Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'MicrosoftEdgeUpdate' = 'C:\msys64\m98Q\ZYpO\QwXci\svc_56AB\edge-date.exe'
- Процесс edge-date.exe, модуль ntdll.dll
- C:\msys64\m98q\zypo\qwxci\svc_56ab\edge-date.exe
- C:\msys64\m98q\zypo\qwxci\svc_56ab\applogrs.dll
- C:\msys64\m98q\zypo\qwxci\svc_56ab\applogrs_original.dll
- C:\msys64\m98q\zypo\qwxci\svc_56ab\edgestore.dll
- C:\msys64\m98q\zypo\qwxci\svc_56ab\edgestore.dat
- C:\msys64\m98q\zypo\qwxci\svc_56ab\webview2loader.dll
- C:\msys64\m98q\zypo\qwxci\svc_56ab\edgedat_svclnr.cfg
- %APPDATA%\microsoft\edgeupdate\edgestore.dll
- %APPDATA%\microsoft\edgeupdate\edgestore.dat
- C:\msys64\m98q\zypo\qwxci\svc_56ab\edgedat_svclnr.cfg
- '19#.#52.180.18':6613
- '19#.#52.180.18':6615
- 'C:\msys64\m98q\zypo\qwxci\svc_56ab\edge-date.exe'
- 'C:\msys64\m98q\zypo\qwxci\svc_56ab\edge-date.exe' (со скрытым окном)