Technical Information
- [HKCU\Environment] 'UserInitMprLogonScript' = '%LOCALAPPDATA%\Microsoft\OneDrive\OneDriveSync.exe'
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'MicrosoftEdgeUpdateSvc' = '%LOCALAPPDATA%\Microsoft\OneDrive\OneDriveSync.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\microsoftedgeupdate.lnk
- Windows Defender
- %LOCALAPPDATA%\microsoft\onedrive\onedrivesync.exe
- %LOCALAPPDATA%\microsoft\onedrive\desktop.ini:syncdata
- '13#.#2.180.28':80
- 'po#####.#pc.subquery.network':443
- 'x1.#.lencr.org':80
- 'po#######or-rpc.publicnode.com':443
- http://x1.#.lencr.org/
- 'po#####.#pc.subquery.network':443
- 'po#######or-rpc.publicnode.com':443
- DNS ASK po#####.#pc.subquery.network
- DNS ASK x1.#.lencr.org
- DNS ASK po#######or-rpc.publicnode.com
- '%LOCALAPPDATA%\microsoft\onedrive\onedrivesync.exe'
- '%LOCALAPPDATA%\microsoft\onedrive\onedrivesync.exe' ' (with hidden window)