Technical Information
- <SYSTEM32>\tasks\windowsdebughelper
- regsvr32.exe process, SHELL32.dll module
- regsvr32.exe process, USER32.dll module
- '10#.#12.97.29':23456
- '%WINDIR%\syswow64\schtasks.exe' /Query /TN "WindowsDebugHelper"
- '%WINDIR%\syswow64\schtasks.exe' /Create /F /TN "WindowsDebugHelper" /TR "\"%WINDIR%\SysWOW64\regsvr32.exe\"" /SC ONLOGON /DELAY 0000:30 /RL HIGHEST
- '%WINDIR%\syswow64\schtasks.exe' /Query /TN "WindowsDebugHelper"' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /Create /F /TN "WindowsDebugHelper" /TR "\"%WINDIR%\SysWOW64\regsvr32.exe\"" /SC ONLOGON /DELAY 0000:30 /RL HIGHEST' (with hidden window)