Technical Information
- [HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%\Microsoft\CoreRuntime' = '00000000'
- iyqwzc.exe process, Amsi.dll module
- searchprotocolhost.exe process, Amsi.dll module
- searchfilterhost.exe process, Amsi.dll module
- taskhostw.exe process, Amsi.dll module
- sihost.exe process, Amsi.dll module
- iyqwzc.exe process, ntdll.dll module
- searchprotocolhost.exe process, ntdll.dll module
- searchfilterhost.exe process, ntdll.dll module
- taskhostw.exe process, ntdll.dll module
- sihost.exe process, ntdll.dll module
- %LOCALAPPDATA%\microsoft\coreruntime\searchprotocolhost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\searchfilterhost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\taskhostw.exe
- %LOCALAPPDATA%\microsoft\coreruntime\sihost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\searchprotocolhost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\searchfilterhost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\taskhostw.exe
- %LOCALAPPDATA%\microsoft\coreruntime\sihost.exe
- 'de####sync.ipv64.de':60485
- DNS ASK de####sync.ipv64.de
- DNS ASK ap#.#pify.org
- '%LOCALAPPDATA%\microsoft\coreruntime\searchprotocolhost.exe'
- '%LOCALAPPDATA%\microsoft\coreruntime\searchfilterhost.exe'
- '%LOCALAPPDATA%\microsoft\coreruntime\taskhostw.exe'
- '%LOCALAPPDATA%\microsoft\coreruntime\sihost.exe'