Technical Information
- <SYSTEM32>\tswbprxy.exe
- %WINDIR%\windowsshell4468810.log
- %WINDIR%\windowssystemupdate422.log
- 'su###xxed.asia':36281
- '43.##9.192.68':46282
- '11#.#78.142.200':60123
- 'su###xxed.asia':36281
- '11#.#78.142.200':60123
- DNS ASK su###xxed.asia
- '255.255.255.255':58049
- '<SYSTEM32>\tswbprxy.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "<SYSTEM32>\tswbprxy.exe"
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> >> NUL
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> >> NUL' (with hidden window)