@ -2,77 +2,77 @@ title: Files
description : delete files
privilege : TrustedInstaller
actions:
- !run:
exeDir : true
exe : "SERV.bat"
- !cmd :
command : "taskkill /f /im explorer.exe "
- !cmd :
command : "taskkill /f /im msedge.ex e"
# - ! run:
# exeDir: true
# exe: "SERV.bat"
- !taskkill :
name : "explorer"
- !taskkill :
name : "msedge"
- !task:
path : "\\Microsoft\\Windows\\Customer Experience Improvement Program\\Consolidator"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\Customer Experience Improvement Program\\KernelCeipTask"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\Application Experience\\Microsoft Compatibility Appraiser"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\Application Experience\\ProgramDataUpdater"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\Application Experience\\StartupAppTask"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\Clip\\License Validation"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\Customer Experience Improvement Program\\UsbCeip"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\HelloFace\\FODCleanupTask"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\Maps\\MapsToastTask"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\Maps\\MapsUpdateTask"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\UpdateOrchestrator\\Schedule Scan"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\UpdateOrchestrator\\Schedule Scan Static Task"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\UpdateOrchestrator\\UpdateModelTask"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\UpdateOrchestrator\\USO_UxBroker"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\Windows Defender\\Windows Defender Cache Maintenance"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\Windows Defender\\Windows Defender Cleanup"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\Windows Defender\\Windows Defender Scheduled Scan"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\Windows Defender\\Windows Defender Verification"
state : absent
operation : delete
- !task:
path : "\\Microsoft\\Windows\\WindowsUpdate\\Scheduled Start"
state : absent
operation : delete
- !taskkill:
name : "NisSrv"
- !taskkill:
name : "MicrosoftEdgeUpdate "
name : "SecurityHealthHost "
- !taskkill:
name : "SecurityHealthService"
- !taskkill:
@ -99,6 +99,32 @@ actions:
path : "%windir%\\System32\\SecurityHealthSSO.dll"
- !file:
path : "%windir%\\System32\\smartscreenps.dll"
- !file:
path : "%windir%\\System32\\wlidsvc.dll"
- !file:
path : "%windir%\\System32\\WpcDesktopMonSvc.dll"
- !file:
path : "%windir%\\System32\\flightsettings.dll"
- !file:
path : "%windir%\\System32\\drivers\\cldflt.sys"
- !file:
path : "%windir%\\System32\\WebThreatDefSvc"
- !file:
path : "%windir%\\System32\\webthreatdefsvc.dll"
- !file:
path : "%windir%\\System32\\en-US\\webthreatdefsvc.dll.mui"
- !file:
path : "%windir%\\System32\\webthreatdefusersvc.dll"
- !file:
path : "%windir%\\System32\\en-US\\webthreatdefusersvc.dll.mui"
- !file:
path : "%windir%\\System32\\AgentService.exe"
- !file:
path : "%windir%\\System32\\InstallService.dll"
- !file:
path : "%windir%\\System32\\cloudidsvc.dll"
- !file:
path : "%windir%\\System32\\devicecensus.exe"
- !file:
path : "%ProgramFiles(x86)%\\Windows Media Player"
- !file:
@ -115,6 +141,12 @@ actions:
path : "%windir%\\System32\\SecurityHealthHost.exe"
- !file:
path : "%windir%\\System32\\SecurityHealthAgent.dll"
- !file:
path : "%windir%\\System32\\SecurityHealthCore.dll"
- !file:
path : "%windir%\\System32\\SecurityHealthProxyStub.dll"
- !file:
path : "%windir%\\System32\\SecurityHealthUdk.dll"
