Technical Information
- <Current directory>\11 (1).exe
- <Current directory>\13 (1).exe
- <Current directory>\13 (2).exe
- <Current directory>\13 (3).exe
- <Current directory>\13 (4).exe
- <Current directory>\13 (5).exe
- <Current directory>\13 (6).exe
- <Current directory>\13 (7).exe
- <Current directory>\13 (8).exe
- <Current directory>\13 (10).exe
- <Current directory>\13 (19).exe
- <Current directory>\13 (11).exe
- <Current directory>\13 (12).exe
- <Current directory>\13 (13).exe
- <Current directory>\13 (14).exe
- <Current directory>\13 (15).exe
- <Current directory>\13 (16).exe
- <Current directory>\13 (17).exe
- <Current directory>\13 (18).exe
- <Current directory>\12 (3).exe
- <Current directory>\13 (9).exe
- <Current directory>\12 (2).exe
- <Current directory>\11 (10).exe
- <Current directory>\11 (2).exe
- <Current directory>\11 (3).exe
- <Current directory>\11 (4).exe
- <Current directory>\11 (5).exe
- <Current directory>\11 (6).exe
- <Current directory>\11 (7).exe
- <Current directory>\11 (8).exe
- <Current directory>\11 (9).exe
- <Current directory>\11 (11).exe
- <Current directory>\11 (20).exe
- <Current directory>\11 (12).exe
- <Current directory>\11 (13).exe
- <Current directory>\11 (14).exe
- <Current directory>\11 (15).exe
- <Current directory>\11 (16).exe
- <Current directory>\11 (17).exe
- <Current directory>\11 (18).exe
- <Current directory>\11 (19).exe
- <Current directory>\12 (1).exe
- <Current directory>\13 (20).exe
- '<Current directory>\11 (1).exe'
- '<Current directory>\13 (3).exe'
- '<Current directory>\13 (4).exe'
- '<Current directory>\13 (5).exe'
- '<Current directory>\13 (6).exe'
- '<Current directory>\13 (8).exe'
- '<Current directory>\13 (9).exe'
- '<Current directory>\13 (10).exe'
- '<Current directory>\13 (11).exe'
- '<Current directory>\13 (7).exe'
- '<Current directory>\13 (2).exe'
- '<Current directory>\13 (15).exe'
- '<Current directory>\13 (16).exe'
- '<Current directory>\13 (17).exe'
- '<Current directory>\13 (18).exe'
- '<Current directory>\13 (19).exe'
- '<Current directory>\13 (20).exe'
- '<Current directory>\13 (12).exe'
- '<Current directory>\13 (13).exe'
- '<Current directory>\13 (14).exe'
- '<Current directory>\12 (3).exe'
- '<Current directory>\13 (1).exe'
- '<Current directory>\12 (1).exe'
- '<Current directory>\11 (10).exe'
- '<Current directory>\11 (4).exe'
- '<Current directory>\11 (5).exe'
- '<Current directory>\12 (2).exe'
- '<Current directory>\11 (7).exe'
- '<Current directory>\11 (8).exe'
- '<Current directory>\11 (9).exe'
- '<Current directory>\11 (11).exe'
- '<Current directory>\11 (2).exe'
- '<Current directory>\11 (12).exe'
- '<Current directory>\11 (3).exe'
- '<Current directory>\11 (13).exe'
- '<Current directory>\11 (20).exe'
- '<Current directory>\11 (19).exe'
- '<Current directory>\11 (18).exe'
- '<Current directory>\11 (16).exe'
- '<Current directory>\11 (17).exe'
- '<Current directory>\11 (15).exe'
- '<Current directory>\11 (6).exe'
- '<Current directory>\11 (14).exe'
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GoogleplugUpdateTaskMachineQC" /f' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "MicrosoftEdgeUpdateTaskMachineUAECE78C85-1670-4798-89BC-9E1510F888B7-36599"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "GoogleUpdateTaskMachineQC"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "FirefoxUpdateTaskMachinesQC"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "GoogleplugERUpdateTaskMachineQC"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "CCleanerSkipEDUAC"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GoogleUpdateTaskMachineQC" /f' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "Opera_scheduled_Autoupdate_1612974563Г§j58566"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "GoogleplugUpdateTaskMachineQC"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "AmdiUpdateTaskMachineQC" /f' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Opera_scheduled_Autoupdate_1612974563Г§j58566" /f' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Opera_Updater_scheduled_Autoupdate_1612974563Г§j58566" /f' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "CCleanerSkipEDUAC" /f' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "AmdiUpdateTaskMachineQC"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Opera_Update_scheduled_Autoupdate_1612974563Г§j58566" /f' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "FirefoxUpdateTaskMachinesQC" /f' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicrosoftEdgeUpdateTaskMachineUAECE78C85-1670-4798-89BC-9E1510F888B7-36599" /f' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GoogleplugERUpdateTaskMachineQC" /f' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "Opera_Update_scheduled_Autoupdate_1612974563Г§j58566"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "Opera_Updater_scheduled_Autoupdate_1612974563Г§j58566"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg copy "HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc_bkp" "HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc" /s /f & reg copy "HKLM\SYSTEM\CurrentControlSet\Services\WaaSMedicSvc_bkp" "HKLM\...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Opera_Updater_scheduled_Autoupdate_1612974563Г§j58566" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GoogleUpdateTaskMachineQC" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "AmdiUpdateTaskMachineQC" /f
