Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'wcmdmgr' = '%WINDIR%\wt\updater\wcmdmgrl.exe -launch'
- '%WINDIR%\wt\updater\wcmdmgr.exe' -updateapp "wtdmmp"
- '%WINDIR%\wt\updater\wcmdmgr.exe' -registerapp "wtdmmp" -applongname "WildTangent Multiplayer Library" -appexe "" -apppath "%WINDIR%\wt" -updateurl "http://up#######rvice.wildtangent.com" -dltype "1" -updatetype "3" -verifytype "2" -interval "1500" -phasekey "" -requestedversion "" -DistID "bhst-32-101403-wildg" -appargs ""
- '%TEMP%\wti9BA9.tmp\DRM3Setup.exe'
- '%WINDIR%\wt\updater\wcmdmgr.exe' -launch -wakeup
- '%WINDIR%\wt\bgmtat.exe'
- '%WINDIR%\wt\updater\wcmdmgr.exe' -getappversion wtdmmp
- '%WINDIR%\wt\updater\wcmdmgr.exe' -getappversion wtwebdriver
- '%WINDIR%\wt\updater\wcmdmgr.exe' -verifyapp wtwebdriver
- '%WINDIR%\wt\updater\wcmdmgr.exe' -registerapp "wtwebdriver" -applongname "WildTangent Web Driver" -appexe "" -apppath "%WINDIR%\wt" -updateurl "http://up#######rvice.wildtangent.com" -dltype "1" -updatetype "3" -verifytype "2" -interval "5" -phasekey "" -requestedversion "" -DistID "bhst-32-101403-wildg" -appargs ""
- '%WINDIR%\wt\updater\wcmdmgr.exe' -verifyapp wtdmmp
- '%WINDIR%\wt\updater\wcmdmgr.exe' -updateapp "wtwebdriver"
- %WINDIR%\wt\wtupdates\wtdmmp\update_info\datadl.wts.tmp
- %WINDIR%\wt\webdriver\wtdmmp.dll
- %WINDIR%\wt\webdriver\wtdmmpi.jar
- %WINDIR%\wt\wtupdates\wtdmmp\files\3.0.1.001\wtdmmp.dll.tmp
- %WINDIR%\wt\wtupdates\wtdmmp\files\3.0.1.001\wtdmmpi.jar.tmp
- %WINDIR%\wt\wtupdates\wtdmmp\files\3.0.1.001\wtdmmpv.dll.tmp
- %TEMP%\wti9BA9.tmp\2_silent_wtdmmpfullcore.pl.tmp
- %TEMP%\wti9BA9.tmp\3_combine_silent_full_with_dmmp_bgm_disabled.pl.tmp
- %TEMP%\wti9BA9.tmp\Clean.bat.tmp
- %WINDIR%\wt\webdriver\wtdmmpv.dll
- %TEMP%\wti9BA9.tmp\0_nsisexec.pl.tmp
- %TEMP%\wti9BA9.tmp\1_webdriverfullsilentcore.pl.tmp
- %WINDIR%\wt\webdriver\wtmulti.dll
- %WINDIR%\wt\webdriver\wtmulti.jar
- %WINDIR%\wt\wtvh.dll
- %WINDIR%\wt\webdriver\wildtangent.jar
- %WINDIR%\wt\webdriver\wthost.exe
- %WINDIR%\wt\webdriver\wthostctl.dll
- %WINDIR%\wt\data.wts
- %WINDIR%\wt\webdriver.dll
- %WINDIR%\wt\wt3d.dll
- %WINDIR%\wt\webdriver\wtwmplug.ax
- %WINDIR%\wt\webdriver\wtwmplug.ini
- %WINDIR%\wt\webdriver\sound.dll
- %TEMP%\wti9BA9.tmp\CopyFiles.bat.tmp
- %WINDIR%\wt\updater\wtisa.dll
- <SYSTEM32>\wtcpl.cpl
- %WINDIR%\wt\updater\updatenow.bat
- %PROGRAM_FILES%\WildTangent\Apps\rDRM0302.dll
- %PROGRAM_FILES%\WildTangent\LicenseStores\WT\wt.sto
- %WINDIR%\wt\bgmtat.exe
- %WINDIR%\wt\updater\data.wts
- %WINDIR%\wt\wtupdates\wtupdater\appinfo.dat
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\updatecheckin[1].htm
- %WINDIR%\wt\updater\stopwcmdr.bat
- %WINDIR%\wt\updater\_privacy.txt
- %WINDIR%\wt\info.txt
- %TEMP%\wti9BA9.tmp\makeme.pl.tmp
- %TEMP%\wti9BA9.tmp\README.txt.tmp
- %TEMP%\wti9BA9.tmp\vssver.scc.tmp
- %TEMP%\wti9BA9.tmp\DelFiles.bat.tmp
- %TEMP%\wti9BA9.tmp\deliver.bat.tmp
- %TEMP%\wti9BA9.tmp\DRM3Setup.exe.tmp
- %WINDIR%\wt\wtDRM\rDRM0302.dll
- %PROGRAM_FILES%\WildTangent\Apps\DRM0302.dll
- %PROGRAM_FILES%\WildTangent\Apps\DRM0302Java.jar
- %WINDIR%\wt\wtDRM\DRM0302.dll
- %WINDIR%\wt\wtDRM\DRM0302Java.jar
- %WINDIR%\wt\wtDRM\jDRM0302.dll
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\dx7drv.dll.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\jdriver.dll.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\legacy\data.wts.tmp
- %WINDIR%\wt\WDInUsePlugin.dll.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\actorobject.dll.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\dx5drv.dll.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\npwtplug.dll.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\nsiwthostplugin.xpt.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\objectbundle.dll.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\legacy\webdriver.dll.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\legacy\wt3d.dll.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\npwthost.dll.tmp
- %WINDIR%\wt\updater\wcmdmgr.exe
- %WINDIR%\wt\backup\1.6.0.037\wcmdmgrl.exe.tmp
- %WINDIR%\wt\updater\wcmdmgrl.exe
- %WINDIR%\wt\updater\wt.ini
- %WINDIR%\wt\updater\install\data.wts.tmp
- %WINDIR%\wt\backup\1.6.0.037\wcmdmgr.exe.tmp
