Technical Information
- <SYSTEM32>\tasks\soldier.extension.watcher
- [<HKLM>\System\CurrentControlSet\Services\Soldier.Extension.Watcher] 'ImagePath' = 'C:\Soldier System\Soldier.Extension.Watcher\Soldier.Extension.Watcher.exe'
- [<HKLM>\System\CurrentControlSet\Services\Soldier.Extension.Watcher] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- 'Soldier.Extension.Watcher' C:\Soldier System\Soldier.Extension.Watcher\Soldier.Extension.Watcher.exe
- Windows Firewall
- Windows Update
- Windows Defender
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="Soldier.Extension.Monitor(in)" dir=in action=allow enable=yes
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="Soldier.Extension.Monitor(out)" dir=out action=allow enable=yes
- '%WINDIR%\syswow64\net.exe' stop SecurityHealthService
- '%WINDIR%\syswow64\net.exe' stop wuauserv
- '%WINDIR%\syswow64\net.exe' stop mpssvc
- %TEMP%\nsxe64a.tmp\nsprocess.dll
- D:\f0e69004bd65ffaaa6\1046\setupresources.dll
- D:\f0e69004bd65ffaaa6\1049\setupresources.dll
- D:\f0e69004bd65ffaaa6\2070\setupresources.dll
- D:\f0e69004bd65ffaaa6\1038\setupresources.dll
- D:\f0e69004bd65ffaaa6\1043\setupresources.dll
- D:\f0e69004bd65ffaaa6\1029\setupresources.dll
- D:\f0e69004bd65ffaaa6\setupui.dll
- %TEMP%\hfia17d.tmp.html
- %TEMP%\setup_20210623_231431230.html
- %TEMP%\microsoft .net framework 4.5.2 setup_20210623_231434896.html
- C:\soldier system\soldier.software.dotnetfx\uninst.exe
- C:\soldier system\soldier.software\soldier.extension.watcher-2.9.1.0.exe
- %TEMP%\nsne782.tmp\nsprocess.dll
- D:\f0e69004bd65ffaaa6\1055\setupresources.dll
- D:\f0e69004bd65ffaaa6\sqmapi.dll
- D:\f0e69004bd65ffaaa6\1045\setupresources.dll
- D:\f0e69004bd65ffaaa6\1040\setupresources.dll
- D:\f0e69004bd65ffaaa6\1053\setupresources.dll
- D:\f0e69004bd65ffaaa6\1044\setupresources.dll
- D:\f0e69004bd65ffaaa6\setupengine.dll
- D:\f0e69004bd65ffaaa6\2052\setupresources.dll
- D:\f0e69004bd65ffaaa6\1028\setupresources.dll
- D:\f0e69004bd65ffaaa6\1025\setupresources.dll
- D:\f0e69004bd65ffaaa6\1033\setupresources.dll
- %TEMP%\nsne782.tmp\dotnetchecker.dll
- D:\f0e69004bd65ffaaa6\1030\setupresources.dll
- D:\f0e69004bd65ffaaa6\1053\eula.rtf
- D:\f0e69004bd65ffaaa6\1035\setupresources.dll
- D:\f0e69004bd65ffaaa6\3082\setupresources.dll
- D:\f0e69004bd65ffaaa6\1036\setupresources.dll
- D:\f0e69004bd65ffaaa6\1032\setupresources.dll
- D:\f0e69004bd65ffaaa6\1042\setupresources.dll
- D:\f0e69004bd65ffaaa6\1041\setupresources.dll
- D:\f0e69004bd65ffaaa6\setup.exe
- D:\f0e69004bd65ffaaa6\1037\setupresources.dll
- D:\f0e69004bd65ffaaa6\1031\setupresources.dll
- D:\f0e69004bd65ffaaa6\setuputility.exe
- C:\soldier system\soldier.extension.watcher\installer.bat
- C:\soldier system\soldier.extension.watcher\soldier.core.dll
- C:\soldier system\soldier.extension.monitor\soldier.core.autobot.dll
- C:\soldier system\soldier.extension.monitor\soldier.core.datapacket.dll
- C:\soldier system\soldier.extension.monitor\soldier.core.dll
- C:\soldier system\soldier.extension.monitor\soldier.core.sqlite.dll
- C:\soldier system\soldier.extension.monitor\soldier.extension.monitor.exe
- C:\soldier system\soldier.extension.monitor\soldier.extension.monitor.exe.config
- C:\soldier system\soldier.extension.monitor\log4net.dll
- C:\soldier system\soldier.extension.monitor\soldier.extension.monitor.pdb
- C:\soldier system\soldier.extension.monitor\uninstaller.bat
