Technical Information
- %WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe
- C:\users\public\pictures\kill$-arab.bat
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\Users\Public\Pictures\Kill$-Arab.bat" "
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\mshta.exe /e /d system
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\mshta.exe /e /d "network service"
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\mshta.exe /e /d mssqlserver
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\mshta.exe /e /d SERVICE
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\mshta.exe /e /g Administrators:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\mshta.exe /e /g Users:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\mshta.exe /g Administrators:f
- '%WINDIR%\syswow64\takeown.exe' /f %WINDIR%\SysWOW64\mshta.exe /a
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\mshta.exe /e /d mssql$sqlexpress
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\mshta.exe /e /d system
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\mshta.exe /e /d mssqlserver
- '%WINDIR%\syswow64\takeown.exe' /f <SYSTEM32>\FTP.exe /a
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\mshta.exe /e /d SERVICE
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\mshta.exe /e /g Administrators:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\mshta.exe /e /g Users:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\mshta.exe /g Administrators:f
- '%WINDIR%\syswow64\takeown.exe' /f <SYSTEM32>\mshta.exe /a
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net1.exe /e /d mssql$sqlexpress
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net1.exe /e /d system
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net1.exe /e /d "network service"
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net1.exe /e /d mssqlserver
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\mshta.exe /e /d "network service"
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net.exe /e /d system
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\FTP.exe /g Administrators:f
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wscript.exe /e /d "network service"
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wscript.exe /e /d mssqlserver
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wscript.exe /e /d SERVICE
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wscript.exe /e /g Administrators:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wscript.exe /e /g Users:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wscript.exe /g Administrators:f
- '%WINDIR%\syswow64\takeown.exe' /f <SYSTEM32>\wscript.exe /a
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\FTP.exe /e /d mssql$sqlexpress
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\FTP.exe /e /d system
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\FTP.exe /e /d "network service"
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net1.exe /e /d SERVICE
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\mshta.exe /e /d mssql$sqlexpress
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\FTP.exe /e /g Administrators:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\FTP.exe /e /g Users:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\FTP.exe /g Administrators:f
- '%WINDIR%\syswow64\takeown.exe' /f %WINDIR%\SysWOW64\FTP.exe /a
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\FTP.exe /e /d mssql$sqlexpress
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\FTP.exe /e /d system
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\FTP.exe /e /d "network service"
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\FTP.exe /e /d mssqlserver
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\FTP.exe /e /d SERVICE
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\FTP.exe /e /g Administrators:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\FTP.exe /e /d SERVICE
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\FTP.exe /e /g Users:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net1.exe /e /g Administrators:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net1.exe /e /g Users:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net1.exe /g Administrators:f
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\cmd.exe /e /d mssql$sqlexpress
- '%WINDIR%\syswow64\takeown.exe' /f <SYSTEM32>\net.exe /a
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\cmd.exe /e /d mssql$sqlexpress
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\cmd.exe /e /g system:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\cmd.exe /e /d "network service"
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\cmd.exe /e /d mssqlserver
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\cmd.exe /e /d SERVICE
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\cmd.exe /e /g Administrators:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\cmd.exe /e /g Users:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\cmd.exe /g Administrators:f
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wscript.exe /e /d system
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net.exe /e /g Users:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\cmd.exe /e /g system:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\cmd.exe /e /d "network service"
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\cmd.exe /e /d mssqlserver
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\cmd.exe /e /d SERVICE
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\cmd.exe /e /g Administrators:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\cmd.exe /e /g Users:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\cmd.exe /g Administrators:f
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" echo y"
- '%WINDIR%\syswow64\takeown.exe' /f <SYSTEM32>\cmd.exe /a
- '%WINDIR%\syswow64\reg.exe' delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor" /v "AutoRun" /f
- '%WINDIR%\syswow64\takeown.exe' /f %WINDIR%\SysWOW64\cmd.exe /a
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\FTP.exe /e /d mssqlserver
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net.exe /e /g Administrators:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net.exe /e /d "network service"
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net.exe /e /d SERVICE
- '%WINDIR%\syswow64\takeown.exe' /f %WINDIR%\SysWOW64\net1.exe /a
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net1.exe /e /d mssql$sqlexpress
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net1.exe /e /d system
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net1.exe /e /d "network service"
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net1.exe /e /d mssqlserver
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net1.exe /e /d SERVICE
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net1.exe /e /g Administrators:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net1.exe /e /g Users:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net1.exe /g Administrators:f
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net.exe /e /d mssqlserver
- '%WINDIR%\syswow64\takeown.exe' /f <SYSTEM32>\net1.exe /a
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net.exe /g Administrators:f
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net.exe /e /d "network service"
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net.exe /e /d mssqlserver
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net.exe /e /d SERVICE
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net.exe /e /g Administrators:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net.exe /e /g Users:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net.exe /g Administrators:f
- '%WINDIR%\syswow64\takeown.exe' /f %WINDIR%\SysWOW64\net.exe /a
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net.exe /e /d mssql$sqlexpress
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\net.exe /e /d system
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\net.exe /e /d mssql$sqlexpress
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wscript.exe /e /d mssql$sqlexpress