Technical Information
- [HKCU\Environment] 'UserInitMprLogonScript' = '%LOCALAPPDATA%\Microsoft\OneDrive\OneDriveSync.exe'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'MicrosoftEdgeUpdateSvc' = '%LOCALAPPDATA%\Microsoft\OneDrive\OneDriveSync.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\microsoftedgeupdate.lnk
- Windows Defender
- %LOCALAPPDATA%\microsoft\onedrive\onedrivesync.exe
- %LOCALAPPDATA%\microsoft\onedrive\desktop.ini:syncdata
- %LOCALAPPDATA%\microsoft\edge\edgeupdate\msedgesynchost.exe
- '13#.#2.180.28':80
- DNS ASK po####n.drpc.org
- DNS ASK po####n.lava.build
- DNS ASK po#####.#pc.subquery.network
- DNS ASK 1r#c.io
- '%LOCALAPPDATA%\microsoft\onedrive\onedrivesync.exe'
- '%LOCALAPPDATA%\microsoft\onedrive\onedrivesync.exe' ' (with hidden window)