Техническая информация
- <SYSTEM32>\tasks\microsoft\windows\runtimebroker-684f44a3
- <SYSTEM32>\dllhost.exe
- Процесс cwqwj.exe, модуль ntdll.dll
- %TEMP%\junk.tmp
- %LOCALAPPDATA%\microsoft\windows\runtimebroker-684f44a3.exe
- %LOCALAPPDATA%\microsoft\windows\runtimebroker-684f44a3.exe
- %TEMP%\junk.tmp
- %TEMP%\junk.tmp
- 'localhost':0
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -WindowStyle Hidden -Command "$ns='root\subscription';$f=Set-WmiInstance -Namespace $ns -Class __EventFilter -Arguments @{Name='RuntimeBroker-684f44a3F';QueryLanguage...
- '<SYSTEM32>\schtasks.exe' /Create /TN Microsoft\Windows\RuntimeBroker-684f44a3 /TR %LOCALAPPDATA%\Microsoft\Windows\RuntimeBroker-684f44a3.exe /SC ONLOGON /RU "" /RL HIGHEST /F
- '<SYSTEM32>\dllhost.exe'
- '%ProgramFiles%\windowsapps\microsoft.windowscalculator_10.1906.55.0_x64__8wekyb3d8bbwe\calculator.exe' -ServerName:App.AppXsm3pg4n7er43kdh1qp4e79f1j7am68r8.mca
- '<SYSTEM32>\svchost.exe' -k appmodel -p -s camsvc