Technical Information
- [HKLM\System\CurrentControlSet\Services\Shadow] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Shadow] 'ImagePath' = '<SYSTEM32>\update.exe'
- 'Shadow' <SYSTEM32>\update.exe
- iexplore.exe
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- '%ProgramFiles%\internet explorer\iexplore.exe'
- '%ProgramFiles%\internet explorer\iexplore.exe' ' (with hidden window)