Техническая информация
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'egui' = '"%ProgramFiles%\ESET\ESET Security\ecmds.exe" /launch /hide'
- [<HKLM>\System\CurrentControlSet\Services\ekrn] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\ekrn] 'ImagePath' = '"%ProgramFiles%\ESET\ESET Security\ekrn.exe"'
- [<HKLM>\System\CurrentControlSet\Services\ehdrv] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\ehdrv] 'ImagePath' = 'system32\DRIVERS\ehdrv.sys'
- [<HKLM>\System\CurrentControlSet\Services\eamonm] 'ImagePath' = 'system32\DRIVERS\eamonm.sys'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\eamonm] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\epfwwfp] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\epfwwfp] 'ImagePath' = 'system32\DRIVERS\epfwwfp.sys'
- [<HKLM>\System\CurrentControlSet\Services\ekrnEpfw] 'ImagePath' = '"%ProgramFiles%\ESET\ESET Security\ekrn.exe"'
- 'ekrn' "%ProgramFiles%\ESET\ESET Security\ekrn.exe"
- 'ekrn' %ProgramFiles%\ESET\ESET Security\ekrn.exe
- 'ehdrv' system32\DRIVERS\ehdrv.sys
- 'eamonm' system32\DRIVERS\eamonm.sys
- 'epfwwfp' system32\DRIVERS\epfwwfp.sys
- 'ekrnEpfw' "%ProgramFiles%\ESET\ESET Security\ekrn.exe"
- '<SYSTEM32>\taskkill.exe' /F /T /IM ehttpsrv.exe
- [<HKLM>\System\CurrentControlSet\Services\eamonm] 'Group' = 'FSFilter Anti-Virus'
- %TEMP%\rarsfx0\ehs_nt64.msi
- %ProgramFiles%\eset\eset security\help\idh_config_update_mode.htm
- %ProgramFiles%\eset\eset security\help\idh_config_update_connection.htm
- %ProgramFiles%\eset\eset security\help\idh_config_update_advanced.htm
- %ProgramFiles%\eset\eset security\help\icon_section.png
- %ProgramFiles%\eset\eset security\help\icon_details_hover.png
- %ProgramFiles%\eset\eset security\help\hmkwindex.htm
- %ProgramFiles%\eset\eset security\help\hmftsearch.htm
- %ProgramFiles%\eset\eset security\help\hmcontextids.js
- %ProgramFiles%\eset\eset security\help\idh_page_update.htm
- %ProgramFiles%\eset\eset security\help\idh_config_update_source.htm
- %ProgramFiles%\eset\eset security\help\helpman_topicinit.js
- %ProgramFiles%\eset\eset security\help\helpman_settings.js
- %ProgramFiles%\eset\eset security\help\helpman_navigation.js
- %ProgramFiles%\eset\eset security\help\default.css
- %ProgramFiles%\eset\eset security\help\copyright.png
- %ProgramFiles%\eset\eset security\help\cicon_loadindex_ani.gif
- %ProgramFiles%\eset\eset security\help\ciconidx.gif
- %ProgramFiles%\eset\eset security\help\cicon9.png
- %ProgramFiles%\eset\eset security\help\hmcontent.htm
- %ProgramFiles%\eset\eset security\eplgoutlooksmonlang.dll
- %ProgramFiles%\eset\eset security\help\idh_wizard_activation_type.htm
- %ProgramFiles%\eset\eset security\help\zoom_pageinfo.js
- %ProgramFiles%\eset\eset security\help\zoom_index.js
- %ProgramFiles%\eset\eset security\help\work_update_tasks.htm
- %ProgramFiles%\eset\eset security\help\work_update_setup_profiles.htm
- %ProgramFiles%\eset\eset security\help\update_advanced.htm
- %ProgramFiles%\eset\eset security\help\sitemap.xml
- %ProgramFiles%\eset\eset security\help\settings.js
- %ProgramFiles%\eset\eset security\help\r_copyright.png
- %ProgramFiles%\eset\eset security\help\plus_small.png
- %ProgramFiles%\eset\eset security\help\ping2.png
- %ProgramFiles%\eset\eset security\help\ping1.png
- %ProgramFiles%\eset\eset security\help\opening_title.htm
- %ProgramFiles%\eset\eset security\help\offline_help_connectivity_problems.htm
- %ProgramFiles%\eset\eset security\help\no_internet_connection_malware.htm
