Technical Information
- %TEMP%\is-73dbr.tmp\<File name>.tmp
- %ProgramFiles(x86)%\kddeskvis\shiboken2\is-0577t.tmp
- %ProgramFiles(x86)%\kddeskvis\pywin32_system32\is-abj23.tmp
- %ProgramFiles(x86)%\kddeskvis\pywin32_system32\is-ihn5v.tmp
- %ProgramFiles(x86)%\kddeskvis\phonon_backend\is-lq9uq.tmp
- %ProgramFiles(x86)%\kddeskvis\phonon_backend\is-83461.tmp
- %ProgramFiles(x86)%\kddeskvis\imageformats\is-rg4kn.tmp
- %ProgramFiles(x86)%\kddeskvis\imageformats\is-qhiqa.tmp
- %ProgramFiles(x86)%\kddeskvis\imageformats\is-jg67f.tmp
- %ProgramFiles(x86)%\kddeskvis\imageformats\is-a7jgb.tmp
- %ProgramFiles(x86)%\kddeskvis\imageformats\is-srvcv.tmp
- %ProgramFiles(x86)%\kddeskvis\imageformats\is-5r4iv.tmp
- %ProgramFiles(x86)%\kddeskvis\imageformats\is-bpl7d.tmp
- %ProgramFiles(x86)%\kddeskvis\imageformats\is-ib6s5.tmp
- %ProgramFiles(x86)%\kddeskvis\imageformats\is-u4of5.tmp
- %ProgramFiles(x86)%\kddeskvis\imageformats\is-p98n6.tmp
- %ProgramFiles(x86)%\kddeskvis\imageformats\is-gibik.tmp
- %ProgramFiles(x86)%\kddeskvis\imageformats\is-pu1cr.tmp
- %ProgramFiles(x86)%\kddeskvis\shiboken2\is-t0035.tmp
- %ProgramFiles(x86)%\kddeskvis\shiboken2\is-ih82n.tmp
- %ProgramFiles(x86)%\kddeskvis\unins000.dat
- %ProgramFiles(x86)%\kddeskvis\is-lesln.tmp
- %ProgramFiles(x86)%\kddeskvis\win32com\shell\is-a60sd.tmp
- %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\is-58j70.tmp
- %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\is-9brav.tmp
- %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\is-2lbjq.tmp
- %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\is-qaqe7.tmp
- %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\is-u0a6f.tmp
- %ProgramFiles(x86)%\kddeskvis\is-d3trm.tmp
- %ProgramFiles(x86)%\kddeskvis\websockets\is-nc8tt.tmp
- %ProgramFiles(x86)%\kddeskvis\sqldrivers\is-t3bv8.tmp
- %ProgramFiles(x86)%\kddeskvis\sqldrivers\is-2c6go.tmp
- %ProgramFiles(x86)%\kddeskvis\sqldrivers\is-chkha.tmp
- %ProgramFiles(x86)%\kddeskvis\sqldrivers\is-9u0e9.tmp
- %ProgramFiles(x86)%\kddeskvis\sqldrivers\is-mrskn.tmp
- %ProgramFiles(x86)%\kddeskvis\sqldrivers\is-fvikr.tmp
- %ProgramFiles(x86)%\kddeskvis\imageformats\is-f843e.tmp
- %ProgramFiles(x86)%\kddeskvis\imageformats\is-01828.tmp
- %ProgramFiles(x86)%\kddeskvis\certifi\is-8fkh2.tmp
- %ProgramFiles(x86)%\kddeskvis\is-aju20.tmp
- %ProgramFiles(x86)%\kddeskvis\is-8hv2d.tmp
- %ProgramFiles(x86)%\kddeskvis\is-6o3co.tmp
- %ProgramFiles(x86)%\kddeskvis\is-li7af.tmp
- %ProgramFiles(x86)%\kddeskvis\is-b0c7r.tmp
- %ProgramFiles(x86)%\kddeskvis\is-rovkv.tmp
- %ProgramFiles(x86)%\kddeskvis\is-9r85r.tmp
- %ProgramFiles(x86)%\kddeskvis\is-g8bos.tmp
- %ProgramFiles(x86)%\kddeskvis\is-h2iuh.tmp
- %ProgramFiles(x86)%\kddeskvis\is-cbt1a.tmp
- %TEMP%\is-qv30u.tmp\_isetup\_iscrypt.dll
- %TEMP%\is-qv30u.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-qv30u.tmp\_isetup\_setup64.tmp
- %TEMP%\is-qv30u.tmp\_isetup\_regdll.tmp
- %ProgramFiles(x86)%\kddeskvis\is-e6cob.tmp
- %ProgramFiles(x86)%\kddeskvis\is-85bnb.tmp
- %ProgramFiles(x86)%\kddeskvis\is-ds806.tmp
