Fake Chrome (Trojan:Win32/Skeeyah.A!rfn)
Dropped in:
Dropped in:
Code: Select all
Changes the autorun value in:
C:\Users\*username*\AppData\Roaming\WebBrowser.exeCode: Select all
URL:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunCode: Select all
VT (55/67): https://www.virustotal.com/en/file/d569 ... /analysis/xxxx://campinglesamis.com/wpscripts/Chrome%20Hijacker.exeAttachments
(396.79 KiB) Downloaded 34 times