Technical Information
- %HOMEPATH%\desktop\000814251_video_01.avi
- %HOMEPATH%\desktop\archer.avi
- %HOMEPATH%\desktop\correct.avi
- %HOMEPATH%\desktop\dashborder_96.bmp
- %HOMEPATH%\desktop\dial.bmp
- %HOMEPATH%\desktop\february_catalogue__2015.doc
- %HOMEPATH%\desktop\fi51.doc
- %HOMEPATH%\desktop\file_p_00000000_1371597592.docx
- %HOMEPATH%\desktop\nwfieldnotes1966.docx
- %HOMEPATH%\desktop\ovp25012015.doc
- %HOMEPATH%\desktop\split.avi
- %HOMEPATH%\desktop\tileimage.bmp
- %HOMEPATH%\desktop\weeklysheet1215.doc
- %TEMP%\office32ww.xml
- %TEMP%\lighthouse.jpg
- %TEMP%\penguins.jpg
- %TEMP%\tulips.jpg
- %TEMP%\wildlife.wmv
- %TEMP%\000814251_video_01.avi
- %TEMP%\google chrome.lnk
- %TEMP%\telegram.lnk
- %TEMP%\archer.avi
- %TEMP%\correct.avi
- %TEMP%\dashborder_96.bmp
- %TEMP%\dial.bmp
- %TEMP%\february_catalogue__2015.doc
- %TEMP%\officemui.xml
- %TEMP%\fi51.doc
- %TEMP%\nwfieldnotes1966.docx
- %TEMP%\ovp25012015.doc
- %TEMP%\split.avi
- %TEMP%\tileimage.bmp
- %TEMP%\weeklysheet1215.doc
- %TEMP%\desktop.lnk
- %TEMP%\downloads.lnk
- %TEMP%\recentplaces.lnk
- %TEMP%\ntuser.ini
- %TEMP%\10thingscondoms.pdf
- %TEMP%\168.jpeg
- %TEMP%\168.jpg
- %TEMP%\jellyfish.jpg
- %TEMP%\koala.jpg
- %TEMP%\hydrangeas.jpg
- %TEMP%\desert.jpg
- %TEMP%\chrysanthemum.jpg
- %TEMP%\setup.xml
- %TEMP%\excelmui.xml
- %TEMP%\powerpointmui.xml
- %TEMP%\publishermui.xml
- %TEMP%\outlookmui.xml
- %TEMP%\wordmui.xml
- %TEMP%\proof.xml
- %TEMP%\proofing.xml
- %TEMP%\office32mui.xml
- %TEMP%\onenotemui.xml
- %TEMP%\infopathmui.xml
- %TEMP%\groovemui.xml
- %TEMP%\1sm_price.xls
- %TEMP%\file_p_00000000_1371597592.docx
- %TEMP%\officemuiset.xml
- %TEMP%\accessmui.xml
- %TEMP%\accessmuiset.xml
- %TEMP%\ntuser.dat.log
- %TEMP%\acrobat reader dc.lnk
- %TEMP%\mozilla thunderbird.lnk
- %TEMP%\firefox.lnk
- %TEMP%\opera.lnk
- %TEMP%\steam.lnk
- %TEMP%\desktop.ini
- %TEMP%\kalimba.mp3
- %TEMP%\maid with the flaxen hair.mp3
- %TEMP%\sleep away.mp3
- %TEMP%\proplusww.xml
- %TEMP%\branding.xml
- %TEMP%\1sm_price.zip
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\office32ww.xml
- C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\officemuiset.xml
- C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\officemui.xml
- C:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\groovemui.xml
- C:\msocache\all users\{90140000-00ba-0409-1000-0000000ff1ce}-c\setup.xml
- C:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\setup.xml
- C:\msocache\all users\{90140000-00a1-0409-1000-0000000ff1ce}-c\onenotemui.xml
- C:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\infopathmui.xml
- C:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\setup.xml
- C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\setup.xml
- C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\office32mui.xml
- C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\setup.xml
- C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proofing.xml
- C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.fr\proof.xml
- C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.es\proof.xml
- C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\proof.xml
- C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\wordmui.xml
- C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\setup.xml
- C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\setup.xml
- C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\outlookmui.xml
- C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\setup.xml
- C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\publishermui.xml
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\powerpointmui.xml
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\setup.xml
- C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\setup.xml
- C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\excelmui.xml
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\proplusww.xml
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\setup.xml
- C:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\setup.xml
- C:\msocache\all users\{90140000-0117-0409-1000-0000000ff1ce}-c\access.en-us\accessmui.xml
- '%WINDIR%\syswow64\cmd.exe' /C "icacls . /grant Everyone:F /T /C /Q"
- '%WINDIR%\syswow64\icacls.exe' . /grant Everyone:F /T /C /Q
- '%WINDIR%\syswow64\cmd.exe' /C "icacls . /grant Everyone:F /T /C /Q"' (with hidden window)