- %ProgramFiles(x86)%\kddeskvis\is-lbihn.tmp
- %ProgramFiles(x86)%\kddeskvis\is-m5nm4.tmp
- %ProgramFiles(x86)%\kddeskvis\is-faohp.tmp
- %ProgramFiles(x86)%\kddeskvis\is-nhi3c.tmp
- %ProgramFiles(x86)%\kddeskvis\is-37pl9.tmp
- %ProgramFiles(x86)%\kddeskvis\is-dj48n.tmp
- %ProgramFiles(x86)%\kddeskvis\is-12bnf.tmp
- %ProgramFiles(x86)%\kddeskvis\is-15mtr.tmp
- %ProgramFiles(x86)%\kddeskvis\is-45f8p.tmp
- %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\is-31ati.tmp
- %ProgramFiles(x86)%\kddeskvis\kddeskvis.exe
- %ProgramFiles(x86)%\kddeskvis\is-nv18t.tmp
- %ProgramFiles(x86)%\kddeskvis\is-qap2p.tmp
- %ProgramFiles(x86)%\kddeskvis\is-1ncck.tmp
- %ProgramFiles(x86)%\kddeskvis\is-2mir1.tmp
- %ProgramFiles(x86)%\kddeskvis\is-h2gfp.tmp
- %ProgramFiles(x86)%\kddeskvis\is-ct25i.tmp
- %ProgramFiles(x86)%\kddeskvis\is-dbhvc.tmp
- %ProgramFiles(x86)%\kddeskvis\is-7mmuq.tmp
- %TEMP%\license.txt
- from %ProgramFiles(x86)%\kddeskvis\is-cbt1a.tmp to %ProgramFiles(x86)%\kddeskvis\unins000.exe
- from %ProgramFiles(x86)%\kddeskvis\imageformats\is-u4of5.tmp to %ProgramFiles(x86)%\kddeskvis\imageformats\qjpegd4.dll
- from %ProgramFiles(x86)%\kddeskvis\imageformats\is-ib6s5.tmp to %ProgramFiles(x86)%\kddeskvis\imageformats\qmng4.dll
- from %ProgramFiles(x86)%\kddeskvis\imageformats\is-bpl7d.tmp to %ProgramFiles(x86)%\kddeskvis\imageformats\qmngd4.dll
- from %ProgramFiles(x86)%\kddeskvis\imageformats\is-5r4iv.tmp to %ProgramFiles(x86)%\kddeskvis\imageformats\qsvg4.dll
- from %ProgramFiles(x86)%\kddeskvis\imageformats\is-srvcv.tmp to %ProgramFiles(x86)%\kddeskvis\imageformats\qsvgd4.dll
- from %ProgramFiles(x86)%\kddeskvis\imageformats\is-a7jgb.tmp to %ProgramFiles(x86)%\kddeskvis\imageformats\qtga4.dll
- from %ProgramFiles(x86)%\kddeskvis\imageformats\is-jg67f.tmp to %ProgramFiles(x86)%\kddeskvis\imageformats\qtgad4.dll
- from %ProgramFiles(x86)%\kddeskvis\imageformats\is-qhiqa.tmp to %ProgramFiles(x86)%\kddeskvis\imageformats\qtiff4.dll
- from %ProgramFiles(x86)%\kddeskvis\imageformats\is-rg4kn.tmp to %ProgramFiles(x86)%\kddeskvis\imageformats\qtiffd4.dll
- from %ProgramFiles(x86)%\kddeskvis\phonon_backend\is-83461.tmp to %ProgramFiles(x86)%\kddeskvis\phonon_backend\phonon_ds94.dll
- from %ProgramFiles(x86)%\kddeskvis\phonon_backend\is-lq9uq.tmp to %ProgramFiles(x86)%\kddeskvis\phonon_backend\phonon_ds9d4.dll
- from %ProgramFiles(x86)%\kddeskvis\pywin32_system32\is-ihn5v.tmp to %ProgramFiles(x86)%\kddeskvis\pywin32_system32\pythoncom38.dll
- from %ProgramFiles(x86)%\kddeskvis\pywin32_system32\is-abj23.tmp to %ProgramFiles(x86)%\kddeskvis\pywin32_system32\pywintypes38.dll
- from %ProgramFiles(x86)%\kddeskvis\imageformats\is-pu1cr.tmp to %ProgramFiles(x86)%\kddeskvis\imageformats\qicod4.dll
- from %ProgramFiles(x86)%\kddeskvis\imageformats\is-p98n6.tmp to %ProgramFiles(x86)%\kddeskvis\imageformats\qjpeg4.dll
- from %ProgramFiles(x86)%\kddeskvis\shiboken2\is-0577t.tmp to %ProgramFiles(x86)%\kddeskvis\shiboken2\msvcp140.dll
- from %ProgramFiles(x86)%\kddeskvis\shiboken2\is-t0035.tmp to %ProgramFiles(x86)%\kddeskvis\shiboken2\shiboken2.abi3.dll
