Technical Information
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, %APPDATA%\Microsoft\Protect\ConexantPerformanceMonitor.exe'
- [HKCU\Software\SimonTatham\PuTTY\Sessions]
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %APPDATA%\microsoft\protect\conexantperformancemonitor.exe
- %TEMP%\dsc1b63.tmp\current
- %TEMP%\dsc1b63.tmp\log
- %TEMP%\dsc1b63.tmp\manifest-000001
- %APPDATA%\microsoft\protect\conexantperformancemonitor.exe
- %TEMP%\dsc1b63.tmp\current
- %TEMP%\dsc1b63.tmp\log
- %TEMP%\dsc1b63.tmp\manifest-000001
- 'ap#.#pify.org':443
- 'di###rd.cyou':80
- 'ap#.#pify.org':443
- DNS ASK ap#.#pify.org
- DNS ASK di###rd.cyou
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --no-first-run --noerrdialogs --disable-background-networking