- C:\soldier system\soldier.extension.monitor\resources\icon.png
- C:\soldier system\soldier.extension.monitor\resources\soldierca.pfx
- C:\soldier system\soldier.extension.monitor\x64\sqlite.interop.dll
- C:\soldier system\soldier.extension.monitor\x86\sqlite.interop.dll
- C:\soldier system\soldier.extension.monitor\configuration\manifest.info
- C:\soldier system\soldier.extension.monitor\plugin.manifest
- C:\soldier system\soldier.extension.monitor\soldier.core.aliyun.dll
- C:\soldier system\soldier.extension.monitor\newtonsoft.json.dll
- C:\soldier system\soldier.extension.monitor\installer.bat
- D:\f0e69004bd65ffaaa6\1053\localizeddata.xml
- C:\soldier system\soldier.extension.watcher\soldier.extension.watcher.exe
- C:\soldier system\soldier.extension.watcher\soldier.extension.watcher.exe.config
- C:\soldier system\soldier.extension.watcher\soldier.extension.watcher.pdb
- C:\soldier system\soldier.extension.watcher\start.bat
- C:\soldier system\soldier.extension.watcher\stop.bat
- C:\soldier system\soldier.extension.watcher\log4net.dll
- C:\soldier system\soldier.extension.watcher\plugin.manifest
- C:\soldier system\soldier.extension.watcher\newtonsoft.json.dll
- C:\soldier system\soldier.extension.watcher\uninstaller.bat
- C:\soldier system\soldier.software\soldier.extension.monitor-2.9.2.0.exe
- %TEMP%\nsn3801.tmp\nsprocess.dll
- %TEMP%\nsn3801.tmp\dotnetchecker.dll
- C:\soldier system\soldier.extension.monitor\disabledefender.reg
- C:\soldier system\soldier.extension.monitor\enabledefender.reg
- C:\soldier system\soldier.extension.watcher\resources\icon.png
- %TEMP%\nsne782.tmp\nsexec.dll
- C:\soldier system\soldier.extension.watcher\uninst.exe
- D:\f0e69004bd65ffaaa6\3082\eula.rtf
- D:\f0e69004bd65ffaaa6\2070\eula.rtf
- D:\f0e69004bd65ffaaa6\1049\eula.rtf
- D:\f0e69004bd65ffaaa6\graphics\stop.ico
- D:\f0e69004bd65ffaaa6\graphics\sysreqmet.ico
- D:\f0e69004bd65ffaaa6\graphics\sysreqnotmet.ico
- D:\f0e69004bd65ffaaa6\graphics\warn.ico
- D:\f0e69004bd65ffaaa6\1025\localizeddata.xml
- D:\f0e69004bd65ffaaa6\2052\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1037\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1028\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1029\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1031\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1033\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1032\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1035\localizeddata.xml
- D:\f0e69004bd65ffaaa6\graphics\rotate8.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate7.ico
- D:\f0e69004bd65ffaaa6\graphics\setup.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate6.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate5.ico
- %TEMP%\nsxe64a.tmp\dialer.dll
- C:\soldier system\soldier.software\manifest.info
- %TEMP%\nsxe64a.tmp\inetc.dll
- C:\soldier system\soldier.software\soldier.software.dotnetfx-4.5.2.exe
- C:\soldier system\soldier.software.dotnetfx\ndp452-kb2901954-web.exe
- %TEMP%\dd_ndp452-kb2901954-web_decompression_log.txt
- D:\f0e69004bd65ffaaa6\3082\localizeddata.xml
- D:\f0e69004bd65ffaaa6\header.bmp
- D:\f0e69004bd65ffaaa6\1030\localizeddata.xml
- D:\f0e69004bd65ffaaa6\watermark.bmp
- D:\f0e69004bd65ffaaa6\graphics\print.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate1.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate2.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate3.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate4.ico
