Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'MicrosoftEdgeUpdate' = '"%APPDATA%\MicrosoftEdgeUpdate.exe"'
- <SYSTEM32>\tasks\microsoftedgeupdate
- Процесс nzanejb.exe, модуль Amsi.dll
- Процесс nzanejb.exe, модуль ntdll.dll
- %APPDATA%\microsoftedgeupdate.exe
- %TEMP%\tmp7b56.tmp
- %TEMP%\tmp7ba5.tmp
- %APPDATA%\microsoft\crypto\keys\7223cd8e71781568690bfb21c483d774_8cf7b530-613e-439b-a8c5-ccfc0e745400
- %TEMP%\tmp7b56.tmp
- %TEMP%\tmp7ba5.tmp
- '15.##4.93.120':56001
- '15.##4.93.120':56001
- '<SYSTEM32>\schtasks.exe' /Create /TN "MicrosoftEdgeUpdate" /TR "\"%APPDATA%\MicrosoftEdgeUpdate.exe\"" /SC ONLOGON /RL HIGHEST /F