Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'iKEoffice' = '%ProgramFiles%\SIS\iKE\iKEoffice.exe'
- [<HKLM>\SOFTWARE\Classes\SIS.inst\Shell\Open\command] '' = '"%ProgramFiles%\SIS\SISinst.exe" "%1"'
- %ProgramFiles%\SIS\liKEdb2\liKEdb2.his
- %ProgramFiles%\SIS\liKEdb2\liKEdb2.log
- %ProgramFiles%\SIS\liKEdb2\liKEdb2.bfg
- %ProgramFiles%\SIS\iKE\NetsetupInstall.cfg
- %ProgramFiles%\SIS\liKEdb2\liKEdb2.map
- %ProgramFiles%\SIS\liKEdb2\liKEdb2.idx
- <SYSTEM32>\spool\drivers\w32x86\acpdfui210.dll
- <SYSTEM32>\spool\drivers\w32x86\acfpdf.txt
- <SYSTEM32>\cdintf210.dll
- %ProgramFiles%\SIS\liKEdb2\liKEdb2.odb
- %ProgramFiles%\SIS\iKE\install.log
- <SYSTEM32>\spool\drivers\w32x86\acpdf210.dll
- %ProgramFiles%\SIS\iKE\wizgui.dll
- %ProgramFiles%\SIS\iKE\skillsets\SIS\Messenger\chimes.wav
- %ProgramFiles%\SIS\iKE\skillsets\SIS\Messenger\chord.wav
- %ProgramFiles%\SIS\iKE\skillEx.dll
- %ProgramFiles%\SIS\iKE\taskdata.dll
- %ProgramFiles%\SIS\iKE\twoToTWAIN.dll
- %ProgramFiles%\SIS\iKE\skillsets\SIS\DocumentManager\skillsetDocumentManager.dep
- %ProgramFiles%\SIS\iKE\skillsets\SIS\DocumentManager\skillsetDocumentManager.dll
- %ALLUSERSPROFILE%\Start Menu\Programs\Office.LNK
- %ProgramFiles%\SIS\iKE\skillsets\SIS\Messenger\skillsetMessenger.dep
- %ProgramFiles%\SIS\iKE\skillsets\SIS\Messenger\skillsetMessenger.dll
- %ProgramFiles%\SIS\iKE\skillsets\SIS\Messenger\skillsetMessenger.hlp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.MAP
- <SYSTEM32>\spool\drivers\w32x86\2\New\acpdf210.dll
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING.VER
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\domain.txt
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\$WinMgmt.CFG
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.BTR
- <SYSTEM32>\spool\drivers\w32x86\2\New\acpdfui210.dll
- <SYSTEM32>\spool\drivers\w32x86\2\New\acfpdf.txt
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING1.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING2.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.DATA
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SYSTEM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SAM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\ComDb.Dat
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_.DEFAULT
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SECURITY
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SOFTWARE
- %ProgramFiles%\SIS\iKE\scangui.dll
- %ProgramFiles%\SIS\iKE\ikeSDK.dll
- %ProgramFiles%\SIS\iKE\app_uninstall.exe
- %ProgramFiles%\SIS\iKE\cdintf.dll
- %ProgramFiles%\SIS\iKE\acfpdfu.dll
- %ProgramFiles%\SIS\iKE\acfpdfui.dll
- %ProgramFiles%\SIS\iKE\ikedata.dll
- %ProgramFiles%\SIS\iKE\itools.dll
- %ProgramFiles%\SIS\iKE\libeay32.dll
- %ProgramFiles%\SIS\iKE\netsetup.exe
- %ProgramFiles%\SIS\iKE\clnt.dll
- %ProgramFiles%\SIS\iKE\iKEoffice.exe
- %ProgramFiles%\SIS\iKE\Install.exe
- %WINDIR%\axe.exe
- %ProgramFiles%\SIS\liKEdb2\app_uninstall.exe
- %ProgramFiles%\SIS\liKEdb2\liKEdb2.cfg
- %TEMP%\SISinst\SISinst.exe
- %TEMP%\SISinst\autorun.inf
- %ProgramFiles%\SIS\iKEde.SISinst
- %ProgramFiles%\SIS\iKE\acfpdf.dll
- %ProgramFiles%\SIS\iKE\acfpdf.drv
- %ProgramFiles%\SIS\iKE\acfpdf.txt
- %ProgramFiles%\SIS\liKEdb2\liKEdb2.exe
- %ProgramFiles%\SIS\liKEdb2\liKEdb2.srv
- %ProgramFiles%\SIS\liKEdb2\netsetup.exe
- %ProgramFiles%\SIS\iKE\oemsetup.inf
- %ProgramFiles%\SIS\iKE\gfxtools.map
- %ProgramFiles%\SIS\iKE\mrktdata.dll
- %ProgramFiles%\SIS\iKE\pemagui.dll
- %ProgramFiles%\SIS\iKE\skillsets\SIS\WorkflowManager\personalAssistants\collaboration\collaboration.dll
- %ProgramFiles%\SIS\iKE\comagui.dll
- %ProgramFiles%\SIS\iKE\gfxtools.dll
- %ProgramFiles%\SIS\iKE\digigui.dll
- %ProgramFiles%\SIS\iKE\msgrgui.dll
- %ProgramFiles%\SIS\iKE\richText.dll
- %ProgramFiles%\SIS\iKE\womagui.dll
- %ProgramFiles%\SIS\iKE\compdata.dll
- %ProgramFiles%\SIS\iKE\corpdata.dll
- %ProgramFiles%\SIS\iKE\qt-mt334.dll
- %ProgramFiles%\SIS\iKE\smartgui.dll
- %ProgramFiles%\SIS\iKE\smarts.dll
- %ProgramFiles%\SIS\iKE\profdata.dll
- %ProgramFiles%\SIS\iKE\qaxcontainer.dll
- %ProgramFiles%\SIS\iKE\qtctrls.dll
- %ProgramFiles%\SIS\iKE\wintools.dll
- %ProgramFiles%\SIS\iKE\xtools.dll
- %ProgramFiles%\SIS\iKE\msgrdata.dll
- %ProgramFiles%\SIS\iKE\ssleay32.dll
- %ProgramFiles%\SIS\iKE\ssltools.dll
- %ProgramFiles%\SIS\iKE\webtools.dll
- from <SYSTEM32>\spool\drivers\w32x86\2\New\acpdfui210.dll to <SYSTEM32>\spool\drivers\w32x86\2\acpdfui210.dll
- from <SYSTEM32>\spool\drivers\w32x86\2\New\acfpdf.txt to <SYSTEM32>\spool\drivers\w32x86\2\acfpdf.txt
- from <SYSTEM32>\spool\drivers\w32x86\2\New\acpdf210.dll to <SYSTEM32>\spool\drivers\w32x86\2\acpdf210.dll
- from %TEMP%\SISinst\SISinst.exe to %ProgramFiles%\SIS\SISinst.exe
- from %TEMP%\SISinst\autorun.inf to %ProgramFiles%\SIS\autorun.inf
- 'ik#.com':80
- http://www.ik#.com:80/index.html via ik#.com
- DNS ASK www.ik#.com
- '%ProgramFiles%\SIS\iKE\Install.exe' /s "iKE Digital File"
- '%ProgramFiles%\SIS\iKE\iKEoffice.exe'
- '%ProgramFiles%\SIS\liKEdb2\liKEdb2.exe'
- '%ProgramFiles%\SIS\liKEdb2\netsetup.exe'
- '%ProgramFiles%\SIS\iKE\netsetup.exe'