Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\ectosphere.vbs
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\aut8574.tmp
- %TEMP%\gammy
- %LOCALAPPDATA%\unhelp\ectosphere.exe
- %TEMP%\aut94fe.tmp
- %TEMP%\aut8574.tmp
- %TEMP%\aut94fe.tmp
- '%LOCALAPPDATA%\unhelp\ectosphere.exe'
- '%WINDIR%\syswow64\svchost.exe'