Technical Information
- <Drive name for removable media>:\revengerat\client.exe
- <Drive name for removable media>:\weeklysheet1215.doc
- <Drive name for removable media>:\testcertificate.cer
- <Drive name for removable media>:\contosoroot_1.cer
- <Drive name for removable media>:\sdkfailsafeemulator.cer
- <Drive name for removable media>:\dashborder_144.bmp
- <Drive name for removable media>:\dashborder_96.bmp
- <Drive name for removable media>:\coffee.bmp
- <Drive name for removable media>:\tileimage.bmp
- <Drive name for removable media>:\toolbar.bmp
- <Drive name for removable media>:\dashborder_192.bmp.exe
- <Drive name for removable media>:\dashborder_192.bmp
- <Drive name for removable media>:\dialmap.bmp.exe
- <Drive name for removable media>:\dialmap.bmp
- <Drive name for removable media>:\dial.bmp.exe
- <Drive name for removable media>:\dial.bmp
- <Drive name for removable media>:\split.avi.exe
- <Drive name for removable media>:\split.avi
- <Drive name for removable media>:\archer.avi.exe
- <Drive name for removable media>:\archer.avi
- <Drive name for removable media>:\correct.avi.exe
- <Drive name for removable media>:\correct.avi
- <Drive name for removable media>:\000814251_video_01.avi.exe
- <Drive name for removable media>:\000814251_video_01.avi
- <Drive name for removable media>:\hanni_umami_chapter.doc
- <Drive name for removable media>:\aoc_saq_d_v3_merchant.docx
- %WINDIR%\microsoft.net\framework\v2.0.50727\aspnet_compiler.exe
- %TEMP%\jzwfrtnhu.txt
- %TEMP%\sesshysl.cmdline
- %TEMP%\sesshysl.out
- %TEMP%\vbc905c.tmp
- %TEMP%\res905d.tmp
- %ALLUSERSPROFILE%\revengerat\dialmap.ico
- %TEMP%\xtxymqfp.0.vb
- %TEMP%\xtxymqfp.cmdline
- %TEMP%\xtxymqfp.out
- %ALLUSERSPROFILE%\revengerat\dial.ico
- %TEMP%\sesshysl.0.vb
- %TEMP%\vbc95aa.tmp
- %TEMP%\9dzan428.0.vb
- %TEMP%\9dzan428.cmdline
- %TEMP%\9dzan428.out
- %APPDATA%\client.exe
- %TEMP%\vbc9bb2.tmp
- %TEMP%\res9bb3.tmp
- %ALLUSERSPROFILE%\revengerat\toolbar.ico
- %TEMP%\u_juegy8.0.vb
- %TEMP%\res95ab.tmp
- %ALLUSERSPROFILE%\revengerat\dashborder_192.ico
- %TEMP%\res8b4f.tmp
- %TEMP%\vbc8b3e.tmp
- %TEMP%\k2tlbcjb.out
- %TEMP%\gwlzety7.0.vb
- %TEMP%\gwlzety7.cmdline
- %TEMP%\gwlzety7.out
- %TEMP%\vbc7c21.tmp
- %TEMP%\res7c22.tmp
- %ALLUSERSPROFILE%\revengerat\correct.ico
- %TEMP%\cmazrmhn.0.vb
- %TEMP%\cmazrmhn.cmdline
- %TEMP%\cmazrmhn.out
- %ALLUSERSPROFILE%\revengerat\000814251_video_01.ico
- %TEMP%\vbc8140.tmp
- %ALLUSERSPROFILE%\revengerat\archer.ico
- %TEMP%\aaqsyo7t.0.vb
- %TEMP%\aaqsyo7t.cmdline
- %TEMP%\aaqsyo7t.out
- %TEMP%\vbc863f.tmp
- %TEMP%\res8640.tmp
- %ALLUSERSPROFILE%\revengerat\split.ico
- %TEMP%\k2tlbcjb.0.vb
- %TEMP%\k2tlbcjb.cmdline
- %TEMP%\res8141.tmp
- %TEMP%\u_juegy8.cmdline
- %TEMP%\u_juegy8.out
- <Drive name for removable media>:\revengerat\client.exe
- %TEMP%\res7c22.tmp
- %TEMP%\res905d.tmp
- %TEMP%\vbc905c.tmp
- %TEMP%\sesshysl.0.vb
- %TEMP%\sesshysl.cmdline
- %TEMP%\sesshysl.out
- %TEMP%\res95ab.tmp
- %TEMP%\vbc95aa.tmp
- %TEMP%\xtxymqfp.0.vb
- %TEMP%\xtxymqfp.out
- %TEMP%\xtxymqfp.cmdline
- %TEMP%\res9bb3.tmp
- %TEMP%\vbc9bb2.tmp
- %TEMP%\9dzan428.0.vb
- %TEMP%\9dzan428.out
- %TEMP%\9dzan428.cmdline
- %TEMP%\k2tlbcjb.cmdline
- %TEMP%\u_juegy8.0.vb
- %TEMP%\k2tlbcjb.0.vb
- %TEMP%\vbc8b3e.tmp
- %TEMP%\vbc7c21.tmp
- %TEMP%\gwlzety7.out
- %TEMP%\gwlzety7.0.vb
- %TEMP%\gwlzety7.cmdline
- %TEMP%\res8141.tmp
- %TEMP%\vbc8140.tmp
- %TEMP%\cmazrmhn.out
- %TEMP%\cmazrmhn.cmdline
- %TEMP%\cmazrmhn.0.vb
- %TEMP%\res8640.tmp
- %TEMP%\vbc863f.tmp
- %TEMP%\aaqsyo7t.out
- %TEMP%\aaqsyo7t.0.vb
- %TEMP%\aaqsyo7t.cmdline
- %TEMP%\res8b4f.tmp
- %TEMP%\k2tlbcjb.out
- %TEMP%\u_juegy8.cmdline
- DNS ASK ro####.hopto.org
- '%APPDATA%\client.exe'
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\gwlzety7.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES193B.tmp" "%TEMP%\vbc193A.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\7x5v3vzq.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1BAB.tmp" "%TEMP%\vbc1B9B.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\4yyr0wly.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1E69.tmp" "%TEMP%\vbc1E68.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\oqxpxujl.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\miotgghk.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES24B0.tmp" "%TEMP%\vbc24AF.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\uhde-ppt.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2684.tmp" "%TEMP%\vbc2683.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\7pcqr-qo.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES28F4.tmp" "%TEMP%\vbc28F3.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ewe5vbef.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\0yl10ebd.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES226F.tmp" "%TEMP%\vbc226E.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES16CB.tmp" "%TEMP%\vbc16CA.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8B4F.tmp" "%TEMP%\vbc8B3E.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7C22.tmp" "%TEMP%\vbc7C21.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\cmazrmhn.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8141.tmp" "%TEMP%\vbc8140.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\aaqsyo7t.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8640.tmp" "%TEMP%\vbc863F.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\k2tlbcjb.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\sesshysl.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\xblubzdf.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES905D.tmp" "%TEMP%\vbc905C.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\xtxymqfp.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES95AB.tmp" "%TEMP%\vbc95AA.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\9dzan428.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9BB3.tmp" "%TEMP%\vbc9BB2.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\u_juegy8.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2B26.tmp" "%TEMP%\vbc2B25.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\jodyyjcf.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\aspnet_compiler.exe'
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES193B.tmp" "%TEMP%\vbc193A.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\7x5v3vzq.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1BAB.tmp" "%TEMP%\vbc1B9B.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\4yyr0wly.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES1E69.tmp" "%TEMP%\vbc1E68.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\0yl10ebd.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\oqxpxujl.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2B26.tmp" "%TEMP%\vbc2B25.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES24B0.tmp" "%TEMP%\vbc24AF.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\uhde-ppt.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2684.tmp" "%TEMP%\vbc2683.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\7pcqr-qo.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES28F4.tmp" "%TEMP%\vbc28F3.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\ewe5vbef.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\miotgghk.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES226F.tmp" "%TEMP%\vbc226E.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES16CB.tmp" "%TEMP%\vbc16CA.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\k2tlbcjb.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\gwlzety7.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES7C22.tmp" "%TEMP%\vbc7C21.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\cmazrmhn.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8141.tmp" "%TEMP%\vbc8140.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\aaqsyo7t.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8640.tmp" "%TEMP%\vbc863F.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES8B4F.tmp" "%TEMP%\vbc8B3E.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\u_juegy8.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\sesshysl.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES905D.tmp" "%TEMP%\vbc905C.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\xtxymqfp.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES95AB.tmp" "%TEMP%\vbc95AA.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\9dzan428.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9BB3.tmp" "%TEMP%\vbc9BB2.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\xblubzdf.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\jodyyjcf.cmdline"