Technical Information
- [<HKLM>\System\CurrentControlSet\Services\MicrosoftEngineering] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\MicrosoftEngineering] 'ImagePath' = '<Full path to file>'
- [<HKLM>\System\CurrentControlSet\Services\keymmdrv] 'ImagePath' = '%WINDIR%\SysWOW64\asm_drivers\keymmdrv.sys'
- 'MicrosoftEngineering' <Full path to file>
- 'keymmdrv' %WINDIR%\SysWOW64\asm_drivers\keymmdrv.sys
- %WINDIR%\temp\abc3a51.tmp
- %WINDIR%\syswow64\asm_drivers\keymmdrv.sys
- %WINDIR%\temp\udd3f7f.tmp
- %WINDIR%\temp\udd4930.tmp
- %WINDIR%\temp\udd510e.tmp
- %WINDIR%\temp\udd58eb.tmp
- %WINDIR%\temp\udd60c9.tmp
- %WINDIR%\temp\udd68a6.tmp
- %WINDIR%\temp\abc3a51.tmp
- %WINDIR%\temp\udd3f7f.tmp
- %WINDIR%\temp\udd4930.tmp
- %WINDIR%\temp\udd510e.tmp
- %WINDIR%\temp\udd58eb.tmp
- %WINDIR%\temp\udd60c9.tmp
- %WINDIR%\temp\udd68a6.tmp
- 'su####tconter.com':443
- 'su####tconter.com':443
- DNS ASK su####tconter.com
- '%WINDIR%\temp\abc3a51.tmp'
- '<Full path to file>' -r debug -z 1' (with hidden window)