Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'sjajdiasodsadq' = '%HOMEPATH%\xdwdMicrosoft Publisher Host.exe'
- %HOMEPATH%\xdwdmicrosoft publisher host.exe
- %HOMEPATH%\xdwdmicrosoft publisher host.exe
- '17.##.gl.ply.gg':39129
- DNS ASK 17.##.gl.ply.gg
- '<SYSTEM32>\cmd.exe' /c SchTaSKs /create /f /sc minute /mo -1 /tn "Adobe Photoshop" /tr "%HOMEPATH%\xdwdMicrosoft Publisher Host.exe" /RL HIGHEST & exit
- '<SYSTEM32>\schtasks.exe' /create /f /sc minute /mo -1 /tn "Adobe Photoshop" /tr "%HOMEPATH%\xdwdMicrosoft Publisher Host.exe" /RL HIGHEST