Technical Information
- [<HKLM>\software\Wow6432Node\microsoft\windows\currentversion\Policies\Explorer\Run] '14842' = '%ProgramFiles%\locals~1\Temp\msvrivyio.exe'
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\winrar-x64-420.exe
- %ProgramFiles%\locals~1\temp\msvrivyio.exe
- '<DNS_SERVER>':53
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%TEMP%\winrar-x64-420.exe'
- '%WINDIR%\syswow64\svchost.exe'