Fake Chrome (Trojan:Win32/Skeeyah.A!rfn)
Dropped in:
Dropped in:
Code: Select all
Changes the autorun value in:
C:\Users\*username*\AppData\Roaming\WebBrowser.exe
Code: Select all
URL:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Code: Select all
VT (55/67): https://www.virustotal.com/en/file/d569 ... /analysis/xxxx://campinglesamis.com/wpscripts/Chrome%20Hijacker.exe
Attachments
(396.79 KiB) Downloaded 34 times