- %ProgramFiles%\eset\eset security\help\no_internet_connection.htm
- %ProgramFiles%\eset\eset security\help\monitor_orange.png
- %ProgramFiles%\eset\eset security\help\minus_small.png
- %ProgramFiles%\eset\eset security\help\jquery.js
- %ProgramFiles%\eset\eset security\help\infected_computer_by_malware.htm
- %ProgramFiles%\eset\eset security\help\cicon2.png
- %ProgramFiles%\eset\eset security\help\highlight.js
- %ProgramFiles%\eset\eset security\help\cicon1.png
- %ProgramFiles%\eset\eset security\help\blank.png
- %ProgramFiles%\eset\eset security\eula.rtf
- %ProgramFiles%\eset\eset security\ekrnmailpluginslang.dll
- %ProgramFiles%\eset\eset security\eplgoelang.dll
- %ProgramFiles%\eset\eset security\ekrnwebcontrollang.dll
- %ProgramFiles%\eset\eset security\ekrnupdatelang.dll
- %ProgramFiles%\eset\eset security\ekrnsmonlang.dll
- %ProgramFiles%\eset\eset security\ekrnscriptmonlang.dll
- %ProgramFiles%\eset\eset security\ekrnscanlang.dll
- %ProgramFiles%\eset\eset security\ekrnparentallang.dll
- %ProgramFiles%\eset\eset security\ekrnopplang.dll
- %ProgramFiles%\eset\eset security\ekrnlicensinglang.dll
- %ProgramFiles%\eset\eset security\eplgoutlookemonlang.dll
- %ProgramFiles%\eset\eset security\ekrnlang.dll
- %ProgramFiles%\eset\eset security\ekrnhipslang.dll
- %ProgramFiles%\eset\eset security\ekrnepfwlang.dll
- %ProgramFiles%\eset\eset security\ekrnemonlang.dll
- %ProgramFiles%\eset\eset security\ekrndmonlang.dll
- %ProgramFiles%\eset\eset security\ekrndevmonlang.dll
- %ProgramFiles%\eset\eset security\ekrnantitheftlang.dll
- %ProgramFiles%\eset\eset security\ekrnamonlang.dll
- %ProgramFiles%\eset\eset security\help\zoom_search.js
- %ProgramFiles%\eset\eset security\help\index.html
- %ProgramFiles%\eset\eset security\eplgoutlooklang.dll
- %ProgramFiles%\eset\eset security\help\help.cab
- %ProgramFiles%\eset\eset security\eplgoesmonlang.dll
- %ProgramFiles%\eset\eset security\eula.html
- %ALLUSERSPROFILE%\eset\eset security\installer\passwordmanagerinstaller.exe
- %ProgramFiles%\eset\eset security\x86\etpcomm.dll
- %ProgramFiles%\eset\eset security\etpcomm.dll
- %ALLUSERSPROFILE%\eset\eset security\installer\deslockinstaller.msi
- %ProgramFiles%\eset\eset security\eguiproduct.dll
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em033_64_l1_.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em033_64_l0_.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em017_64_l2_.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em017_64_l1_.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em017_64_l0_.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em006_64_l1_.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em006_64_l0_.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em000k_64_l0_.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em000_64_l0_.dll.nup
- %ProgramFiles%\eset\eset security\sysrescue.url
- %ProgramFiles%\eset\eset security\sysinspectorlang.dll
- %ProgramFiles%\eset\eset security\shellextlang.dll
- %ProgramFiles%\eset\eset security\eula.cab
- %TEMP%\nupef4d.tmp
- %ALLUSERSPROFILE%\eset\eset security\updfiles\nod7f4c.dll.nup
- %WINDIR%\installer\{0813f772-f554-4da9-9cea-abce6321bdfd}\icon_help
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\oem3.cat
- %WINDIR%\temp\versions.csv
- %ALLUSERSPROFILE%\eset\eset security\versions.csv
- %ALLUSERSPROFILE%\eset\eset security\logs\devctrllog.dat
- %WINDIR%\temp\{25fe962e-16a8-696c-eafe-613a56c8b024}\set4f7e.tmp
