall "windows web experience pack" --accept-source-agreements
- '<SYSTEM32>\cmd.exe' /c sc stop DiagTrack
- '<SYSTEM32>\sc.exe' stop DiagTrack
- '<SYSTEM32>\cmd.exe' /c sc config DiagTrack start= disabled
- '<SYSTEM32>\sc.exe' config DiagTrack start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop diagnosticshub.standardcollector.service
- '<SYSTEM32>\sc.exe' stop diagnosticshub.standardcollector.service
- '<SYSTEM32>\cmd.exe' /c sc config diagnosticshub.standardcollector.service start= disabled
- '<SYSTEM32>\sc.exe' config diagnosticshub.standardcollector.service start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop dmwappushservice
- '<SYSTEM32>\sc.exe' stop dmwappushservice
- '<SYSTEM32>\cmd.exe' /c sc config dmwappushservice start= disabled
- '<SYSTEM32>\sc.exe' config dmwappushservice start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop RemoteRegistry
- '<SYSTEM32>\cmd.exe' /c sc config RemoteRegistry start= disabled
- '<SYSTEM32>\sc.exe' stop WerSvc
- '<SYSTEM32>\cmd.exe' /c sc config WerSvc start= disabled
- '<SYSTEM32>\sc.exe' config WerSvc start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop WalletService
- '<SYSTEM32>\cmd.exe' /c sc config WalletService start= disabled
- '<SYSTEM32>\sc.exe' config WalletService start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop RetailDemo
- '<SYSTEM32>\sc.exe' stop RetailDemo
- '<SYSTEM32>\cmd.exe' /c sc config RetailDemo start= disabled
- '<SYSTEM32>\sc.exe' config RetailDemo start= disabled
- '<SYSTEM32>\sc.exe' stop RemoteAccess
- '<SYSTEM32>\cmd.exe' /c sc stop SEMgrSvc
- '<SYSTEM32>\cmd.exe' /c sc config SEMgrSvc start= disabled
- '<SYSTEM32>\sc.exe' config SEMgrSvc start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop diagsvc
- '<SYSTEM32>\sc.exe' stop diagsvc
- '<SYSTEM32>\cmd.exe' /c sc config diagsvc start= disabled
- '<SYSTEM32>\sc.exe' config lfsvc start= disabled
- '<SYSTEM32>\cmd.exe' /c sc config lfsvc start= disabled
- '<SYSTEM32>\sc.exe' stop WalletService
- '<SYSTEM32>\sc.exe' stop lfsvc
- '<SYSTEM32>\cmd.exe' /c sc stop lfsvc
- '<SYSTEM32>\cmd.exe' /c sc stop NvTelemetryContainer
- '<SYSTEM32>\cmd.exe' /c sc config NvTelemetryContainer start= disabled
- '<SYSTEM32>\sc.exe' config NvTelemetryContainer start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop gadjservice
- '<SYSTEM32>\sc.exe' stop gadjservice
- '<SYSTEM32>\cmd.exe' /c sc config gadjservice start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop AJRouter
- '<SYSTEM32>\sc.exe' config gadjservice start= disabled
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v TaskbarDa /t REG_DWORD /d 0 /f
- '<SYSTEM32>\sc.exe' stop AdobeARMservice
- '<SYSTEM32>\sc.exe' config AdobeARMservice start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop PSI_SVC_2
- '<SYSTEM32>\sc.exe' stop PSI_SVC_2
- '<SYSTEM32>\cmd.exe' /c sc config PSI_SVC_2 start= disabled
- '<SYSTEM32>\sc.exe' config PSI_SVC_2 start= disabled
- '<SYSTEM32>\cmd.exe' /c sc stop AdobeARMservice
- '<SYSTEM32>\sc.exe' stop NvTelemetryContainer
- '<SYSTEM32>\cmd.exe' /c sc config AdobeARMservice start= disabled
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Assistance\Client\1.0" /v NoActiveHelp /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v HideRecentlyAddedApps /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v HideRecentlyAddedApps /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games /v "Priority" /t REG_DWORD /d 6 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverride /t REG_DWORD /d 3 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverride /t REG_DWORD /d 3 /f
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverride /t REG_DWORD /d 3 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverrideMask /t REG_DWORD /d 3 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverrideMask /t REG_DWORD /d 3 /f
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverrideMask /t REG_DWORD /d 3 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Sensor\Permissions\{BFA794E4 - F964 - 4FDB - 90F6 - 51056BFE4B44}" /v SensorPermissionState /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Sensor\Permissions\{BFA794E4 - F964 - 4FDB - 90F6 - 51056BFE4B44}" /v SensorPermissionState /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Sensor\Permissions\{BFA794E4 - F964 - 4FDB - 90F6 - 51056BFE4B44}" /v SensorPermissionState /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKLM\Software\Microsoft\PolicyManager\default\WiFi\AllowWiFiHotSpotReporting" /v value /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\Software\Microsoft\PolicyManager\default\WiFi\AllowWiFiHotSpotReporting" /v value /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Microsoft\PolicyManager\default\WiFi\AllowWiFiHotSpotReporting" /v value /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games /v "GPU Priority" /t REG_DWORD /d 8 /f
