Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'NetHelper' = '<Полный путь к файлу>'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'SysHelper' = '<Полный путь к файлу>'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Runtime32' = '<Полный путь к файлу>'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'MsHelper' = '<Полный путь к файлу>'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'AgentHost' = '<Полный путь к файлу>'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'WinHelper' = '<Полный путь к файлу>'
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Load' = '<Полный путь к файлу>'
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Run' = '<Полный путь к файлу>'
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "<Полный путь к файлу>"'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,,"<Полный путь к файлу>"'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = '<Полный путь к файлу>'
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe] 'Debugger' = '<Полный путь к файлу>'
- [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{HostMonitorRuntimeCore-lvrium}] 'StubPath' = '<Полный путь к файлу>'
- [HKCU\Environment] 'UserInitMprLogonScript' = '<Полный путь к файлу>'
- [HKCU\Software\Microsoft\Command Processor] 'AutoRun' = '<Полный путь к файлу>'
- [HKLM\SOFTWARE\Microsoft\Command Processor] 'AutoRun' = '<Полный путь к файлу>'
- [HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\Helper32] 'Driver' = '<Полный путь к файлу>'
- [\REGISTRY\USER\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] 'NetMonitor' = '<Полный путь к файлу>'
- [\REGISTRY\USER\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'Runtime32' = '<Полный путь к файлу>'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WinMonitor' = '<Полный путь к файлу>'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'UpdateAgent' = '<Полный путь к файлу>'
- [\REGISTRY\USER\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'NetProc' = '<Полный путь к файлу>'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'NetProc' = '<Полный путь к файлу>'
- [\REGISTRY\USER\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Load' = '<Полный путь к файлу>'
- [\REGISTRY\USER\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Run' = '<Полный путь к файлу>'
- [\REGISTRY\USER\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, "<Полный путь к файлу>"'
- [HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{WinHelperCore32-lvrium}] 'StubPath' = '<Полный путь к файлу>'
- [\REGISTRY\USER\S-1-5-18\Software\Microsoft\Command Processor] 'AutoRun' = '<Полный путь к файлу>'
- [HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\CoreSvc] 'Driver' = '<Полный путь к файлу>'
- <SYSTEM32>\tasks\loaderhelper
- [HKLM\SYSTEM\CurrentControlSet\Services\CoreSvc] 'ImagePath' = '<Полный путь к файлу>'
- [HKLM\SYSTEM\CurrentControlSet\Services\CoreSvc] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\HelperTask] 'ImagePath' = '<Полный путь к файлу>'
- [HKLM\SYSTEM\CurrentControlSet\Services\HelperTask] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\HelperTask] 'ImagePath' = '"<Полный путь к файлу>"'
- [HKLM\SYSTEM\CurrentControlSet\Services\HostMgr] 'ImagePath' = '<Полный путь к файлу>'
- [HKLM\SYSTEM\CurrentControlSet\Services\HostMgr] 'Start' = '00000002'
- 'CoreSvc' <Полный путь к файлу>
- 'HelperTask' <Полный путь к файлу>
- Системный антивирус (Защитник Windows)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Set-MpPreference -DisableRealtimeMonitoring $true"
- Процесс kbahnua.exe, модуль Amsi.dll
- Процесс kbahnua.exe, модуль ntdll.dll
- %APPDATA%\31
- nul
- %APPDATA%\loader32.exe
- %HOMEPATH%\desktop\svc32.exe
- %HOMEPATH%\documents\helpermonitor.exe
- %HOMEPATH%\downloads\loaderhelper.exe
- %APPDATA%\hostmgr.exe
- %LOCALAPPDATA%\helpercore.exe
- %TEMP%\svchost.exe
- %TEMP%\mssvc.exe
- %TEMP%\hostmgr.exe
- %WINDIR%\temp\svcsvc.exe
- <SYSTEM32>\svcmonitor.exe
- %WINDIR%\syswow64\update64.exe
- %WINDIR%\updatehelper.exe
- %ALLUSERSPROFILE%\helperhost.exe
- C:\mstask.exe
- C:\users\public\updatemgr.exe
- C:\users\public\desktop\helper64.exe
- %ProgramFiles%\runtimemonitor.exe
- %ProgramFiles(x86)%\msproc.exe
- <SYSTEM32>\config\systemprofile\appdata\roaming\hostagent.exe
- <SYSTEM32>\config\systemprofile\appdata\local\coremonitor.exe
- %WINDIR%\serviceprofiles\localservice\desktop\helpermonitor.exe
- %WINDIR%\serviceprofiles\localservice\appdata\roaming\msmonitor.exe
- %WINDIR%\serviceprofiles\localservice\appdata\local\winhost.exe
- %WINDIR%\serviceprofiles\networkservice\desktop\svccore.exe
- %WINDIR%\serviceprofiles\networkservice\appdata\roaming\svcmonitor.exe
- %WINDIR%\serviceprofiles\networkservice\appdata\local\update32.exe
- %HOMEPATH%\desktop\hostsvc.exe
- %APPDATA%\svcmgr.exe
- %LOCALAPPDATA%\nethost.exe
- <SYSTEM32>\config\systemprofile\appdata\roaming\31
- %WINDIR%\temp\__psscriptpolicytest_2trle0eq.0b3.ps1
- %WINDIR%\temp\__psscriptpolicytest_30a0yrro.puv.psm1
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-04-935.dump
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-6a402f85-460.pma
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-05-223.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-05-357.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-05-878.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-05-920.dump
- %WINDIR%\temp\__psscriptpolicytest_jabi3ha0.5fh.ps1
- %WINDIR%\temp\__psscriptpolicytest_2dvlis3o.pxu.psm1
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-06-538.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-06-582.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-06-659.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-06-766.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-06-926.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-07-010.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-07-139.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-07-174.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-07-205.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-07-249.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-07-289.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-07-363.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-07-416.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-08-973.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-09-174.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-09-271.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-09-293.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-09-296.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-09-385.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-09-468.dump
- %WINDIR%\temp\content\5596-3172-powershell.exe-13-16-09-519.dump
- <SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\powershell\startupprofiledata-noninteractive
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-6a402f8a-1100.pma
- %LOCALAPPDATA%\microsoft\edge\user data\default\manifest-000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\000001.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\manifest-000002
- %LOCALAPPDATA%\microsoft\edge\user data\default\000002.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\gpucache\index
- %LOCALAPPDATA%\microsoft\edge\user data\default\gpucache\data_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\gpucache\data_2
- %LOCALAPPDATA%\microsoft\edge\user data\default\gpucache\data_3
- %LOCALAPPDATA%\microsoft\edge\user data\default\cookies-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\cookies
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\index
- %LOCALAPPDATA%\microsoft\edge\user data\default\session storage\manifest-000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\session storage\000001.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\session storage\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\session storage\000003.log
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\data_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\shared_proto_db\metadata\manifest-000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\shared_proto_db\metadata\000001.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\shared_proto_db\metadata\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\shared_proto_db\metadata\000003.log
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\data_2
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\data_3
- %LOCALAPPDATA%\microsoft\edge\user data\default\reporting and nel-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\reporting and nel
- <SYSTEM32>\config\systemprofile\appdata\roaming\syssvc.exe
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\38d86d9e034a6121_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\f4598f8fb4f83f4e_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000002
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000003
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\dca37be666d1de40_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\badfddb2a861554b_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\779c893959f0438e_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\cec3ad135d7fcafd_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000004
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000005
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000006
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\819b17ee0bbafcb3_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\videodecodestats\manifest-000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\videodecodestats\000001.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\videodecodestats\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\indexeddb\https_www.youtube.com_0.indexeddb.leveldb\manifest-000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\indexeddb\https_www.youtube.com_0.indexeddb.leveldb\000001.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\indexeddb\https_www.youtube.com_0.indexeddb.leveldb\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\indexeddb\https_www.youtube.com_0.indexeddb.leveldb\000003.log
- %LOCALAPPDATA%\microsoft\edge\user data\default\quotamanager-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\quotamanager
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000007
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000008
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000009
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\379ee581d1a0a82d_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\27beadee8c2e7e2d_0
- %WINDIR%\temp\__psscriptpolicytest_uskigm15.cbv.ps1
- %WINDIR%\temp\__psscriptpolicytest_gntxsxgm.0mq.psm1
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-29-838.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-30-143.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-30-290.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-30-557.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-30-627.dump
- %WINDIR%\temp\__psscriptpolicytest_oti2ccx4.qw0.ps1
- %WINDIR%\temp\__psscriptpolicytest_sf1ni5ml.pqr.psm1
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\2488d03e91746e97_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\7ef26bc23058c765_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\4292d495f85a26f7_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\d896239e1a3f4cb5_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\3935e32b81e06905_0
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-30-852.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-30-882.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-31-001.dump
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\index
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\index-dir\temp-index
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_00000a
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-31-149.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-31-297.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-31-413.dump
