Loads dropped or rewritten executable
- spoolsv.exe (PID: 1196)
- Setup.exe (PID: 3180)
- IKernel.exe (PID: 3260)
Application was dropped or rewritten from another process
- Setup.exe (PID: 3180)
- IKernel.exe (PID: 3868)
- IKernel.exe (PID: 3260)
- iKernel.exe (PID: 3700)
- iKernel.exe (PID: 3500)
|
Executable content was dropped or overwritten
- Setup.exe (PID: 3180)
- lj1488en.exe (PID: 3908)
- IKernel.exe (PID: 3260)
Creates files in the program directory
- Setup.exe (PID: 3180)
- IKernel.exe (PID: 3260)
Creates files in the Windows directory
Creates a software uninstall entry
Starts itself from another location
Searches for installed software
- IKernel.exe (PID: 3260)
- DllHost.exe (PID: 2460)
Removes files from Windows directory
Creates COM task schedule object
|
Low-level read access rights to disk partition
|