Technical Information
- <Drive name for removable media>:\autorun.inf
- <Drive name for removable media>:\setup.exe
- <Drive name for removable media>:\a.bat
- <Drive name for removable media>:\go.exe
- %TEMP%\aut28c1.tmp
- %TEMP%\cwxp2.jpg
- %TEMP%\aut28d2.tmp
- %TEMP%\cwxp2.bat
- C:\autorun.inf
- D:\autorun.inf
- C:\setup.exe
- D:\setup.exe
- C:\a.bat
- D:\a.bat
- C:\go.exe
- D:\go.exe
- %WINDIR%\0sy.exe
- %WINDIR%\1.com
- %WINDIR%\1sy.exe
- %WINDIR%\2sy.exe
- %WINDIR%\3sy.exe
- %WINDIR%\4sy.exe
- %WINDIR%\5sy.exe
- %WINDIR%\6sy.exe
- %WINDIR%\7sy.exe
- %WINDIR%\8sy.exe
- %WINDIR%\9sy.exe
- %WINDIR%\215366.dll
- %WINDIR%\215366m.bmp
- %WINDIR%\cmdbcs.exe
- %WINDIR%\dll.dll
- %WINDIR%\exerouter.exe
- %WINDIR%\exp10rer.com
- %WINDIR%\finders.com
- %WINDIR%\logo1_.exe
- %WINDIR%\logo_1.exe
- %WINDIR%\logo_.exe
- %WINDIR%\lsass.exe
- %WINDIR%\msccrt.exe
- %WINDIR%\ravdm.exe
- %WINDIR%\richdll.dll
- %WINDIR%\rund1l32.exe
- %WINDIR%\rundl132.exe
- %WINDIR%\rundll32.exe
- %WINDIR%\shell.sys
- %WINDIR%\smss.exe
- %WINDIR%\svchost.exe
- %WINDIR%\tdll.dll
- %WINDIR%\vdll.dll
- %WINDIR%\winlogon.exe
- %WINDIR%\wldll.dll
- %WINDIR%\wsttrs.exe
- %WINDIR%\wsvs.exe
- %WINDIR%\syswow64\0sy.exe
- %WINDIR%\syswow64\1.com
- %WINDIR%\syswow64\1sy.exe
- %WINDIR%\syswow64\2sy.exe
- %WINDIR%\syswow64\3sy.exe
- %WINDIR%\syswow64\4sy.exe
- %WINDIR%\syswow64\5sy.exe
- %WINDIR%\syswow64\6sy.exe
- %WINDIR%\syswow64\7sy.exe
- %WINDIR%\syswow64\8sy.exe
- %WINDIR%\syswow64\9sy.exe
- %WINDIR%\syswow64\215366.dll
- %WINDIR%\syswow64\215366m.bmp
- %WINDIR%\syswow64\cmdbcs.exe
- %WINDIR%\syswow64\exerouter.exe
- %WINDIR%\syswow64\exp10rer.com
- %WINDIR%\syswow64\finders.com
- %WINDIR%\syswow64\logo1_.exe
- %WINDIR%\syswow64\logo_1.exe
- %WINDIR%\syswow64\logo_.exe
- %WINDIR%\syswow64\lsass.exe
- %WINDIR%\syswow64\msccrt.exe
- %WINDIR%\syswow64\ravdm.exe
- %WINDIR%\syswow64\richdll.dll
- %WINDIR%\syswow64\rund1l32.exe
- %WINDIR%\syswow64\rundl132.exe
- %WINDIR%\syswow64\services.exe
- %WINDIR%\syswow64\shell.sys
- %WINDIR%\syswow64\smss.exe
- %WINDIR%\syswow64\tdll.dll
- %WINDIR%\syswow64\vdll.dll
- %WINDIR%\syswow64\winlogon.exe
- %WINDIR%\syswow64\wldll.dll
- %WINDIR%\syswow64\wsttrs.exe
- %WINDIR%\syswow64\wsvs.exe
- %WINDIR%\syswow64\drivers\nvscv32.exe
- %WINDIR%\syswow64\cmdbcs.dll
- %WINDIR%\syswow64\msccrt.dll
- %WINDIR%\syswow64\wc1.exe
- %WINDIR%\syswow64\wc2.exe
- %WINDIR%\syswow64\wsttrs.dll
- %WINDIR%\syswow64\wsvs.dll
- %WINDIR%\system\1.exe
- %WINDIR%\system\4.exe
- %WINDIR%\system\7.exe
- %WINDIR%\system\c.dll
- %WINDIR%\system\cmd.dll
- %WINDIR%\system\icehbo.dll
- %WINDIR%\system\internat.exe
- %WINDIR%\system\internat.exe.tmp
- %WINDIR%\system\system32.vxd
- %WINDIR%\system\taskmgr.exe.tmp
- %WINDIR%\system\wc1.exe
- %WINDIR%\system\wc2.exe
- %WINDIR%\1.exe
- %WINDIR%\4.exe
- %WINDIR%\7.exe
- %WINDIR%\mppds.exe
- %WINDIR%\wc1.exe
- %WINDIR%\wc2.exe
- %WINDIR%\crasos.exe
- %WINDIR%\syswow64\mswsock30.dll
- %WINDIR%\syswow64\msxos.dll
- %WINDIR%\syswow64\tmp.zip
- %WINDIR%\syswow64\maindownloadselfinfo.tmp
- %WINDIR%\syswow64\wsp_fix.dll
- %WINDIR%\syswow64\win_std32.dll
- %WINDIR%\syswow64\shell32_cn.dll
- %WINDIR%\syswow64\seh_dbg.dll
- %WINDIR%\syswow64\msspi.dll
- C:\a.bat
- C:\autorun.inf
- C:\go.exe
- C:\setup.exe
- D:\setup.exe
- <Drive name for removable media>:\setup.exe
- D:\autorun.inf
- <Drive name for removable media>:\autorun.inf
- D:\a.bat
- <Drive name for removable media>:\a.bat
- D:\go.exe
- <Drive name for removable media>:\go.exe
- %WINDIR%\crasos.exe
- %WINDIR%\syswow64\mswsock30.dll
- %WINDIR%\syswow64\msxos.dll
- %WINDIR%\syswow64\tmp.zip
- %WINDIR%\syswow64\maindownloadselfinfo.tmp
- %WINDIR%\syswow64\wsp_fix.dll
- %WINDIR%\syswow64\win_std32.dll
- %WINDIR%\syswow64\shell32_cn.dll
- %WINDIR%\syswow64\seh_dbg.dll
- %WINDIR%\syswow64\msspi.dll
- %WINDIR%\0sy.exe
- %WINDIR%\1.com
- %WINDIR%\1sy.exe
- %WINDIR%\2sy.exe
- %WINDIR%\3sy.exe
- %WINDIR%\4sy.exe
- %WINDIR%\5sy.exe
- %WINDIR%\6sy.exe
- %WINDIR%\7sy.exe
- %WINDIR%\8sy.exe
- %WINDIR%\9sy.exe
- %WINDIR%\215366.dll
- %WINDIR%\215366m.bmp
- %WINDIR%\cmdbcs.exe
- %WINDIR%\dll.dll
- %WINDIR%\exerouter.exe
- %WINDIR%\exp10rer.com
- %WINDIR%\finders.com
- %WINDIR%\logo1_.exe
- %WINDIR%\logo_1.exe
- %WINDIR%\logo_.exe
- %WINDIR%\lsass.exe
- %WINDIR%\msccrt.exe
- %WINDIR%\ravdm.exe
- %WINDIR%\richdll.dll
- %WINDIR%\rund1l32.exe
- %WINDIR%\rundl132.exe
- %WINDIR%\rundll32.exe
- %WINDIR%\shell.sys
- %WINDIR%\smss.exe
- %WINDIR%\svchost.exe
- %WINDIR%\tdll.dll
- %WINDIR%\vdll.dll
- %WINDIR%\winlogon.exe
- %WINDIR%\wldll.dll
- %WINDIR%\wsttrs.exe
- %WINDIR%\wsvs.exe
- %WINDIR%\syswow64\0sy.exe
- %WINDIR%\syswow64\1.com
- %WINDIR%\syswow64\1sy.exe
- %WINDIR%\syswow64\2sy.exe
- %WINDIR%\syswow64\3sy.exe
- %WINDIR%\syswow64\4sy.exe
- %WINDIR%\syswow64\5sy.exe
- %WINDIR%\syswow64\6sy.exe
- %WINDIR%\syswow64\7sy.exe
- %WINDIR%\syswow64\8sy.exe
- %WINDIR%\syswow64\9sy.exe
- %WINDIR%\syswow64\215366.dll
- %WINDIR%\syswow64\215366m.bmp
- %WINDIR%\syswow64\cmdbcs.exe
- %WINDIR%\syswow64\exerouter.exe
- %WINDIR%\syswow64\exp10rer.com
- %WINDIR%\syswow64\finders.com
- %WINDIR%\syswow64\logo1_.exe
- %WINDIR%\syswow64\logo_1.exe
- %WINDIR%\syswow64\logo_.exe
- %WINDIR%\syswow64\lsass.exe
- %WINDIR%\syswow64\msccrt.exe
