Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WinBioPlugIns2' = '"%APPDATA%\notepad.exe"'
- <SYSTEM32>\tasks\winbioplugins2
- %ALLUSERSPROFILE%\isolated storage\fc7076bb\59fd041e
- %APPDATA%\notepad.exe
- %TEMP%\tmp3c44.tmp.bat
- %APPDATA%\visualelements\lpt5\notepad
- nul
- <Full path to file>
- %APPDATA%\notepad.exe
- %APPDATA%\notepad.exe
- '<SYSTEM32>\schtasks.exe' /create /f /sc ONLOGON /RL HIGHEST /tn "WinBioPlugIns2" /tr "%APPDATA%\VisualElements\LPT5\notepad"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c md \\?\%APPDATA%\VisualElements\LPT5\
- '<SYSTEM32>\cmd.exe' /c SCHTASKS /Create /SC MINUTE /MO 180 /TN "WinBioPlugIns2" /TR %APPDATA%\VisualElements\LPT5\notepad
- '<SYSTEM32>\schtasks.exe' /Create /SC MINUTE /MO 180 /TN "WinBioPlugIns2" /TR %APPDATA%\VisualElements\LPT5\notepad
- '<SYSTEM32>\schtasks.exe' /create /f /sc ONLOGON /RL HIGHEST /tn "WinBioPlugIns2" /tr "%APPDATA%\VisualElements\LPT5\notepad"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp3C44.tmp.bat""
- '<SYSTEM32>\cmd.exe' /c copy %APPDATA%\notepad.exe %APPDATA%\VisualElements\LPT5\notepad
- '<SYSTEM32>\timeout.exe' 3