Техническая информация
- '<SYSTEM32>\rundll32.exe' shell32.dll,ShellExec_RunDLL %LOCALAPPDATA%\Temphkl560yhk5h40ikhp4kh09k.lnk
- %APPDATA%\signal_update_6.0.3.4\glkgh90kjykjkl650kj0.dll
- %LOCALAPPDATA%\temphkl560yhk5h40ikhp4kh09k.lnk
- %TEMP%\jbljdesk.dll
- '<SYSTEM32>\rundll32.exe' shell32.dll,ShellExec_RunDLL %LOCALAPPDATA%\Temphkl560yhk5h40ikhp4kh09k.lnk' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' /u /s "%APPDATA%\Signal_update_6.0.3.4\glkgh90kjykjkl650kj0.dll"' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' /u /s "%APPDATA%\Signal_update_6.0.3.4\glkgh90kjykjkl650kj0.dll"
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\JBLJDESK.dll",ProcessGroupExServices