I verified in v2004, edgegdi.dll is not being loaded from Temp dir. No scheduled task, but there is a COM interface to trigger the update. Powershell has Update-MpSignature
-
This Tweet is unavailable.
-
-
Replying to @HackSysTeam
did you take a look for other dlls loaded from there then?
1 reply 0 retweets 0 likes -
Replying to @jonasLyk
At least in v2004 I didn't see any such DLLs loading from GUID-Sigs folder. Which version you are using?
1 reply 0 retweets 1 like -
Replying to @HackSysTeam @jonasLyk
It's an immature optimization after 20221 that cause the loading. I don't know the exact build of the change, but 20270 already have the change.
1 reply 0 retweets 3 likes
Replying to @_f0rgetting_ @HackSysTeam
looks like disaster avoided. used as web infector,email attachment and eop you welcome ms
8:21 PM - 6 Dec 2020
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.