- %WINDIR%\temp\{25fe962e-16a8-696c-eafe-613a56c8b024}\set4ef1.tmp
- %WINDIR%\temp\{25fe962e-16a8-696c-eafe-613a56c8b024}\set4e73.tmp
- %ALLUSERSPROFILE%\eset\eset security\logs\urllog.dat
- <DRIVERS>\set6d05.tmp
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\oem4.cat
- %WINDIR%\temp\{266e3aef-71d3-1933-3af1-8f0d1f554110}\set4888.tmp
- %WINDIR%\temp\{266e3aef-71d3-1933-3af1-8f0d1f554110}\set47fa.tmp
- %WINDIR%\temp\epfwtrace.etl
- %ALLUSERSPROFILE%\eset\eset security\diagnostics\ecp\190848_1184451407_get-license-file_resp.xml
- %ALLUSERSPROFILE%\eset\eset security\pki\ctl\7301e3f5a2c9da4198f4cf8a195381e6f44fb380.stl
- %ALLUSERSPROFILE%\eset\eset security\diagnostics\ecp\190847_1158746332_get-license-file_req.xml
- %ALLUSERSPROFILE%\eset\eset security\logs\hipslog.dat
- %ALLUSERSPROFILE%\eset\eset security\logs\warnlog.dat
- %ALLUSERSPROFILE%\eset\eset security\epfwuser.dat
- %WINDIR%\installer\{0813f772-f554-4da9-9cea-abce6321bdfd}\icon_product
- <DRIVERS>\set6f76.tmp
- %ALLUSERSPROFILE%\eset\eset security\updfiles\nod13df.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\nod37d7.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\nod0f09.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\nod4b00.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\nod3f1d.dll.nup
- %WINDIR%\temp\nsf7dcf.tmp
- %WINDIR%\temp\nsf7dbf.tmp
- %WINDIR%\temp\nsf7dbe.tmp
- %WINDIR%\temp\nsf7dbd.tmp
- %WINDIR%\temp\nsf7dac.tmp
- %WINDIR%\temp\nsf7d9b.tmp
- %WINDIR%\temp\nsf7d9a.tmp
- %WINDIR%\temp\nsf7d99.tmp
- %WINDIR%\temp\nsf7d98.tmp
- %ALLUSERSPROFILE%\eset\eset security\updfiles\lastupd.ver
- %ALLUSERSPROFILE%\eset\eset security\updfiles\http_update.eset.com\eset_upd\v10\dll\update.ver
- %ALLUSERSPROFILE%\eset\eset security\updfiles\upd.ver
- %ALLUSERSPROFILE%\eset\eset security\updfiles\upd7bb4.tmp
- %ALLUSERSPROFILE%\eset\eset security\backup\db.xml
- %ALLUSERSPROFILE%\eset\eset security\logs\virlog.dat
- %WINDIR%\temp\{266e3aef-71d3-1933-3af1-8f0d1f554110}\set4934.tmp
- %ALLUSERSPROFILE%\eset\eset security\installer\ehs_nt64.msi
- <DRIVERS>\set37e1.tmp
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\oem2.cat
- %TEMP%\nsfecd2.tmp
- %TEMP%\nupef1a.tmp
- %TEMP%\nsfef1b.tmp
- %TEMP%\nupedff.tmp
- %TEMP%\nsfee00.tmp
- %TEMP%\nsfed04.tmp
- %TEMP%\nsfed03.tmp
- %TEMP%\nsfece3.tmp
- %TEMP%\nsfece2.tmp
- %TEMP%\nsfecc1.tmp
- %TEMP%\nupef2b.tmp
- %TEMP%\nsfecc0.tmp
- %TEMP%\nsfecaf.tmp
- %TEMP%\nsfecae.tmp
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\eset\eset security\eset sysrescue.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\eset\eset security\eset sysinspector.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\eset\eset security\eset security.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\eset\eset security\uninstall.lnk
- %WINDIR%\installer\{0813f772-f554-4da9-9cea-abce6321bdfd}\icon_uninstall
- %WINDIR%\installer\{0813f772-f554-4da9-9cea-abce6321bdfd}\icon_license
- %ProgramFiles%\eset\eset security\eguiupdatelang.dll
- %TEMP%\nsfef4e.tmp
- %TEMP%\nupef6f.tmp
- %TEMP%\nsfef2c.tmp
- %WINDIR%\temp\{0edbed76-3c4d-237a-61bf-af12d6c5eb6b}\set1298.tmp
- %WINDIR%\temp\{0edbed76-3c4d-237a-61bf-af12d6c5eb6b}\set11eb.tmp
- %WINDIR%\temp\{0edbed76-3c4d-237a-61bf-af12d6c5eb6b}\set10f0.tmp
- %TEMP%\nup10b.tmp
- %TEMP%\nupea.tmp
- %TEMP%\nupd9.tmp
- %TEMP%\nsfda.tmp
- %TEMP%\nup98.tmp
- %TEMP%\nsfa9.tmp
- %TEMP%\nupf467.tmp
- %TEMP%\nupf273.tmp
- %TEMP%\nupf050.tmp
- %TEMP%\nupf03f.tmp
- %TEMP%\nsff040.tmp
- %TEMP%\nupf02d.tmp