- !file:
path : "%windir%\\System32\\wscsvc.dll"
- !file:
@ -126,6 +158,8 @@ actions:
- !file:
path : "%ProgramFiles(x86)%\\Windows Defender"
weight : 10
- !file:
path : "%windir%\\System32\\drivers\\WdNisDrv.sys"
- !file:
path : "%ProgramData%\\Microsoft OneDrive"
- !file:
@ -155,9 +189,11 @@ actions:
- !file:
path : "%ProgramW6432%\\Windows Defender Advanced Threat Protection"
- !file:
path : "C: \\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection"
path : "%SystemDrive% \\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection"
- !file:
path : "%windir%\\System32\\MoNotificationUx.exe"
- !file:
path : "%windir%\\System32\\MoNotificationUxStub.exe"
- !file:
path : "%windir%\\System32\\MusNotifyIcon.exe"
- !file:
@ -172,8 +208,17 @@ actions:
path : "%windir%\\System32\\MusUxToastHandler.dll"
- !file:
path : "%windir%\\UUS"
# - !file:
# path: "%windir%\\SoftwareDistribution"
- !service:
name : "bits"
operation : stop
- !service:
name : "appidsvc"
operation : stop
- !service:
name : "cryptsvc"
operation : stop
- !file:
path : "%windir%\\SoftwareDistribution"
- !file:
path : "%windir%\\System32\\OOBE"
# - !file:
@ -210,15 +255,15 @@ actions:
- !file:
path : "%windir%\\SysWOW64\\WindowsPowerShell\\v1.0\\Modules\\AppLocker\\AppLocker.psd1"
- !file:
path : "C: \\ProgramData\\Microsoft\\Diagnosis\\ETLLogs\\Autologger\\AutoLogger-Diagtrack-Listener.etl"
path : "%SystemDrive% \\ProgramData\\Microsoft\\Diagnosis\\ETLLogs\\Autologger\\AutoLogger-Diagtrack-Listener.etl"
- !file:
path : "C: \\Users\\All Users\\Microsoft\\Diagnosis\\ETLLogs\\Autologger\\AutoLogger-Diagtrack-Listener.etl"
path : "%SystemDrive% \\Users\\All Users\\Microsoft\\Diagnosis\\ETLLogs\\Autologger\\AutoLogger-Diagtrack-Listener.etl"
- !file:
path : "%windir%\\System32\\WindowsPowerShell\\v1.0\\Modules\\EventTracingManagement\\MSFT_AutologgerConfig_v1.0.cdxml"
- !file:
path : "%windir%\\SysWOW64\\WindowsPowerShell\\v1.0\\Modules\\EventTracingManagement\\MSFT_AutologgerConfig_v1.0.cdxml"
- !file:
path : "C: \\Documents and Settings\\All Users\\Microsoft\\Diagnosis\\ETLLogs\\Autologger\\AutoLogger-Diagtrack-Listener.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\Microsoft\\Diagnosis\\ETLLogs\\Autologger\\AutoLogger-Diagtrack-Listener.etl"
- !file:
path : "%windir%\\System32\\WindowsPowerShell\\v1.0\\Modules\\EventTracingManagement\\MSFT_AutologgerConfig_v1.0.format.ps1xml"
- !file:
@ -231,26 +276,34 @@ actions:
path : "%windir%\\SysWOW64\\WindowsPowerShell\\v1.0\\Modules\\Provisioning\\provautologger_add.reg"
- !file:
path : "%windir%\\SysWOW64\\WindowsPowerShell\\v1.0\\Modules\\Provisioning\\provautologger_del.reg"
- !file:
path : "%windir%\\System32\\OneDriveSetup.exe"
- !file:
path : "%windir%\\SysWOW64\\OneDriveSetup.exe"
- !file:
path : "%windir%\\SysWOW64\\OneDriveSettingSyncProvider.dll"
- !file:
path : "%SystemDrive%\\OneDriveTemp"
- !file:
path : "%windir%\\System32\\IESettingSync.exe"
- !file:
path : "%windir%\\System32\\gamepanel.exe"
#- !file:
# path: "%windir%\\System32\\ClipSVC.dll"
#- !file:
# path: "%windir%\\System32\\en-US\\clipsvc.dll.mui"
- !file:
path : "C:\\ProgramData\\Microsoft\\Windows\\ClipSVC\\tokens.dat"
path : "%SystemDrive% \\ProgramData\\Microsoft\\Windows\\ClipSVC\\tokens.dat"
- !file:
path : "C: \\Users\\All Users\\Microsoft\\Windows\\ClipSVC\\tokens.dat"
path : "%SystemDrive% \\Users\\All Users\\Microsoft\\Windows\\ClipSVC\\tokens.dat"
- !file:
path : "C: \\Documents and Settings\\All Users\\Microsoft\\Windows\\ClipSVC\\tokens.dat"
path : "%SystemDrive% \\Documents and Settings\\All Users\\Microsoft\\Windows\\ClipSVC\\tokens.dat"
