Technical Information
- <Current directory>\killme.bat
- ClassName: 'MS_WINHELP' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /c /e /p everyone:f' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\dllcache\sethc.exe /c /e /p everyone:f' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r everyone' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r administrators' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r users' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r system' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r "Power users"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /c /e /p administrators:r' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /c /e /p system:r' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /c /e /p "Power users":r' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /c /e /p users:r' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c <Current directory>\killme.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /c /e /p everyone:f
- '%WINDIR%\syswow64\cmd.exe' /c <Current directory>\killme.bat
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\\sethc.exe /c /e /p users:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r "Power users"
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r users
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\\sethc.exe /c /e /p administrators:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r everyone
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r administrators
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r system
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /c /e /p users:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\\sethc.exe /c /e /p "Power users":r
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /c /e /p "Power users":r
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /c /e /p administrators:r
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r "Power users"
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r system
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r users
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r administrators
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /t /c /e /r everyone
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\\dllcache\sethc.exe /c /e /p everyone:f
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\\sethc.exe /c /e /p everyone:f
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\dllcache\sethc.exe /c /e /p everyone:f
- '%WINDIR%\syswow64\cmd.exe' /c cacls %WINDIR%\SysWOW64\\sethc.exe /c /e /p system:r
- '%WINDIR%\syswow64\cacls.exe' %WINDIR%\SysWOW64\\sethc.exe /c /e /p system:r