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games /v "SFIO Priority" /t REG_SZ /d "High" /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games /v "Priority" /t REG_DWORD /d 6 /f
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Microsoft\PolicyManager\default\WiFi\AllowAutoConnectToWiFiSenseHotspots" /v value /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKLM\Software\Microsoft\PolicyManager\default\WiFi\AllowAutoConnectToWiFiSenseHotspots" /v value /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\Software\Microsoft\PolicyManager\default\WiFi\AllowAutoConnectToWiFiSenseHotspots" /v value /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c bcdedit /set {current} numproc 2
- '<SYSTEM32>\cmd.exe' /c bcdedit /set {current} numproc 2
- '<SYSTEM32>\bcdedit.exe' /set {current} numproc 2
- '<SYSTEM32>\cmd.exe' /c wmic cpu get name | findstr /r "Intel"
- '<SYSTEM32>\wbem\wmic.exe' cpu get name
- '<SYSTEM32>\findstr.exe' /r "Intel"
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games /v Affinity /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games /v Affinity /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games /v "Background Only" /t REG_SZ /d "False" /f
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games /v "Background Only" /t REG_SZ /d "False" /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games /v "Clock Rate" /t REG_DWORD /d 10000 /f
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games /v "Clock Rate" /t REG_DWORD /d 10000 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games /v "Scheduling Category" /t REG_SZ /d "High" /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games /v "SFIO Priority" /t REG_SZ /d "High" /f
- '<SYSTEM32>\wbem\wmic.exe' cpu get NumberOfLogicalProcessors
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games /v "Scheduling Category" /t REG_SZ /d "High" /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v UxOption /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338387Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config" /v DODownloadMode /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338388Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338388Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338389Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338389Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338389Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Search" /v BackgroundAppGlobalToggle /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338393Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338393Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-353698Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-353698Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-353698Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\UserProfileEngagement /v ScoobeSystemSettingEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338387Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-314563Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338393Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338388Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338387Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-314563Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-314563Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config" /v DODownloadMode /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config" /v DODownloadMode /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control" /v "WaitToKillServiceTimeout" /t REG_SZ /d 2000 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control" /v "WaitToKillServiceTimeout" /t REG_SZ /d 2000 /f
- '<SYSTEM32>\cmd.exe' /c wmic cpu get NumberOfLogicalProcessors | findstr /r "[0-9]"
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control" /v "WaitToKillServiceTimeout" /t REG_SZ /d 2000 /f
- '<SYSTEM32>\cmd.exe' /c SET DEVMGR_SHOW_NONPRESENT_DEVICES=1
- '<SYSTEM32>\findstr.exe' /r "[0-9]"
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-310093Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-310093Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-314559Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-314559Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-314559Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c SET DEVMGR_SHOW_NONPRESENT_DEVICES=1
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v UxOption /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v UxOption /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-310093Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c ipconfig / renew
