Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\bitcd2e.tmp
- %WINDIR%\syswow64\svchost.exe
- <SYSTEM32>\svchost.exe
- %APPDATA%\bitac16.tmp
- %APPDATA%\svrta.lnk
- %TEMP%\tmp.tmp
- %APPDATA%\bitac16.tmp
- %APPDATA%\microsoft\windows\start menu\programs\startup\bitcd2e.tmp
- %APPDATA%\svrta.lnk
- from %APPDATA%\bitac16.tmp to %APPDATA%\svrta.exe
- '%WINDIR%\syswow64\svchost.exe'
- '<SYSTEM32>\svchost.exe'