Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%ALLUSERSPROFILE%'
- ClassName: 'OLLYDBG', WindowName: 'OllYDbg'
- %ALLUSERSPROFILE%\datajs\tsmsoqo.exe
- %ALLUSERSPROFILE%\datajs\tsmsoqo.exe