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\UserProfileEngagement /v ScoobeSystemSettingEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDIS\Parameters /v ThreadPriority /t REG_DWORD /d 31 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c powercfg /S ceb6bfc7-d55c-4d56-ae37-ff264aade12d >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c powercfg /X standby-timeout-ac 0 >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c powercfg /X standby-timeout-dc 0 >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c bcdedit /timeout 3
- '<SYSTEM32>\cmd.exe' /c bcdedit /timeout 3
- '<SYSTEM32>\bcdedit.exe' /timeout 3
- '<SYSTEM32>\cmd.exe' /c cmd /c powercfg -hibernate off
- '<SYSTEM32>\cmd.exe' /c powercfg -hibernate off
- '<SYSTEM32>\powercfg.exe' -hibernate off
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKLM\SOFTWARE\Microsoft\PolicyManager\current\device\System" /v "AllowExperimentation" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Microsoft\PolicyManager\current\device\System" /v "AllowExperimentation" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\PolicyManager\current\device\System" /v "AllowExperimentation" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKLM\SOFTWARE\Microsoft\PolicyManager\default\System\AllowExperimentation" /v "value" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Microsoft\PolicyManager\default\System\AllowExperimentation" /v "value" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c powercfg -setactive scheme_min >$null 2>$null
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\PolicyManager\default\System\AllowExperimentation" /v "value" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge" /v WebWidgetAllowed /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge" /v WebWidgetAllowed /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "HideFileExt" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "HideFileExt" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "HideFileExt" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Themes\Personalize" /v "EnableTransparency" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Themes\Personalize" /v "EnableTransparency" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Themes\Personalize" /v "EnableTransparency" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v "EnableTransparency" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v "EnableTransparency" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v "EnableTransparency" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "Start_TrackDocs" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "Start_TrackDocs" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "Start_TrackDocs" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "LaunchTo" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "LaunchTo" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "LaunchTo" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge" /v WebWidgetAllowed /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "Start_TrackProgs" /d 0 /t REG_DWORD /f
- '<SYSTEM32>\cmd.exe' /c cmd /c powercfg -setactive e9a42b02-d5df-448d-aa00-03f14749eb61 >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "Start_TrackProgs" /d 0 /t REG_DWORD /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Main" /v DoNotTrack /t REG_DWORD /d ...
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\User\Default\SearchScopes" /v...
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\User\Default\SearchScopes" /v ShowSe...
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FlipAhead" /v FPEnable...
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FlipAhead" /v FPEnabled /t RE...
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FlipAhead" /v FPEnabled /t REG_DWORD...
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\WindowsCurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" /v Enab...
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\WindowsCurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" /v EnabledV9 /...
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\WindowsCurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" /v EnabledV9 /t REG_D...
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbxhci\Parameters /v ThreadPriority /t REG_DWORD /d 31 /f
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbxhci\Parameters /v ThreadPriority /t REG_DWORD /d 31 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBHUB3\Parameters /v ThreadPriority /t REG_DWORD /d 31 /f
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBHUB3\Parameters /v ThreadPriority /t REG_DWORD /d 31 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NDIS\Parameters /v ThreadPriority /t REG_DWORD /d 31 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Main" /v DoNotTrack /t REG_DW...
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsStore" /v "AutoDownload" /t REG_DWORD /d 2 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\User\Default\SearchSco...
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Main" /v DoNotTrack /t...