- %TEMP%\nsff02e.tmp
- %TEMP%\nupef7f.tmp
- %TEMP%\nsfef90.tmp
- %TEMP%\nupef5e.tmp
- %WINDIR%\temp\udd734b.tmp
- %ProgramFiles%\eset\eset security\eguismonlang.dll
- %ProgramFiles%\eset\eset security\sciter-x.dll
- %ProgramFiles%\eset\eset security\ecapture.exe
- %ProgramFiles%\eset\eset security\x86\eamsi.dll
- %ProgramFiles%\eset\eset security\eamsi.dll
- %ProgramFiles%\eset\eset security\drivers\eamonm\eamonm.sys
- %ProgramFiles%\eset\eset security\drivers\eamonm\eamonm.inf
- %ProgramFiles%\eset\eset security\drivers\eamonm\eamonm.cat
- %ProgramFiles%\eset\eset security\x86\dmon.dll
- %ProgramFiles%\eset\eset security\dmon.dll
- %ProgramFiles%\eset\eset security\ecmd.exe
- %ProgramFiles%\eset\eset security\ecls.exe
- %ProgramFiles%\eset\eset security\callmsi.exe
- %ProgramFiles%\eset\eset security\api-ms-win-crt-utility-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-crt-time-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-crt-string-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-crt-stdio-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-crt-runtime-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-crt-process-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-crt-private-l1-1-0.dll
- %ProgramFiles%\eset\eset security\concrt140.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-heap-l1-1-0.dll
- %ProgramFiles%\eset\eset security\ecmds.exe
- %ProgramFiles%\eset\eset security\eguimailplugins.dll
- %ProgramFiles%\eset\eset security\eguiipm.dll
- %ProgramFiles%\eset\eset security\eguihips.dll
- %ProgramFiles%\eset\eset security\eguiepfw.dll
- %ProgramFiles%\eset\eset security\eguiemon.dll
- %ProgramFiles%\eset\eset security\eguidmon.dll
- %ProgramFiles%\eset\eset security\eguidevmon.dll
- %ProgramFiles%\eset\eset security\eguidemeter.dll
- %ProgramFiles%\eset\eset security\eguiantitheft.dll
- %ProgramFiles%\eset\eset security\eguiamon.dll
- %ProgramFiles%\eset\eset security\eguiactivation.dll
- %ProgramFiles%\eset\eset security\egui.exe
- %ProgramFiles%\eset\eset security\drivers\eelam\eelam.sys
- %ProgramFiles%\eset\eset security\drivers\eelam\eelam.inf
- %ProgramFiles%\eset\eset security\drivers\eelam\eelam.cat
- %ProgramFiles%\eset\eset security\eeclnt.exe
- %ProgramFiles%\eset\eset security\drivers\edevmon\edevmon.sys
- %ProgramFiles%\eset\eset security\drivers\edevmon\edevmon.inf
- %ProgramFiles%\eset\eset security\drivers\edevmon\edevmon.cat
- %ProgramFiles%\eset\eset security\api-ms-win-crt-multibyte-l1-1-0.dll
- %ProgramFiles%\eset\eset security\cfgres.dll
- %ProgramFiles%\eset\eset security\api-ms-win-crt-math-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-crt-locale-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\eset.temp\{02d83bbe-21e9-398d-c071-14cd1d24def2}\cfg_updater_user.xml
- %ProgramFiles%\eset\eset security\api-ms-win-core-file-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-errorhandling-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-debug-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-datetime-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-console-l1-1-0.dll
- %BOOT_VOL%\boot\bcd
- %BOOT_VOL%\boot\bcd.log
- %TEMP%\eset.temp\{02d83bbe-21e9-398d-c071-14cd1d24def2}\cfg_epfw_user.xml
- %TEMP%\eset.temp\{02d83bbe-21e9-398d-c071-14cd1d24def2}\cfg_ekrn_user.xml
- %ProgramFiles%\eset\eset security\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\eset.temp\{02d83bbe-21e9-398d-c071-14cd1d24def2}\cfg_hips_sd.xml
