Technical Information
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\A9Rhsue3y_2vlifd_358.tmp\Product Catalogue & Pricelist.doc"
- rdrcef.exe
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1400' = '00000003'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1C00' = '00000000'
- %TEMP%\a9rhsue3y_2vlifd_358.tmp\product catalogue & pricelist.doc
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\cookies-journal
- %TEMP%\etilqs_n2qnsq3orlps88x
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\cookies
- %TEMP%\a9rtzn8zg_2vliff_358.tmp
- 'ab##zr.ma':80
- http://www.ab##zr.ma/nokwar2.1.exe
- DNS ASK ab##zr.ma
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding