Technical Information
- %TEMP%\is-4p4el.tmp\<File name>.tmp
- %ProgramFiles(x86)%\ldeskorganizer\shiboken2\is-vuism.tmp
- %ProgramFiles(x86)%\ldeskorganizer\pywin32_system32\is-pk2sj.tmp
- %ProgramFiles(x86)%\ldeskorganizer\pywin32_system32\is-056ak.tmp
- %ProgramFiles(x86)%\ldeskorganizer\phonon_backend\is-3880s.tmp
- %ProgramFiles(x86)%\ldeskorganizer\phonon_backend\is-tu6v0.tmp
- %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-t1uf8.tmp
- %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-pdbe5.tmp
- %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-to8v0.tmp
- %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-5essq.tmp
- %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-kbcak.tmp
- %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-0q39r.tmp
- %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-dhbhu.tmp
- %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-04u8d.tmp
- %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-c06bu.tmp
- %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-5gu9t.tmp
- %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-epio0.tmp
- %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-ofu8u.tmp
- %ProgramFiles(x86)%\ldeskorganizer\shiboken2\is-e1gsc.tmp
- %ProgramFiles(x86)%\ldeskorganizer\shiboken2\is-tvkn0.tmp
- %ProgramFiles(x86)%\ldeskorganizer\unins000.dat
- %ProgramFiles(x86)%\ldeskorganizer\is-94151.tmp
- %ProgramFiles(x86)%\ldeskorganizer\win32com\shell\is-pu45k.tmp
- %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\is-ft7s0.tmp
- %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\is-v3j4t.tmp
- %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\is-sa93o.tmp
- %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\is-6sc0c.tmp
- %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\is-vioic.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-ctjho.tmp
- %ProgramFiles(x86)%\ldeskorganizer\websockets\is-dsln1.tmp
- %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\is-5vklk.tmp
- %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\is-3tt0c.tmp
- %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\is-rc6f0.tmp
- %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\is-4a8a5.tmp
- %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\is-fs37l.tmp
- %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\is-b7l9d.tmp
- %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-4d64f.tmp
- %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-flvuj.tmp
- %ProgramFiles(x86)%\ldeskorganizer\certifi\is-60i5s.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-plri9.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-cq057.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-7gial.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-563ap.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-fcoef.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-vps1r.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-0h7rc.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-9sv9u.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-c9oha.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-sq6fq.tmp
- %TEMP%\is-r1rcc.tmp\_isetup\_iscrypt.dll
- %TEMP%\is-r1rcc.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-r1rcc.tmp\_isetup\_setup64.tmp
- %TEMP%\is-r1rcc.tmp\_isetup\_regdll.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-vnpvu.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-jg6ml.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-ogrsr.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-m5tcg.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-s0epe.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-29aes.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-200s6.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-dar46.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-aumg8.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-vqn44.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-slgqu.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-42tau.tmp
- %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\is-0m30b.tmp
- %ProgramFiles(x86)%\ldeskorganizer\ldeskorganizer.exe
- %ProgramFiles(x86)%\ldeskorganizer\is-a2on2.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-l8jqp.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-tnc7i.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-l703i.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-5osgq.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-td46u.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-t9u50.tmp
