Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\smartclock.lnk
- <SYSTEM32>\tasks\smart clock
- %TEMP%\nsn1d60.tmp\uac.dll
- %ProgramFiles(x86)%\foler\olader\acppage.dll
- %ProgramFiles(x86)%\foler\olader\adprovider.dll
- %ProgramFiles(x86)%\foler\olader\acledit.dll
- %TEMP%\new feature\4.exe
- %TEMP%\new feature\vpn.exe
- %APPDATA%\smart clock\smartclock.exe
- %TEMP%\ac36.tmp
- %TEMP%\boxyposm.vbs
- %TEMP%\6116.tmp
- %TEMP%\xvdctvtsfp.vbs
- %TEMP%\nsn1d60.tmp\uac.dll
- 'ip##pi.com':80
- '2n#.co':443
- 'microsoft.com':80
- 'r3.#.lencr.org':80
- 'ip###ger.org':443
- '2n#.co':443
- DNS ASK ip##pi.com
- DNS ASK 2n#.co
- DNS ASK microsoft.com
- DNS ASK r3.#.lencr.org
- DNS ASK ip###ger.org
- '%TEMP%\new feature\4.exe'
- '%TEMP%\new feature\vpn.exe'
- '%APPDATA%\smart clock\smartclock.exe'
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\boxyposm.vbs"
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\xvdctvtsfp.vbs"