Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\PROCMON20] 'ImagePath' = '<DRIVERS>\PROCMON20.SYS'
- NtQueryKey, handler: PROCMON20.SYS
- NtOpenKey, handler: PROCMON20.SYS
- NtLoadKey, handler: PROCMON20.SYS
- NtUnloadKey, handler: PROCMON20.SYS
- NtSetValueKey, handler: PROCMON20.SYS
- NtQueryValueKey, handler: PROCMON20.SYS
- NtFlushKey, handler: PROCMON20.SYS
- NtDeleteKey, handler: PROCMON20.SYS
- NtCreateKey, handler: PROCMON20.SYS
- NtClose, handler: PROCMON20.SYS
- NtEnumerateValueKey, handler: PROCMON20.SYS
- NtEnumerateKey, handler: PROCMON20.SYS
- NtDeleteValueKey, handler: PROCMON20.SYS
- <DRIVERS>\PROCMON20.SYS
- <DRIVERS>\PROCMON20.SYS
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'