- %ProgramFiles(x86)%\ldeskorganizer\is-4hdpd.tmp
- %TEMP%\license.txt
- from %ProgramFiles(x86)%\ldeskorganizer\is-sq6fq.tmp to %ProgramFiles(x86)%\ldeskorganizer\unins000.exe
- from %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-c06bu.tmp to %ProgramFiles(x86)%\ldeskorganizer\imageformats\qjpegd4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-04u8d.tmp to %ProgramFiles(x86)%\ldeskorganizer\imageformats\qmng4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-dhbhu.tmp to %ProgramFiles(x86)%\ldeskorganizer\imageformats\qmngd4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-0q39r.tmp to %ProgramFiles(x86)%\ldeskorganizer\imageformats\qsvg4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-kbcak.tmp to %ProgramFiles(x86)%\ldeskorganizer\imageformats\qsvgd4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-5essq.tmp to %ProgramFiles(x86)%\ldeskorganizer\imageformats\qtga4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-to8v0.tmp to %ProgramFiles(x86)%\ldeskorganizer\imageformats\qtgad4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-pdbe5.tmp to %ProgramFiles(x86)%\ldeskorganizer\imageformats\qtiff4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-t1uf8.tmp to %ProgramFiles(x86)%\ldeskorganizer\imageformats\qtiffd4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\phonon_backend\is-tu6v0.tmp to %ProgramFiles(x86)%\ldeskorganizer\phonon_backend\phonon_ds94.dll
- from %ProgramFiles(x86)%\ldeskorganizer\phonon_backend\is-3880s.tmp to %ProgramFiles(x86)%\ldeskorganizer\phonon_backend\phonon_ds9d4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\pywin32_system32\is-056ak.tmp to %ProgramFiles(x86)%\ldeskorganizer\pywin32_system32\pythoncom38.dll
- from %ProgramFiles(x86)%\ldeskorganizer\pywin32_system32\is-pk2sj.tmp to %ProgramFiles(x86)%\ldeskorganizer\pywin32_system32\pywintypes38.dll
- from %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-ofu8u.tmp to %ProgramFiles(x86)%\ldeskorganizer\imageformats\qicod4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-5gu9t.tmp to %ProgramFiles(x86)%\ldeskorganizer\imageformats\qjpeg4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\shiboken2\is-vuism.tmp to %ProgramFiles(x86)%\ldeskorganizer\shiboken2\msvcp140.dll
- from %ProgramFiles(x86)%\ldeskorganizer\shiboken2\is-e1gsc.tmp to %ProgramFiles(x86)%\ldeskorganizer\shiboken2\shiboken2.abi3.dll
- from %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\is-ft7s0.tmp to %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\wheel
- from %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\is-v3j4t.tmp to %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\top_level.txt
- from %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\is-sa93o.tmp to %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\record
- from %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\is-6sc0c.tmp to %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\metadata
- from %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\is-0m30b.tmp to %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\license
- from %ProgramFiles(x86)%\ldeskorganizer\is-42tau.tmp to %ProgramFiles(x86)%\ldeskorganizer\_overlapped.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\is-vioic.tmp to %ProgramFiles(x86)%\ldeskorganizer\websockets-10.4.dist-info\installer
- from %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\is-5vklk.tmp to %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\qsqlpsqld4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\is-3tt0c.tmp to %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\qsqlpsql4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\is-rc6f0.tmp to %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\qsqlodbcd4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\is-4a8a5.tmp to %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\qsqlodbc4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\is-fs37l.tmp to %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\qsqlited4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\is-b7l9d.tmp to %ProgramFiles(x86)%\ldeskorganizer\sqldrivers\qsqlite4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\shiboken2\is-tvkn0.tmp to %ProgramFiles(x86)%\ldeskorganizer\shiboken2\shiboken2.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-epio0.tmp to %ProgramFiles(x86)%\ldeskorganizer\imageformats\qico4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-4d64f.tmp to %ProgramFiles(x86)%\ldeskorganizer\imageformats\qgifd4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\imageformats\is-flvuj.tmp to %ProgramFiles(x86)%\ldeskorganizer\imageformats\qgif4.dll
