Malware
puzzlemaker
The dropper module is used to install two executables that pretend to be legitimate files belonging to Microsoft Windows OS.
puzzlemaker is a Windows malware family operated by [Unnamed group].
Background
The dropper module drops two executables that masquerade as legitimate Microsoft Windows OS files. The first (%SYSTEM%\WmiPrvMon.exe) is registered as a service and serves as a launcher for the second. That second file (%SYSTEM%\wmimon.dll) acts as a remote shell and represents the attack's main payload.
Source: Malpedia (Fraunhofer FKIE).