Technical Information
- <SYSTEM32>\cacls.exe "%PROGRAM_FILES%\ttb.ico" /e /c /r "Authenticated Users"
- <SYSTEM32>\cacls.exe "%PROGRAM_FILES%\ttb.ico" /e /c /r "%USERNAME%
- <SYSTEM32>\cacls.exe "%PROGRAM_FILES%\ttb.ico" /e /c /r Users
- <SYSTEM32>\cacls.exe "<Full path to virus>" /e /c /r %USERNAME%s
- <SYSTEM32>\cacls.exe "<Full path to virus>" /e /c /G Everyone:r
- <SYSTEM32>\cacls.exe "%PROGRAM_FILES%\ttb.ico" /e /c /r "Power Users"
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\购物淘宝.lnk" /e /c /r "Power Users"
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\购物淘宝.lnk" /e /c /r "Authenticated Users"
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\购物淘宝.lnk" /e /c /r "%USERNAME%
- <SYSTEM32>\cacls.exe "%PROGRAM_FILES%\ttb.ico" /e /c /r System
- <SYSTEM32>\cacls.exe "%PROGRAM_FILES%\ttb.ico" /e /c /r %USERNAME%s
- <SYSTEM32>\cacls.exe "%PROGRAM_FILES%\ttb.ico" /e /c /G Everyone:r
- <SYSTEM32>\cacls.exe "<Full path to virus>" /e /c /r System
- <SYSTEM32>\cacls.exe "%HOMEPATH%\Desktop\Intrenet Expolrer.lnk" /e /c /r "%USERNAME%
- <SYSTEM32>\cacls.exe "%HOMEPATH%\Desktop\Intrenet Expolrer.lnk" /e /c /r Users
- <SYSTEM32>\cacls.exe "%HOMEPATH%\Desktop\Intrenet Expolrer.lnk" /e /c /r System
- <SYSTEM32>\cmd.exe /c ""<Current directory>\k.bat""
- <SYSTEM32>\cacls.exe "%HOMEPATH%\Desktop\Intrenet Expolrer.lnk" /e /c /r "Power Users"
- <SYSTEM32>\cacls.exe "%HOMEPATH%\Desktop\Intrenet Expolrer.lnk" /e /c /r "Authenticated Users"
- <SYSTEM32>\cacls.exe "<Full path to virus>" /e /c /r "Authenticated Users"
- <SYSTEM32>\cacls.exe "<Full path to virus>" /e /c /r "%USERNAME%
- <SYSTEM32>\cacls.exe "<Full path to virus>" /e /c /r Users
- <SYSTEM32>\cacls.exe "%HOMEPATH%\Desktop\Intrenet Expolrer.lnk" /e /c /r %USERNAME%s
- <SYSTEM32>\cacls.exe "%HOMEPATH%\Desktop\Intrenet Expolrer.lnk" /e /c /G Everyone:r
- <SYSTEM32>\cacls.exe "<Full path to virus>" /e /c /r "Power Users"
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\购物淘宝.lnk" /e /c /r Users
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\上网指南.lnk" /e /c /G Everyone:r
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\Intrenet Expolrer.lnk" /e /c /r "Power Users"
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\Intrenet Expolrer.lnk" /e /c /r "Authenticated Users"
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\上网指南.lnk" /e /c /r Users
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\上网指南.lnk" /e /c /r System
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\上网指南.lnk" /e /c /r %USERNAME%s
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\Intrenet Expolrer.lnk" /e /c /r %USERNAME%s
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\Intrenet Expolrer.lnk" /e /c /G Everyone:r
- <SYSTEM32>\ipconfig.exe /all
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\Intrenet Expolrer.lnk" /e /c /r "%USERNAME%
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\Intrenet Expolrer.lnk" /e /c /r Users
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\Intrenet Expolrer.lnk" /e /c /r System
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\上网指南.lnk" /e /c /r "%USERNAME%
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\精彩小游戏.lnk" /e /c /r "Power Users"
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\精彩小游戏.lnk" /e /c /r "Authenticated Users"
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\精彩小游戏.lnk" /e /c /r "%USERNAME%
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\购物淘宝.lnk" /e /c /r System
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\购物淘宝.lnk" /e /c /r %USERNAME%s
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\购物淘宝.lnk" /e /c /G Everyone:r
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\精彩小游戏.lnk" /e /c /G Everyone:r
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\上网指南.lnk" /e /c /r "Power Users"
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\上网指南.lnk" /e /c /r "Authenticated Users"
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\精彩小游戏.lnk" /e /c /r Users
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\精彩小游戏.lnk" /e /c /r System
- <SYSTEM32>\cacls.exe "%ALLUSERSPROFILE%\Desktop\精彩小游戏.lnk" /e /c /r %USERNAME%s
- %ALLUSERSPROFILE%\Start Menu\iiee.lnk
- <Current directory>\k.bat
- %ALLUSERSPROFILE%\Start Menu\iiieee.lnk
- %PROGRAM_FILES%\ttb.ico
- %WINDIR%\Temp\ld08.tmp
- %ALLUSERSPROFILE%\Desktop\Intrenet Expolrer.lnk
- %PROGRAM_FILES%\ttb.ico
- %WINDIR%\Temp\ld08.tmp
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Progman' WindowName: ''