Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Messenger] 'Start' = '00000002'
- <SYSTEM32>\net.exe stop "aswUpdSv"
- <SYSTEM32>\sc.exe stop ashWebSv
- <SYSTEM32>\sc.exe stop ashServ
- <SYSTEM32>\net1.exe stop "ashServ"
- <SYSTEM32>\net.exe stop "ashServ"
- <SYSTEM32>\net1.exe stop "aswUpdSv"
- <SYSTEM32>\sc.exe config aswUpdSv start= disabled
- <SYSTEM32>\tskill.exe "ekrn"
- <SYSTEM32>\tskill.exe "EhttpSrv"
- <SYSTEM32>\sc.exe stop aswUpdSv
- <SYSTEM32>\sc.exe config ashWebSv start= disabled
- <SYSTEM32>\sc.exe config ashServ start= disabled
- <SYSTEM32>\net.exe stop "ashWebSv"
- <SYSTEM32>\sc.exe config SNDSrvc start= disabled
- <SYSTEM32>\sc.exe config ccSetMgr start= disabled
- <SYSTEM32>\sc.exe config ccPwdSvc start= disabled
- <SYSTEM32>\sc.exe config TMBMServer start= disabled
- <SYSTEM32>\sc.exe config symlcsvc start= disabled
- <SYSTEM32>\sc.exe config SymWSC start= disabled
- <SYSTEM32>\tskill.exe "ashServ"
- <SYSTEM32>\tskill.exe "aswUpdSv"
- <SYSTEM32>\net1.exe stop "ashWebSv"
- <SYSTEM32>\sc.exe config ccProxy start= disabled
- <SYSTEM32>\sc.exe config ccEvtMgr start= disabled
- <SYSTEM32>\tskill.exe "ashWebSv"
- <SYSTEM32>\net1.exe stop "Tmntsrv"
- <SYSTEM32>\net.exe stop "Tmntsrv"
- <SYSTEM32>\net1.exe stop "PcCtlCom"
- <SYSTEM32>\net.exe stop "tmproxy"
- <SYSTEM32>\net1.exe stop "TmPfw"
- <SYSTEM32>\net.exe stop "TmPfw"
- <SYSTEM32>\sc.exe stop Tmntsrv
- <SYSTEM32>\sc.exe stop PcCtlCom
- <SYSTEM32>\sc.exe config tmproxy start= disabled
- <SYSTEM32>\net.exe stop "PcCtlCom"
- <SYSTEM32>\sc.exe stop tmproxy
- <SYSTEM32>\sc.exe stop TmPfw
- <SYSTEM32>\net1.exe stop "tmproxy"
- <SYSTEM32>\net.exe stop "EhttpSrv"
- <SYSTEM32>\sc.exe stop ekrn
- <SYSTEM32>\sc.exe stop EhttpSrv
- <SYSTEM32>\net1.exe stop "ekrn"
- <SYSTEM32>\net.exe stop "ekrn"
- <SYSTEM32>\net1.exe stop "EhttpSrv"
- <SYSTEM32>\tskill.exe "Tmntsrv"
- <SYSTEM32>\tskill.exe "TmPfw"
- <SYSTEM32>\tskill.exe "tmproxy"
- <SYSTEM32>\sc.exe config ekrn start= disabled
- <SYSTEM32>\sc.exe config EhttpSrv start= disabled
- <SYSTEM32>\tskill.exe "PcCtlCom"
- <SYSTEM32>\tskill.exe "ntrtscan"
- <SYSTEM32>\tskill.exe "OfcPfwSvc"
- <SYSTEM32>\tskill.exe "TMBMServer"
- <SYSTEM32>\sc.exe config NPFMntor start= disabled
- <SYSTEM32>\sc.exe config navapsvc start= disabled
- <SYSTEM32>\tskill.exe "SAVscan"
- <SYSTEM32>\tskill.exe "ccSetMgr"
- <SYSTEM32>\net1.exe stop "SAVscan"
- <SYSTEM32>\net.exe stop "SAVscan"
- <SYSTEM32>\tskill.exe "symlcsvc"
- <SYSTEM32>\tskill.exe "SymWSC"
- <SYSTEM32>\tskill.exe "SNDSrvc"
- <SYSTEM32>\sc.exe config NSCService start= disabled
- <SYSTEM32>\net1.exe stop "NSCService"
- <SYSTEM32>\net.exe stop "NSCService"
- <SYSTEM32>\net1.exe stop "NPFMntor"
- <SYSTEM32>\tskill.exe "navapsvc"
