Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\drivers32] 'vidc.H264' = 'vicovfw.dll'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- %WINDIR%\syswow64\xvidcore.dll
- %WINDIR%\syswow64\vicovfw.dll
- %WINDIR%\syswow64\xvid.ax
- %WINDIR%\inf\vicoc.inf
- %LOCALAPPDATA%\microsoft\windows\explorer\explorerstartuplog_runonce.etl
- '%WINDIR%\syswow64\runonce.exe' -r
- '%WINDIR%\syswow64\grpconv.exe' -o