Technical Information
- [HKLM\System\CurrentControlSet\Services\ialdnwxf] 'ImagePath' = '%WINDIR%\SysWOW64\superec.ProcessMemory.sys'
- 'ialdnwxf' %WINDIR%\SysWOW64\\superec.ProcessMemory.sys
- 'ialdnwxf' %WINDIR%\SysWOW64\superec.ProcessMemory.sys
- '' %WINDIR%\SysWOW64\\superec.ProcessMemory.sys
- %WINDIR%\syswow64\superec.processmemory.sys
- %WINDIR%\temp\udd5e84.tmp
- %WINDIR%\temp\udd5e84.tmp