Technical Information
- '' (downloaded from the Internet)
- %TEMP%\is-RB7V2.tmp\<File name>.tmp
- %TEMP%\is-H1NKR.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-H1NKR.tmp\itdownload.dll
- %TEMP%\is-H1NKR.tmp\jfk0021.exe.config
- %TEMP%\is-H1NKR.tmp\jfk0021.exe
- %TEMP%\is-H1NKR.tmp\itdownload.dll
- %TEMP%\is-H1NKR.tmp\jfk0021.exe
- %TEMP%\is-H1NKR.tmp\jfk0021.exe.config
- %TEMP%\is-H1NKR.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-RB7V2.tmp\<File name>.tmp
- 'ge###syfile.com':80
- http://ge###syfile.com/kL3CuYDWuF/Yx5cJur3eX/jfk0021.exe
- DNS ASK ge###syfile.com
- '%TEMP%\is-RB7V2.tmp\<File name>.tmp' /SL5="$30092,300225,216576,<Full path to file>"
- '%TEMP%\is-H1NKR.tmp\jfk0021.exe' /VS /CID=15150