Technical Information
- nul
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\SogouExplorer\config.xml" >nul 2>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\topmost.dat /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\thumbnail" >nul 2>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\thumbnail /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\115Chrome\User Data\Default\Preferences" /T /C /G EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Preferences" /T /C /G EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\2345chrome\User Data\Default\page_file.dat" /T /C /G EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\2345chrome\User Data\Default\PreferencesV2" /T /C /G EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Preferences" /T /C /G EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ping 127.0.0.1 -n 1&del /q "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences" /T /C /G EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\liebao\User Data\Default\Preferences" /T /C /G EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\TheWorld6\User Data\Default\Preferences" /T /C /G EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\UCBrowser\User Data\Default\Preferences" /T /C /G EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\UCBrowser\User Data\Default\Secure Preferences" /T /C /G EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default" /T /C /G EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Preferences" /T /C /G EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\topmost.dat" >nul 2>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Current Session" /T /C /G EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\Bookmarks.db /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Local\115Chrome\User Data\Default\Preferences" >nul 2>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\SogouExplorer\config.xml /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\SogouExplorer\commcfg.xml" >nul 2>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\SogouExplorer\commcfg.xml /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Baidu\BaiduBrowser\user_data\default\settings\user_setting.db" >nul 2>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\Baidu\BaiduBrowser\user_data\default\settings\user_setting.db /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Baidu\BaiduBrowser\plugin\extends\{CAC8ED57-54D1-4AF1-B5D2-C9534DEFEBFE}" >nul 2>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\Baidu\BaiduBrowser\plugin\extends\{CAC8ED57-54D1-4AF1-B5D2-C9534DEFEBFE} /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Local\115Chrome\User Data\Default\Preferences /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default\Bookmark.db /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\JuziBrowser\User_Data\Default\Bookmark.db" >nul 2>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\JuziBrowser\User_Data\Default\Bookmark.db /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\\AppData\Roaming\JuziBrowser\User_Data\Default\newtab" >nul 2>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\\AppData\Roaming\JuziBrowser\User_Data\Default\newtab /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default\newtab\newtab.dat" >nul 2>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default\newtab\newtab.dat /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default\Bookmark.db" >nul 2>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\Bookmarks.db" >nul 2>nul' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ping -n 3 127.1 & del /q "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\SogouExplorer\config.xml" >nul 2>nul
- '%WINDIR%\syswow64\cacls.exe' "C:\Users\Administrator\AppData\Local\2345chrome\User Data\Default\PreferencesV2" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\2345chrome\User Data\Default\PreferencesV2" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cacls.exe' "C:\Users\Administrator\AppData\Local\2345chrome\User Data\Default\page_file.dat" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\2345chrome\User Data\Default\page_file.dat" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cacls.exe' "C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\360Chrome\Chrome\User Data\Default\Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cacls.exe' "C:\Users\Administrator\AppData\Local\115Chrome\User Data\Default\Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Current Session" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" echo y"
- '%WINDIR%\syswow64\cacls.exe' C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\thumbnail /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\thumbnail /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\attrib.exe' +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\thumbnail"
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\thumbnail" >nul 2>nul
- '%WINDIR%\syswow64\cacls.exe' C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\topmost.dat /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\topmost.dat /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\attrib.exe' +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\topmost.dat"
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\115Chrome\User Data\Default\Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cacls.exe' "C:\Users\Administrator\AppData\Local\UCBrowser\User Data\Default\Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1 -n 1
- '%WINDIR%\syswow64\cacls.exe' "C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /c ping -n 3 127.1 & del /q "<Full path to file>"
- '%WINDIR%\syswow64\cmd.exe' /c ping 127.0.0.1 -n 1&del /q "<Full path to file>"
- '%WINDIR%\syswow64\cacls.exe' "C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Roaming\Opera Software\Opera Stable\Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cacls.exe' "C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cacls.exe' "C:\Users\Administrator\AppData\Local\UCBrowser\User Data\Default\Secure Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\topmost.dat" >nul 2>nul
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\UCBrowser\User Data\Default\Secure Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\UCBrowser\User Data\Default\Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cacls.exe' "C:\Users\Administrator\AppData\Local\TheWorld6\User Data\Default\Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\TheWorld6\User Data\Default\Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cacls.exe' "C:\Users\Administrator\AppData\Local\liebao\User Data\Default\Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\liebao\User Data\Default\Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cacls.exe' "C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cacls.exe' "C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Current Session" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /c echo y|cacls "C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Preferences" /T /C /G EVERYONE:R
- '%WINDIR%\syswow64\cacls.exe' C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\Bookmarks.db /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\cacls.exe' C:\Users\Administrator\AppData\Local\115Chrome\User Data\Default\Preferences /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Local\115Chrome\User Data\Default\Preferences" >nul 2>nul
- '%WINDIR%\syswow64\cacls.exe' C:\Users\Administrator\AppData\Roaming\Baidu\BaiduBrowser\plugin\extends\{CAC8ED57-54D1-4AF1-B5D2-C9534DEFEBFE} /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\Baidu\BaiduBrowser\plugin\extends\{CAC8ED57-54D1-4AF1-B5D2-C9534DEFEBFE} /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:...