- %TEMP%\eset.temp\{02d83bbe-21e9-398d-c071-14cd1d24def2}\cfg_cfg.xml
- %TEMP%\eset.temp\{02d83bbe-21e9-398d-c071-14cd1d24def2}\cfg_presets.xml
- %TEMP%\eset.temp\{02d83bbe-21e9-398d-c071-14cd1d24def2}\insthelper.exe
- %TEMP%\eset.temp\{02d83bbe-21e9-398d-c071-14cd1d24def2}\_instdata.xml
- %TEMP%\msi3620\eeh.dll
- %TEMP%\msi65917.log
- %TEMP%\rarsfx0\digitalnetworks.url
- %ProgramFiles%\eset\eset security\eguionlinehelp.dll
- %ProgramFiles%\eset\eset security\ecomserver.exe
- %ProgramFiles%\eset\eset security\api-ms-win-core-handle-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-libraryloader-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-file-l1-2-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-crt-filesystem-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-crt-environment-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-crt-convert-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-crt-conio-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-util-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-timezone-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-sysinfo-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-synch-l1-2-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-synch-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-string-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-rtlsupport-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-profile-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-processthreads-l1-1-1.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-processthreads-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-processenvironment-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-namedpipe-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-memory-l1-1-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-localization-l1-2-0.dll
- %ProgramFiles%\eset\eset security\api-ms-win-core-interlocked-l1-1-0.dll
- %ProgramFiles%\eset\eset security\ekrnopp.dll
- %ProgramFiles%\eset\eset security\eguiparentallang.dll
- %ProgramFiles%\eset\eset security\eguismon.dll
- %ProgramFiles%\eset\eset security\x86\eplgoutlooksmon.dll
- %ProgramFiles%\eset\eset security\eplgoutlooksmon.dll
- %ProgramFiles%\eset\eset security\x86\eplgoutlookemon.dll
- %ProgramFiles%\eset\eset security\eplgoutlookemon.dll
- %ProgramFiles%\eset\eset security\x86\eplgoutlook.dll
- %ProgramFiles%\eset\eset security\eplgoutlook.dll
- %ProgramFiles%\eset\eset security\x86\eplgoesmon.dll
- %ProgramFiles%\eset\eset security\eplgoesmon.dll
- %ProgramFiles%\eset\eset security\msvcp140.dll
- %ProgramFiles%\eset\eset security\instsuppex.dll
- %ProgramFiles%\eset\eset security\x86\eplgoe.dll
- %ProgramFiles%\eset\eset security\eplgoe.dll
- %ProgramFiles%\eset\eset security\x86\eplghooks.dll
- %ProgramFiles%\eset\eset security\eplghooks.dll
- %ProgramFiles%\eset\eset security\drivers\epfwwfp\epfwwfp.sys
- %ProgramFiles%\eset\eset security\drivers\epfwwfp\epfwwfp.inf
- %ProgramFiles%\eset\eset security\drivers\epfwwfp\epfwwfp.cat
- %ProgramFiles%\eset\eset security\drivers\epfwtdir\epfwtdir.sys
- %ProgramFiles%\eset\eset security\x86\eplgoeemon.dll
- %ProgramFiles%\eset\eset security\eguiparental.dll
- %ProgramFiles%\eset\eset security\notice
- %ProgramFiles%\eset\eset security\eguionlinehelplang.dll
- %ProgramFiles%\eset\eset security\eguilang.dll
- %ProgramFiles%\eset\eset security\eguihipslang.dll
- %ProgramFiles%\eset\eset security\eguiepfwlang.dll
- %ProgramFiles%\eset\eset security\eguidevmonlang.dll
