Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{8A19A704-B823-5AF6-17BC-12ED6CA3ADDF}] 'stubpath' = '<SYSTEM32>\vmtoolsd.exe'
- ClassName: 'FileMonClass', WindowName: ''
- ClassName: 'OLLYDBG', WindowName: ''
- %WINDIR%\syswow64\vmtoolsd.exe
- ClassName: '18467-41' WindowName: ''