- from %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\is-58j70.tmp to %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\wheel
- from %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\is-9brav.tmp to %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\top_level.txt
- from %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\is-2lbjq.tmp to %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\record
- from %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\is-qaqe7.tmp to %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\metadata
- from %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\is-31ati.tmp to %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\license
- from %ProgramFiles(x86)%\kddeskvis\is-45f8p.tmp to %ProgramFiles(x86)%\kddeskvis\_overlapped.pyd
- from %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\is-u0a6f.tmp to %ProgramFiles(x86)%\kddeskvis\websockets-10.4.dist-info\installer
- from %ProgramFiles(x86)%\kddeskvis\sqldrivers\is-t3bv8.tmp to %ProgramFiles(x86)%\kddeskvis\sqldrivers\qsqlpsqld4.dll
- from %ProgramFiles(x86)%\kddeskvis\sqldrivers\is-2c6go.tmp to %ProgramFiles(x86)%\kddeskvis\sqldrivers\qsqlpsql4.dll
- from %ProgramFiles(x86)%\kddeskvis\sqldrivers\is-chkha.tmp to %ProgramFiles(x86)%\kddeskvis\sqldrivers\qsqlodbcd4.dll
- from %ProgramFiles(x86)%\kddeskvis\sqldrivers\is-9u0e9.tmp to %ProgramFiles(x86)%\kddeskvis\sqldrivers\qsqlodbc4.dll
- from %ProgramFiles(x86)%\kddeskvis\sqldrivers\is-mrskn.tmp to %ProgramFiles(x86)%\kddeskvis\sqldrivers\qsqlited4.dll
- from %ProgramFiles(x86)%\kddeskvis\sqldrivers\is-fvikr.tmp to %ProgramFiles(x86)%\kddeskvis\sqldrivers\qsqlite4.dll
- from %ProgramFiles(x86)%\kddeskvis\shiboken2\is-ih82n.tmp to %ProgramFiles(x86)%\kddeskvis\shiboken2\shiboken2.pyd
- from %ProgramFiles(x86)%\kddeskvis\imageformats\is-gibik.tmp to %ProgramFiles(x86)%\kddeskvis\imageformats\qico4.dll
- from %ProgramFiles(x86)%\kddeskvis\imageformats\is-f843e.tmp to %ProgramFiles(x86)%\kddeskvis\imageformats\qgifd4.dll
- from %ProgramFiles(x86)%\kddeskvis\imageformats\is-01828.tmp to %ProgramFiles(x86)%\kddeskvis\imageformats\qgif4.dll
- from %ProgramFiles(x86)%\kddeskvis\is-g8bos.tmp to %ProgramFiles(x86)%\kddeskvis\libffi-7.dll
- from %ProgramFiles(x86)%\kddeskvis\is-9r85r.tmp to %ProgramFiles(x86)%\kddeskvis\libssl-1_1.dll
- from %ProgramFiles(x86)%\kddeskvis\is-rovkv.tmp to %ProgramFiles(x86)%\kddeskvis\pyexpat.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-b0c7r.tmp to %ProgramFiles(x86)%\kddeskvis\python3.dll
- from %ProgramFiles(x86)%\kddeskvis\is-li7af.tmp to %ProgramFiles(x86)%\kddeskvis\pythoncom38.dll
- from %ProgramFiles(x86)%\kddeskvis\is-6o3co.tmp to %ProgramFiles(x86)%\kddeskvis\pywintypes38.dll
- from %ProgramFiles(x86)%\kddeskvis\is-8hv2d.tmp to %ProgramFiles(x86)%\kddeskvis\select.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-aju20.tmp to %ProgramFiles(x86)%\kddeskvis\tagging.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-ds806.tmp to %ProgramFiles(x86)%\kddeskvis\vcruntime140.dll