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsStore" /v "AutoDownload" /t REG_DWORD /d 2 /f
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "Start_TrackProgs" /d 0 /t REG_DWORD /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SYSTEM\CurrentControlSet\Control\Power\PowerThrottling" /v "PowerThrottlingOff" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\Control\Power\PowerThrottling" /v "PowerThrottlingOff" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c REG ADD "HKEY_CURRENT_USERSoftware\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications" /v GlobalUserDisabled /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_CURRENT_USERSoftware\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications" /v GlobalUserDisabled /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_CURRENT_USERSoftware\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications" /v GlobalUserDisabled /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c REG ADD "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Search" /v BackgroundAppGlobalToggle /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvlddmkm\Parameters /v ThreadPriority /t REG_DWORD /d 31 /f
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvlddmkm\Parameters /v ThreadPriority /t REG_DWORD /d 31 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Search" /v BackgroundAppGlobalToggle /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_CURRENT_USER\Control Panel\Accessibility\StickyKeys" /v "Flags" /t REG_SZ /d 506 /f
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Control Panel\Accessibility\StickyKeys" /v "Flags" /t REG_SZ /d 506 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System" /v "PublishUserActivities" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System" /v "PublishUserActivities" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System" /v "PublishUserActivities" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsStore" /v "AutoDownload" /t REG_DWORD /d 2 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKLM\SYSTEM\CurrentControlSet\Control\Power\PowerThrottling" /v "PowerThrottlingOff" /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKEY_CURRENT_USER\Control Panel\Accessibility\StickyKeys" /v "Flags" /t REG_SZ /d 506 /f
- '<SYSTEM32>\cmd.exe' /c ipconfig / release
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\UserProfileEngagement /v ScoobeSystemSettingEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Policies\Microsoft\Windows\CloudContent /v DisableWindowsConsumerFeatures /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Office\OfficeTelemetryAgentLogOn" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Office\OfficeTelemetryAgentFallBack" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Office\OfficeTelemetryAgentFallBack2016" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Office\OfficeTelemetryAgentLogOn2016" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Office\Office 15 Subscription Heartbeat" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Office\Office 16 Subscription Heartbeat" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\Windows Error Reporting\QueueReporting" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\WindowsUpdate\Automatic App Update" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "NIUpdateServiceStartupTask" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "CCleaner Update" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "CCleanerCrashReportings" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "CCleanerSkipUAC - $env:username" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "updater" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Adobe Acrobat Update Task" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "MicrosoftEdgeUpdateTaskMachineCore" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\Shell\FamilySafetyUpload" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "MicrosoftEdgeUpdateTaskMachineUA" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\Uploader" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvent" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c esentutl /d %ALLUSERSPROFILE%\Microsoft\Search\Data\Applications\Windows\Windows.edb
- '<SYSTEM32>\cmd.exe' /c esentutl /d %ALLUSERSPROFILE%\Microsoft\Search\Data\Applications\Windows\Windows.edb
- '<SYSTEM32>\esentutl.exe' /d %ALLUSERSPROFILE%\Microsoft\Search\Data\Applications\Windows\Windows.edb
- '<SYSTEM32>\cmd.exe' /c cmd /c net start wsearch
- '<SYSTEM32>\cmd.exe' /c net start wsearch
- '<SYSTEM32>\net.exe' start wsearch
- '<SYSTEM32>\net1.exe' start wsearch
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\AppID\SmartScreenSpecific" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\Application Experience\ProgramDataUpdater" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\Application Experience\StartupAppTask" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\Consolidator" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\UsbCeip" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "MiniToolPartitionWizard" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "AMDLinkUpdate" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Office\Office Feature Updates" /Disable >$null 2>$null
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoInstrumentation /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoInstrumentation /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoInstrumentation /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\HandwritingErrorReports" /v PreventHandwritingErrorReports /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\HandwritingErrorReports" /v PreventHandwritingErrorReports /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\CloudContent /v DisableWindowsConsumerFeatures /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v DoNotShowFeedbackNotifications /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v AllowDeviceNameInTelemetry /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v AllowDeviceNameInTelemetry /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer" /v SmartScreenEnabled /t REG_SZ /d "Off" /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer" /v SmartScreenEnabled /t REG_SZ /d "Off" /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_CURRENT_USER\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" ...
- '<SYSTEM32>\reg.exe' ADD "HKEY_CURRENT_USER\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" /v Enab...