- D:\f0e69004bd65ffaaa6\splashscreen.bmp
- %TEMP%\nsxe64a.tmp\system.dll
- D:\f0e69004bd65ffaaa6\displayicon.ico
- D:\f0e69004bd65ffaaa6\graphics\save.ico
- D:\f0e69004bd65ffaaa6\1036\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1031\eula.rtf
- D:\f0e69004bd65ffaaa6\1033\eula.rtf
- D:\f0e69004bd65ffaaa6\1037\eula.rtf
- D:\f0e69004bd65ffaaa6\1036\eula.rtf
- D:\f0e69004bd65ffaaa6\1038\eula.rtf
- D:\f0e69004bd65ffaaa6\1041\eula.rtf
- D:\f0e69004bd65ffaaa6\1025\eula.rtf
- D:\f0e69004bd65ffaaa6\1040\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1032\eula.rtf
- D:\f0e69004bd65ffaaa6\1042\eula.rtf
- D:\f0e69004bd65ffaaa6\1040\eula.rtf
- D:\f0e69004bd65ffaaa6\1045\eula.rtf
- D:\f0e69004bd65ffaaa6\1046\eula.rtf
- D:\f0e69004bd65ffaaa6\1055\eula.rtf
- D:\f0e69004bd65ffaaa6\2052\eula.rtf
- D:\f0e69004bd65ffaaa6\1035\eula.rtf
- D:\f0e69004bd65ffaaa6\1044\eula.rtf
- D:\f0e69004bd65ffaaa6\1043\eula.rtf
- C:\soldier system\soldier.extension.monitor\system.data.sqlite.dll
- C:\soldier system\soldier.repository\soldier.extension.monitor\configuration.db
- D:\f0e69004bd65ffaaa6\1029\eula.rtf
- D:\f0e69004bd65ffaaa6\1042\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1041\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1044\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1043\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1045\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1046\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1028\eula.rtf
- D:\f0e69004bd65ffaaa6\1030\eula.rtf
- D:\f0e69004bd65ffaaa6\2070\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1055\localizeddata.xml
- D:\f0e69004bd65ffaaa6\parameterinfo.xml
- D:\f0e69004bd65ffaaa6\strings.xml
- D:\f0e69004bd65ffaaa6\uiinfo.xml
- D:\f0e69004bd65ffaaa6\setupui.xsd
- D:\f0e69004bd65ffaaa6\dhtmlheader.html
- D:\f0e69004bd65ffaaa6\1038\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1049\localizeddata.xml
- %TEMP%\nsn3801.tmp\nsexec.dll
- D:\f0e69004bd65ffaaa6\header.bmp
- D:\f0e69004bd65ffaaa6\1025\setupresources.dll
- D:\f0e69004bd65ffaaa6\1028\setupresources.dll
- D:\f0e69004bd65ffaaa6\2052\setupresources.dll
- D:\f0e69004bd65ffaaa6\setupengine.dll
- D:\f0e69004bd65ffaaa6\setuputility.exe
- D:\f0e69004bd65ffaaa6\setup.exe
- D:\f0e69004bd65ffaaa6\1053\eula.rtf
- D:\f0e69004bd65ffaaa6\3082\eula.rtf
- D:\f0e69004bd65ffaaa6\2070\eula.rtf
- D:\f0e69004bd65ffaaa6\1049\eula.rtf
- D:\f0e69004bd65ffaaa6\2052\eula.rtf
- D:\f0e69004bd65ffaaa6\1055\eula.rtf
- D:\f0e69004bd65ffaaa6\1046\eula.rtf
- D:\f0e69004bd65ffaaa6\1045\eula.rtf
- D:\f0e69004bd65ffaaa6\1040\eula.rtf
- D:\f0e69004bd65ffaaa6\1043\eula.rtf
- D:\f0e69004bd65ffaaa6\1044\eula.rtf
- D:\f0e69004bd65ffaaa6\1035\eula.rtf
- D:\f0e69004bd65ffaaa6\1042\eula.rtf
- D:\f0e69004bd65ffaaa6\1041\eula.rtf
- D:\f0e69004bd65ffaaa6\1038\eula.rtf
- D:\f0e69004bd65ffaaa6\1036\eula.rtf
- D:\f0e69004bd65ffaaa6\1037\eula.rtf
- D:\f0e69004bd65ffaaa6\1033\setupresources.dll
- D:\f0e69004bd65ffaaa6\1029\setupresources.dll
- %TEMP%\nsn3801.tmp\nsexec.dll
- D:\f0e69004bd65ffaaa6\1035\setupresources.dll
- %TEMP%\nsn3801.tmp\dotnetchecker.dll
- %TEMP%\nsne782.tmp\nsprocess.dll
- %TEMP%\nsne782.tmp\nsexec.dll
- %TEMP%\nsne782.tmp\dotnetchecker.dll
- D:\f0e69004bd65ffaaa6\sqmapi.dll
- D:\f0e69004bd65ffaaa6\setupui.dll
- D:\f0e69004bd65ffaaa6\1043\setupresources.dll
- D:\f0e69004bd65ffaaa6\1038\setupresources.dll
