Technical Information
- %TEMP%\is-g33jh.tmp\<File name>.tmp
- %TEMP%\is-kedl3.tmp\_isetup\_setup64.tmp
- %TEMP%\is-kedl3.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-kedl3.tmp\idp.dll
- %TEMP%\is-kedl3.tmp\rk_setup.exe
- 'x.##2.us':80
- 'microsoft.com':80
- 'o.##2.us':80
- 'oc##.###tg2.amazontrust.com':80
- 'oc##.####ca1.amazontrust.com':80
- 'cr#.####ca1.amazontrust.com':80
- 'oc##.###1b.amazontrust.com':80
- 'cr#.####b.amazontrust.com':80
- 'dp#.###urestudies.com':443
- DNS ASK dp#.###urestudies.com
- DNS ASK x.##2.us
- DNS ASK microsoft.com
- DNS ASK o.##2.us
- DNS ASK oc##.###tg2.amazontrust.com
- DNS ASK oc##.####ca1.amazontrust.com
- DNS ASK po##.##curestudies.com
- DNS ASK cr#.####ca1.amazontrust.com
- DNS ASK oc##.###1b.amazontrust.com
- DNS ASK cr#.####b.amazontrust.com
- '%TEMP%\is-g33jh.tmp\<File name>.tmp' /SL5="$140226,428986,119296,<Full path to file>"