Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\Zemana] 'ImagePath' = 'C:\Zemana.sys'
- 'Zemana' C:\Zemana.sys
- User Account Control (UAC)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "<Full path to file>" -Force
- %WINDIR%\microsoft.net\framework64\v4.0.30319\aspnet_compiler.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\addinprocess32.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\aspnet_compiler.exe
- %TEMP%\content\3324-3568-<File name>.exe-13-21-10-804.dump
- %TEMP%\content\3324-3568-<File name>.exe-13-21-11-315.dump
- C:\zemana.sys
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
- %WINDIR%\zam.krnl.trace
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\addinprocess32.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "<Full path to file>" -Force' (with hidden window)