- %WINDIR%\syswow64\ravdm.exe
- %WINDIR%\syswow64\richdll.dll
- %WINDIR%\syswow64\rund1l32.exe
- %WINDIR%\syswow64\rundl132.exe
- %WINDIR%\syswow64\services.exe
- %WINDIR%\syswow64\shell.sys
- %WINDIR%\syswow64\smss.exe
- %WINDIR%\syswow64\tdll.dll
- %WINDIR%\syswow64\vdll.dll
- %WINDIR%\syswow64\winlogon.exe
- %WINDIR%\syswow64\wldll.dll
- %WINDIR%\syswow64\wsttrs.exe
- %WINDIR%\syswow64\wsvs.exe
- %WINDIR%\syswow64\drivers\nvscv32.exe
- %WINDIR%\syswow64\cmdbcs.dll
- %WINDIR%\syswow64\msccrt.dll
- %WINDIR%\syswow64\wc1.exe
- %WINDIR%\syswow64\wc2.exe
- %WINDIR%\syswow64\wsttrs.dll
- %WINDIR%\syswow64\wsvs.dll
- %WINDIR%\system\1.exe
- %WINDIR%\system\4.exe
- %WINDIR%\system\7.exe
- %WINDIR%\system\c.dll
- %WINDIR%\system\cmd.dll
- %WINDIR%\system\icehbo.dll
- %WINDIR%\system\internat.exe
- %WINDIR%\system\internat.exe.tmp
- %WINDIR%\system\system32.vxd
- %WINDIR%\system\taskmgr.exe.tmp
- %WINDIR%\system\wc1.exe
- %WINDIR%\system\wc2.exe
- %WINDIR%\1.exe
- %WINDIR%\4.exe
- %WINDIR%\7.exe
- %WINDIR%\mppds.exe
- %WINDIR%\wc1.exe
- %WINDIR%\wc2.exe
- %TEMP%\aut28c1.tmp
- %TEMP%\aut28d2.tmp
- %TEMP%\cwxp2.jpg
- %TEMP%\cwxp2.bat
- DNS ASK fi#####.###tings.services.mozilla.com
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\cwxp2.bat
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" echo y"
- '%WINDIR%\syswow64\cacls.exe' c:\autorun.inf /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' d:\autorun.inf /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' e:\autorun.inf /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' <Drive name for removable media>:\autorun.inf /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' g:\autorun.inf /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' c:\setup.exe /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' d:\setup.exe /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' e:\setup.exe /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' <Drive name for removable media>:\setup.exe /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' g:\setup.exe /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' c:\go.exe /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' d:\go.exe /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' e:\go.exe /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' <Drive name for removable media>:\go.exe /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' g:\go.exe /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' c:\a.bat /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' d:\a.bat /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' e:\a.bat /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' <Drive name for removable media>:\a.bat /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' g:\a.bat /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\crasos.exe /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\mswsock30.dll /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\msxos.dll /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\tmp.zip /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\maindownloadselfinfo.tmp /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wsp_fix.dll /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\win_std32.dll /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\shell32_cn.dll /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\seh_dbg.dll /c /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\msspi.dll /c /p everyone:f
- '%WINDIR%\syswow64\attrib.exe' c:\*.* -r -h -s
- '%WINDIR%\syswow64\attrib.exe' d:\*.* -r -h -s
- '%WINDIR%\syswow64\attrib.exe' e:\*.* -r -h -s
- '%WINDIR%\syswow64\attrib.exe' <Drive name for removable media>:\*.* -r -h -s
- '%WINDIR%\syswow64\attrib.exe' c:\*.* +r +h +s
- '%WINDIR%\syswow64\attrib.exe' c:\setup.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' d:\setup.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' e:\setup.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <Drive name for removable media>:\setup.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' c:\autorun.inf +r +h +s
- '%WINDIR%\syswow64\attrib.exe' d:\autorun.inf +r +h +s
- '%WINDIR%\syswow64\attrib.exe' e:\autorun.inf +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <Drive name for removable media>:\autorun.inf +r +h +s
- '%WINDIR%\syswow64\attrib.exe' c:\a.bat +r +h +s
- '%WINDIR%\syswow64\attrib.exe' d:\a.bat +r +h +s
- '%WINDIR%\syswow64\attrib.exe' e:\a.bat +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <Drive name for removable media>:\a.bat +r +h +s
