Technical Information
- Handler for all processes: %TEMP%\nvrw.dll
- %TEMP%\ad-mymacro.xml
- %TEMP%\mymacro.zip
- %TEMP%\2.tmp
- %TEMP%\1.tmp
- %WINDIR%\snv.dll
- <Current directory>\plugin\window.dll
- <Current directory>\plugin\web.dll
- <Current directory>\plugin\sys.dll
- <Current directory>\plugin\pic.dll
- <Current directory>\plugin\office.dll
- <Current directory>\plugin\net.dll
- <Current directory>\plugin\msg.dll
- <Current directory>\plugin\memory.dll
- <Current directory>\plugin\media.dll
- <Current directory>\plugin\getsysinfo.dll
- <Current directory>\plugin\file.dll
- <Current directory>\plugin\encrypt.dll
- <Current directory>\plugin\console.dll
- <Current directory>\plugin\color.dll
- <Current directory>\plugin\bkgndcolor.dll
- <Current directory>\plugin\bkgnd.dll
- %TEMP%\temp02.dll
- %TEMP%\temp01.dll
- %TEMP%\adcon\mm\tmpad.xml
- %TEMP%\nvrw.dll
- %TEMP%\2
- %TEMP%\adcon\mm\tmpad.xml
- %TEMP%\temp01.dll
- %TEMP%\mymacro.zip
- %TEMP%\temp02.dll
- %TEMP%\2
- %TEMP%\2.tmp
- DNS ASK do##.#rbrothers.com
- DNS ASK ad.###rothers.com