Technical Information
- %WINDIR%\microsoft.net\framework64\v4.0.30319\installutil.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\installutil.exe
- [HKCU\Software\Martin Prikryl\WinSCP 2\Sessions]
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %APPDATA%\opera software\opera stable\login data
- %TEMP%\content\3716-1608-<File name>.exe-09-21-07-597.dump
- %TEMP%\content\3716-1608-<File name>.exe-09-21-07-976.dump
- %TEMP%\content\3716-1608-<File name>.exe-09-21-08-431.dump
- %TEMP%\content\3716-1608-<File name>.exe-09-21-08-478.dump
- %TEMP%\content\5540-5728-installutil.exe-09-21-10-028.dump
- %TEMP%\content\5540-5728-installutil.exe-09-21-13-485.dump
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\installutil.exe.log
- '92.##6.87.36':5888
- '92.##6.87.36':5888
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\installutil.exe'