Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ContainerHost' = '"%APPDATA%\Microsoft\Windows\Containers\ContainerHost.exe"'
- <Current directory>\~tmp69f3f7d4.exe
- %TEMP%\edgewebview2.exe
- %APPDATA%\microsoft\windows\containers\containerhost.exe
- %TEMP%\nsqbe3.tmp
- %TEMP%\nsbc23.tmp\system.dll
- %TEMP%\nsbc23.tmp\userinfo.dll
- %TEMP%\nsbc23.tmp\uac.dll
- %TEMP%\nsbc23.tmp\modern-wizard.bmp
- <Current directory>\~tmp69f3f7d4.exe
- %APPDATA%\microsoft\windows\containers\containerhost.exe
- ClassName: '#32770' WindowName: ''
- '%TEMP%\edgewebview2.exe'
- '<Current directory>\~tmp69f3f7d4.exe'
- '%APPDATA%\microsoft\windows\containers\containerhost.exe'
- '<SYSTEM32>\cmd.exe' /c start "" \\?\<Current directory>\~tmp69f3f7d4.exe
- '%TEMP%\edgewebview2.exe' ' (with hidden window)