- <SYSTEM32>\tskill.exe "NPFMntor"
- <SYSTEM32>\tskill.exe "NSCService"
- <SYSTEM32>\sc.exe stop NSCService
- <SYSTEM32>\sc.exe stop NPFMntor
- <SYSTEM32>\sc.exe stop navapsvc
- <SYSTEM32>\net.exe stop "NPFMntor"
- <SYSTEM32>\net1.exe stop "navapsvc"
- <SYSTEM32>\net.exe stop "navapsvc"
- <SYSTEM32>\sc.exe stop OfcPfwSvc
- <SYSTEM32>\sc.exe stop TMBMServer
- <SYSTEM32>\sc.exe stop symlcsvc
- <SYSTEM32>\net.exe stop "ccSetMgr"
- <SYSTEM32>\sc.exe stop SAVscan
- <SYSTEM32>\sc.exe stop ntrtscan
- <SYSTEM32>\sc.exe config SAVscan start= disabled
- <SYSTEM32>\sc.exe config ntrtscan start= disabled
- <SYSTEM32>\sc.exe config OfcPfwSvc start= disabled
- <SYSTEM32>\sc.exe stop SymWSC
- <SYSTEM32>\sc.exe stop SNDSrvc
- <SYSTEM32>\sc.exe stop ccSetMgr
- <SYSTEM32>\net1.exe stop "ccSetMgr"
- <SYSTEM32>\net.exe stop "OfcPfwSvc"
- <SYSTEM32>\net1.exe stop "TMBMServer"
- <SYSTEM32>\net.exe stop "TMBMServer"
- <SYSTEM32>\net1.exe stop "ntrtscan"
- <SYSTEM32>\net.exe stop "ntrtscan"
- <SYSTEM32>\net1.exe stop "OfcPfwSvc"
- <SYSTEM32>\net.exe stop "SymWSC"
- <SYSTEM32>\net1.exe stop "SNDSrvc"
- <SYSTEM32>\net.exe stop "SNDSrvc"
- <SYSTEM32>\net1.exe stop "symlcsvc"
- <SYSTEM32>\net.exe stop "symlcsvc"
- <SYSTEM32>\net1.exe stop "SymWSC"
- <SYSTEM32>\sc.exe config TmPfw start= disabled
- <SYSTEM32>\sc.exe config MpfService start= disabled
- <SYSTEM32>\sc.exe config McDetect.exe start= disabled
- <SYSTEM32>\sc.exe config MSK80Service start= disabled
- <SYSTEM32>\sc.exe stop McAfeeFramework
- <SYSTEM32>\sc.exe stop McShield
- <SYSTEM32>\sc.exe stop McTaskManager
- <SYSTEM32>\sc.exe config McNASvc start= disabled
- <SYSTEM32>\sc.exe config mcmscsvc start= disabled
- <SYSTEM32>\sc.exe config McAfeeFramework start= disabled
- <SYSTEM32>\sc.exe config McSysmon start= disabled
- <SYSTEM32>\sc.exe config McProxy start= disabled
- <SYSTEM32>\sc.exe config McODS start= disabled
- <SYSTEM32>\sc.exe stop mcmscsvc
- <SYSTEM32>\net1.exe stop "McTaskManager"
- <SYSTEM32>\net.exe stop "McTaskManager"
- <SYSTEM32>\sc.exe stop MpfService
- <SYSTEM32>\net.exe stop "McAfeeFramework"
- <SYSTEM32>\net1.exe stop "McShield"
- <SYSTEM32>\net.exe stop "McShield"
- <SYSTEM32>\sc.exe stop McProxy
- <SYSTEM32>\sc.exe stop McODS
- <SYSTEM32>\sc.exe stop McNASvc
- <SYSTEM32>\sc.exe stop McDetect
- <SYSTEM32>\sc.exe stop MSK80Service
- <SYSTEM32>\sc.exe stop McSysmon
- <SYSTEM32>\sc.exe config ERSvc start= disabled
- <SYSTEM32>\tskill.exe "Messenger"
- <SYSTEM32>\net1.exe start "Messenger"
- <SYSTEM32>\net1.exe stop "ERSvc"
- <SYSTEM32>\net.exe stop "ERSvc"
- <SYSTEM32>\sc.exe stop ERSvc
- <SYSTEM32>\net1.exe start "mnsrvc"
- <SYSTEM32>\sc.exe start mnsrvc
- <SYSTEM32>\sc.exe config mnsrvc start= auto
