Jump to content

Recommended Posts

Posted

Properties

 

Name MpKsl600f8005.sys

 

Location C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{09109067-7859-489F-B2B1-10FA2B44E05C}

 

Size 56.8 KB

 

Time 0.7 days ago (2018-09-15 17:01:41)

 

Entropy 6.7

 

Product Microsoft Malware Protection

 

Publisher Microsoft Corporation

 

Description KSLDriver

 

Version 1.2.1009.0

 

Copyright ? Microsoft Corporation. All rights reserved.

 

Service MpKsl600f8005

 

LanguageID 1033

 

SHA-256 F6DB64112CC50EEE495E2D7C61B8BDBE757A31B03144B0396615FD38C312824E

 

 

 

Scoring (47.0)

 

The file is hidden from Windows API. This is typical for malware.

 

The file is completely hidden from view and most antivirus products. It may belong to a rootkit.

 

Starts automatically as a service during system bootup.

 

Program starts automatically without user intervention.

 

Time indicates that the file appeared recently on this computer.

 

The file is a device driver. Device drivers run as trusted (highly privileged) code.

 

 

 

Startup

 

HKLM\SYSTEM\CurrentControlSet\Services\MpKsl600f8005\

 

 

 

More...

  • Replies 0
  • Created
  • Last Reply

Top Posters In This Topic

Popular Days

Top Posters In This Topic

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...