Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'Winipdat' = '{3FB26F77-200E-4213-AA3E-5EE4C759B4BD}'
- [<HKLM>\SYSTEM\ControlSet001\Services\System Event Dispatcher] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\System Event Dispatcher] 'ImagePath' = '%WINDIR%\winipbin\sgvrfy32.exe'
- %WINDIR%\Logs\splog.txt
- %TEMP%\UUU1.tmp
- %TEMP%\MSVxRsc.dll
- %TEMP%\UUU2.tmp
- %WINDIR%\winipbin\cmpuxbat32.dll
- %TEMP%\UUU3.tmp
- %WINDIR%\winipbin\svrltwp.dll
- %WINDIR%\winipbin\vdorctrl.dll
- %WINDIR%\winipbin\rcxaemap.dll
- %WINDIR%\winipbin\quasimo.dll
- %WINDIR%\winipbin\svrltmgr.dll
- %WINDIR%\winipbin\cmproxfr.dll
- %WINDIR%\winipbin\sgvrfy32.exe
- %TEMP%\ra.dll
- %TEMP%\UUU1.tmp
- %TEMP%\UUU2.tmp
- %TEMP%\UUU3.tmp
- %TEMP%\ra.dll
- %TEMP%\MSVxRsc.dll
- '%WINDIR%\winipbin\sgvrfy32.exe' -i