Technical Information
- <SYSTEM32>\tasks\asos1
- %TEMP%\unpack1.log
- %TEMP%\unpacksos\1\streamer1.cab
- %TEMP%\unpacksos\1\.init_setting.ini
- %TEMP%\unpacksos\1\.cloudbuild.check.rsa
- %TEMP%\unpacksos\1\.cloudbuild.check
- %TEMP%\unpacksos\1\.splashtop.sostheme
- %TEMP%\unpacksos\1\.config.json
- %TEMP%\unpacksos\1\default.ico
- %TEMP%\unpacksos\1\$dpx$.tmp\51f730f30a26034b8914e421b388518e.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\f2984585518a8a42bf41bbbb46cdeb8c.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\68e28e6d5d3cfd4e88ec3d7893a81e31.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\83d3bc20372ea846a94eafbf34e67b7c.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\63f001f281d8614aad8d33fc3fcd1c04.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\f72b434749078f45b7b40d8c52b59487.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\014ecc96ffaca241a118f498d6831133.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\5348e8c444d530469de9fa9bcefd5758.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\a88859e9d41f2b469f20d41280107af9.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\5f753c794ffe1c43b845342867a9d2c9.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\549f06a23beef04bb836043a223591ad.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\2f442872c986354bbc72ac215dec9039.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\c2f68f4cc8503c4d85675964542abf26.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\728a5bef11f32344a880506aba077820.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\302ae088896fc9469161938ef6eb727c.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\f1552e64e7b2ce45a6171410e59fe6a8.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\faef668a0750e046a75d43111f177f41.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\9904d73a18fd4a45b0ebdb21483f7d52.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\50f3dda9bd649041a06be4beca448a97.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\d0a9731fa32ffa4ebec94e6737deae6d.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\9b21d4f4fe70484d9b2ff6c1e9ac4b6e.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\94e505be81dfcf46a0f25f2897ad5178.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\17feeca8be703e4c90d76b80ab9cba3a.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\e97e7b36e284e54cb8a54ccef0ee71d0.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\94310ae1ba2edb409a9da03215ae9a9f.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\b763e63f99de3c46af080ff3b79d688a.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\6387926675bd1840b51b2f1441808b09.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\e99f3b610abb764e965349c1eea88c8f.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\92913e0dc6f94f4794b9f5a51070879a.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\0101f284fd4b354ba83d09b4518b9230.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\27d0cc0c778d5741b8c18b0f35180daf.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\5189c67d32871f4faabd227a174b83e6.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\4a5da2e61a7f7a499ea02e413bec89c0.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\a0ad7328738fb644af954134785035da.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\226879ed7417da409040806321999926.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\3956a740e779f549abbdda0de95d2abc.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\66b68d4f857e1545bf546b04d1b93ab6.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\03a7a74e9bb33d4084100bc2af7a16a7.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\064f321b138266429f0b56e3d9d9a314.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\03107ff4bcc1fe42918bb0f45a641444.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\88a02347ee1e9d4da1a6f1f824f88a9b.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\4bca2e218d8dd64ebbe6b1d0fc0ca734.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\5a943ec30f3be440aec999e3358c24c6.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\3eaceb6e088a6741ad136a4b4f498721.tmp
