Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\siszfc32.exe
- %WINDIR%\syswow64\svchost.exe
- %WINDIR%\explorer.exe
- %TEMP%\~tm4cd7.tmp
- %TEMP%\~tm4da3.tmp
- %TEMP%\~tm4e11.tmp
- %APPDATA%\avdrn.dat
- %TEMP%\~tm15258.tmp
- %TEMP%\~tm4fb5.tmp
- %TEMP%\~tm5042.tmp
- %TEMP%\~tm50a1.tmp
- %APPDATA%\microsoft\windows\start menu\programs\startup\siszfc32.exe
- %TEMP%\~tm4cd7.tmp
- %TEMP%\~tm4da3.tmp
- %TEMP%\~tm4e11.tmp
- %TEMP%\~tm15258.tmp
- %TEMP%\~tm4fb5.tmp
- %TEMP%\~tm5042.tmp
- %TEMP%\~tm50a1.tmp
- from <Full path to file> to %TEMP%\~tm4f2b.tmp
- DNS ASK wo####ostdns.com
- '%WINDIR%\syswow64\svchost.exe' -k netsvcs