- '%WINDIR%\syswow64\attrib.exe' +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Baidu\BaiduBrowser\plugin\extends\{CAC8ED57-54D1-4AF1-B5D2-C9534DEFEBFE}"
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Baidu\BaiduBrowser\plugin\extends\{CAC8ED57-54D1-4AF1-B5D2-C9534DEFEBFE}" >nul 2>nul
- '%WINDIR%\syswow64\cacls.exe' C:\Users\Administrator\AppData\Roaming\Baidu\BaiduBrowser\user_data\default\settings\user_setting.db /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\Baidu\BaiduBrowser\user_data\default\settings\user_setting.db /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\attrib.exe' +a +s +h +r "C:\Users\Administrator\AppData\Local\115Chrome\User Data\Default\Preferences"
- '%WINDIR%\syswow64\attrib.exe' +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Baidu\BaiduBrowser\user_data\default\settings\user_setting.db"
- '%WINDIR%\syswow64\cacls.exe' C:\Users\Administrator\AppData\Roaming\SogouExplorer\commcfg.xml /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\SogouExplorer\commcfg.xml /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\attrib.exe' +a +s +h +r "C:\Users\Administrator\AppData\Roaming\SogouExplorer\commcfg.xml"
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\SogouExplorer\commcfg.xml" >nul 2>nul
- '%WINDIR%\syswow64\cacls.exe' C:\Users\Administrator\AppData\Roaming\SogouExplorer\config.xml /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\SogouExplorer\config.xml /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\attrib.exe' +a +s +h +r "C:\Users\Administrator\AppData\Roaming\SogouExplorer\config.xml"
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Baidu\BaiduBrowser\user_data\default\settings\user_setting.db" >nul 2>nul
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default\newtab\newtab.dat" >nul 2>nul
- '%WINDIR%\syswow64\attrib.exe' +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\Bookmarks.db"
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\JuziBrowser\User_Data\Default\Bookmark.db" >nul 2>nul
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\Bookmarks.db" >nul 2>nul
- '%WINDIR%\syswow64\cacls.exe' C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default\Bookmark.db /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default\Bookmark.db /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\attrib.exe' +a +s +h +r "C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default\Bookmark.db"
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default\Bookmark.db" >nul 2>nul
- '%WINDIR%\syswow64\cacls.exe' C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default\newtab\newtab.dat /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default\newtab\newtab.dat /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\Shouxin\UserData\Default\Bookmarks.db /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\attrib.exe' +a +s +h +r "C:\Users\Administrator\AppData\Roaming\hao123JuziBrowser\User_Data\Default\newtab\newtab.dat"
- '%WINDIR%\syswow64\cacls.exe' C:\Users\Administrator\\AppData\Roaming\JuziBrowser\User_Data\Default\newtab /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\\AppData\Roaming\JuziBrowser\User_Data\Default\newtab /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\attrib.exe' +a +s +h +r "C:\Users\Administrator\\AppData\Roaming\JuziBrowser\User_Data\Default\newtab"
- '%WINDIR%\syswow64\cmd.exe' /c attrib +a +s +h +r "C:\Users\Administrator\\AppData\Roaming\JuziBrowser\User_Data\Default\newtab" >nul 2>nul
- '%WINDIR%\syswow64\cacls.exe' C:\Users\Administrator\AppData\Roaming\JuziBrowser\User_Data\Default\Bookmark.db /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Roaming\JuziBrowser\User_Data\Default\Bookmark.db /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\attrib.exe' +a +s +h +r "C:\Users\Administrator\AppData\Roaming\JuziBrowser\User_Data\Default\Bookmark.db"
- '%WINDIR%\syswow64\cmd.exe' /C cacls C:\Users\Administrator\AppData\Local\115Chrome\User Data\Default\Preferences /T /C /E /R ADMINISTRATORS ADMINISTRATOR SYSTEM GUEST USERS /P EVERYONE:R
- '%WINDIR%\syswow64\ping.exe' -n 3 127.1