Technical Information
- '%TEMP%\mw-078bbe8c-14a0-434d-bdfa-496bd3f6bcd1\files\pixlr.exe'
- ClassName: 'OLLYDBG', WindowName: ''
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %HOMEPATH%\pixlr.msi
- %TEMP%\mw-078bbe8c-14a0-434d-bdfa-496bd3f6bcd1\msiwrapper.ini
- %TEMP%\mw-078bbe8c-14a0-434d-bdfa-496bd3f6bcd1\files.cab
- %TEMP%\mw-078bbe8c-14a0-434d-bdfa-496bd3f6bcd1\files\$dpx$.tmp\d632e52fae25614a87d5a4f8711fecc7.tmp
- from %TEMP%\mw-078bbe8c-14a0-434d-bdfa-496bd3f6bcd1\files\$dpx$.tmp\d632e52fae25614a87d5a4f8711fecc7.tmp to %TEMP%\mw-078bbe8c-14a0-434d-bdfa-496bd3f6bcd1\files\pixlr.exe
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK vi###svinyl.com
- DNS ASK microsoft.com
- '%WINDIR%\syswow64\expand.exe' -R files.cab -F:* files' (with hidden window)
- '<SYSTEM32>\msiexec.exe' /i %HOMEPATH%\Pixlr.msi /quiet /qn /norestart
- '%WINDIR%\syswow64\expand.exe' -R files.cab -F:* files