- '%WINDIR%\syswow64\attrib.exe' c:\go.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' d:\go.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' e:\go.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <Drive name for removable media>:\go.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\crasos.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\mswsock30.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\msxos.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\tmp.zip +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\maindownloadselfinfo.tmp +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\wsp_fix.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\win_std32.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\shell32_cn.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\seh_dbg.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\msspi.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\0Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\1.com +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\1Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\2Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\3Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\4Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\5Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\6Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\7Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\8Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\9Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\215366.DLL +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\215366M.BMP +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\cmdbcs.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\dll.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\exerouter.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\EXP10RER.com +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\finders.com +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\logo1_.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\logo_1.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\logo_.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\LSASS.EXE +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\msccrt.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\Ravdm.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\RichDll.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\rund1l32.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\rundl132.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\RUNDLL32.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\Shell.sys +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\smss.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\SVCHOST.EXE +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\tdll.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\vdll.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\WINLOGON.EXE +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\wldll.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\wsttrs.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\wsvs.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\0Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\1.com +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\1Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\2Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\3Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\4Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\5Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\6Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\7Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\8Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\9Sy.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\215366.DLL +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\215366M.BMP +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\cmdbcs.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\exerouter.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\EXP10RER.com +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\finders.com +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\logo1_.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\logo_1.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\logo_.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\LSASS.EXE +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\msccrt.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\Ravdm.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\RichDll.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\rund1l32.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\rundl132.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\RUNDLL32.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\SERVICES.EXE +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\Shell.sys +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\smss.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\SVCHOST.EXE +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\tdll.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\vdll.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\WINLOGON.EXE +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\wldll.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\wsttrs.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\wsvs.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <DRIVERS>\nvscv32.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\Logo1_.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\cmdbcs.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\msccrt.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\wc1.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\wc2.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\wsttrs.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' <SYSTEM32>\wsvs.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\system\1.