Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\drivers32] 'vidc.DIVX' = 'DivX.dll'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'Wrapper' = 'runonce'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- %TEMP%\ixp000.tmp\divx.dll
- %TEMP%\ixp000.tmp\divx6.inf
- %TEMP%\ixp000.tmp\divxdec.ax
- %TEMP%\ixp000.tmp\dpl100.dll
- %WINDIR%\inf\set6b4.tmp
- %WINDIR%\syswow64\set6d4.tmp
- %WINDIR%\syswow64\set713.tmp
- %WINDIR%\syswow64\set743.tmp
- %TEMP%\ixp000.tmp\dpl100.dll
- %TEMP%\ixp000.tmp\divxdec.ax
- %TEMP%\ixp000.tmp\divx6.inf
- %TEMP%\ixp000.tmp\divx.dll
- %WINDIR%\inf\set6b4.tmp в %WINDIR%\inf\divx6.inf
- %WINDIR%\syswow64\set6d4.tmp в %WINDIR%\syswow64\divx.dll
- %WINDIR%\syswow64\set713.tmp в %WINDIR%\syswow64\dpl100.dll
- %WINDIR%\syswow64\set743.tmp в %WINDIR%\syswow64\divxdec.ax
- %LOCALAPPDATA%\microsoft\windows\explorer\explorerstartuplog_runonce.etl
- '%WINDIR%\syswow64\rundll32.exe' setupapi.dll,InstallHinfSection DefaultInstall 128 %TEMP%\IXP000.TMP\DivX6.inf
- '%WINDIR%\syswow64\runonce.exe' -r
- '%WINDIR%\syswow64\runonce.exe'
- '%WINDIR%\syswow64\regsvr32.exe' /s <SYSTEM32>\DivXdec.ax
- '%WINDIR%\syswow64\grpconv.exe' -o