Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '' = '%TEMP%\performagenhost.exe'
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- %TEMP%\performagenhost.exe
- '62.##3.96.239':80
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'