- from %ProgramFiles(x86)%\kddeskvis\is-e6cob.tmp to %ProgramFiles(x86)%\kddeskvis\win32api.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-85bnb.tmp to %ProgramFiles(x86)%\kddeskvis\win32evtlog.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-lbihn.tmp to %ProgramFiles(x86)%\kddeskvis\win32trace.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-faohp.tmp to %ProgramFiles(x86)%\kddeskvis\win32wnet.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-dbhvc.tmp to %ProgramFiles(x86)%\kddeskvis\_asyncio.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-h2iuh.tmp to %ProgramFiles(x86)%\kddeskvis\kscol
- from %ProgramFiles(x86)%\kddeskvis\is-ct25i.tmp to %ProgramFiles(x86)%\kddeskvis\_brotli.cp38-win32.pyd
- from %ProgramFiles(x86)%\kddeskvis\certifi\is-8fkh2.tmp to %ProgramFiles(x86)%\kddeskvis\certifi\cacert.pem
- from %ProgramFiles(x86)%\kddeskvis\is-h2gfp.tmp to %ProgramFiles(x86)%\kddeskvis\_bz2.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-2mir1.tmp to %ProgramFiles(x86)%\kddeskvis\_ctypes.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-1ncck.tmp to %ProgramFiles(x86)%\kddeskvis\_decimal.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-qap2p.tmp to %ProgramFiles(x86)%\kddeskvis\_elementtree.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-nv18t.tmp to %ProgramFiles(x86)%\kddeskvis\_hashlib.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-d3trm.tmp to %ProgramFiles(x86)%\kddeskvis\_lzma.pyd
- from %ProgramFiles(x86)%\kddeskvis\websockets\is-nc8tt.tmp to %ProgramFiles(x86)%\kddeskvis\websockets\speedups.cp38-win32.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-7mmuq.tmp to %ProgramFiles(x86)%\kddeskvis\_multiprocessing.pyd
- from %ProgramFiles(x86)%\kddeskvis\win32com\shell\is-a60sd.tmp to %ProgramFiles(x86)%\kddeskvis\win32com\shell\shell.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-12bnf.tmp to %ProgramFiles(x86)%\kddeskvis\_socket.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-dj48n.tmp to %ProgramFiles(x86)%\kddeskvis\_sqlite3.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-37pl9.tmp to %ProgramFiles(x86)%\kddeskvis\_ssl.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-nhi3c.tmp to %ProgramFiles(x86)%\kddeskvis\_testcapi.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-m5nm4.tmp to %ProgramFiles(x86)%\kddeskvis\_win32sysloader.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-15mtr.tmp to %ProgramFiles(x86)%\kddeskvis\_queue.pyd
- from %ProgramFiles(x86)%\kddeskvis\is-lesln.tmp to %ProgramFiles(x86)%\kddeskvis\kddeskvis.exe
- 'mi####njobs.works':80
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?43######
- http://mi####njobs.works/new/net_api
- DNS ASK mi####njobs.works
- ClassName: 'ja9a89_kddv1141Class_ja9a89' WindowName: ''
- '%TEMP%\is-73dbr.tmp\<File name>.tmp' /SL5="$5023A,8385741,52224,<Full path to file>"
- '%ProgramFiles(x86)%\kddeskvis\kddeskvis.exe'
- '%ProgramFiles(x86)%\kddeskvis\kddeskvis.exe' 6e1628e11c17cfff84a9c7db9893412c
- '%WINDIR%\syswow64\schtasks.exe' /Delete /F /TN "KDDV1104-2"
- '%WINDIR%\syswow64\schtasks.exe' /Query