Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\monmvr32.exe
- %WINDIR%\syswow64\svchost.exe
- %WINDIR%\explorer.exe
- %TEMP%\~tm1b0e.tmp
- %TEMP%\~tm1b8c.tmp
- %TEMP%\~tm1bdb.tmp
- %APPDATA%\avdrn.dat
- %TEMP%\~tm15258.tmp
- %TEMP%\~tm1d40.tmp
- %TEMP%\~tm1ddd.tmp
- %TEMP%\~tm1e3c.tmp
- %APPDATA%\microsoft\windows\start menu\programs\startup\monmvr32.exe
- %TEMP%\~tm1b0e.tmp
- %TEMP%\~tm1b8c.tmp
- %TEMP%\~tm1bdb.tmp
- %TEMP%\~tm15258.tmp
- %TEMP%\~tm1d40.tmp
- %TEMP%\~tm1ddd.tmp
- %TEMP%\~tm1e3c.tmp
- from <Full path to file> to %TEMP%\~tm1c49.tmp
- DNS ASK be####rverside.com
- '%WINDIR%\syswow64\svchost.exe' -k netsvcs