Technical Information
- %WINDIR%\temp\javasetup8u261.exe
- %TEMP%\jds1004281.tmp\jds1004296.tmp
- from %TEMP%\jds1004281.tmp\jds1004296.tmp to %TEMP%\jds1004281.tmp\javasetup8u261.exe
- 'public-trust.com':80
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- DNS ASK ja#######d-secure.oracle.com
- DNS ASK ja####.oracle.com
- DNS ASK sd####sd.oracle.com
- DNS ASK oc##.#tartssl.com
- DNS ASK public-trust.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\temp\javasetup8u261.exe' ""
- '%TEMP%\jds1004281.tmp\javasetup8u261.exe' ""
- '<SYSTEM32>\cmd.exe' /C del "<Full path to file>"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C del "<Full path to file>"