Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\isspecialname.vbs
- %WINDIR%\microsoft.net\framework64\v4.0.30319\regasm.exe
- %WINDIR%\microsoft.net\framework64\v4.0.30319\regasm.exe
- %TEMP%\content\4008-4228-<File name>.exe-18-51-20-759.dump
- %TEMP%\content\4008-4228-<File name>.exe-18-51-22-233.dump
- %TEMP%\content\4008-4228-<File name>.exe-18-51-22-280.dump
- %APPDATA%\isspecialname.exe
- %TEMP%\content\3912-3892-regasm.exe-18-51-28-271.dump
- %TEMP%\content\3912-3892-regasm.exe-18-51-28-417.dump
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\regasm.exe.log
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\regasm.exe'