Technical Information
- [HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%\Microsoft\CoreRuntime' = '00000000'
- ~7bb3.tmp process, Amsi.dll module
- searchprotocolhost.exe process, Amsi.dll module
- searchfilterhost.exe process, Amsi.dll module
- taskhostw.exe process, Amsi.dll module
- sihost.exe process, Amsi.dll module
- ~7bb3.tmp process, ntdll.dll module
- searchprotocolhost.exe process, ntdll.dll module
- searchfilterhost.exe process, ntdll.dll module
- taskhostw.exe process, ntdll.dll module
- sihost.exe process, ntdll.dll module
- %TEMP%\~7bb3.tmp
- %LOCALAPPDATA%\microsoft\coreruntime\searchprotocolhost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\searchfilterhost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\taskhostw.exe
- %LOCALAPPDATA%\microsoft\coreruntime\sihost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\searchprotocolhost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\searchfilterhost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\taskhostw.exe
- %LOCALAPPDATA%\microsoft\coreruntime\sihost.exe
- DNS ASK de####sync.ipv64.de
- DNS ASK mo#####.map.fastly.net
- '%TEMP%\~7bb3.tmp'
- '%LOCALAPPDATA%\microsoft\coreruntime\searchprotocolhost.exe'
- '%LOCALAPPDATA%\microsoft\coreruntime\searchfilterhost.exe'
- '%LOCALAPPDATA%\microsoft\coreruntime\taskhostw.exe'
- '%LOCALAPPDATA%\microsoft\coreruntime\sihost.exe'
- '%TEMP%\~7bb3.tmp' ' (with hidden window)