Technical Information
- %ProgramFiles%\microsoft office\office14\bcssync.exe
- <Current directory>\log.txt
- %APPDATA%\startup infector\infector_app.exe
- %APPDATA%\startup infector\log.txt
- %ProgramFiles%\microsoft office\office14\bcssync.exe.bak
- %ProgramFiles%\microsoft office\office14\checkfile0.tmp
- %APPDATA%\flash\flashplayer.exe
- '%APPDATA%\startup infector\infector_app.exe'
- '%APPDATA%\flash\flashplayer.exe'