Technical Information
- <SYSTEM32>\tasks\microsoftbt
- %TEMP%\~e945.tmp
- %TEMP%\~e946.tmp
- %TEMP%\~e947.tmp
- %ALLUSERSPROFILE%\microsoft.bt\microsoft.bt.exe
- %ALLUSERSPROFILE%\microsoft.bt\lbtserv.dll
- %ALLUSERSPROFILE%\microsoft.bt\microsoft.bt
- %TEMP%\~e945.tmp
- %TEMP%\~e946.tmp
- %TEMP%\~e947.tmp
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /sc minute /mo 10 /tn "MicrosoftBT" /tr "%ALLUSERSPROFILE%\Microsoft.BT\Microsoft.BT.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /sc minute /mo 10 /tn "MicrosoftBT" /tr "%ALLUSERSPROFILE%\Microsoft.BT\Microsoft.BT.exe"
- '%WINDIR%\syswow64\schtasks.exe' /create /sc minute /mo 10 /tn "MicrosoftBT" /tr "%ALLUSERSPROFILE%\Microsoft.BT\Microsoft.BT.exe"