- !file:
path : "C: \\ProgramData\\Microsoft\\Windows\\ClipSVC"
path : "%SystemDrive% \\ProgramData\\Microsoft\\Windows\\ClipSVC"
- !file:
path : "C: \\Users\\All Users\\Microsoft\\Windows\\ClipSVC"
path : "%SystemDrive% \\Users\\All Users\\Microsoft\\Windows\\ClipSVC"
- !file:
path : "C: \\Documents and Settings\\All Users\\Microsoft\\Windows\\ClipSVC"
path : "%SystemDrive% \\Documents and Settings\\All Users\\Microsoft\\Windows\\ClipSVC"
- !file:
path : "%windir%\\System32\\ClipUp.exe"
- !file:
@ -352,17 +405,17 @@ actions:
- !file:
path : "%windir%\\DiagTrack\\Settings\\telemetry.ASM-WindowsDefault.json"
- !file:
path : "C: \\ProgramData\\Microsoft\\Diagnosis\\ETLLogs\\ShutdownLogger\\Diagtrack-Listener.etl"
path : "%SystemDrive% \\ProgramData\\Microsoft\\Diagnosis\\ETLLogs\\ShutdownLogger\\Diagtrack-Listener.etl"
- !file:
path : "C: \\Users\\All Users\\Microsoft\\Diagnosis\\ETLLogs\\ShutdownLogger\\Diagtrack-Listener.etl"
path : "%SystemDrive% \\Users\\All Users\\Microsoft\\Diagnosis\\ETLLogs\\ShutdownLogger\\Diagtrack-Listener.etl"
- !file:
path : "C: \\ProgramData\\Microsoft\\Diagnosis\\ETLLogs\\Autologger\\AutoLogger-Diagtrack-Listener.etl"
path : "%SystemDrive% \\ProgramData\\Microsoft\\Diagnosis\\ETLLogs\\Autologger\\AutoLogger-Diagtrack-Listener.etl"
- !file:
path : "C: \\Users\\All Users\\Microsoft\\Diagnosis\\ETLLogs\\Autologger\\AutoLogger-Diagtrack-Listener.etl"
path : "%SystemDrive% \\Users\\All Users\\Microsoft\\Diagnosis\\ETLLogs\\Autologger\\AutoLogger-Diagtrack-Listener.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\Microsoft\\Diagnosis\\ETLLogs\\ShutdownLogger\\Diagtrack-Listener.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\Microsoft\\Diagnosis\\ETLLogs\\ShutdownLogger\\Diagtrack-Listener.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\Microsoft\\Diagnosis\\ETLLogs\\Autologger\\AutoLogger-Diagtrack-Listener.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\Microsoft\\Diagnosis\\ETLLogs\\Autologger\\AutoLogger-Diagtrack-Listener.etl"
- !file:
path : "%windir%\\System32\\dmclient.exe"
- !file:
@ -446,47 +499,47 @@ actions:
- !file:
path : "%windir%\\System32\\MoUsoCoreWorker.exe"
- !file:
path : "C: \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.2bdb351a-82b4-4f2c-bc55-ec328ca677be.1.etl"
path : "%SystemDrive% \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.2bdb351a-82b4-4f2c-bc55-ec328ca677be.1.etl"
- !file:
path : "C: \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.4a695923-0852-4c25-9999-60bc09954fbe.1.etl"
path : "%SystemDrive% \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.4a695923-0852-4c25-9999-60bc09954fbe.1.etl"
- !file:
path : "C: \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.5e2840a3-5955-481c-83b8-ddd64cdaa7ae.1.etl"
path : "%SystemDrive% \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.5e2840a3-5955-481c-83b8-ddd64cdaa7ae.1.etl"
- !file:
path : "C: \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.761c6d23-f36c-46be-bf3f-26ba35c4dcca.1.etl"
path : "%SystemDrive% \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.761c6d23-f36c-46be-bf3f-26ba35c4dcca.1.etl"
- !file:
path : "C: \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.80c59111-3f67-46a5-9fd1-379f4b7c2f7d.1.etl"
path : "%SystemDrive% \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.80c59111-3f67-46a5-9fd1-379f4b7c2f7d.1.etl"
- !file:
path : "C: \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.86ba5ad4-3ec9-43cf-997e-568832e6e2b8.1.etl"
path : "%SystemDrive% \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.86ba5ad4-3ec9-43cf-997e-568832e6e2b8.1.etl"