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\system\4.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\system\7.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\system\C.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\system\CMD.DLL +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\system\IceHBO.dll +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\system\internat.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\system\internat.exe.tmp +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\system\SYSTEM32.vxd +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\system\taskmgr.exe.tmp +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\system\wc1.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\system\wc2.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\1.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\4.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\7.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\mppds.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\wc1.exe +r +h +s
- '%WINDIR%\syswow64\attrib.exe' %WINDIR%\wc2.exe +r +h +s
- '%WINDIR%\syswow64\cacls.exe' c:\autorun.inf /c /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' d:\autorun.inf /c /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' e:\autorun.inf /c /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' <Drive name for removable media>:\autorun.inf /c /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' c:\setup.exe /c /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' d:\setup.exe /c /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' e:\setup.exe /c /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' <Drive name for removable media>:\setup.exe /c /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' c:\a.bat /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' D:\a.bat /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' E:\a.bat /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' <Drive name for removable media>:\a.bat /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' c:\go.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' D:\go.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' E:\go.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' <Drive name for removable media>:\go.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\crasos.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\mswsock30.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\msxos.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\tmp.zip /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\maindownloadselfinfo.tmp /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wsp_fix.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\win_std32.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\shell32_cn.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\seh_dbg.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\msspi.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\0Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\1.com /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\1Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\2Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\3Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\4Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\5Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\6Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\7Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\8Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\9Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\215366.DLL /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\215366M.BMP /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\cmdbcs.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\dll.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\exerouter.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\EXP10RER.com /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\finders.com /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\logo1_.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\logo_1.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\logo_.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\LSASS.EXE /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\msccrt.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\Ravdm.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\RichDll.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\rund1l32.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\rundl132.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\RUNDLL32.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\Shell.sys /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\smss.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SVCHOST.EXE /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\tdll.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\vdll.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\WINLOGON.EXE /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\wldll.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\wsttrs.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\wsvs.