Technical Information
- http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/office/data/v32.cab as %temp%\over135797\v32.cab
- http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/office/data/v32.cab as %temp%\over685568\v32.cab
- http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/office/data/v32.cab as %temp%\over296121\v32.cab
- http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/office/data/v32.cab as %temp%\over731420\v32.cab
- http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/office/data/v32.cab as %temp%\over404070\v32.cab
- http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/office/data/v32.cab as %temp%\over682221\v32.cab
- http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/office/data/v32.cab as %temp%\over474862\v32.cab
- http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/office/data/v32.cab as %temp%\over487731\v32.cab
- <Current directory>\files\setup.exe
- %TEMP%\over474862\v32.txt
- %TEMP%\over474862\$dpx$.tmp\04365f98780a984f9ac2eece4d7aafd3.tmp
- %TEMP%\over474862\v32.cab
- %TEMP%\over682221\v32.txt
- %TEMP%\over682221\$dpx$.tmp\600d16a13209ab4199bd11fb2cbcabdf.tmp
- %TEMP%\over682221\v32.cab
- %TEMP%\over404070\v32.txt
- %TEMP%\over404070\$dpx$.tmp\1ea644eb8cfc4f499ef12225c7863327.tmp
- %TEMP%\over404070\v32.cab
- %TEMP%\over731420\v32.txt
- %TEMP%\over731420\$dpx$.tmp\8b6f0b03684f4448904a5f4e2dcd3756.tmp
- %TEMP%\over731420\v32.cab
- %TEMP%\over296121\v32.txt
- %TEMP%\over487731\v32.cab
- %TEMP%\over296121\$dpx$.tmp\ab6d8604db24444e893170020511b2b8.tmp
- %TEMP%\over685568\v32.txt
- %TEMP%\over685568\$dpx$.tmp\f2ef9569991311409245a4cc068af53e.tmp
- %TEMP%\over685568\v32.cab
- %TEMP%\over135797\v32.txt
- %TEMP%\over135797\$dpx$.tmp\6cb7e4314d9c814f86e0574856d2ca78.tmp
- %TEMP%\over135797\v32.cab
- <Current directory>\files\configure.xml
- <Current directory>\files\x86\msvcr100.dll
- <Current directory>\files\x86\cleanospp.exe
- <Current directory>\files\x64\msvcr100.dll
- <Current directory>\files\x64\cleanospp.exe
- <Current directory>\files\uninstall.xml
- <Current directory>\files\files.dat
- %TEMP%\over296121\v32.cab
- %TEMP%\over487731\$dpx$.tmp\5830eb49cf225440801a333a965e07e5.tmp
- <Current directory>\files\files.dat
- %TEMP%\over474862\versiondescriptor.xml
- %TEMP%\over474862\v32.txt
- %TEMP%\over474862\v32.cab
- %TEMP%\over682221\versiondescriptor.xml
- %TEMP%\over682221\v32.txt
- %TEMP%\over682221\v32.cab
- %TEMP%\over404070\versiondescriptor.xml
- %TEMP%\over404070\v32.txt
- %TEMP%\over404070\v32.cab
- %TEMP%\over731420\versiondescriptor.xml
- %TEMP%\over731420\v32.txt
- %TEMP%\over731420\v32.cab
- %TEMP%\over296121\versiondescriptor.xml
- %TEMP%\over296121\v32.txt
- %TEMP%\over296121\v32.cab
- %TEMP%\over685568\versiondescriptor.xml
- %TEMP%\over685568\v32.txt
- %TEMP%\over685568\v32.cab
- %TEMP%\over135797\versiondescriptor.xml
- %TEMP%\over135797\v32.txt
- %TEMP%\over135797\v32.cab
- %TEMP%\over487731\v32.cab
- %TEMP%\over487731\versiondescriptor.xml
- from %TEMP%\over135797\$dpx$.tmp\6cb7e4314d9c814f86e0574856d2ca78.tmp to %TEMP%\over135797\versiondescriptor.xml
- from %TEMP%\over685568\$dpx$.tmp\f2ef9569991311409245a4cc068af53e.tmp to %TEMP%\over685568\versiondescriptor.xml
- from %TEMP%\over296121\$dpx$.tmp\ab6d8604db24444e893170020511b2b8.tmp to %TEMP%\over296121\versiondescriptor.xml
- from %TEMP%\over731420\$dpx$.tmp\8b6f0b03684f4448904a5f4e2dcd3756.tmp to %TEMP%\over731420\versiondescriptor.xml
- from %TEMP%\over404070\$dpx$.tmp\1ea644eb8cfc4f499ef12225c7863327.tmp to %TEMP%\over404070\versiondescriptor.xml
- from %TEMP%\over682221\$dpx$.tmp\600d16a13209ab4199bd11fb2cbcabdf.tmp to %TEMP%\over682221\versiondescriptor.xml
- from %TEMP%\over474862\$dpx$.tmp\04365f98780a984f9ac2eece4d7aafd3.tmp to %TEMP%\over474862\versiondescriptor.xml
- from %TEMP%\over487731\$dpx$.tmp\5830eb49cf225440801a333a965e07e5.tmp to %TEMP%\over487731\versiondescriptor.xml
- 'officecdn.microsoft.com':80
- http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32.cab
- DNS ASK officecdn.microsoft.com
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over731420\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over404070\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over296121\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over682221\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over487731\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over474862\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over685568\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }
- '<Current directory>\files\files.dat' -y -pkmsauto
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over135797\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over404070' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { (New-Object Net.WebClient).DownloadFile('http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32.cab', '%TEMP%\over404070\v32.cab') }"' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over404070\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { (New-Object Net.WebClient).DownloadFile('http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32.cab', '%TEMP%\over682221\v32.cab') }"' (with hidden window)
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over682221' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { (New-Object Net.WebClient).DownloadFile('http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32.cab', '%TEMP%\over474862\v32.cab') }"' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over682221\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over474862\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }' (with hidden window)
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings" /v Enabled /t REG_DWORD /d 1 /f' (with hidden window)
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over474862' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { (New-Object Net.WebClient).DownloadFile('http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32.cab', '%TEMP%\over487731\v32.cab') }"' (with hidden window)
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over487731' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { (New-Object Net.WebClient).DownloadFile('http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32.cab', '%TEMP%\over731420\v32.cab') }"' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { (New-Object Net.WebClient).DownloadFile('http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32.cab', '%TEMP%\over685568\v32.cab') }"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /D /c files.dat -y -pkmsauto' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over731420\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }' (with hidden window)
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over135797' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over135797\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { (New-Object Net.WebClient).DownloadFile('http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32.cab', '%TEMP%\over135797\v32.cab') }"' (with hidden window)
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over685568' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over685568\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { (New-Object Net.WebClient).DownloadFile('http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32.cab', '%TEMP%\over296121\v32.cab') }"' (with hidden window)
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over296121' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over296121\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }' (with hidden window)
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over731420' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "& { Get-Content %TEMP%\over487731\VersionDescriptor.xml | Set-Content -Encoding ASCII v32.txt }' (with hidden window)
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings" /v Enabled /t REG_DWORD /d 1 /f
- '<SYSTEM32>\cmd.exe' /D /c files.dat -y -pkmsauto
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over135797
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over685568
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over296121
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over731420
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over404070
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over682221
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over474862
- '%WINDIR%\syswow64\expand.exe' v32.cab -F:VersionDescriptor.xml %TEMP%\over487731