- !file:
path : "C: \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.ab8bb825-292c-450d-ac06-03e39e89d684.1.etl"
path : "%SystemDrive% \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.ab8bb825-292c-450d-ac06-03e39e89d684.1.etl"
- !file:
path : "C: \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.2bdb351a-82b4-4f2c-bc55-ec328ca677be.1.etl"
path : "%SystemDrive% \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.2bdb351a-82b4-4f2c-bc55-ec328ca677be.1.etl"
- !file:
path : "C: \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.4a695923-0852-4c25-9999-60bc09954fbe.1.etl"
path : "%SystemDrive% \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.4a695923-0852-4c25-9999-60bc09954fbe.1.etl"
- !file:
path : "C: \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.5e2840a3-5955-481c-83b8-ddd64cdaa7ae.1.etl"
path : "%SystemDrive% \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.5e2840a3-5955-481c-83b8-ddd64cdaa7ae.1.etl"
- !file:
path : "C: \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.761c6d23-f36c-46be-bf3f-26ba35c4dcca.1.etl"
path : "%SystemDrive% \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.761c6d23-f36c-46be-bf3f-26ba35c4dcca.1.etl"
- !file:
path : "C: \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.80c59111-3f67-46a5-9fd1-379f4b7c2f7d.1.etl"
path : "%SystemDrive% \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.80c59111-3f67-46a5-9fd1-379f4b7c2f7d.1.etl"
- !file:
path : "C: \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.86ba5ad4-3ec9-43cf-997e-568832e6e2b8.1.etl"
path : "%SystemDrive% \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.86ba5ad4-3ec9-43cf-997e-568832e6e2b8.1.etl"
- !file:
path : "C: \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.ab8bb825-292c-450d-ac06-03e39e89d684.1.etl"
path : "%SystemDrive% \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.ab8bb825-292c-450d-ac06-03e39e89d684.1.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.2bdb351a-82b4-4f2c-bc55-ec328ca677be.1.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.2bdb351a-82b4-4f2c-bc55-ec328ca677be.1.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.4a695923-0852-4c25-9999-60bc09954fbe.1.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.4a695923-0852-4c25-9999-60bc09954fbe.1.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.5e2840a3-5955-481c-83b8-ddd64cdaa7ae.1.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.5e2840a3-5955-481c-83b8-ddd64cdaa7ae.1.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.761c6d23-f36c-46be-bf3f-26ba35c4dcca.1.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.761c6d23-f36c-46be-bf3f-26ba35c4dcca.1.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.80c59111-3f67-46a5-9fd1-379f4b7c2f7d.1.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.80c59111-3f67-46a5-9fd1-379f4b7c2f7d.1.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.86ba5ad4-3ec9-43cf-997e-568832e6e2b8.1.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.86ba5ad4-3ec9-43cf-997e-568832e6e2b8.1.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.ab8bb825-292c-450d-ac06-03e39e89d684.1.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.ab8bb825-292c-450d-ac06-03e39e89d684.1.etl"
- !file:
path : "%windir%\\Prefetch\\MOUSOCOREWORKER.EXE-681A8FEE.pf"
- !file:
@ -494,47 +547,47 @@ actions:
- !file:
path : "%windir%\\System32\\MoUsoCoreWorker.exe"
- !file:
path : "C: \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.2bdb351a-82b4-4f2c-bc55-ec328ca677be.1.etl"
path : "%SystemDrive% \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.2bdb351a-82b4-4f2c-bc55-ec328ca677be.1.etl"
