Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'CloudSync' = '"%APPDATA%\Microsoft\Windows\CloudStore\CloudSync.exe"'
- <Current directory>\~tmp69f3d060.exe
- %TEMP%\microsoftedgeupdate.exe
- %APPDATA%\microsoft\windows\cloudstore\cloudsync.exe
- %TEMP%\nsh1c00.tmp
- %TEMP%\nsn1c6f.tmp\system.dll
- %TEMP%\nsn1c6f.tmp\userinfo.dll
- %TEMP%\nsn1c6f.tmp\uac.dll
- %TEMP%\nsn1c6f.tmp\modern-wizard.bmp
- <Current directory>\~tmp69f3d060.exe
- %APPDATA%\microsoft\windows\cloudstore\cloudsync.exe
- ClassName: '#32770' WindowName: ''
- '%TEMP%\microsoftedgeupdate.exe'
- '<Current directory>\~tmp69f3d060.exe'
- '%APPDATA%\microsoft\windows\cloudstore\cloudsync.exe'
- '<SYSTEM32>\cmd.exe' /c start "" \\?\<Current directory>\~tmp69f3d060.exe
- '%TEMP%\microsoftedgeupdate.exe' ' (with hidden window)