Tasks

  • Immediate: Quarantine system, block execution in AppData\Roaming.

  • Registry / Task Cleanup:

    schtasks /delete /tn "EggsUpdate" /f
    reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v EggsUpdate /f
  • File & Process Removal:

    • Delete: C:\Users\redacted\AppData\Roaming\Microsoft\Network\msxsl.exe
    • Delete: 12CD877E9F06A22D3.txt
  • Credential Reset: Force password changes for affected users.

  • Verification: Confirm no further DNS TXT or DOH activity.