Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\register-cimprovider.url
- '%TEMP%\srt4rtghnmjklfgdr54gpro4.scr'
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\srt4rtghnmjklfgdr54gpro4.scr
- %HOMEPATH%\register-cimprovider\register-cimprovider.vbs
- %HOMEPATH%\register-cimprovider\authfwcfg.exe
- http://ma###-bg.com/xmlInstall/adkp.scr
- DNS ASK ma###-bg.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\svchost.exe'