- %ProgramFiles%\eset\eset security\eguidemeterlang.dll
- %ProgramFiles%\eset\eset security\eguiantitheftlang.dll
- %ProgramFiles%\eset\eset security\eguiamonlang.dll
- %ProgramFiles%\eset\eset security\eguiactivationlang.dll
- %ProgramFiles%\eset\eset security\eclslang.dll
- %ProgramFiles%\eset\eset security\windowsperformancerecordercontrol.dll
- %ProgramFiles%\eset\eset security\vcruntime140.dll
- %ProgramFiles%\eset\eset security\updater.dll
- %ProgramFiles%\eset\eset security\ucrtbase.dll
- %ProgramFiles%\eset\eset security\toastnotify.dll
- %ProgramFiles%\eset\eset security\sysinspector.exe
- %ProgramFiles%\eset\eset security\x86\shellext.dll
- %ProgramFiles%\eset\eset security\shellext.dll
- %ProgramFiles%\eset\eset security\securityproductinformation.ini
- %ProgramFiles%\eset\eset security\drivers\epfwtdir\epfwtdir.inf
- %ProgramFiles%\eset\eset security\eplgoeemon.dll
- %ProgramFiles%\eset\eset security\drivers\epfwtdir\epfwtdir.cat
- %ProgramFiles%\eset\eset security\drivers\epfwtdi\epfwtdi.sys
- %ProgramFiles%\eset\eset security\drivers\epfwtdi\epfwtdi.inf
- %ProgramFiles%\eset\eset security\ekrnantitheft.dll
- %ProgramFiles%\eset\eset security\ekrnhips.dll
- %ProgramFiles%\eset\eset security\ekrnepfw.dll
- %ProgramFiles%\eset\eset security\ekrnemon.dll
- %ProgramFiles%\eset\eset security\ekrnecp.dll
- %ProgramFiles%\eset\eset security\ekrndmon.dll
- %ProgramFiles%\eset\eset security\ekrndevmon.dll
- %ProgramFiles%\eset\eset security\ekrndemeter.dll
- %ProgramFiles%\eset\eset security\ekrncerberus.dll
- %ProgramFiles%\eset\eset security\ekrnamon.dll
- %ProgramFiles%\eset\eset security\ekrnlicensing.dll
- %ProgramFiles%\eset\eset security\ekrn.exe
- %ProgramFiles%\eset\eset security\drivers\ekbdflt\ekbdflt.sys
- %ProgramFiles%\eset\eset security\drivers\ekbdflt\ekbdflt.inf
- %ProgramFiles%\eset\eset security\drivers\ekbdflt\ekbdflt.cat
- %ProgramFiles%\eset\eset security\drivers\ehdrv\ehdrv.sys
- %ProgramFiles%\eset\eset security\drivers\ehdrv\ehdrv.inf
- %ProgramFiles%\eset\eset security\drivers\ehdrv\ehdrv.cat
- %ProgramFiles%\eset\eset security\eguiupdate.dll
- %ProgramFiles%\eset\eset security\eguiscan.dll
- %ProgramFiles%\eset\eset security\eguiscanlang.dll
- %ProgramFiles%\eset\eset security\ekrnmailplugins.dll
- %ProgramFiles%\eset\eset security\ekrnscan.dll
- %ProgramFiles%\eset\eset security\ekrnipm.dll
- %ProgramFiles%\eset\eset security\drivers\epfwtdi\epfwtdi.cat
- %ProgramFiles%\eset\eset security\drivers\epfwndis\epfwndis.sys
- %ProgramFiles%\eset\eset security\drivers\epfwndis\epfwndis.inf
- %ProgramFiles%\eset\eset security\drivers\epfwndis\epfwndis.cat
- %ProgramFiles%\eset\eset security\drivers\epfwndis\epfwnd_m.inf
- %ProgramFiles%\eset\eset security\drivers\epfwlwf\epfwlwf.sys
- %ProgramFiles%\eset\eset security\drivers\epfwlwf\epfwlwf.inf
- %ProgramFiles%\eset\eset security\drivers\epfwlwf\epfwlwf.cat
- %ProgramFiles%\eset\eset security\drivers\epfw\epfw.sys
- %ProgramFiles%\eset\eset security\drivers\epfw\epfw.inf
- %ProgramFiles%\eset\eset security\drivers\epfw\epfw.cat
- %ProgramFiles%\eset\eset security\eoppframe.exe
- %ProgramFiles%\eset\eset security\x86\eoppbrowser.dll
- %ProgramFiles%\eset\eset security\eoppbrowser.dll
- %ProgramFiles%\eset\eset security\ekrnwebcontrol.dll
- %ProgramFiles%\eset\eset security\ekrnupdate.dll
- %ProgramFiles%\eset\eset security\ekrnsmon.dll
- %ProgramFiles%\eset\eset security\ekrnscriptmon.dll
- %ProgramFiles%\eset\eset security\ekrnparental.dll
