Technical Information
- '<SYSTEM32>\rundll32.exe' shell32.dll,ShellExec_RunDLL %LOCALAPPDATA%\Tempfghkl045kfdlkdf4j3igo.lnk
- C:\users\public\.desktop\fgkjg9grjk9jkgrji394jgkfdgjllj3.dll
- %LOCALAPPDATA%\tempfghkl045kfdlkdf4j3igo.lnk
- from C:\users\public\.desktop\fgkjg9grjk9jkgrji394jgkfdgjllj3.dll to %TEMP%\5xyf0mbstkrdkjkd392jgk.dll
- from %TEMP%\5xyf0mbstkrdkjkd392jgk.dll to %TEMP%\zn0f5cgujl3
- '<SYSTEM32>\rundll32.exe' shell32.dll,ShellExec_RunDLL %LOCALAPPDATA%\Tempfghkl045kfdlkdf4j3igo.lnk' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /u /s "C:\Users\Public\.desktop\fgkjg9grjk9jkgrji394jgkfdgjllj3.dll"' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /u /s "C:\Users\Public\.desktop\fgkjg9grjk9jkgrji394jgkfdgjllj3.dll"
- '%WINDIR%\syswow64\regsvr32.exe' /u /s "%TEMP%\\5xyf0mbstkrdkjkd392jgk.dll"