Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'MicrosoftEdgeUpdate' = '%APPDATA%\Microsoft\Windows\MicrosoftEdgeUpdate.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\microsoftedgeupdate.exe
- %APPDATA%\microsoft\windows\microsoftedgeupdate.exe
- %APPDATA%\microsoft\windows\windowssecurityhealth.exe
- %APPDATA%\microsoft\95771266\update.exe
- %ALLUSERSPROFILE%\microsoft\windows\drvupdate.exe
- %TEMP%\95771266\update.exe
- %TEMP%\edgeupdate.exe
- 'ob##########dream-amazingly.ngrok-free.dev':443
- 'ob##########dream-amazingly.ngrok-free.dev':443
- DNS ASK ob##########dream-amazingly.ngrok-free.dev
- '<SYSTEM32>\cmd.exe' /c "schtasks /create /tn \"MicrosoftEdgeUpdateTask\" /tr \"\\\"<Полный путь к файлу>\\\"\" /sc onlogon /rl highest /f"
- '<SYSTEM32>\cmd.exe' /c "/c ping -n 4 127.0.0.1 >nul 2>&1 & del /f /q \"<Полный путь к файлу>\" >nul 2>&1"
- '<SYSTEM32>\schtasks.exe' /create /tn \"MicrosoftEdgeUpdateTask\" /tr \"\\\"<Полный путь к файлу>\\\"\" /sc onlogon /rl highest /f