Technical Information
- <SYSTEM32>\tasks\windows defender center
- %TEMP%\66b10d58-b73b-4be1-9ddb-50e7c6d30c2a\agiledotnetrt64.dll
- <SYSTEM32>\windefender\defend.exe
- '<LOCALNET>.178.30':4782
- '<SYSTEM32>\windefender\defend.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "Windows Defender Center" /sc ONLOGON /tr "<Full path to file>" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "Windows Defender Center" /sc ONLOGON /tr "<SYSTEM32>\WinDefender\defend.exe" /rl HIGHEST /f