- %TEMP%\unpacksos\1\$dpx$.tmp\c438addf6b877242821ed0067b164540.tmp
- %TEMP%\unpacksos\1\srfeatminisos.exe
- %TEMP%\splashtop\sos\launcher.txt
- %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\metadata\c86bd7751d53f10f65aaad66bbdf33c7
- %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\c86bd7751d53f10f65aaad66bbdf33c7
- %WINDIR%\temp\cabb885.tmp
- %WINDIR%\temp\tarb895.tmp
- %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\temp\cabd3b5.tmp
- %WINDIR%\temp\tard3b6.tmp
- <SYSTEM32>\tasks\asos1
- %WINDIR%\temp\cabb885.tmp
- %WINDIR%\temp\tarb895.tmp
- %WINDIR%\temp\cabd3b5.tmp
- %WINDIR%\temp\tard3b6.tmp
- from %TEMP%\unpacksos\1\$dpx$.tmp\51f730f30a26034b8914e421b388518e.tmp to %TEMP%\unpacksos\1\acknowledgements.htm
- from %TEMP%\unpacksos\1\$dpx$.tmp\f2984585518a8a42bf41bbbb46cdeb8c.tmp to %TEMP%\unpacksos\1\launcher.exe
- from %TEMP%\unpacksos\1\$dpx$.tmp\68e28e6d5d3cfd4e88ec3d7893a81e31.tmp to %TEMP%\unpacksos\1\avutil-59.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\83d3bc20372ea846a94eafbf34e67b7c.tmp to %TEMP%\unpacksos\1\dbghelp.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\63f001f281d8614aad8d33fc3fcd1c04.tmp to %TEMP%\unpacksos\1\fips.cnf
- from %TEMP%\unpacksos\1\$dpx$.tmp\f72b434749078f45b7b40d8c52b59487.tmp to %TEMP%\unpacksos\1\fips.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\014ecc96ffaca241a118f498d6831133.tmp to %TEMP%\unpacksos\1\legacy.cnf
- from %TEMP%\unpacksos\1\$dpx$.tmp\5348e8c444d530469de9fa9bcefd5758.tmp to %TEMP%\unpacksos\1\legacy.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\a88859e9d41f2b469f20d41280107af9.tmp to %TEMP%\unpacksos\1\libcrypto-3.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\5f753c794ffe1c43b845342867a9d2c9.tmp to %TEMP%\unpacksos\1\libssl-3.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\549f06a23beef04bb836043a223591ad.tmp to %TEMP%\unpacksos\1\libcelt-0.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\2f442872c986354bbc72ac215dec9039.tmp to %TEMP%\unpacksos\1\libcurl.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\c2f68f4cc8503c4d85675964542abf26.tmp to %TEMP%\unpacksos\1\libx264-116.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\728a5bef11f32344a880506aba077820.tmp to %TEMP%\unpacksos\1\p_mount.bat
- from %TEMP%\unpacksos\1\$dpx$.tmp\302ae088896fc9469161938ef6eb727c.tmp to %TEMP%\unpacksos\1\p_unmount.bat
- from %TEMP%\unpacksos\1\$dpx$.tmp\f1552e64e7b2ce45a6171410e59fe6a8.tmp to %TEMP%\unpacksos\1\reboot.bat
- from %TEMP%\unpacksos\1\$dpx$.tmp\faef668a0750e046a75d43111f177f41.tmp to %TEMP%\unpacksos\1\stprinter.cat
- from %TEMP%\unpacksos\1\$dpx$.tmp\9904d73a18fd4a45b0ebdb21483f7d52.tmp to %TEMP%\unpacksos\1\stprinterx.cat
- from %TEMP%\unpacksos\1\$dpx$.tmp\50f3dda9bd649041a06be4beca448a97.tmp to %TEMP%\unpacksos\1\stprinter.inf
- from %TEMP%\unpacksos\1\$dpx$.tmp\d0a9731fa32ffa4ebec94e6737deae6d.tmp to %TEMP%\unpacksos\1\stprintmon_x86.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\9b21d4f4fe70484d9b2ff6c1e9ac4b6e.tmp to %TEMP%\unpacksos\1\stprintmon_x64.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\94e505be81dfcf46a0f25f2897ad5178.tmp to %TEMP%\unpacksos\1\swresample-5.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\17feeca8be703e4c90d76b80ab9cba3a.tmp to %TEMP%\unpacksos\1\asos.xml
- from %TEMP%\unpacksos\1\$dpx$.tmp\e97e7b36e284e54cb8a54ccef0ee71d0.tmp to %TEMP%\unpacksos\1\srserver.pem
- from %TEMP%\unpacksos\1\$dpx$.tmp\94310ae1ba2edb409a9da03215ae9a9f.tmp to %TEMP%\unpacksos\1\srclient.pem
- from %TEMP%\unpacksos\1\$dpx$.tmp\b763e63f99de3c46af080ff3b79d688a.tmp to %TEMP%\unpacksos\1\sragentsos.exe
