Technical Information
- %APPDATA%\microsoft\windows\templates\scheduler_b.dll
- %HOMEPATH%\application data\microsoft\forms\winword.box
- %TEMP%\~wrd0000.tmp
- %TEMP%\videmem.docx.zip
- %TEMP%\~wrd0001.tmp
- %TEMP%\videmem.docx
- %TEMP%\oleobject1.bin
- %APPDATA%\microsoft\windows\templates\scheduler_b.dll
- from %TEMP%\~wrd0000.tmp to %TEMP%\videmem.docx.zip
- from %TEMP%\~wrd0001.tmp to %TEMP%\videmem.docx
- 'mi#####ft-hub-us.com':443
- DNS ASK mi#####ft-hub-us.com
- ClassName: '' WindowName: 'Microsoft Office Components'