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NvTelemetryContainer" /v Start /t REG_DWORD /d 4 /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v DoNotShowFeedbackNotifications /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoInstrumentation /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NvTelemetryContainer" /v Start /t REG_DWORD /d 4 /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Global\FTS" /v EnableRID66610 /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Global\FTS" /v EnableRID66610 /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Office\Office Feature Updates Logon" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "GoogleUpdateTaskMachineCore" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "GoogleUpdateTaskMachineUA" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "AMDInstallLauncher" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "AMDRyzenMasterSDKTask" /Disable >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c net stop wsearch /y
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "DUpdaterTask" /Disable >$null 2>$null
- '<SYSTEM32>\net1.exe' stop wsearch /y
- '<SYSTEM32>\cmd.exe' /c del /q "%temp%\NVIDIA Corporation\NV_Cache\*" >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\NvControlPanel2\Client" /v OptInOrOutPreference /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\NvControlPanel2\Client" /v OptInOrOutPreference /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Global\FTS" /v EnableRID44231 /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Global\FTS" /v EnableRID44231 /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Global\FTS" /v EnableRID64640 /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Office\Office Automatic Updates 2.0" /Disable >$null 2>$null
- '<SYSTEM32>\reg.exe' ADD "HKEY_LOCAL_MACHINE\SOFTWARE\NVIDIA Corporation\Global\FTS" /v EnableRID64640 /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c del /q "%programdata%\NVIDIA Corporation\NV_Cache\*" >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\CloudContent /v DisableWindowsConsumerFeatures /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "ModifyLinkUpdate" /Disable >$null 2>$null
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games /v "GPU Priority" /t REG_DWORD /d 8 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SoftLandingEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SoftLandingEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v RemediationRequired /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v RemediationRequired /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v RemediationRequired /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContentEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContentEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContentEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-310093Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-310093Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-310093Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338388Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338388Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338388Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338389Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SoftLandingEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338389Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v FeatureManagementEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v FeatureManagementEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v ContentDeliveryAllowed /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v ContentDeliveryAllowed /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v ContentDeliveryAllowed /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v OemPreInstalledAppsEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v OemPreInstalledAppsEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v OemPreInstalledAppsEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v PreInstalledAppsEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v PreInstalledAppsEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v PreInstalledAppsEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v PreInstalledAppsEverEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v PreInstalledAppsEverEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v PreInstalledAppsEverEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SilentInstalledAppsEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SilentInstalledAppsEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SilentInstalledAppsEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v FeatureManagementEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338389Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338393Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338393Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v RotatingLockScreenOverlayEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v RotatingLockScreenOverlayEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v RotatingLockScreenOverlayEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add "HKLM\SOFTWARE\Microsoft\PolicyManager\default\WindowsInkWorkspace\AllowSuggestedAppsInWindowsInkWorkspace" /v "value" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Microsoft\PolicyManager\default\WindowsInkWorkspace\AllowSuggestedAppsInWindowsInkWorkspace" /v "value" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /RL LIMITED
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\PolicyManager\default\WindowsInkWorkspace\AllowSuggestedAppsInWindowsInkWorkspace" /v "value" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Disable-WindowsOptionalFeature -Online -FeatureName Printing-PrintToPDFServices-Features -NoRestart"
- '<SYSTEM32>\cmd.exe' /c powershell -Command "Disable-WindowsOptionalFeature -Online -FeatureName Printing-XPSServices-Features -NoRestart"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Disable-WindowsOptionalFeature -Online -FeatureName Printing-XPSServices-Features -NoRestart"
- '<SYSTEM32>\cmd.exe' /c powershell -Command "Disable-WindowsOptionalFeature -Online -FeatureName Xps-Foundation-Xps-Viewer -NoRestart"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Disable-WindowsOptionalFeature -Online -FeatureName Xps-Foundation-Xps-Viewer -NoRestart"
- '<SYSTEM32>\cmd.exe' /c cmd /c schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /RL LIMITED >$null 2>$nullf
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v RotatingLockScreenEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c powershell -Command "Disable-WindowsOptionalFeature -Online -FeatureName Printing-PrintToPDFServices-Features -NoRestart"
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v RotatingLockScreenEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v RotatingLockScreenEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v ShowSyncProviderNotifications /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v ShowSyncProviderNotifications /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-353694Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-353694Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-353694Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-353696Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-353696Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\schtasks.exe' /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /RL LIMITED
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-353696Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c net stop wsearch /y
- '<SYSTEM32>\cmd.exe' /c reg add HKLM\Software\Policies\Microsoft\PushToInstall /v DisablePushToInstall /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions /f >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\SuggestedApps /f >$null 2>$null
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SystemPaneSuggestionsEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SystemPaneSuggestionsEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SystemPaneSuggestionsEnabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager /v SubscribedContent-338393Enabled /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c cmd /c reg add HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced /v ShowSyncProviderNotifications /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add HKLM\Software\Policies\Microsoft\PushToInstall /v DisablePushToInstall /t REG_DWORD /d 1 /f
- '<SYSTEM32>\ipconfig.exe' / renew