Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\gwvsdflt] 'ImagePath' = '%PROGRAM_FILES%\Gateway\SSLVPN\gwvsdflt.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\gwredirector] 'ImagePath' = '<DRIVERS>\gwredirector.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\gwredirector6] 'ImagePath' = '<DRIVERS>\gwredirector6.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\gwdevflt] 'ImagePath' = '%PROGRAM_FILES%\Gateway\SSLVPN\gwdevflt.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\gwupdater] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\gwservice] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\gwvdisk] 'ImagePath' = '%PROGRAM_FILES%\Gateway\SSLVPN\gwvdisk.sys'
- '%PROGRAM_FILES%\Gateway\SSLVPN\gwservice.exe'
- '%PROGRAM_FILES%\Gateway\SSLVPN\gwupdater.exe'
- %TEMP%\gwtemp\gwstub.exe.cab
- %TEMP%\gwtemp\gwstub.exe
- %TEMP%\gwtemp\gwvsdctrl.dll
- %TEMP%\gwtemp\gwvsdflt.sys.64.cab
- %TEMP%\gwtemp\gwvsdctrl.dll.cab
- %TEMP%\gwtemp\gwstub.exe.64.cab
- %TEMP%\gwtemp\gwieplugin.dll.cab
- %TEMP%\gwtemp\gwieplugin.dll
- %TEMP%\gwtemp\gwuimng.dll.64.cab
- %TEMP%\gwtemp\gwuimng.dll.cab
- %TEMP%\gwtemp\gwuimng.dll
- %TEMP%\gwtemp\gwvdisk.sys.cab
- %TEMP%\gwtemp\gwvdisk.sys
- %TEMP%\gwtemp\gwvdiskctrl.dll
- %TEMP%\gwtemp\gwvsdserver.dll
- %TEMP%\gwtemp\gwvdiskctrl.dll.cab
- %TEMP%\gwtemp\gwvdisk.sys.64.cab
- %TEMP%\gwtemp\gwvsdflt.sys.cab
- %TEMP%\gwtemp\gwvsdflt.sys
- %TEMP%\gwtemp\gwdevflt.sys.64.cab
- %TEMP%\gwtemp\gwdevflt.sys.cab
- %TEMP%\gwtemp\gwdevflt.sys
- %TEMP%\gwtemp\gwieplugin.dll.64.cab
- %TEMP%\gwtemp\gwredirector.sys.64.cab
- %TEMP%\gwtemp\gwredirector6.sys.cab
- %TEMP%\gwtemp\gwredirector.sys
- %TEMP%\gwtemp\libeay32.dll
- %TEMP%\gwtemp\gwredirector.sys.cab
- %TEMP%\gwtemp\gwredirector6.sys
- %ALLUSERSPROFILE%\Start Menu\Programs\Gateway SSLVPN\SSLVPN Client.lnk
- %PROGRAM_FILES%\Gateway\SSLVPN\gwsso.dll
- %ALLUSERSPROFILE%\Start Menu\Programs\Gateway SSLVPN\Uninstall SSLVPN Client.lnk
- %TEMP%\gwtemp\gwredirector6.sys.64.cab
- %TEMP%\gwtemp\package.conf
- %TEMP%\gwtemp\gwendsecurity.dll.cab
- %TEMP%\gwtemp\gwendsecurity.dll
- %TEMP%\gwtemp\gwsso.dll.64.cab
- %TEMP%\gwtemp\gwsso.dll.cab