- from %TEMP%\unpacksos\1\$dpx$.tmp\6387926675bd1840b51b2f1441808b09.tmp to %TEMP%\unpacksos\1\srapppbsos.exe
- from %TEMP%\unpacksos\1\$dpx$.tmp\e99f3b610abb764e965349c1eea88c8f.tmp to %TEMP%\unpacksos\1\srappsos.exe
- from %TEMP%\unpacksos\1\$dpx$.tmp\92913e0dc6f94f4794b9f5a51070879a.tmp to %TEMP%\unpacksos\1\sraudiochatsos.exe
- from %TEMP%\unpacksos\1\$dpx$.tmp\0101f284fd4b354ba83d09b4518b9230.tmp to %TEMP%\unpacksos\1\sraudioresample.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\27d0cc0c778d5741b8c18b0f35180daf.tmp to %TEMP%\unpacksos\1\srchatsos.exe
- from %TEMP%\unpacksos\1\$dpx$.tmp\5189c67d32871f4faabd227a174b83e6.tmp to %TEMP%\unpacksos\1\srfeaturesos.exe
- from %TEMP%\unpacksos\1\$dpx$.tmp\4a5da2e61a7f7a499ea02e413bec89c0.tmp to %TEMP%\unpacksos\1\srfeaturesosnouia.exe
- from %TEMP%\unpacksos\1\$dpx$.tmp\a0ad7328738fb644af954134785035da.tmp to %TEMP%\unpacksos\1\srmanagersos.exe
- from %TEMP%\unpacksos\1\$dpx$.tmp\226879ed7417da409040806321999926.tmp to %TEMP%\unpacksos\1\sropus.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\3956a740e779f549abbdda0de95d2abc.tmp to %TEMP%\unpacksos\1\srsocketctrl.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\66b68d4f857e1545bf546b04d1b93ab6.tmp to %TEMP%\unpacksos\1\srserversos.exe
- from %TEMP%\unpacksos\1\$dpx$.tmp\03a7a74e9bb33d4084100bc2af7a16a7.tmp to %TEMP%\unpacksos\1\srservicesos.exe
- from %TEMP%\unpacksos\1\$dpx$.tmp\064f321b138266429f0b56e3d9d9a314.tmp to %TEMP%\unpacksos\1\srutilitysos.exe
- from %TEMP%\unpacksos\1\$dpx$.tmp\03107ff4bcc1fe42918bb0f45a641444.tmp to %TEMP%\unpacksos\1\srvideoctrl.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\88a02347ee1e9d4da1a6f1f824f88a9b.tmp to %TEMP%\unpacksos\1\srvideoctrlex.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\4bca2e218d8dd64ebbe6b1d0fc0ca734.tmp to %TEMP%\unpacksos\1\srx264wrapper.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\5a943ec30f3be440aec999e3358c24c6.tmp to %TEMP%\unpacksos\1\srx264wrapperex.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\3eaceb6e088a6741ad136a4b4f498721.tmp to %TEMP%\unpacksos\1\srx264wrapperexx.dll
- from %TEMP%\unpacksos\1\$dpx$.tmp\c438addf6b877242821ed0067b164540.tmp to %TEMP%\unpacksos\1\wz264.dll
- 'microsoft.com':80
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK microsoft.com
- ClassName: 'SplashtopRemoteAttendedSupport' WindowName: ''
- '%TEMP%\unpacksos\1\launcher.exe' SRManagerSOS.exe 1
- '%TEMP%\unpacksos\1\srmanagersos.exe'
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\expand.exe *.cab /f:* .\
- '<SYSTEM32>\expand.exe' *.cab /f:* .\
- '<SYSTEM32>\cmd.exe' /c schtasks /create /xml ASOS.xml /ru "system" /tn ASOS1
- '<SYSTEM32>\schtasks.exe' /create /xml ASOS.xml /ru "system" /tn ASOS1
- '<SYSTEM32>\cmd.exe' /c schtasks /change /tn ASOS1 /ru "system" /tr "'%TEMP%\unpacksos\1\\Launcher.exe' SRManagerSOS.exe 1 "
- '<SYSTEM32>\schtasks.exe' /change /tn ASOS1 /ru "system" /tr "'%TEMP%\unpacksos\1\\Launcher.exe' SRManagerSOS.exe 1 "
- '<SYSTEM32>\cmd.exe' /c schtasks /run /tn ASOS1
- '<SYSTEM32>\schtasks.exe' /run /tn ASOS1
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn ASOS1
- '<SYSTEM32>\schtasks.exe' /delete /f /tn ASOS1
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\expand.exe *.cab /f:* .\' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /create /xml ASOS.xml /ru "system" /tn ASOS1' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /change /tn ASOS1 /ru "system" /tr "'%TEMP%\unpacksos\1\\Launcher.exe' SRManagerSOS.exe 1 "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /run /tn ASOS1' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /delete /f /tn ASOS1' (with hidden window)
- '%TEMP%\unpacksos\1\launcher.exe' SRManagerSOS.exe 1' (with hidden window)
- '%TEMP%\unpacksos\1\srmanagersos.exe' ' (with hidden window)