- D:\f0e69004bd65ffaaa6\2070\setupresources.dll
- D:\f0e69004bd65ffaaa6\1049\setupresources.dll
- D:\f0e69004bd65ffaaa6\1046\setupresources.dll
- D:\f0e69004bd65ffaaa6\1045\setupresources.dll
- D:\f0e69004bd65ffaaa6\1040\setupresources.dll
- D:\f0e69004bd65ffaaa6\1055\setupresources.dll
- D:\f0e69004bd65ffaaa6\1053\setupresources.dll
- D:\f0e69004bd65ffaaa6\1044\setupresources.dll
- D:\f0e69004bd65ffaaa6\1037\setupresources.dll
- D:\f0e69004bd65ffaaa6\1041\setupresources.dll
- D:\f0e69004bd65ffaaa6\1042\setupresources.dll
- D:\f0e69004bd65ffaaa6\1032\setupresources.dll
- D:\f0e69004bd65ffaaa6\1036\setupresources.dll
- D:\f0e69004bd65ffaaa6\3082\setupresources.dll
- D:\f0e69004bd65ffaaa6\1031\setupresources.dll
- D:\f0e69004bd65ffaaa6\1033\eula.rtf
- D:\f0e69004bd65ffaaa6\1030\setupresources.dll
- D:\f0e69004bd65ffaaa6\1032\eula.rtf
- D:\f0e69004bd65ffaaa6\1033\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1029\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1030\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1028\localizeddata.xml
- D:\f0e69004bd65ffaaa6\2052\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1025\localizeddata.xml
- D:\f0e69004bd65ffaaa6\graphics\warn.ico
- D:\f0e69004bd65ffaaa6\graphics\sysreqnotmet.ico
- D:\f0e69004bd65ffaaa6\graphics\sysreqmet.ico
- D:\f0e69004bd65ffaaa6\graphics\stop.ico
- D:\f0e69004bd65ffaaa6\graphics\setup.ico
- D:\f0e69004bd65ffaaa6\graphics\save.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate8.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate7.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate6.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate5.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate4.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate3.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate2.ico
- D:\f0e69004bd65ffaaa6\graphics\rotate1.ico
- D:\f0e69004bd65ffaaa6\graphics\print.ico
- D:\f0e69004bd65ffaaa6\displayicon.ico
- D:\f0e69004bd65ffaaa6\watermark.bmp
- D:\f0e69004bd65ffaaa6\splashscreen.bmp
- D:\f0e69004bd65ffaaa6\1031\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1032\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1025\eula.rtf
- D:\f0e69004bd65ffaaa6\1035\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1030\eula.rtf
- D:\f0e69004bd65ffaaa6\1028\eula.rtf
- D:\f0e69004bd65ffaaa6\1029\eula.rtf
- D:\f0e69004bd65ffaaa6\dhtmlheader.html
- D:\f0e69004bd65ffaaa6\setupui.xsd
- D:\f0e69004bd65ffaaa6\uiinfo.xml
- D:\f0e69004bd65ffaaa6\strings.xml
- D:\f0e69004bd65ffaaa6\parameterinfo.xml
- D:\f0e69004bd65ffaaa6\1055\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1049\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1053\localizeddata.xml
- D:\f0e69004bd65ffaaa6\2070\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1046\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1045\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1043\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1044\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1041\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1042\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1038\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1040\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1036\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1037\localizeddata.xml
- D:\f0e69004bd65ffaaa6\3082\localizeddata.xml