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\461332cdd388ee21_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\9b63a39d-0454-4680-a107-694fee224563\index
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\9b63a39d-0454-4680-a107-694fee224563\index-dir\temp-index
- %LOCALAPPDATA%\microsoft\edge\user data\default\databases\databases.db-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\databases\databases.db
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\335e69ddec2b9ac6_0
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-31-996.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-32-455.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-32-676.dump
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\c8e3d243213c2816_0
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-33-152.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-33-234.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-33-350.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-33-395.dump
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\scriptcache\index
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\database\manifest-000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\database\000001.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\scriptcache\index-dir\temp-index
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\database\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\database\000003.log
- %LOCALAPPDATA%\microsoft\edge\user data\default\extension state\manifest-000001
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-34-212.dump
- %LOCALAPPDATA%\microsoft\edge\user data\default\extension state\000001.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\extension state\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\scriptcache\2cc80dabc69f58b6_0
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-34-344.dump
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\scriptcache\4cb013792b196a35_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_00000b
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-34-449.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-34-489.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-34-493.dump
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\scriptcache\4cb013792b196a35_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\scriptcache\2cc80dabc69f58b6_1
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-34-658.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-34-702.dump
- %WINDIR%\temp\content\5164-1856-powershell.exe-13-16-34-821.dump
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_00000c
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_00000d
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_00000e
- %TEMP%\8021d87a-4337-4068-bd2e-12327f49ac10.tmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_00000f
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\fd4fd5017525dc9c_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000010
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\index
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\index-dir\temp-index
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\99ae2c8023f08b62_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\99ae2c8023f08b62_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\3579cda51c16e462_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\bf54ce61e659fd4d_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\8c968d0324c35513_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\bb0be3bef1a81004_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\bb0be3bef1a81004_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\51ca5b214a5ad622_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000011
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\51ca5b214a5ad622_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\061dfa48c5cf8533_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\061dfa48c5cf8533_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\94861ce1716a7324_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\94861ce1716a7324_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\62589e5a85b66878_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\62589e5a85b66878_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\39670dfe7b5165f0_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\32d080329e18ef6b_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\63a60c9b4b9770fb_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\63a60c9b4b9770fb_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\701cc4eee594e9f7_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\e4220b2977b9f8b0_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\e4220b2977b9f8b0_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\393a03308c5213f8_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\393a03308c5213f8_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\e8a102ded5102c52_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\e8a102ded5102c52_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\726eaed2b4d7e7f9_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\blob_storage\f6c21a97-436d-4caa-9ec3-581531f44683\0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\726eaed2b4d7e7f9_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\0a19cf580043d766_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\0a19cf580043d766_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\ac74bdd5262a1eb3_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\ac74bdd5262a1eb3_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\b3b8c078e814a76b_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\b3b8c078e814a76b_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\b2141b088ee5e98c_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\2e2413a06637b0ec_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\9fd5f62bf71b3d75_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\8527e1a8da3c2dc9_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\d27edc667f4632e2_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