chcp.com chcp 65001
2816reg.exe reg query "HKU\S-1-5-19"
2884reg.exe reg add "HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v "AppsUseLightTheme" /t reg_dword /d 0 /f
2928chcp.com chcp 65001
2204reg.exe reg query "HKU\S-1-5-19"
2244reg.exe reg add "HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v "AppsUseLightTheme" /t reg_dword /d 0 /f
2424mode.com Mode 79,49
2524cmd.exe C:\Windows\system32\cmd.exe /c ver
2576reg.exe reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v "EnableLUA"
2688find.exe find /i "0x0"
2564tasklist.exe tasklist
2872reg.exe reg query "HKLM\System\CurrentControlSet\Services\WinDefend"
2868reg.exe reg query "HKLM\System\CurrentControlSet\Services\MDCoreSvc"
604reg.exe reg query "HKLM\System\CurrentControlSet\Services\WdNisSvc"
2988reg.exe reg query "HKLM\System\CurrentControlSet\Services\Sense"
1356reg.exe reg query "HKLM\System\CurrentControlSet\Services\wscsvc"
1384reg.exe reg query "HKLM\System\CurrentControlSet\Services\SgrmBroker"
2472reg.exe reg query "HKLM\System\CurrentControlSet\Services\SecurityHealthService"
2544reg.exe reg query "HKLM\System\CurrentControlSet\Services\webthreatdefsvc"
2612reg.exe reg query "HKLM\System\CurrentControlSet\Services\webthreatdefusersvc"
2800reg.exe reg query "HKLM\System\CurrentControlSet\Services\WdNisDrv"
2924reg.exe reg query "HKLM\System\CurrentControlSet\Services\WdBoot"
2372reg.exe reg query "HKLM\System\CurrentControlSet\Services\WdFilter"
2080reg.exe reg query "HKLM\System\CurrentControlSet\Services\SgrmAgent"
148reg.exe reg query "HKLM\System\CurrentControlSet\Services\MsSecWfp"
2320reg.exe reg query "HKLM\System\CurrentControlSet\Services\MsSecFlt"
2532reg.exe reg query "HKLM\System\CurrentControlSet\Services\MsSecCore"
2608reg.exe reg query HKLM\System\CurrentControlset\Services\WdFilter
2904reg.exe reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion" /v "ProductName"
2392find.exe find /i "Windows 7"
192cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ver "
2240findstr.exe findstr /c:"6.1.7601"
2672sc.exe sc config "WinDefend" start= disabled
2956sc.exe sc stop "WinDefend"
2784sc.exe sc delete "WinDefend"
2380reg.exe reg delete "HKLM\System\CurrentControlset\Services\WinDefend" /f
2520sc.exe sc config "MDCoreSvc" start= disabled
884sc.exe sc stop "MDCoreSvc"
560sc.exe sc delete "MDCoreSvc"
2208reg.exe reg delete "HKLM\System\CurrentControlset\Services\MDCoreSvc" /f
504sc.exe sc config "WdNisSvc" start= disabled
2720sc.exe sc stop "WdNisSvc"
1120sc.exe sc delete "WdNisSvc"
2776reg.exe reg delete "HKLM\System\CurrentControlset\Services\WdNisSvc" /f
1796sc.exe sc config "Sense" start= disabled
2652sc.exe sc stop "Sense"
2064sc.exe sc delete "Sense"
2052reg.exe reg delete "HKLM\System\CurrentControlset\Services\Sense" /f
1864sc.exe sc config "wscsvc" start= disabled
232sc.exe sc stop "wscsvc"
1892sc.exe sc delete "wscsvc"
1852reg.exe reg delete "HKLM\System\CurrentControlset\Services\wscsvc" /f
1560sc.exe sc config "SgrmBroker" start= disabled
3108sc.exe sc stop "SgrmBroker"
3156sc.exe sc delete "SgrmBroker"
3204reg.exe reg delete "HKLM\System\CurrentControlset\Services\SgrmBroker" /f
3252sc.exe sc config "SecurityHealthService" start= disabled
3300sc.exe sc stop "SecurityHealthService"
3348sc.exe sc delete "SecurityHealthService"
3396reg.exe reg delete "HKLM\System\CurrentControlset\Services\SecurityHealthService" /f
3444sc.exe sc config "webthreatdefsvc" start= disabled
3488sc.exe sc stop "webthreatdefsvc"
3536sc.exe sc delete "webthreatdefsvc"
3584reg.exe reg delete "HKLM\System\CurrentControlset\Services\webthreatdefsvc" /f
