Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsSecurityHealthService' = 'C:\Users\Public\AppData\ie.vbs'
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\AppData\ie.vbs"
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' -Embedding
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v "WindowsSecurityHealthService" /t REG_SZ /d "C:\Users\Public\AppData\ie.vbs" /f
- '<SYSTEM32>\cmd.exe' /c ""C:\Users\Public\AppData\regedit.bat" "
- C:\Users\Public\AppData\ie.vbs
- C:\Users\Public\AppData\regedit.bat
- 'localhost':1037
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''