- %WINDIR%\wt\backup\1.6.0.037\stopwcmdr.bat.tmp
- %WINDIR%\wt\backup\1.6.0.037\_privacy.txt.tmp
- %WINDIR%\wt\backup\1.6.0.037\info.txt.tmp
- %WINDIR%\wt\backup\1.6.0.037\wtcpl.cpl.tmp
- %WINDIR%\wt\backup\1.6.0.037\wtisa.dll.tmp
- %WINDIR%\wt\backup\1.6.0.037\updatenow.bat.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\rdriver.dll.tmp
- %WINDIR%\wt\webdriver\dx5drv.dll
- %WINDIR%\wt\webdriver\dx7drv.dll
- %WINDIR%\wt\webdriver\jdriver.dll
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtwmplug.ini.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\update_info\datadl.wts.tmp
- %WINDIR%\wt\webdriver\actorobject.dll
- %WINDIR%\wt\webdriver\wdengine.dll
- %WINDIR%\wt\webdriver\webdriver.dll
- %WINDIR%\wt\wt3d.ini
- %WINDIR%\wt\webdriver\objectbundle.dll
- %WINDIR%\wt\webdriver\rdriver.dll
- %WINDIR%\wt\webdriver\wdcaps.ded
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\webdriver.dll.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wildtangent.jar.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthost.exe.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\sound.dll.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wdcaps.ded.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wdengine.dll.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtmulti.jar.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtvh.dll.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtwmplug.ax.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthost.jar.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthostctl.dll.tmp
- %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtmulti.dll.tmp
- %TEMP%\wti9BA9.tmp\DRM3Setup.exe
- %TEMP%\wti9BA9.tmp\deliver.bat
- %TEMP%\wti9BA9.tmp\DelFiles.bat
- %TEMP%\wti9BA9.tmp\makeme.pl
- %WINDIR%\wt\updater\install\data.wts
- %TEMP%\wti9BA9.tmp\vssver.scc
- %TEMP%\wti9BA9.tmp\README.txt
- %TEMP%\wti9BA9.tmp\1_webdriverfullsilentcore.pl
- %TEMP%\wti9BA9.tmp\0_nsisexec.pl
- %WINDIR%\wt\WDInUsePlugin.dll
- %TEMP%\wti9BA9.tmp\2_silent_wtdmmpfullcore.pl
- %TEMP%\wti9BA9.tmp\CopyFiles.bat
- %TEMP%\wti9BA9.tmp\Clean.bat
- %TEMP%\wti9BA9.tmp\3_combine_silent_full_with_dmmp_bgm_disabled.pl
- from %WINDIR%\wt\wtupdates\wtwebdriver\update_info\datadl.wts to %WINDIR%\wt\wtupdates\wtwebdriver\update_info\data.wts
- from %WINDIR%\wt\wtupdates\wtwebdriver\update_info\datadl.wts.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\update_info\datadl.wts
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtwmplug.ini.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtwmplug.ini
- from %WINDIR%\wt\wtupdates\wtdmmp\files\3.0.1.001\wtdmmpv.dll.tmp to %WINDIR%\wt\wtupdates\wtdmmp\files\3.0.1.001\wtdmmpv.dll
- from %WINDIR%\wt\wtupdates\wtdmmp\files\3.0.1.001\wtdmmpi.jar.tmp to %WINDIR%\wt\wtupdates\wtdmmp\files\3.0.1.001\wtdmmpi.jar
- from %WINDIR%\wt\wtupdates\wtdmmp\files\3.0.1.001\wtdmmp.dll.tmp to %WINDIR%\wt\wtupdates\wtdmmp\files\3.0.1.001\wtdmmp.dll
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtwmplug.ax.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtwmplug.ax
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthostctl.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthostctl.dll
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthost.jar.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthost.jar
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthost.exe.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wthost.exe
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtvh.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtvh.dll
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtmulti.jar.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtmulti.jar
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtmulti.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wtmulti.dll
- from %WINDIR%\wt\wtupdates\wtdmmp\update_info\datadl.wts.tmp to %WINDIR%\wt\wtupdates\wtdmmp\update_info\datadl.wts
- from %TEMP%\wti9BA9.tmp\DRM3Setup.exe.tmp to %TEMP%\wti9BA9.tmp\DRM3Setup.exe
- from %TEMP%\wti9BA9.tmp\deliver.bat.tmp to %TEMP%\wti9BA9.tmp\deliver.bat
- from %TEMP%\wti9BA9.tmp\DelFiles.bat.tmp to %TEMP%\wti9BA9.tmp\DelFiles.bat
- from %TEMP%\wti9BA9.tmp\vssver.scc.tmp to %TEMP%\wti9BA9.tmp\vssver.scc