- <SYSTEM32>\sc.exe start Messenger
- <SYSTEM32>\sc.exe config Messenger start= auto
- <SYSTEM32>\tskill.exe "mnsrvc"
- <SYSTEM32>\tskill.exe "ERSvc"
- <SYSTEM32>\tskill.exe "AntiVirService"
- <SYSTEM32>\net1.exe stop "AntiVirScheduler"
- <SYSTEM32>\net.exe stop "AntiVirScheduler"
- <SYSTEM32>\sc.exe config McShield start= disabled
- <SYSTEM32>\sc.exe config McTaskManager start= disabled
- <SYSTEM32>\tskill.exe "AntiVirScheduler"
- <SYSTEM32>\sc.exe stop AntiVirService
- <SYSTEM32>\sc.exe config AntiVirScheduler start= disabled
- <SYSTEM32>\sc.exe config AntiVirService start= disabled
- <SYSTEM32>\net1.exe stop "AntiVirService"
- <SYSTEM32>\net.exe stop "AntiVirService"
- <SYSTEM32>\sc.exe stop AntiVirScheduler
- <SYSTEM32>\sc.exe config Vsmon start= disabled
- <SYSTEM32>\tskill.exe "SmcService"
- <SYSTEM32>\net1.exe stop "SmcService"
- <SYSTEM32>\net1.exe stop "Vsmon"
- <SYSTEM32>\net.exe stop "Vsmon"
- <SYSTEM32>\sc.exe stop Vsmon
- <SYSTEM32>\tskill.exe "McTaskManager"
- <SYSTEM32>\tskill.exe "McShield"
- <SYSTEM32>\tskill.exe "McAfeeFramework"
- <SYSTEM32>\net.exe stop "SmcService"
- <SYSTEM32>\sc.exe stop SmcService
- <SYSTEM32>\sc.exe config SmcService start= disabled
- <SYSTEM32>\tskill.exe "Vsmon"
- <SYSTEM32>\tskill.exe "Avg7Alrt"
- <SYSTEM32>\net1.exe stop "Avg7Alrt"
- <SYSTEM32>\net.exe stop "Avg7Alrt"
- <SYSTEM32>\sc.exe config Tmntsrv start= disabled
- <SYSTEM32>\sc.exe config PcCtlCom start= disabled
- <SYSTEM32>\tskill.exe "avg8wd"
- <SYSTEM32>\sc.exe stop avg8wd
- <SYSTEM32>\sc.exe config Avg7Alrt start= disabled
- <SYSTEM32>\sc.exe config avg8wd start= disabled
- <SYSTEM32>\net1.exe stop "avg8wd"
- <SYSTEM32>\net.exe stop "avg8wd"
- <SYSTEM32>\sc.exe stop Avg7Alrt
- <SYSTEM32>\net1.exe stop "McProxy"
- <SYSTEM32>\net.exe stop "McProxy"
- <SYSTEM32>\net1.exe stop "McODS"
- <SYSTEM32>\net.exe stop "MSK80Service"
- <SYSTEM32>\net1.exe stop "McSysmon"
- <SYSTEM32>\net.exe stop "McSysmon"
- <SYSTEM32>\net1.exe stop "mcmscsvc"
- <SYSTEM32>\net.exe stop "mcmscsvc"
- <SYSTEM32>\net1.exe stop "McAfeeFramework"
- <SYSTEM32>\net.exe stop "McODS"
- <SYSTEM32>\net1.exe stop "McNASvc"
- <SYSTEM32>\net.exe stop "McNASvc"
- <SYSTEM32>\net1.exe stop "MSK80Service"
- <SYSTEM32>\tskill.exe "McProxy"
- <SYSTEM32>\tskill.exe "McSysmon"
- <SYSTEM32>\tskill.exe "MSK80Service"
- <SYSTEM32>\tskill.exe "mcmscsvc"
- <SYSTEM32>\tskill.exe "McNASvc"
- <SYSTEM32>\tskill.exe "McODS"
- <SYSTEM32>\net.exe stop "MpfService"
- <SYSTEM32>\net1.exe stop "McDetect"
- <SYSTEM32>\net.exe stop "McDetect"
- <SYSTEM32>\tskill.exe "McDetect"
- <SYSTEM32>\tskill.exe "MpfService"
- <SYSTEM32>\net1.exe stop "MpfService"
- ekrn.exe
- %TEMP%\bt87344.bat
- %TEMP%\bt87344.bat
- %TEMP%\bt87344.bat