Technical Information
- <SYSTEM32>\svchost.exe
- %TEMP%\aut1.tmp
- %TEMP%\system.exe
- %TEMP%\aut2.tmp
- %TEMP%\video_2014-12-07_201129.mp4
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- '%TEMP%\system.exe'
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe'
- '<SYSTEM32>\svchost.exe'
- '%ProgramFiles%\mozilla firefox\firefox.exe'