persistence-info.github.io

View on GitHub

Natural Language 6 DLLs

Location:

HKLM\System\CurrentControlSet\Control\ContentIndex\Language

Classification:

Criteria Value
Permissions Admin
Security context System
Persistence type Registry
Code type DLL
Launch type Automatic
Impact Non-destructive1
OS Version All OS versions2
Dependencies OS only
Toolset Scriptable

Description:

C:\WINDOWS\system32\SearchIndexer.exe process looks for the DLLOverridePath entries under the following locations (language may vary on non-English OS versions):
HKLM\System\CurrentControlSet\Control\ContentIndex\Language\English_UK HKLM\System\CurrentControlSet\Control\ContentIndex\Language\English_US HKLM\System\CurrentControlSet\Control\ContentIndex\Language\Neutral

References:

https://www.hexacorn.com/blog/2018/12/30/beyond-good-ol-run-key-part-98/

Credits:

@Hexacorn

See also:

Remarks:

  1. To be verified 

  2. To be verified