Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%APPDATA%\WindowsUpdates\svchost_update.exe' -Force"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%APPDATA%\WindowsUpdates' -Force"
- ClassName: 'OLLYDBG', WindowName: ''
- %APPDATA%\windowsupdates\svchost_update.exe
- ClassName: 'WinDbgFrameClass' WindowName: ''
- ClassName: 'ID' WindowName: ''
- ClassName: 'Zeta Debugger' WindowName: ''
- ClassName: 'Rock Debugger' WindowName: ''
- ClassName: 'ObsidianGUI' WindowName: ''
- ClassName: 'x64dbg' WindowName: ''
- ClassName: 'x32dbg' WindowName: ''
- '%APPDATA%\windowsupdates\svchost_update.exe'