Technical Information
- %TEMP%\content\2208-4212-<File name>.exe-18-11-35-053.dump
- %TEMP%\content\2208-4212-<File name>.exe-18-11-35-156.dump
- %TEMP%\content\2208-4212-<File name>.exe-18-11-35-199.dump
- %TEMP%\content\2208-3180-<File name>.exe-18-11-36-691.dump
- <SYSTEM32>\windowspowershell\v1.0\profiles\startup.ini
- <SYSTEM32>\windowspowershell\v1.0\profiles\default\config.ini
- %TEMP%\aft.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\aft.exe.log
- '%TEMP%\aft.exe' %TEMP%\<File name>.exe