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\0Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\1.com /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\1Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\2Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\3Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\4Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\5Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\6Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\7Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\8Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\9Sy.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\215366.DLL /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\215366M.BMP /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\cmdbcs.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\exerouter.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\EXP10RER.com /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\finders.com /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\logo1_.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\logo_1.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\logo_.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\LSASS.EXE /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\msccrt.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\Ravdm.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\RichDll.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\rund1l32.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\rundl132.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\RUNDLL32.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\SERVICES.EXE /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\Shell.sys /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\smss.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\SVCHOST.EXE /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\tdll.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\vdll.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\WINLOGON.EXE /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wldll.dll /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wsttrs.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wsvs.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <DRIVERS>\nvscv32.exe /c /p everyone:r
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\cmdbcs.dll /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\msccrt.dll /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wc1.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wc2.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wsttrs.dll /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' <SYSTEM32>\wsvs.dll /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\system\1.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\system\4.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\system\7.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\system\C.dll /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\system\CMD.DLL /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\system\IceHBO.dll /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\system\internat.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\system\internat.exe.tmp /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\system\SYSTEM32.vxd /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\system\taskmgr.exe.tmp /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\system\wc1.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\system\wc2.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\1.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\4.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\7.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\cmdbcs.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\mppds.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\wsttrs.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\wsvs.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\wc1.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\wc2.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' c:\wc1.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' c:\wc2.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' d:\wc1.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' d:\wc2.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' e:\wc1.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' e:\wc2.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' <Drive name for removable media>:\wc1.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' <Drive name for removable media>:\wc2.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' c:\autorun.inf /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' D:\autorun.inf /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' E:\autorun.inf /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' <Drive name for removable media>:\autorun.inf /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' c:\setup.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' D:\setup.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' E:\setup.exe /p everyone:n
- '%WINDIR%\syswow64\cacls.exe' <Drive name for removable media>:\setup.exe /p everyone:n
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\cwxp2.bat' (with hidden window)