Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'KASHPRMSLN12166392587256' = '"%PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\KaUsrTsk.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\KAPRMSLN12166392587256] 'Start' = '00000002'
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\AgentMon.exe
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\KaUsrTsk.exe
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\drivers\KaseyaD.VXD
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\sporder.dll
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\drivers\KAPFA.sys
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\drivers\KaseyaSP.dll
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\drivers\KAPFA64.sys
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\LogParser.dll
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\kGetELMg64.exe
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\KaUsrTsk.exe
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\KPrtPng.exe
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\KEventLog.dll
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\KAgentExt.dll
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\KaseyaD.ini
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\custom\offline.ico
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\custom\blink.ico
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\custom\online.ico
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\KasError.log
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\AgentMon.log
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\custom\noremote.ico
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\Package.xml
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\KaseyaFW.ini
- <DRIVERS>\KAPFA.sys
- %ALLUSERSPROFILE%\Start Menu\Programs\Kaseya\Kaseya Agent.lnk
- <SYSTEM32>\KaseyaSP.dll
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\AgentMon.exe
- %TEMP%\pft3.tmp\KAgentExt.dll
- %TEMP%\pft3.tmp\AgentMon.exe
- %TEMP%\pft3.tmp\KaPFA.sys
- %TEMP%\pft3.tmp\KASetup.exe
- %TEMP%\pft3.tmp\kapfa64.sys
- %TEMP%\pft3.tmp\pftw1.pkg
- %TEMP%\KAgentSilent.exe
- %TEMP%\KASetup.log
- %TEMP%\KaseyaD.ini
- %TEMP%\plf1.tmp
- %TEMP%\ext2.tmp
- %TEMP%\pft3.tmp\KaseyaD.ini
- %TEMP%\pft3.tmp\LogParser.dll
- %TEMP%\pft3.tmp\KPrtPng.exe
- %TEMP%\pft3.tmp\Psapi.Dll
- %PROGRAM_FILES%\Kaseya\PRMSLN12166392587256\KASetup.exe
- %TEMP%\pft3.tmp\sporder.dll
- %TEMP%\pft3.tmp\kGetELMg64.exe
- %TEMP%\pft3.tmp\KaseyaFW.ini
- %TEMP%\pft3.tmp\KaseyaD.VXD
- %TEMP%\pft3.tmp\KaseyaSP.dll
- %TEMP%\pft3.tmp\KEventLog.dll
- %TEMP%\pft3.tmp\KaUsrTsk.exe
- %TEMP%\pft3.tmp\kGetELMg64.exe
- %TEMP%\pft3.tmp\KPrtPng.exe
- %TEMP%\pft3.tmp\KEventLog.dll
- %TEMP%\pft3.tmp\KaseyaSP.dll
- %TEMP%\pft3.tmp\KaUsrTsk.exe
- %TEMP%\KaseyaD.ini
- %TEMP%\KAgentSilent.exe
- %TEMP%\pft3.tmp\sporder.dll
- %TEMP%\pft3.tmp\LogParser.dll
- %TEMP%\pft3.tmp\Psapi.Dll
- %TEMP%\pft3.tmp\KaseyaFW.ini
- %TEMP%\pft3.tmp\AgentMon.exe
- %TEMP%\pft3.tmp\KAgentExt.dll
- %TEMP%\plf1.tmp
- %TEMP%\ext2.tmp
- %TEMP%\pft3.tmp\pftw1.pkg
- %TEMP%\pft3.tmp\KaseyaD.ini
- %TEMP%\pft3.tmp\KaseyaD.VXD
- %TEMP%\pft3.tmp\KASetup.exe
- %TEMP%\pft3.tmp\KaPFA.sys
- %TEMP%\pft3.tmp\kapfa64.sys
- 'ka####.parmac.com':5721
- DNS ASK ka####.parmac.com
- ClassName: 'Shell_TrayWnd' WindowName: ''