- %TEMP%\gwtemp\gwsso.dll
- %TEMP%\gwtemp\gwhook.sys.cab
- %TEMP%\gwtemp\ssleay32.dll
- %TEMP%\gwtemp\libeay32.dll.cab
- %TEMP%\gwtemp\ssleay32.dll.cab
- %TEMP%\gwtemp\gwhook.sys
- %TEMP%\gwtemp\gwhook.sys.64.cab
- %TEMP%\gwtemp\gwvnic.sys.64.cab
- %TEMP%\gwtemp\gwvnic.cat.64.cab
- %TEMP%\gwtemp\gwvnic.sys
- %TEMP%\gwtemp\gwservice.exe
- %TEMP%\gwtemp\gwvnic.sys.cab
- %TEMP%\gwtemp\gwvnic.cat.64
- %TEMP%\gwtemp\devcon.exe.64.cab
- %TEMP%\gwtemp\devcon.exe.64
- %TEMP%\gwtemp\gwvnic.inf.64.cab
- %TEMP%\gwtemp\gwvnic.inf.cab
- %TEMP%\gwtemp\gwvnic.inf
- %TEMP%\gwtemp\gwupdater.dll
- %TEMP%\gwtemp\gwclient.exe.cab
- %TEMP%\gwtemp\gwupdater.dll.cab
- %TEMP%\gwtemp\gwuninstall.exe.cab
- %TEMP%\gwtemp\gwuninstall.exe
- %TEMP%\gwtemp\gwclient.exe
- %TEMP%\gwtemp\gwupdater.exe
- %TEMP%\gwtemp\gwservice.exe.cab
- %TEMP%\gwtemp\gwupdater.exe.cab
- %TEMP%\gwtemp\vsdagent.exe.cab
- %TEMP%\gwtemp\vsdagent.exe
- %TEMP%\gwtemp\gwnetflt.sys.cab
- %TEMP%\gwtemp\NetFltInstaller.exe.64.cab
- %TEMP%\gwtemp\gwproxy.dll.cab
- %TEMP%\gwtemp\NetFltInstaller.exe
- %TEMP%\gwtemp\gwnetflt_m.inf.64.cab
- %TEMP%\gwtemp\NetFltInstaller.exe.cab
- %TEMP%\gwtemp\gwproxy.dll
- %TEMP%\gwtemp\gwnc.dll
- %TEMP%\gwtemp\gwvsdserver.dll.cab
- %TEMP%\gwtemp\gwnc.dll.cab
- %TEMP%\gwtemp\gwsession.dll.cab
- %TEMP%\gwtemp\gwsession.dll
- %TEMP%\gwtemp\gwnetflt.cat.64
- %TEMP%\gwtemp\gwnetflt_m.cat.64.cab
- %TEMP%\gwtemp\gwnetflt.cat.64.cab
- %TEMP%\gwtemp\gwnetflt.sys
- %TEMP%\gwtemp\gwnetflt.sys.64.cab
- %TEMP%\gwtemp\gwnetflt_m.cat.64
- %TEMP%\gwtemp\gwnetflt_m.inf.cab
- %TEMP%\gwtemp\gwnetflt_m.inf
- %TEMP%\gwtemp\gwnetflt.inf.64.cab
- %TEMP%\gwtemp\gwnetflt.inf.cab
- %TEMP%\gwtemp\gwnetflt.inf
- %TEMP%\gwtemp\gwstub.exe.cab
- %TEMP%\gwtemp\gwvsdctrl.dll.cab
- %TEMP%\gwtemp\gwvsdflt.sys.64.cab
- %TEMP%\gwtemp\gwuimng.dll.64.cab
- %TEMP%\gwtemp\gwuimng.dll.cab
- %TEMP%\gwtemp\gwstub.exe.64.cab
- %TEMP%\gwtemp\gwvdisk.sys.64.cab
- %TEMP%\gwtemp\gwvdisk.sys.cab
- %TEMP%\gwtemp\gwvdiskctrl.dll.cab
- %TEMP%\gwtemp\gwvsdflt.sys.cab
- %TEMP%\gwtemp\gwdevflt.sys.64.cab
- %TEMP%\gwtemp\gwdevflt.sys.cab
- %TEMP%\gwtemp\gwieplugin.dll.cab
