1

Is there a easy way to see which underlying malware provider is handling the requests for Antimalware Scan Interface? Win32 call or registry key?

Windows Server 2019

user2368632
  • 990
  • 1
  • 12
  • 33

1 Answers1

1

According to MSFT docs, appears there are two registry keys for finding this info:

HKLM\SOFTWARE\Microsoft\AMSI\Providers

HKLM\SOFTWARE\Classes\CLSID

user2368632
  • 990
  • 1
  • 12
  • 33