Technical Information
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\is-e0cdc.tmp\<File name>.tmp
- %TEMP%\is-nin6v.tmp\_isetup\_setup64.tmp
- %TEMP%\is-nin6v.tmp\yvibiajwi.dll
- %TEMP%\is-blnjc.tmp\<File name>.tmp
- %TEMP%\is-0rcdj.tmp\_isetup\_setup64.tmp
- %TEMP%\is-0rcdj.tmp\yvibiajwi.dll
- %TEMP%\is-nin6v.tmp\yvibiajwi.dll
- %TEMP%\is-nin6v.tmp\_isetup\_setup64.tmp
- %TEMP%\is-e0cdc.tmp\<File name>.tmp
- %TEMP%\is-blnjc.tmp\<File name>.tmp
- '15#.#01.1.91':443
- DNS ASK do##dns.com
- '%TEMP%\is-e0cdc.tmp\<File name>.tmp' /SL5="$1F02F4,3261874,977920,<Full path to file>"
- '%TEMP%\is-blnjc.tmp\<File name>.tmp' /SL5="$A01A8,3261874,977920,<Full path to file>" /VERYSILENT
- '%WINDIR%\syswow64\explorer.exe'