Technical Information
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\is-5cg5n.tmp\<File name>.tmp
- %TEMP%\is-kk4ak.tmp\_isetup\_setup64.tmp
- %TEMP%\is-kk4ak.tmp\yvibiajwi.dll
- %TEMP%\is-5pb6l.tmp\<File name>.tmp
- %TEMP%\is-4vbkh.tmp\_isetup\_setup64.tmp
- %TEMP%\is-4vbkh.tmp\yvibiajwi.dll
- %TEMP%\is-kk4ak.tmp\yvibiajwi.dll
- %TEMP%\is-kk4ak.tmp\_isetup\_setup64.tmp
- %TEMP%\is-5cg5n.tmp\<File name>.tmp
- %TEMP%\is-5pb6l.tmp\<File name>.tmp
- '15#.#01.129.91':443
- DNS ASK do##dns.com
- '%TEMP%\is-5cg5n.tmp\<File name>.tmp' /SL5="$80296,3245878,963072,<Full path to file>"
- '%TEMP%\is-5pb6l.tmp\<File name>.tmp' /SL5="$90296,3245878,963072,<Full path to file>" /VERYSILENT
- '%WINDIR%\syswow64\explorer.exe'