- !file:
path : "C: \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.4a695923-0852-4c25-9999-60bc09954fbe.1.etl"
path : "%SystemDrive% \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.4a695923-0852-4c25-9999-60bc09954fbe.1.etl"
- !file:
path : "C: \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.5e2840a3-5955-481c-83b8-ddd64cdaa7ae.1.etl"
path : "%SystemDrive% \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.5e2840a3-5955-481c-83b8-ddd64cdaa7ae.1.etl"
- !file:
path : "C: \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.761c6d23-f36c-46be-bf3f-26ba35c4dcca.1.etl"
path : "%SystemDrive% \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.761c6d23-f36c-46be-bf3f-26ba35c4dcca.1.etl"
- !file:
path : "C: \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.80c59111-3f67-46a5-9fd1-379f4b7c2f7d.1.etl"
path : "%SystemDrive% \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.80c59111-3f67-46a5-9fd1-379f4b7c2f7d.1.etl"
- !file:
path : "C: \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.86ba5ad4-3ec9-43cf-997e-568832e6e2b8.1.etl"
path : "%SystemDrive% \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.86ba5ad4-3ec9-43cf-997e-568832e6e2b8.1.etl"
- !file:
path : "C: \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.ab8bb825-292c-450d-ac06-03e39e89d684.1.etl"
path : "%SystemDrive% \\ProgramData\\USOShared\\Logs\\System\\MoUsoCoreWorker.ab8bb825-292c-450d-ac06-03e39e89d684.1.etl"
- !file:
path : "C: \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.2bdb351a-82b4-4f2c-bc55-ec328ca677be.1.etl"
path : "%SystemDrive% \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.2bdb351a-82b4-4f2c-bc55-ec328ca677be.1.etl"
- !file:
path : "C: \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.4a695923-0852-4c25-9999-60bc09954fbe.1.etl"
path : "%SystemDrive% \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.4a695923-0852-4c25-9999-60bc09954fbe.1.etl"
- !file:
path : "C: \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.5e2840a3-5955-481c-83b8-ddd64cdaa7ae.1.etl"
path : "%SystemDrive% \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.5e2840a3-5955-481c-83b8-ddd64cdaa7ae.1.etl"
- !file:
path : "C: \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.761c6d23-f36c-46be-bf3f-26ba35c4dcca.1.etl"
path : "%SystemDrive% \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.761c6d23-f36c-46be-bf3f-26ba35c4dcca.1.etl"
- !file:
path : "C: \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.80c59111-3f67-46a5-9fd1-379f4b7c2f7d.1.etl"
path : "%SystemDrive% \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.80c59111-3f67-46a5-9fd1-379f4b7c2f7d.1.etl"
- !file:
path : "C: \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.86ba5ad4-3ec9-43cf-997e-568832e6e2b8.1.etl"
path : "%SystemDrive% \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.86ba5ad4-3ec9-43cf-997e-568832e6e2b8.1.etl"
- !file:
path : "C: \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.ab8bb825-292c-450d-ac06-03e39e89d684.1.etl"
path : "%SystemDrive% \\Users\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.ab8bb825-292c-450d-ac06-03e39e89d684.1.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.2bdb351a-82b4-4f2c-bc55-ec328ca677be.1.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.2bdb351a-82b4-4f2c-bc55-ec328ca677be.1.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.4a695923-0852-4c25-9999-60bc09954fbe.1.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.4a695923-0852-4c25-9999-60bc09954fbe.1.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.5e2840a3-5955-481c-83b8-ddd64cdaa7ae.1.