Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'SearchIndexer' = '%APPDATA%\Microsoft\Windows\SearchIndex\SearchIndexer.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'HealthMonitor' = '%LOCALAPPDATA%\Microsoft\Windows\Security\Health\HealthMonitor.exe'
- <SYSTEM32>\tasks\windowssearchindexer
- %APPDATA%\microsoft\windows\start menu\programs\startup\searchindexer.exe
- %APPDATA%\microsoft\windows\searchindex\searchindexer.exe
- %LOCALAPPDATA%\microsoft\windows\security\health\healthmonitor.exe
- DNS ASK df####iofwr.info
- '%APPDATA%\microsoft\windows\searchindex\searchindexer.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "WindowsSearchIndexer" /tr "%LOCALAPPDATA%\Microsoft\Windows\Security\Health\HealthMonitor.exe" /sc daily /st 00:00 /rl limited /f (со скрытым окном)
- '%APPDATA%\microsoft\windows\searchindex\searchindexer.exe' (со скрытым окном)