Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%APPDATA%\SearchIndexer\desktopsearchservice.exe' = '%APPDATA%\SearchIndexer\desktopsearchservice.exe:*:Enabled:DesktopSearchService'
- '%APPDATA%\SearchIndexer\desktopsearchservice.exe' /inno
- '%TEMP%\is-BAET4.tmp\ModuleInno.tmp' /SL5="$40092,5068578,118784,%APPDATA%\SearchIndexer\ModuleInno.exe" /VERYSILENT
- '%APPDATA%\SearchIndexer\ModuleInno.exe' /VERYSILENT
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
- ClassName: 'RegMonClass' WindowName: ''
- ClassName: 'FileMonClass' WindowName: ''
- %APPDATA%\SearchIndexer\is-H1UEE.tmp
- %TEMP%\is-8H06G.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-BAET4.tmp\ModuleInno.tmp
- %APPDATA%\SearchIndexer\is-1OFMA.tmp
- %ALLUSERSPROFILE%\Application Data\Licenses\0A0995EA86D1FCCEB.Lic
- %ALLUSERSPROFILE%\Application Data\TEMP:44504F07
- %ALLUSERSPROFILE%\Application Data\TEMP\RAIDTest
- %TEMP%\nsc3.tmp\SimpleFC.dll
- %APPDATA%\SearchIndexer\ModuleInno.exe
- %TEMP%\nsc3.tmp\Processes.dll
- %TEMP%\nsc2.tmp
- %APPDATA%\SearchIndexer\cudart32_60.dll
- %TEMP%\nsc3.tmp\System.dll
- %APPDATA%\SearchIndexer\pthreadVC2.dll
- %APPDATA%\SearchIndexer\desktopsearchservice.exe
- %TEMP%\is-8H06G.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-BAET4.tmp\ModuleInno.tmp
- %TEMP%\nsc3.tmp\System.dll
- %TEMP%\nsc3.tmp\Processes.dll
- %TEMP%\nsc3.tmp\SimpleFC.dll
- %APPDATA%\SearchIndexer\is-1OFMA.tmp в %APPDATA%\SearchIndexer\SearchIndexer2.exe
- %APPDATA%\SearchIndexer\is-H1UEE.tmp в %APPDATA%\SearchIndexer\SearchIndexer1.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''