Technical Information
- <SYSTEM32>\tasks\shell hardware detection
- %TEMP%\montreuil.jpg
- '%WINDIR%\explorer.exe' "%TEMP%\HoSo.doc"
- %TEMP%\montreuil.jpg
- %TEMP%\hoso.doc
- %ALLUSERSPROFILE%\mpsvc.dll
- %ALLUSERSPROFILE%\msmpeng.exe
- '%WINDIR%\explorer.exe' "%TEMP%\HoSo.doc"' (with hidden window)
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\HoSo.doc"' (with hidden window)
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\HoSo.doc"