Suspicious Scheduled Task Created for Persistence
New scheduled task created via schtasks.exe named "WindowsUpdateHelper" configured to run at system startup. The task executes PowerShell with an encoded command from a file in %AppData%\Local\Temp. This naming convention and execution pattern is consistent with persistence mechanisms used by multiple commodity malware families.
