Техническая информация
- [<HKLM>\SOFTWARE\Classes\MSProgramGroup\Shell\Open\Command] '' = '<SYSTEM32>\grpconv.exe %1'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] 'vidc.H264' = 'vicovfw.dll'
- %WINDIR%\inf\vicoc.inf
- %WINDIR%\inf\vicoc.PNF
- <SYSTEM32>\xvid.ax
- <SYSTEM32>\xvidcore.dll
- <SYSTEM32>\vicovfw.dll
- '<SYSTEM32>\grpconv.exe' -o
- '<SYSTEM32>\runonce.exe' -r