Technical Information
- <SYSTEM32>\colorcpl.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "%APPDATA%\eEkpoxtGLuQ.exe"' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /Create /TN "Updates\eEkpoxtGLuQ" /XML "%TEMP%\tmp52D0.tmp"' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "%APPDATA%\eEkpoxtGLuQ.exe"
- '<SYSTEM32>\schtasks.exe' /Create /TN "Updates\eEkpoxtGLuQ" /XML "%TEMP%\tmp52D0.tmp"
- '<SYSTEM32>\colorcpl.exe'