Beyond good ol’ Run key, Part 74
March 26, 2018 in Anti-Forensics, Autostart (Persistence), Compromise Detection, Forensic Riddles, Incident Response
This is a very obscure persistence mechanism that affects VMWare Tools versions that utilize the vm3dum DLL (‘VMware SVGA 3D Usermode’): c:\Program Files\Common Files\VMware\Drivers\video_wddm\vm3dum.dll When loaded (which happens e.g. when […]