Technical Information
- %TEMP%\is-bdnrf.tmp\<File name>.tmp
- %TEMP%\is-99jkd.tmp\_isetup\_setup64.tmp
- %TEMP%\is-99jkd.tmp\itdownload.dll
- %LOCALAPPDATA%low\sun\java\deployment\security\securitypack.jar
- %LOCALAPPDATA%low\sun\java\deployment\security\update.securitypack.timestamp
- %TEMP%\is-99jkd.tmp\rkinstaller.exe
- %TEMP%\is-99jkd.tmp\rkverify.exe
- %ALLUSERSPROFILE%\mozilla\updates\308046b0af4a39cb\updates.xml.tmp
- from %ALLUSERSPROFILE%\mozilla\updates\308046b0af4a39cb\updates.xml.tmp to %ALLUSERSPROFILE%\mozilla\updates\308046b0af4a39cb\updates.xml
- 'po##.##curestudies.com':80
- 'dp#.###urestudies.com':443
- http://po##.##curestudies.com/packages/RI1034/ContentI3.exe
- http://po##.##curestudies.com/packages/RV0267/ContentV3.exe
- http://oc##.#igicert.com/
- '88.##1.96.133':443
- 'dp#.###urestudies.com':443
- '34.##7.35.28':443
- DNS ASK po##.##curestudies.com
- DNS ASK dp#.###urestudies.com
- '%TEMP%\is-bdnrf.tmp\<File name>.tmp' /SL5="$50262,2662786,721408,<Full path to file>"