Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\SA3285] 'ImagePath' = '%TEMP%\N7yXURL.sys'
- NtProtectVirtualMemory, handler: unknown
- NtCreateThread, handler: unknown
- <APATH_LOADLIB.EXE>
- %TEMP%\N7yXURL.sys
- %TEMP%\N7yXURL.sys
- %TEMP%\N7yXURL.sys