Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'OneDriveHealthMonitor' = '%APPDATA%\Microsoft\Windows\svchost.exe'
- <SYSTEM32>\tasks\onedrivehealthtask
- %APPDATA%\microsoft\windows\svchost.exe
- 'ap#.##legram.org':443
- DNS ASK ap#.##legram.org
- '<SYSTEM32>\cmd.exe' /C schtasks /Create /SC ONLOGON /TN "OneDriveHealthTask" /TR "\"%APPDATA%\Microsoft\Windows\svchost.exe\"" /F /RL LIMITED
- '<SYSTEM32>\schtasks.exe' /Create /SC ONLOGON /TN "OneDriveHealthTask" /TR "\"%APPDATA%\Microsoft\Windows\svchost.exe\"" /F /RL LIMITED
- '<SYSTEM32>\cmd.exe' /C schtasks /Create /SC ONLOGON /TN "OneDriveHealthTask" /TR "\"%APPDATA%\Microsoft\Windows\svchost.exe\"" /F /RL LIMITED' (with hidden window)