Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\biowin] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\biowin] 'ImagePath' = '%WINDIR%\SysWOW64\biowin.exe'
- 'biowin' %WINDIR%\SysWOW64\biowin.exe
- from <Full path to file> to %WINDIR%\syswow64\biowin.exe
- '13#.#.103.194':8080
- '19#.#87.140.51':443