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.5e2840a3-5955-481c-83b8-ddd64cdaa7ae.1.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.761c6d23-f36c-46be-bf3f-26ba35c4dcca.1.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.761c6d23-f36c-46be-bf3f-26ba35c4dcca.1.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.80c59111-3f67-46a5-9fd1-379f4b7c2f7d.1.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.80c59111-3f67-46a5-9fd1-379f4b7c2f7d.1.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.86ba5ad4-3ec9-43cf-997e-568832e6e2b8.1.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.86ba5ad4-3ec9-43cf-997e-568832e6e2b8.1.etl"
- !file:
path : "C: \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.ab8bb825-292c-450d-ac06-03e39e89d684.1.etl"
path : "%SystemDrive% \\Documents and Settings\\All Users\\USOShared\\Logs\\System\\MoUsoCoreWorker.ab8bb825-292c-450d-ac06-03e39e89d684.1.etl"
- !file:
path : "%windir%\\Prefetch\\MOUSOCOREWORKER.EXE-681A8FEE.pf"
- !file:
@ -576,9 +629,9 @@ actions:
- !file:
path : "%windir%\\System32\\Tasks\\Microsoft\\Windows\\WaaSMedic\\PerformRemediation"
- !file:
path : "C: \\ProgramData\\Microsoft\\Windows\\AppRepository\\Microsoft.WindowsMaps_5.1906.1972.0_neutral_split.scale-125_8wekyb3d8bbwe.xml"
path : "%SystemDrive% \\ProgramData\\Microsoft\\Windows\\AppRepository\\Microsoft.WindowsMaps_5.1906.1972.0_neutral_split.scale-125_8wekyb3d8bbwe.xml"
- !file:
path : "C: \\Users\\All Users\\Microsoft\\Windows\\AppRepository\\Microsoft.WindowsMaps_5.1906.1972.0_neutral_split.scale-125_8wekyb3d8bbwe.xml"
path : "%SystemDrive% \\Users\\All Users\\Microsoft\\Windows\\AppRepository\\Microsoft.WindowsMaps_5.1906.1972.0_neutral_split.scale-125_8wekyb3d8bbwe.xml"
- !file:
path : "%ProgramW6432%\\WindowsApps\\DeletedAllUserPackages\\Microsoft.WindowsMaps_5.1906.1972.0_neutral_split.scale-125_8wekyb3d8bbwe\\resources.pri"
- !file:
@ -588,7 +641,7 @@ actions:
- !file:
path : "%ProgramW6432%\\WindowsApps\\DeletedAllUserPackages\\Microsoft.WindowsMaps_5.1906.1972.0_neutral_split.scale-125_8wekyb3d8bbwe\\AppxSignature.p7x"
- !file:
path : "C: \\Documents and Settings\\All Users\\Microsoft\\Windows\\AppRepository\\Microsoft.WindowsMaps_5.1906.1972.0_neutral_split.scale-125_8wekyb3d8bbwe.xml"
path : "%SystemDrive% \\Documents and Settings\\All Users\\Microsoft\\Windows\\AppRepository\\Microsoft.WindowsMaps_5.1906.1972.0_neutral_split.scale-125_8wekyb3d8bbwe.xml"
- !file:
path : "%ProgramW6432%\\WindowsApps\\DeletedAllUserPackages\\Microsoft.WindowsMaps*"
- !file:
@ -670,13 +723,13 @@ actions:
- !file:
path : "%windir%\\SysWOW64\\WindowsPowerShell\\v1.0\\Modules\\WindowsUpdate\\WindowsUpdateLog.psm1"
- !file:
path : "C: \\Users\\Public\\Desktop\\Microsoft Edge.lnk"
path : "%SystemDrive% \\Users\\Public\\Desktop\\Microsoft Edge.lnk"
- !file:
path : "C: \\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Microsoft Edge.lnk"
path : "%SystemDrive% \\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Microsoft Edge.lnk"
- !file:
path : "%APPDATA%\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\Microsoft Edge.lnk"
- !file:
path : "C: \\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\PC Health Check.lnk"
path : "%SystemDrive% \\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\PC Health Check.lnk"
- !file:
path : "%windir%\\System32\\wsqmcons.exe"
- !file:
@ -711,5 +764,7 @@ actions:
path : "%windir%\\System32\\wups2.dll"
- !file:
path : "%windir%\\System32\\wuaueng.dll"
- !file:
path : "%windir%\\System32\\MRT.exe"
- !file:
path : "%windir%\\System32\\calc.exe"