\55248bf5cdb1f722_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\98a16392447e67ac_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\d3d3117da1954c11_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\a8861e49fb8957aa_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\0b8c705721509f10_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\a14b1d1ba3ffefc8_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\9f4ad6f7051df145_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\16559ac9c884651f_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\10d52c8541d8e931_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\91bffe440af90184_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\e939b9c74705d0f2_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\40a9bd45a75375db_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\c9adc58020b2b3de_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\9527542be48ffabc_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\c09d11a05755e8de_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\f549ece535126cd0_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\bca21f99472447f3_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\0b3bd81b114681fa_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\d48cca5b61f158fe_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\383152c2a19b4e8f_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\a6f27ff03ba78ebe_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\551f311ce70a041a_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\b5f29d0312456036_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\ce5fdc792b67fd6e_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\88c1d03bb90903c8_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\be581dea90cddde7_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\e8f209bb953d0431_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\97de5abfe883dbcf_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\50ec495042a41f6d_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\63650b2efa24c917_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\4c9a3bb214971f6c_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\8ab4bfc157c68e03_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\06c49d2fa0ad4bcd_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\4bfb0fd95edd59d2_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\ee0df4a02bea74ec_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\b3f87b55d8dbfa47_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\3107558eea9ba321_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\c3d986f17b5dc565_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\366f560b67a386ee_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\dec87465aca36c9e_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\8383e54a78e96fc0_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\data_reduction_proxy_leveldb\manifest-000004
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\0e68ef3e3bc686b2_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\6b991611054a2e9f_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\data_reduction_proxy_leveldb\000004.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\166a5b768db2d6dc_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\shortcuts-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\e8c610db15382c0d_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\e00a14b7237f316a_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\f7d87e9c65f44131_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\network action predictor-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\ca5a67fda3466f4d_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\cd85acb1c0e5f8f6_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\ff7d190261fb21f8_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\3761f940ae901389_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\f6f13d7893cf7781_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\a6b7c04cc881aa8f_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\aa2af9656088cce5_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\986d0106ec1842ce_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\4eceab7d2e5e75bd_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\4816386a87d7566c_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\shortcuts
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\44fdad3a201128f8_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\21d60d8d92bf19bf_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\7e048a4ec5b9e1d4_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\3865648767564005_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\87b78db93ca06597_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\network action predictor
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\4c4800b635ae2098_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\38720ab1369ba567_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\e31f7a7e623b4b27_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\6635a01024910e7c_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\3dd738a47abc8dee_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\577dbf0b91a4fd20_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\7a80e0d12aa14c6c_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\375db0c2ac836167_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\cde968a267e2506f_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\92f3fbe0cc645cda_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\d57fe2c6b1537486_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\ac4be60b26fb5511_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\fdd89d27c13f85e5_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\0db7075bc130b313_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\1ada7ade10cca105_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\db529ccd665da8b5_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\0dbec196046ed063_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\fc496558f77f6d37_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\eaffc3a9ed933df4_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\afbf989a8c95bf2e_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\22063dd5403b833c_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\9e14eade795efe8c_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\54920af5f79603ff_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\ecf4f84b241d1325_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\dc1d8d198ab144a4_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\e0679885439abda2_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\fff368752d794b37_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\fad7b2239e784870_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\88a5e52ddb6d6d2c_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\feature