Technical Information
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\A9R1bdon8q_veqfok_140.tmp\eicar-dropper.doc"
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1400' = '00000003'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1C00' = '00000000'
- %TEMP%\a9r1bdon8q_veqfok_140.tmp\eicar-dropper.doc
- %TEMP%\a9r1u9avv3_veqfol_140.tmp
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\cookies-journal
- %TEMP%\etilqs_nhvdwvi6clykopt
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\cookies
- %TEMP%\radf5631.tmp
- %TEMP%\a9r1rk3qv4_veqfon_140.tmp