Technical Information
- <SYSTEM32>\tasks\plug and play - helper
- <SYSTEM32>\p\o.txt
- <SYSTEM32>\p\plugandplay__.exe
- <SYSTEM32>\p\plugandplay_t.txt
- <SYSTEM32>\p\plugandplay_t.txt
- '<SYSTEM32>\p\plugandplay__.exe' -install
- '<SYSTEM32>\schtasks.exe' /Create /TN "Plug and Play - Helper" /XML "<SYSTEM32>\p\plugandplay_t.txt"' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /Create /TN "Plug and Play - Helper" /XML "<SYSTEM32>\p\plugandplay_t.txt"
- '<SYSTEM32>\taskeng.exe' {D12F49EC-1C2C-4540-B6E2-165487B734E2} S-1-5-21-1960123792-2022915161-3775307078-1001:womjpmkh\user:Interactive:[1]
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\dw20.exe' -x -s 840