engagement tracker\eventdb\manifest-000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\feature engagement tracker\eventdb\000001.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\feature engagement tracker\eventdb\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\feature engagement tracker\availabilitydb\manifest-000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\feature engagement tracker\availabilitydb\000001.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\feature engagement tracker\availabilitydb\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\autofillstrikedatabase\manifest-000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\autofillstrikedatabase\000001.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\autofillstrikedatabase\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\feature engagement tracker\availabilitydb\000003.log
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000012
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000013
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000014
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000015
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\5e92743cb6de0717_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\5e92743cb6de0717_1
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\0a41c5226f4ea45c_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\c77e17c8-545d-4f0f-84c0-78aca0f7a07a\index
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\c77e17c8-545d-4f0f-84c0-78aca0f7a07a\index-dir\temp-index
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\index-dir\temp-index
- %WINDIR%\temp\__psscriptpolicytest_2trle0eq.0b3.ps1
- %WINDIR%\temp\__psscriptpolicytest_30a0yrro.puv.psm1
- %WINDIR%\temp\__psscriptpolicytest_jabi3ha0.5fh.ps1
- %WINDIR%\temp\__psscriptpolicytest_2dvlis3o.pxu.psm1
- %LOCALAPPDATA%\microsoft\edge\user data\default\manifest-000001
- %WINDIR%\temp\__psscriptpolicytest_uskigm15.cbv.ps1
- %WINDIR%\temp\__psscriptpolicytest_gntxsxgm.0mq.psm1
- %WINDIR%\temp\__psscriptpolicytest_oti2ccx4.qw0.ps1
- %WINDIR%\temp\__psscriptpolicytest_sf1ni5ml.pqr.psm1
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-6a402f85-460.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-6a402f8a-1100.pma
- %LOCALAPPDATA%\microsoft\edge\user data\default\blob_storage\f6c21a97-436d-4caa-9ec3-581531f44683\0
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\9b63a39d-0454-4680-a107-694fee224563\index
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\9b63a39d-0454-4680-a107-694fee224563\index-dir\the-real-index
- %LOCALAPPDATA%\microsoft\edge\user data\default\000001.dbtmp в %LOCALAPPDATA%\microsoft\edge\user data\default\current
- %LOCALAPPDATA%\microsoft\edge\user data\default\session storage\000001.dbtmp в %LOCALAPPDATA%\microsoft\edge\user data\default\session storage\current
- %LOCALAPPDATA%\microsoft\edge\user data\default\shared_proto_db\metadata\000001.dbtmp в %LOCALAPPDATA%\microsoft\edge\user data\default\shared_proto_db\metadata\current
- %LOCALAPPDATA%\microsoft\edge\user data\default\videodecodestats\000001.dbtmp в %LOCALAPPDATA%\microsoft\edge\user data\default\videodecodestats\current
- %LOCALAPPDATA%\microsoft\edge\user data\default\indexeddb\https_www.youtube.com_0.indexeddb.leveldb\000001.dbtmp в %LOCALAPPDATA%\microsoft\edge\user data\default\indexeddb\https_www.youtube.com_0.indexeddb.leveldb\current
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\index-dir\temp-index в %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\index-dir\the-real-index
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\9b63a39d-0454-4680-a107-694fee224563\index-dir\temp-index в %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\9b63a39d-0454-4680-a107-694fee224563\index-dir\the-real-index
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\scriptcache\index-dir\temp-index в %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\scriptcache\index-dir\the-real-index
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\database\000001.dbtmp в %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\database\current
- %LOCALAPPDATA%\microsoft\edge\user data\default\extension state\000001.dbtmp в %LOCALAPPDATA%\microsoft\edge\user data\default\extension state\current
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\index-dir\temp-index в %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\index-dir\the-real-index
- %LOCALAPPDATA%\microsoft\edge\user data\default\feature engagement tracker\eventdb\000001.dbtmp в %LOCALAPPDATA%\microsoft\edge\user data\default\feature engagement tracker\eventdb\current
- %LOCALAPPDATA%\microsoft\edge\user data\default\feature engagement tracker\availabilitydb\000001.dbtmp в %LOCALAPPDATA%\microsoft\edge\user data\default\feature engagement tracker\availabilitydb\current
- %LOCALAPPDATA%\microsoft\edge\user data\default\autofillstrikedatabase\000001.dbtmp в %LOCALAPPDATA%\microsoft\edge\user data\default\autofillstrikedatabase\current
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\c77e17c8-545d-4f0f-84c0-78aca0f7a07a\index-dir\temp-index в %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\c77e17c8-545d-4f0f-84c0-78aca0f7a07a\index-dir\the-real-index
