Malware authors place a malicious library in the %WINDIR% folder. The same folder also hosts the program explorer.exe. This enables the attackers to ensure that the malicious DLL is loaded at system startup. The malicious library is designed to load the original winmm.dll from the %windIR%System32 folder. When a program that depends on the original library is loaded, the DLL will be loaded when this program is executed instead of the. original library that is located at %windir%.System32winmm.DLL is a Windows system library which provides multimedia functions.”]
Source: https://securelist.com/winnti-1-0-technical-analysis/37002/