- %ALLUSERSPROFILE%\eset\eset security\updfiles\nod32ca.dll.nup
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\oem2.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\oem3.cat
- <SYSTEM32>\catroot\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\oem4.cat
- %TEMP%\nsfecae.tmp
- %TEMP%\nsfda.tmp
- %WINDIR%\temp\{0edbed76-3c4d-237a-61bf-af12d6c5eb6b}\ehdrv.cat
- %WINDIR%\temp\{0edbed76-3c4d-237a-61bf-af12d6c5eb6b}\ehdrv.inf
- %WINDIR%\temp\{0edbed76-3c4d-237a-61bf-af12d6c5eb6b}\ehdrv.sys
- %WINDIR%\temp\{266e3aef-71d3-1933-3af1-8f0d1f554110}\eamonm.cat
- %WINDIR%\temp\{266e3aef-71d3-1933-3af1-8f0d1f554110}\eamonm.inf
- %WINDIR%\temp\{266e3aef-71d3-1933-3af1-8f0d1f554110}\eamonm.sys
- %WINDIR%\temp\{25fe962e-16a8-696c-eafe-613a56c8b024}\epfwwfp.cat
- %WINDIR%\temp\{25fe962e-16a8-696c-eafe-613a56c8b024}\epfwwfp.inf
- %WINDIR%\temp\{25fe962e-16a8-696c-eafe-613a56c8b024}\epfwwfp.sys
- %TEMP%\msi3620\eeh.dll
- %WINDIR%\temp\epfwtrace.etl
- %WINDIR%\temp\udd734b.tmp
- %ALLUSERSPROFILE%\eset\eset security\updfiles\upd7bb4.tmp
- %WINDIR%\temp\nsf7d98.tmp
- %WINDIR%\temp\nsf7d99.tmp
- %WINDIR%\temp\nsf7d9a.tmp
- %WINDIR%\temp\nsf7d9b.tmp
- %WINDIR%\temp\nsf7dac.tmp
- %WINDIR%\temp\nsf7dbd.tmp
- %WINDIR%\temp\nsf7dbe.tmp
- %WINDIR%\temp\nsf7dbf.tmp
- %WINDIR%\temp\nsf7dcf.tmp
- %TEMP%\nupd9.tmp
- %TEMP%\rarsfx0\digitalnetworks.url
- %TEMP%\nsfa9.tmp
- %TEMP%\nup98.tmp
- %TEMP%\nsfecaf.tmp
- %TEMP%\nsfecc0.tmp
- %TEMP%\nsfecc1.tmp
- %TEMP%\nsfecd2.tmp
- %TEMP%\nsfece2.tmp
- %TEMP%\nsfece3.tmp
- %TEMP%\nsfed03.tmp
- %TEMP%\nsfed04.tmp
- %TEMP%\nsfee00.tmp
- %TEMP%\nsfef1b.tmp
- %TEMP%\nupef2b.tmp
- %TEMP%\nupef5e.tmp
- %TEMP%\nsfef2c.tmp
- %TEMP%\nupef4d.tmp
- %TEMP%\nsfef4e.tmp
- %TEMP%\nupef7f.tmp
- %TEMP%\nupf050.tmp
- %TEMP%\nupf273.tmp
- %TEMP%\nsfef90.tmp
- %TEMP%\nupf02d.tmp
- %TEMP%\nsff02e.tmp
- %TEMP%\nupf03f.tmp
- %TEMP%\nsff040.tmp
- %TEMP%\nupea.tmp
- %TEMP%\rarsfx0\ehs_nt64.msi
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em000k_64_l0_.dll.nup в %ALLUSERSPROFILE%\eset\eset security\updfiles\em000k_64_l0_20210902190826.dll.nup
- %WINDIR%\temp\{25fe962e-16a8-696c-eafe-613a56c8b024}\set4f7e.tmp в %WINDIR%\temp\{25fe962e-16a8-696c-eafe-613a56c8b024}\epfwwfp.sys
- %WINDIR%\temp\{25fe962e-16a8-696c-eafe-613a56c8b024}\set4ef1.tmp в %WINDIR%\temp\{25fe962e-16a8-696c-eafe-613a56c8b024}\epfwwfp.inf
- %WINDIR%\temp\{25fe962e-16a8-696c-eafe-613a56c8b024}\set4e73.tmp в %WINDIR%\temp\{25fe962e-16a8-696c-eafe-613a56c8b024}\epfwwfp.cat
- %WINDIR%\temp\{266e3aef-71d3-1933-3af1-8f0d1f554110}\set4934.tmp в %WINDIR%\temp\{266e3aef-71d3-1933-3af1-8f0d1f554110}\eamonm.inf
- %WINDIR%\temp\{266e3aef-71d3-1933-3af1-8f0d1f554110}\set4888.tmp в %WINDIR%\temp\{266e3aef-71d3-1933-3af1-8f0d1f554110}\eamonm.cat
- %WINDIR%\temp\{266e3aef-71d3-1933-3af1-8f0d1f554110}\set47fa.tmp в %WINDIR%\temp\{266e3aef-71d3-1933-3af1-8f0d1f554110}\eamonm.sys
- <DRIVERS>\set37e1.tmp в <DRIVERS>\ehdrv.sys
- %WINDIR%\temp\{0edbed76-3c4d-237a-61bf-af12d6c5eb6b}\set1298.tmp в %WINDIR%\temp\{0edbed76-3c4d-237a-61bf-af12d6c5eb6b}\ehdrv.sys
- %WINDIR%\temp\{0edbed76-3c4d-237a-61bf-af12d6c5eb6b}\set11eb.tmp в %WINDIR%\temp\{0edbed76-3c4d-237a-61bf-af12d6c5eb6b}\ehdrv.inf
- %WINDIR%\temp\{0edbed76-3c4d-237a-61bf-af12d6c5eb6b}\set10f0.tmp в %WINDIR%\temp\{0edbed76-3c4d-237a-61bf-af12d6c5eb6b}\ehdrv.cat
- %TEMP%\nup10b.tmp в %ProgramFiles%\eset\eset security\modules\em033_64\1415\em033_64.dll
- %TEMP%\nupf467.tmp в %ProgramFiles%\eset\eset security\modules\em017_64\1776\em017_64.dll