- %LOCALAPPDATA%\microsoft\edge\user data\last version
- %LOCALAPPDATA%\microsoft\edge\user data\default\sync data\leveldb\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\sync data\leveldb\000003.log
- %LOCALAPPDATA%\microsoft\edge\user data\default\site characteristics database\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %LOCALAPPDATA%\microsoft\edge\user data\default\visited links
- %LOCALAPPDATA%\microsoft\edge\user data\default\history-journal
- %LOCALAPPDATA%\microsoft\tokenbroker\cache\9cd93bc6dcf544bae69531052e64647ec02f2bb4.tbres
- %LOCALAPPDATA%\microsoft\edge\user data\default\local storage\leveldb\000003.log
- %LOCALAPPDATA%\microsoft\edge\user data\default\favicons-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\history
- %LOCALAPPDATA%\microsoft\edge\user data\default\favicons
- %LOCALAPPDATA%\microsoft\edge\user data\last browser
- %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Local Storage\leveldb\LOG
- %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Platform Notifications\LOG
- %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\data_reduction_proxy_leveldb\LOG
- %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\BudgetDatabase\LOG
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\scriptcache\index-dir\temp-index
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\65a22b2e-f8ca-4a09-95f5-60d24ccac5da\index-dir\temp-index
- %LOCALAPPDATA%\microsoft\edge\user data\default\service worker\cachestorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\f5c58710-4bd8-4705-96e8-f6755c9bc062\index-dir\temp-index
- 'ap#.#pify.org':443
- 'ca####.discord.com':443
- 'co####.edge.skype.com':443
- 'yo##ube.com':443
- 'i.##img.com':443
- 'rr##########onuxaxjvh-n8v6.googlevideo.com':443
- 'fo###.#oogleapis.com':443
- 'fo###.gstatic.com':443
- 'accounts.google.com':443
- 'go######s.g.doubleclick.net':443
- 'rr########hnekn7l.googlevideo.com':443
- 'st####.doubleclick.net':443
- 'yt#.#gpht.com':443
- 'rr########g5edn6y.googlevideo.com':443
- 'go##le.ru':443
- 'rr########4fl6nzy.googlevideo.com':443
- 'ap#.#pify.org':443
- 'ca####.discord.com':443
- 'co####.edge.skype.com':443
- 'yo##ube.com':443
- 'i.##img.com':443
- 'rr##########onuxaxjvh-n8v6.googlevideo.com':443
- 'rr########j5go5-5i.c.youtube.com':443
- 'fo###.#oogleapis.com':443
- 'fo###.gstatic.com':443
- 'accounts.google.com':443
- 'google.com':443
- 'go######s.g.doubleclick.net':443
- 'gs##tic.com':443
- 'rr########hnekn7l.googlevideo.com':443
- 'st####.doubleclick.net':443
- 'rr########g5edn6y.googlevideo.com':443
- 'go##le.ru':443
- 'rr########4fl6nzy.googlevideo.com':443
- DNS ASK ap#.#pify.org
- DNS ASK ca####.discord.com
- DNS ASK co####.edge.skype.com
- DNS ASK yo##ube.com
- DNS ASK i.##img.com
- DNS ASK rr##########onuxaxjvh-n8v6.googlevideo.com
- DNS ASK rr########j5go5-5i.c.youtube.com
- DNS ASK fo###.#oogleapis.com
- DNS ASK fo###.gstatic.com
- DNS ASK accounts.google.com
- DNS ASK google.com
- DNS ASK go######s.g.doubleclick.net
- DNS ASK gs##tic.com
- DNS ASK rr########hnekn7l.googlevideo.com
- DNS ASK st####.doubleclick.net
- DNS ASK yt#.#gpht.com
- DNS ASK rr########g5edn6y.googlevideo.com
- DNS ASK go##le.ru
- DNS ASK rr########4fl6nzy.googlevideo.com
- ClassName: 'Chrome_MessageWindow' WindowName: '%LOCALAPPDATA%\Microsoft\Edge\User Data'
- '<SYSTEM32>\cmd.exe' /c powershell -Command "Set-MpPreference -DisableRealtimeMonitoring $true" 2>nul (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c sc config WinDefend start=disabled 2>nul (со скрытым окном)
- '<SYSTEM32>\sc.exe' config WinDefend start=disabled
- '<SYSTEM32>\cmd.exe' /c sc stop WinDefend 2>nul (со скрытым окном)
- '<SYSTEM32>\sc.exe' stop WinDefend
- '<SYSTEM32>\cmd.exe' /c vssadmin delete shadows /all /quiet 2>nul (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f 2>nul & reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection... (со скрытым окном)
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableBehaviorMonitoring /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableOnAccessProtection /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableScanOnRealtimeEnable /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\SpyNet" /v DisableBlockAtFirstSeen /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\SpyNet" /v SpynetReporting /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\SpyNet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f
- '<SYSTEM32>\cmd.exe' /c schtasks /Create /F /SC ONLOGON /TN "LoaderHelper" /TR "\"%APPDATA%\Loader32.exe\"" /RL HIGHEST (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /Create /F /SC ONLOGON /TN "LoaderHelper" /TR "\"%APPDATA%\Loader32.exe\"" /RL HIGHEST
- '<SYSTEM32>\cmd.exe' /c sc create "HelperTask" binPath= "\"<Полный путь к файлу>\"" start= auto type= own DisplayName= "HelperTask" 2>nul (со скрытым окном)
- '<SYSTEM32>\sc.exe' create "HelperTask" binPath= "\"<Полный путь к файлу>\"" start= auto type= own DisplayName= "HelperTask"
- '<SYSTEM32>\cmd.exe' /c sc start "HelperTask" 2>nul (со скрытым окном)
- '<SYSTEM32>\sc.exe' start "HelperTask"
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --single-argument https://www.youtube.com/watch?v=H_WN-xTp7oU
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --flag-switches-begin --flag-switches-end --do-not-de-elevate https://www.youtube.com/watch?v=H_WN-xTp7oU (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c schtasks /Create /F /SC ONLOGON /TN "SysSvc" /TR "\"<SYSTEM32>\config\systemprofile\AppData\Roaming\SysSvc.exe\"" /RL HIGHEST (со скрытым окном)
- '<SYSTEM32>\schtasks.exe' /Create /F /SC ONLOGON /TN "SysSvc" /TR "\"<SYSTEM32>\config\systemprofile\AppData\Roaming\SysSvc.exe\"" /RL HIGHEST
- '%ProgramFiles(x86)%\microsoft\edge\application\89.0.774.68\identity_helper.exe' --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --field-trial-handle=1852,6579717303268112331,1536890469761605964,131072 --lang=en-US --service-sandbox-type=none --mojo-p...