- '<SYSTEM32>\schtasks.exe' /delete /f /tn "FirefoxUpdateTaskMachinesQC"
- '<SYSTEM32>\schtasks.exe' /delete /f /tn "Opera_Update_scheduled_Autoupdate_1612974563Г§j58566"
- '<SYSTEM32>\schtasks.exe' /delete /f /tn "MicrosoftEdgeUpdateTaskMachineUAECE78C85-1670-4798-89BC-9E1510F888B7-36599"
- '<SYSTEM32>\schtasks.exe' /delete /f /tn "CCleanerSkipEDUAC"
- '<SYSTEM32>\schtasks.exe' /delete /f /tn "GoogleplugERUpdateTaskMachineQC"
- '<SYSTEM32>\schtasks.exe' /delete /f /tn "GoogleplugUpdateTaskMachineQC"
- '<SYSTEM32>\schtasks.exe' /delete /f /tn "GoogleUpdateTaskMachineQC"
- '<SYSTEM32>\schtasks.exe' /delete /f /tn "AmdiUpdateTaskMachineQC"
- '<SYSTEM32>\schtasks.exe' /delete /f /tn "Opera_scheduled_Autoupdate_1612974563Г§j58566"
- '<SYSTEM32>\reg.exe' delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GoogleplugUpdateTaskMachineQC" /f
- '<SYSTEM32>\reg.exe' copy "HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc_bkp" "HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc" /s /f
- '<SYSTEM32>\reg.exe' copy "HKLM\SYSTEM\CurrentControlSet\Services\BITS_bkp" "HKLM\SYSTEM\CurrentControlSet\Services\BITS" /s /f
- '<SYSTEM32>\reg.exe' copy "HKLM\SYSTEM\CurrentControlSet\Services\dosvc_bkp" "HKLM\SYSTEM\CurrentControlSet\Services\dosvc" /s /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc_bkp" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SYSTEM\CurrentControlSet\Services\WaaSMedicSvc_bkp" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SYSTEM\CurrentControlSet\Services\wuauserv_bkp" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SYSTEM\CurrentControlSet\Services\BITS_bkp" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SYSTEM\CurrentControlSet\Services\dosvc_bkp" /f
- '<SYSTEM32>\sc.exe' start UsoSvc
- '<SYSTEM32>\sc.exe' start WaaSMedicSvc
- '<SYSTEM32>\sc.exe' start wuauserv
- '<SYSTEM32>\reg.exe' copy "HKLM\SYSTEM\CurrentControlSet\Services\WaaSMedicSvc_bkp" "HKLM\SYSTEM\CurrentControlSet\Services\WaaSMedicSvc" /s /f
- '<SYSTEM32>\reg.exe' copy "HKLM\SYSTEM\CurrentControlSet\Services\wuauserv_bkp" "HKLM\SYSTEM\CurrentControlSet\Services\wuauserv" /s /f
- '<SYSTEM32>\reg.exe' delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GoogleplugERUpdateTaskMachineQC" /f
- '<SYSTEM32>\schtasks.exe' /delete /f /tn "Opera_Updater_scheduled_Autoupdate_1612974563Г§j58566"
- '<SYSTEM32>\reg.exe' delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicrosoftEdgeUpdateTaskMachineUAECE78C85-1670-4798-89BC-9E1510F888B7-36599" /f
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Opera_Update_scheduled_Autoupdate_1612974563Г§j58566" /f
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "FirefoxUpdateTaskMachinesQC" /f
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "MicrosoftEdgeUpdateTaskMachineUAECE78C85-1670-4798-89BC-9E1510F888B7-36599" /f
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GoogleplugERUpdateTaskMachineQC" /f
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GoogleplugUpdateTaskMachineQC" /f
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "CCleanerSkipEDUAC" /f
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "Opera_Updater_scheduled_Autoupdate_1612974563Г§j58566"
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "Opera_Update_scheduled_Autoupdate_1612974563Г§j58566"
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "Opera_scheduled_Autoupdate_1612974563Г§j58566"
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "GoogleUpdateTaskMachineQC" /f
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "AmdiUpdateTaskMachineQC" /f
- '<SYSTEM32>\cmd.exe' /c reg delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Opera_scheduled_Autoupdate_1612974563Г§j58566" /f
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "FirefoxUpdateTaskMachinesQC"
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "GoogleplugERUpdateTaskMachineQC"
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "CCleanerSkipEDUAC"
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "GoogleplugUpdateTaskMachineQC"
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "GoogleUpdateTaskMachineQC"
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "AmdiUpdateTaskMachineQC"
- '<SYSTEM32>\cmd.exe' /c reg copy "HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc_bkp" "HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc" /s /f & reg copy "HKLM\SYSTEM\CurrentControlSet\Services\WaaSMedicSvc_bkp" "HKLM\...
- '<SYSTEM32>\reg.exe' delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "FirefoxUpdateTaskMachinesQC" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "CCleanerSkipEDUAC" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Opera_Updater_scheduled_Autoupdate_1612974563Г§j58566" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Opera_scheduled_Autoupdate_1612974563Г§j58566" /f
- '<SYSTEM32>\reg.exe' delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Opera_Update_scheduled_Autoupdate_1612974563Г§j58566" /f
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn "MicrosoftEdgeUpdateTaskMachineUAECE78C85-1670-4798-89BC-9E1510F888B7-36599"
- '<SYSTEM32>\sc.exe' start bits
- '<SYSTEM32>\sc.exe' start dosvc