- from %TEMP%\wti9BA9.tmp\README.txt.tmp to %TEMP%\wti9BA9.tmp\README.txt
- from %TEMP%\wti9BA9.tmp\makeme.pl.tmp to %TEMP%\wti9BA9.tmp\makeme.pl
- from %TEMP%\wti9BA9.tmp\CopyFiles.bat.tmp to %TEMP%\wti9BA9.tmp\CopyFiles.bat
- from %TEMP%\wti9BA9.tmp\1_webdriverfullsilentcore.pl.tmp to %TEMP%\wti9BA9.tmp\1_webdriverfullsilentcore.pl
- from %TEMP%\wti9BA9.tmp\0_nsisexec.pl.tmp to %TEMP%\wti9BA9.tmp\0_nsisexec.pl
- from %WINDIR%\wt\wtupdates\wtdmmp\update_info\datadl.wts to %WINDIR%\wt\wtupdates\wtdmmp\update_info\data.wts
- from %TEMP%\wti9BA9.tmp\Clean.bat.tmp to %TEMP%\wti9BA9.tmp\Clean.bat
- from %TEMP%\wti9BA9.tmp\3_combine_silent_full_with_dmmp_bgm_disabled.pl.tmp to %TEMP%\wti9BA9.tmp\3_combine_silent_full_with_dmmp_bgm_disabled.pl
- from %TEMP%\wti9BA9.tmp\2_silent_wtdmmpfullcore.pl.tmp to %TEMP%\wti9BA9.tmp\2_silent_wtdmmpfullcore.pl
- from %WINDIR%\wt\WDInUsePlugin.dll.tmp to %WINDIR%\wt\WDInUsePlugin.dll
- from %WINDIR%\wt\backup\1.6.0.037\info.txt.tmp to %WINDIR%\wt\backup\1.6.0.037\info.txt
- from %WINDIR%\wt\backup\1.6.0.037\_privacy.txt.tmp to %WINDIR%\wt\backup\1.6.0.037\_privacy.txt
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\dx7drv.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\dx7drv.dll
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\dx5drv.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\dx5drv.dll
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\actorobject.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\actorobject.dll
- from %WINDIR%\wt\backup\1.6.0.037\stopwcmdr.bat.tmp to %WINDIR%\wt\backup\1.6.0.037\stopwcmdr.bat
- from %WINDIR%\wt\backup\1.6.0.037\wcmdmgrl.exe.tmp to %WINDIR%\wt\backup\1.6.0.037\wcmdmgrl.exe
- from %WINDIR%\wt\backup\1.6.0.037\wcmdmgr.exe.tmp to %WINDIR%\wt\backup\1.6.0.037\wcmdmgr.exe
- from %WINDIR%\wt\updater\install\data.wts.tmp to %WINDIR%\wt\updater\install\data.wts
- from %WINDIR%\wt\backup\1.6.0.037\updatenow.bat.tmp to %WINDIR%\wt\backup\1.6.0.037\updatenow.bat
- from %WINDIR%\wt\backup\1.6.0.037\wtisa.dll.tmp to %WINDIR%\wt\backup\1.6.0.037\wtisa.dll
- from %WINDIR%\wt\backup\1.6.0.037\wtcpl.cpl.tmp to %WINDIR%\wt\backup\1.6.0.037\wtcpl.cpl
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\jdriver.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\jdriver.dll
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wdcaps.ded.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wdcaps.ded
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\sound.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\sound.dll
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\rdriver.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\rdriver.dll
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wildtangent.jar.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wildtangent.jar
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\webdriver.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\webdriver.dll
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wdengine.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\wdengine.dll
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\objectbundle.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\objectbundle.dll
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\legacy\wt3d.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\legacy\wt3d.dll
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\legacy\webdriver.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\legacy\webdriver.dll
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\legacy\data.wts.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\legacy\data.wts
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\nsiwthostplugin.xpt.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\nsiwthostplugin.xpt
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\npwtplug.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\npwtplug.dll
- from %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\npwthost.dll.tmp to %WINDIR%\wt\wtupdates\wtwebdriver\files\3.3.1.001\npwthost.dll
- 'up#######rvice.wildtangent.com':80
- up#######rvice.wildtangent.com/updater/updatecheckin.wss
- DNS ASK up#######rvice.wildtangent.com