- from %ProgramFiles(x86)%\ldeskorganizer\is-9sv9u.tmp to %ProgramFiles(x86)%\ldeskorganizer\libffi-7.dll
- from %ProgramFiles(x86)%\ldeskorganizer\is-0h7rc.tmp to %ProgramFiles(x86)%\ldeskorganizer\libssl-1_1.dll
- from %ProgramFiles(x86)%\ldeskorganizer\is-vps1r.tmp to %ProgramFiles(x86)%\ldeskorganizer\pyexpat.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-fcoef.tmp to %ProgramFiles(x86)%\ldeskorganizer\python3.dll
- from %ProgramFiles(x86)%\ldeskorganizer\is-563ap.tmp to %ProgramFiles(x86)%\ldeskorganizer\pythoncom38.dll
- from %ProgramFiles(x86)%\ldeskorganizer\is-7gial.tmp to %ProgramFiles(x86)%\ldeskorganizer\pywintypes38.dll
- from %ProgramFiles(x86)%\ldeskorganizer\is-cq057.tmp to %ProgramFiles(x86)%\ldeskorganizer\select.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-plri9.tmp to %ProgramFiles(x86)%\ldeskorganizer\tagging.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-ogrsr.tmp to %ProgramFiles(x86)%\ldeskorganizer\vcruntime140.dll
- from %ProgramFiles(x86)%\ldeskorganizer\is-vnpvu.tmp to %ProgramFiles(x86)%\ldeskorganizer\win32api.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-jg6ml.tmp to %ProgramFiles(x86)%\ldeskorganizer\win32evtlog.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-m5tcg.tmp to %ProgramFiles(x86)%\ldeskorganizer\win32trace.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-29aes.tmp to %ProgramFiles(x86)%\ldeskorganizer\win32wnet.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-t9u50.tmp to %ProgramFiles(x86)%\ldeskorganizer\_asyncio.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-c9oha.tmp to %ProgramFiles(x86)%\ldeskorganizer\lscol
- from %ProgramFiles(x86)%\ldeskorganizer\is-td46u.tmp to %ProgramFiles(x86)%\ldeskorganizer\_brotli.cp38-win32.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\certifi\is-60i5s.tmp to %ProgramFiles(x86)%\ldeskorganizer\certifi\cacert.pem
- from %ProgramFiles(x86)%\ldeskorganizer\is-5osgq.tmp to %ProgramFiles(x86)%\ldeskorganizer\_bz2.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-l703i.tmp to %ProgramFiles(x86)%\ldeskorganizer\_ctypes.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-tnc7i.tmp to %ProgramFiles(x86)%\ldeskorganizer\_decimal.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-l8jqp.tmp to %ProgramFiles(x86)%\ldeskorganizer\_elementtree.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-a2on2.tmp to %ProgramFiles(x86)%\ldeskorganizer\_hashlib.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-ctjho.tmp to %ProgramFiles(x86)%\ldeskorganizer\_lzma.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\websockets\is-dsln1.tmp to %ProgramFiles(x86)%\ldeskorganizer\websockets\speedups.cp38-win32.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-4hdpd.tmp to %ProgramFiles(x86)%\ldeskorganizer\_multiprocessing.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\win32com\shell\is-pu45k.tmp to %ProgramFiles(x86)%\ldeskorganizer\win32com\shell\shell.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-vqn44.tmp to %ProgramFiles(x86)%\ldeskorganizer\_socket.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-aumg8.tmp to %ProgramFiles(x86)%\ldeskorganizer\_sqlite3.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-dar46.tmp to %ProgramFiles(x86)%\ldeskorganizer\_ssl.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-200s6.tmp to %ProgramFiles(x86)%\ldeskorganizer\_testcapi.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-s0epe.tmp to %ProgramFiles(x86)%\ldeskorganizer\_win32sysloader.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-slgqu.tmp to %ProgramFiles(x86)%\ldeskorganizer\_queue.pyd
- from %ProgramFiles(x86)%\ldeskorganizer\is-94151.tmp to %ProgramFiles(x86)%\ldeskorganizer\ldeskorganizer.exe
- 'mi####njobs.works':80
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?43######
- http://mi####njobs.works/new/net_api
- DNS ASK mi####njobs.works
- ClassName: 'f5e05_ldo1151Class_f5e05' WindowName: ''
- '%TEMP%\is-4p4el.tmp\<File name>.tmp' /SL5="$90248,8336458,53248,<Full path to file>"
- '%ProgramFiles(x86)%\ldeskorganizer\ldeskorganizer.exe'
- '%ProgramFiles(x86)%\ldeskorganizer\ldeskorganizer.exe' 550e9684cd2a77f06eb2174e90c1d887
- '%WINDIR%\syswow64\schtasks.exe' /Delete /F /TN "LDO1105-1"
- '%WINDIR%\syswow64\schtasks.exe' /Query