Home Malware Programs Trojans HTASploit

HTASploit

Posted: March 28, 2006

It starts the mshta.exe process. This process enables running Visual Basic scripts on the web-pages that you view, which is a big threat.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 winmain.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Browsetothekey:HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunDeletethevaluewinmain
Loading...