3632sc.exe sc config "webthreatdefusersvc" start= disabled
3676sc.exe sc stop "webthreatdefusersvc"
3732sc.exe sc delete "webthreatdefusersvc"
3780reg.exe reg delete "HKLM\System\CurrentControlset\Services\webthreatdefusersvc" /f
3852sc.exe sc config "WdNisDrv" start= disabled
3896sc.exe sc stop "WdNisDrv"
3944sc.exe sc delete "WdNisDrv"
3992reg.exe reg delete "HKLM\System\CurrentControlset\Services\WdNisDrv" /f
4040sc.exe sc config "WdBoot" start= disabled
4084sc.exe sc stop "WdBoot"
3128sc.exe sc delete "WdBoot"
3188reg.exe reg delete "HKLM\System\CurrentControlset\Services\WdBoot" /f
1108sc.exe sc config "WdFilter" start= disabled
3316sc.exe sc stop "WdFilter"
3376sc.exe sc delete "WdFilter"
3460reg.exe reg delete "HKLM\System\CurrentControlset\Services\WdFilter" /f
3532sc.exe sc config "SgrmAgent" start= disabled
3600sc.exe sc stop "SgrmAgent"
3660sc.exe sc delete "SgrmAgent"
1632reg.exe reg delete "HKLM\System\CurrentControlset\Services\SgrmAgent" /f
3680sc.exe sc config "MsSecWfp" start= disabled
3796sc.exe sc stop "MsSecWfp"
3848sc.exe sc delete "MsSecWfp"
3924reg.exe reg delete "HKLM\System\CurrentControlset\Services\MsSecWfp" /f
4012sc.exe sc config "MsSecFlt" start= disabled
4072sc.exe sc stop "MsSecFlt"
2932sc.exe sc delete "MsSecFlt"
3216reg.exe reg delete "HKLM\System\CurrentControlset\Services\MsSecFlt" /f
3340sc.exe sc config "MsSecCore" start= disabled
3428sc.exe sc stop "MsSecCore"
3552sc.exe sc delete "MsSecCore"
3664reg.exe reg delete "HKLM\System\CurrentControlset\Services\MsSecCore" /f
3692schtasks.exe schtasks /Delete /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /f
3812schtasks.exe schtasks /Delete /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /f
3964schtasks.exe schtasks /Delete /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /f
4060schtasks.exe schtasks /Delete /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /f
3184schtasks.exe schtasks /Delete /TN "Microsoft\Windows\AppID\SmartScreenSpecific" /f
3248reg.exe reg delete "HKLM\Software\Microsoft\Windows Defender" /f
3504reg.exe reg delete "HKLM\Software\Microsoft\Windows Defender Security Center" /f
3648reg.exe reg delete "HKLM\Software\Microsoft\Windows Advanced Threat Protection" /f
3704reg.exe reg delete "HKLM\Software\Microsoft\Windows Security Health" /f
3844reg.exe reg delete "HKLM\System\CurrentControlset\Control\WMI\Autologger\DefenderApiLogger" /f
4036reg.exe reg delete "HKLM\System\CurrentControlset\Control\WMI\Autologger\DefenderAuditLogger" /f
4008reg.exe reg delete "HKCR\*\shellex\ContextMenuHandlers\EPP" /f
3352reg.exe reg delete "HKCR\Directory\shellex\ContextMenuHandlers\EPP" /f
3564reg.exe reg delete "HKCR\Drive\shellex\ContextMenuHandlers\EPP" /f
1316reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v "SecurityHealth" /f
3784reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v "WindowsDefender" /f
3236reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run" /v "SecurityHealth" /f
3360reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Windows Defender" /f
3880reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC" /f
3436reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\Channels\NIS-Driver-WFP/Diagnostic" /f
3588reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/Operational" /f
3424reg.exe reg delete "HKLM\Software\Microsoft\SystemSettings\SettingId\SystemSettings_WindowsDefender_UseWindowsDefender" /f
3628reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{D8559EB9-20C0-410E-BEDA-7ED416AECC2A}" /f
1320sc.exe sc start VMTools
4124sc.exe sc start VMTools
4172