Техническая информация
- [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'MRHealth' = '"<SYSTEM32>\dllhostmhealth.exe" health'
- <SYSTEM32>\tasks\microsoft\windows\windows
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath %WINDIR%
- %TEMP%\wusdata\windllhost.exe
- <SYSTEM32>\dllhostmhealth.exe
- nul
- %WINDIR%\windllhost.exe
- %WINDIR%\runtime broker.exe
- %WINDIR%\winring0x64.sys
- %WINDIR%\taskmgrh.dll
- %WINDIR%\tickerserv.exe
- '%TEMP%\wusdata\windllhost.exe' first