Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Kaseya Agent Service Helper' = '%ProgramFiles%\Kaseya\Agent\KaUsrTsk.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\KaseyaAgent] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\KaseyaAgent] 'ImagePath' = '%ProgramFiles%\Kaseya\Agent\AgentMon.exe'
- %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\data88e3.rra
- %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\data8885.rra
- %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\layo8847.rra
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.MAP
- %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\Setu8ba2.rra
- %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\Setu8ad7.rra
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.DATA
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.BTR
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\$WinMgmt.CFG
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING2.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING1.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING.VER
- %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\setu8c00.rra
- %ProgramFiles%\Kaseya\Agent\Kase9651.rra
- <SYSTEM32>\kase9508.rra
- %ProgramFiles%\Kaseya\Agent\Psap948b.rra
- <DRIVERS>\Kase9aa6.rra
- <DRIVERS>\KaPF99ea.rra
- %ProgramFiles%\Kaseya\Agent\Kase96ae.rra
- %ProgramFiles%\Kaseya\Agent\spor945d.rra
- %ALLUSERSPROFILE%\Start Menu\Programs\Kaseya\Uninstall Kaseya Agent.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\Kaseya\Kaseya Agent.lnk
- %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\Setup.ini
- %ProgramFiles%\Kaseya\Agent\Agen9363.rra
- %ProgramFiles%\Kaseya\Agent\KaUs9278.rra
- %ProgramFiles%\Kaseya\Agent\KPrt923a.rra
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\ctor19dd.rra
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\core1951.rra
- %TEMP%\1132.rra
- %CommonProgramFiles%\InstallShield\IScript\iscr2140.rra
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\iuse1e42.rra
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\obje1db6.rra
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\temp.000
- %TEMP%\KaseyaD.ini
- %TEMP%\KAgentSilent.exe
- %TEMP%\KASetup.log
- %TEMP%\IEC4.tmp
- %TEMP%\plf1.tmp
- %TEMP%\ext2.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SYSTEM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SOFTWARE
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SECURITY
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\domain.txt
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\ComDb.Dat
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SAM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_.DEFAULT
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
- %TEMP%\pft3~tmp\layout.bin
- %TEMP%\pft3~tmp\Setup.bmp
- %TEMP%\pft3~tmp\Setup.exe
- %TEMP%\pft3~tmp\data1.hdr
- %TEMP%\pft3~tmp\data2.cab
- %TEMP%\pft3~tmp\ikernel.ex_
- %TEMP%\pft3~tmp\setup.log
- %ProgramFiles%\Kaseya\Agent\KaseyaD.ini
- %TEMP%\KAgentSilent.exe
- %TEMP%\pft3~tmp\Setup.ini
- %TEMP%\pft3~tmp\setup.inx
- %TEMP%\pft3~tmp\setup.iss
- %TEMP%\{48c76121-4f90-11d5-9884-0050ba85a903}\_IsRes.dll
- %TEMP%\{48c76121-4f90-11d5-9884-0050ba85a903}\default.pal
- %TEMP%\{48c76121-4f90-11d5-9884-0050ba85a903}\isrt.dll
- %TEMP%\ext2.tmp
- %TEMP%\pft3~tmp\pftw1.pkg
- %TEMP%\IEC4.tmp
- %TEMP%\{48c76121-4f90-11d5-9884-0050ba85a903}\setup.inx
- %TEMP%\plf1.tmp
- %TEMP%\pft3~tmp\data1.cab
- %TEMP%\{48c76121-4f90-11d5-9884-0050ba85a903}\value.shl
- %TEMP%\{48c76121-4f90-11d5-9884-0050ba85a903}\Psapi.Dll
- %TEMP%\{48c76121-4f90-11d5-9884-0050ba85a903}\KSetup.dll
- from %ProgramFiles%\Kaseya\Agent\spor945d.rra to %ProgramFiles%\Kaseya\Agent\sporder.dll
- from %ProgramFiles%\Kaseya\Agent\Psap948b.rra to %ProgramFiles%\Kaseya\Agent\Psapi.Dll
- from %ProgramFiles%\Kaseya\Agent\Agen9363.rra to %ProgramFiles%\Kaseya\Agent\AgentMon.exe
- from %ProgramFiles%\Kaseya\Agent\KPrt923a.rra to %ProgramFiles%\Kaseya\Agent\KPrtPng.exe
- from %ProgramFiles%\Kaseya\Agent\KaUs9278.rra to %ProgramFiles%\Kaseya\Agent\KaUsrTsk.exe
- from <SYSTEM32>\kase9508.rra to <SYSTEM32>\kaseyasp.dll
- from <DRIVERS>\Kase9aa6.rra to <DRIVERS>\KaseyaHA.sys
- from %TEMP%\1132.rra to %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\setup.ilg
- from <DRIVERS>\KaPF99ea.rra to <DRIVERS>\KaPFA.sys
- from %ProgramFiles%\Kaseya\Agent\Kase9651.rra to %ProgramFiles%\Kaseya\Agent\KaseyaD.ini
- from %ProgramFiles%\Kaseya\Agent\Kase96ae.rra to %ProgramFiles%\Kaseya\Agent\KaseyaFW.ini
- from %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\setu8c00.rra to %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\setup.inx
- from %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\obje1db6.rra to %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\objectps.dll
- from %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\iuse1e42.rra to %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\iuser.dll
- from %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\ctor19dd.rra to %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\ctor.dll
- from %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\temp.000 to %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\IKernel.exe
- from %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\core1951.rra to %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\corecomp.ini
- from %CommonProgramFiles%\InstallShield\IScript\iscr2140.rra to %CommonProgramFiles%\InstallShield\IScript\iscript.dll
- from %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\Setu8ad7.rra to %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\Setup.exe
- from %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\Setu8ba2.rra to %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\Setup.ini
- from %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\data88e3.rra to %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\data1.cab
- from %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\layo8847.rra to %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\layout.bin
- from %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\data8885.rra to %ProgramFiles%\InstallShield Installation Information\{48C76121-4F90-11D5-9884-0050BA85A903}\data1.hdr
- %ProgramFiles%\Kaseya\Agent\KaseyaD.ini
- '%CommonProgramFiles%\InstallShield\Engine\6\Intel 32\IKernel.exe' /REGSERVER
- '%ProgramFiles%\Kaseya\Agent\KaUsrTsk.exe'
- '%ProgramFiles%\Kaseya\Agent\AgentMon.exe'
- '%CommonProgramFiles%\InstallShield\Engine\6\Intel 32\IKernel.exe' 32\IKernel.exe -Embedding
- '%TEMP%\KAgentSilent.exe' /a /PATH %TEMP%\KASetup.log
- '%TEMP%\pft3~tmp\Setup.exe' /PATH %TEMP%\KASetup.log /SMS /s
- '%CommonProgramFiles%\InstallShield\Engine\6\Intel 32\IKernel.exe' -RegServer