- %TEMP%\nupef6f.tmp в %ProgramFiles%\eset\eset security\modules\em006_64\1192\em006_64.dll
- %TEMP%\nupef1a.tmp в %ProgramFiles%\eset\eset security\modules\em000k_64\1012\em000k_64.dll
- %TEMP%\nupedff.tmp в %ProgramFiles%\eset\eset security\modules\em000_64\1029\em000_64.dll
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em017_64_l2_.dll.nup в %ALLUSERSPROFILE%\eset\eset security\updfiles\em017_64_l2_20210902190826.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em033_64_l1_.dll.nup в %ALLUSERSPROFILE%\eset\eset security\updfiles\em033_64_l1_20210902190826.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em017_64_l1_.dll.nup в %ALLUSERSPROFILE%\eset\eset security\updfiles\em017_64_l1_20210902190826.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em006_64_l1_.dll.nup в %ALLUSERSPROFILE%\eset\eset security\updfiles\em006_64_l1_20210902190826.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em033_64_l0_.dll.nup в %ALLUSERSPROFILE%\eset\eset security\updfiles\em033_64_l0_20210902190826.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em017_64_l0_.dll.nup в %ALLUSERSPROFILE%\eset\eset security\updfiles\em017_64_l0_20210902190826.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em006_64_l0_.dll.nup в %ALLUSERSPROFILE%\eset\eset security\updfiles\em006_64_l0_20210902190826.dll.nup
- %ALLUSERSPROFILE%\eset\eset security\updfiles\em000_64_l0_.dll.nup в %ALLUSERSPROFILE%\eset\eset security\updfiles\em000_64_l0_20210902190826.dll.nup
- <DRIVERS>\set6d05.tmp в <DRIVERS>\eamonm.sys
- <DRIVERS>\set6f76.tmp в <DRIVERS>\epfwwfp.sys
- %LOCALAPPDATA%\microsoft\windows\usrclass.dat.log1
- %LOCALAPPDATA%\microsoft\windows\usrclass.dat
- 'ed#.#set.com':443
- 'pk#.#set.com':80
- 'up###e.eset.com':80
- 'sp###driver.com':443
- http://up###e.eset.com/eset_upd/v10/dll/update.ver
- http://91.###.167.132:80/v10-dll-rel-sta/mod_005_cleaner_1354/em005_64_l0.dll.nup
- http://91.###.167.132:80/v10-dll-rel-sta/mod_000_nativeloader_1067/em000_64_l0.dll.nup
- http://91.###.167.132:80/v10-dll-rel-sta/mod_000_nativeloader_km_1022/em000k_64_l0.dll.nup
- http://91.###.167.132:80/v10-dll-rel-sta/mod_001_perseus_2187/em001_64_l0.dll.nup
- http://91.###.167.132:80/v10-dll-rel-sta/mod_001_perseus_2202/em001_64_l1.dll.nup
- http://91.###.167.132:80/v10-dll-rel-sta/mod_001_perseus_2232/em001_64_l2.dll.nup
- http://91.###.167.132:80/v10-dll-rel-sta/mod_002_engine_48650/em002_64_l0.dll.nup
- 'ed#.#set.com':443
- DNS ASK ed#.#set.com
- DNS ASK pk#.#set.com
- DNS ASK up###e.eset.com
- DNS ASK sp###driver.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'ESET Main Frame' WindowName: ''
- ClassName: 'ESET Client Frame' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: '' WindowName: 'EplgHooksWindow'
- ClassName: 'Static' WindowName: ''
- '%TEMP%\eset.temp\{02d83bbe-21e9-398d-c071-14cd1d24def2}\insthelper.exe' -ci "%TEMP%\eset.temp\{02D83BBE-21E9-398D-C071-14CD1D24DEF2}\_InstData.xml"
- '%ProgramFiles%\eset\eset security\ekrn.exe'
- '%ProgramFiles%\eset\eset security\egui.exe' /hide
- '<SYSTEM32>\taskkill.exe' /F /T /IM ehttpsrv.exe' (со скрытым окном)
- '%TEMP%\eset.temp\{02d83bbe-21e9-398d-c071-14cd1d24def2}\insthelper.exe' -ci "%TEMP%\eset.temp\{02D83BBE-21E9-398D-C071-14CD1D24DEF2}\_InstData.xml"' (со скрытым окном)
- '<SYSTEM32>\msiexec.exe' /i "%TEMP%\RarSFX0\ehs_nt64.msi" /qb PRODUCTTYPE=eav CFG_POTENTIALLYUNWANTED_ENABLED=0 CFG_LIVEGRID_ENABLED=0 FIRSTSCAN_ENABLE=0 CFG_EPFW_MODE=0 ACTIVATION_DLG_SUPPRESS=0