Technical Information
- '<SYSTEM32>\reg.exe' EXPORT HKCU\Software\Microsoft\Office\14.0\Excel\Security C:\Users\Public\KSRUrLX.reg /y
- %TEMP%\d501.tmp
- %TEMP%\reg1342.tmp
- C:\users\public\ksrurlx.reg
- %TEMP%\reg1342.tmp
- C:\users\public\ksrurlx.reg
- %TEMP%\d501.tmp