dll_UnReg
Description
Chinese Hacktool Set - file UnReg.bat
Query · yara
strings:
$s0 = "regsvr32.exe /u C:\\windows\\system32\\PacketX.dll" fullword ascii
$s1 = "del /F /Q C:\\windows\\system32\\PacketX.dll" fullword ascii
condition:
filesize < 1KB and 1 of them