- D:\f0e69004bd65ffaaa6\1031\eula.rtf
- %TEMP%\nsn3801.tmp\nsprocess.dll
- from %TEMP%\hfia17d.tmp.html to %TEMP%\setup_20210623_231431230.html
- from %TEMP%\setup_20210623_231431230.html to %TEMP%\microsoft .net framework 4.5.2 setup_20210623_231434896.html
- 'vi##.#rtaccd.com':443
- 'x1.#.lencr.org':80
- 'r3.#.lencr.org':80
- 'microsoft.com':80
- 'of###########are.oss-cn-shenzhen.aliyuncs.com':443
- 'vi##.#rtaccd.com':443
- 'of###########are.oss-cn-shenzhen.aliyuncs.com':443
- DNS ASK vi##.#rtaccd.com
- DNS ASK x1.#.lencr.org
- DNS ASK r3.#.lencr.org
- DNS ASK microsoft.com
- DNS ASK of###########are.oss-cn-shenzhen.aliyuncs.com
- ClassName: '#32770' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- 'C:\soldier system\soldier.software\soldier.software.dotnetfx-4.5.2.exe'
- 'C:\soldier system\soldier.software.dotnetfx\ndp452-kb2901954-web.exe' /q /norestart /ChainingPackage FullX64Bootstrapper
- 'D:\f0e69004bd65ffaaa6\setup.exe' /q /norestart /ChainingPackage FullX64Bootstrapper /x86 /x64 /web
- 'C:\soldier system\soldier.software\soldier.extension.watcher-2.9.1.0.exe'
- 'C:\soldier system\soldier.extension.watcher\soldier.extension.watcher.exe'
- 'C:\soldier system\soldier.software\soldier.extension.monitor-2.9.2.0.exe'
- 'C:\soldier system\soldier.extension.monitor\soldier.extension.monitor.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\Soldier System\Soldier.Extension.Watcher\Installer.bat""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "C:\Soldier System\Soldier.Extension.Watcher\Start.bat"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\Soldier System\Soldier.Extension.Monitor\Installer.bat""' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\Soldier System\Soldier.Extension.Watcher\Installer.bat""
- '%WINDIR%\syswow64\net1.exe' stop SecurityHealthService
- '%WINDIR%\syswow64\regedit.exe' /s DisableDefender.reg
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall delete rule name="Soldier.Extension.Monitor(out)"
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall delete rule name="Soldier.Extension.Monitor(in)"
- '%WINDIR%\syswow64\netsh.exe' http add urlacl url=http://+:#314/ user=Everyone
- '%WINDIR%\syswow64\netsh.exe' http delete urlacl url=http://+:#314/
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\Soldier System\Soldier.Extension.Monitor\Installer.bat""
- '<SYSTEM32>\net1.exe' start Soldier.Extension.Watcher
- '<SYSTEM32>\net.exe' start Soldier.Extension.Watcher
- '<SYSTEM32>\cmd.exe' /c "C:\Soldier System\Soldier.Extension.Watcher\Start.bat"
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "Soldier.Extension.Watcher" /ru system /sc MINUTE /mo 1 /tr "\"C:\Soldier System\Soldier.Extension.Watcher\Start.bat\"" /f
- '%WINDIR%\syswow64\sc.exe' start "Soldier.Extension.Watcher"
- '%WINDIR%\syswow64\sc.exe' failure "Soldier.Extension.Watcher" reset= 86400 actions= restart/3000/restart/3000/restart/3000
- '%WINDIR%\syswow64\sc.exe' config "Soldier.Extension.Watcher" start= auto
- '%WINDIR%\syswow64\sc.exe' create "Soldier.Extension.Watcher" binpath= "C:\Soldier System\Soldier.Extension.Watcher\Soldier.Extension.Watcher.exe"
- '%WINDIR%\syswow64\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v "CurrentVersion"
- '%WINDIR%\syswow64\cmd.exe' /c reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v "CurrentVersion"
- '%WINDIR%\syswow64\net1.exe' stop wuauserv
- '%WINDIR%\syswow64\net1.exe' stop mpssvc