- %TEMP%\gwtemp\gwredirector.sys.cab
- %TEMP%\gwtemp\libeay32.dll.cab
- %TEMP%\gwtemp\ssleay32.dll.cab
- %TEMP%\gwtemp\gwredirector6.sys.64.cab
- %TEMP%\gwtemp\gwredirector6.sys.cab
- %TEMP%\gwtemp\gwredirector.sys.64.cab
- %TEMP%\gwtemp\gwsso.dll.64.cab
- %TEMP%\gwtemp\gwsso.dll.cab
- %TEMP%\gwtemp\gwieplugin.dll.64.cab
- %TEMP%\gwtemp\gwhook.sys.64.cab
- %TEMP%\gwtemp\gwhook.sys.cab
- %TEMP%\gwtemp\gwendsecurity.dll.cab
- %TEMP%\gwtemp\gwvsdserver.dll.cab
- %TEMP%\gwtemp\gwvnic.cat.64.cab
- %TEMP%\gwtemp\gwvnic.sys.64.cab
- %TEMP%\gwtemp\gwvnic.sys.cab
- %TEMP%\gwtemp\devcon.exe.64.cab
- %TEMP%\gwtemp\gwvnic.inf.64.cab
- %TEMP%\gwtemp\gwvnic.inf.cab
- %TEMP%\gwtemp\gwclient.exe.cab
- %TEMP%\gwtemp\gwupdater.dll.cab
- %TEMP%\gwtemp\gwuninstall.exe.cab
- %TEMP%\gwtemp\gwservice.exe.cab
- %TEMP%\gwtemp\gwupdater.exe.cab
- %TEMP%\gwtemp\vsdagent.exe.cab
- %TEMP%\gwtemp\gwnetflt.sys.cab
- %TEMP%\gwtemp\NetFltInstaller.exe.64.cab
- %TEMP%\gwtemp\NetFltInstaller.exe.cab
- %TEMP%\gwtemp\gwnetflt_m.inf.64.cab
- %TEMP%\gwtemp\gwnc.dll.cab
- %TEMP%\gwtemp\gwsession.dll.cab
- %TEMP%\gwtemp\gwproxy.dll.cab
- %TEMP%\gwtemp\gwnetflt_m.cat.64.cab
- %TEMP%\gwtemp\gwnetflt.cat.64.cab
- %TEMP%\gwtemp\gwnetflt.sys.64.cab
- %TEMP%\gwtemp\gwnetflt_m.inf.cab
- %TEMP%\gwtemp\gwnetflt.inf.64.cab
- %TEMP%\gwtemp\gwnetflt.inf.cab
- %TEMP%\gwtemp\gwvdisk.sys в %PROGRAM_FILES%\Gateway\SSLVPN\gwvdisk.sys
- %TEMP%\gwtemp\gwvdiskctrl.dll в %PROGRAM_FILES%\Gateway\SSLVPN\gwvdiskctrl.dll
- %TEMP%\gwtemp\gwvsdflt.sys в %PROGRAM_FILES%\Gateway\SSLVPN\gwvsdflt.sys
- %TEMP%\gwtemp\gwdevflt.sys в %PROGRAM_FILES%\Gateway\SSLVPN\gwdevflt.sys
- %TEMP%\gwtemp\gwsession.dll в %PROGRAM_FILES%\Gateway\SSLVPN\gwsession.dll
- %TEMP%\gwtemp\gwproxy.dll в %PROGRAM_FILES%\Gateway\SSLVPN\gwproxy.dll
- %TEMP%\gwtemp\gwvsdserver.dll в %PROGRAM_FILES%\Gateway\SSLVPN\gwvsdserver.dll
- %TEMP%\gwtemp\gwnc.dll в %PROGRAM_FILES%\Gateway\SSLVPN\gwnc.dll
- %TEMP%\gwtemp\gwredirector.sys в <DRIVERS>\gwredirector.sys
- %TEMP%\gwtemp\libeay32.dll в %PROGRAM_FILES%\Gateway\SSLVPN\libeay32.dll
- %TEMP%\gwtemp\package.conf в %PROGRAM_FILES%\Gateway\SSLVPN\package.conf
- %TEMP%\gwtemp\gwredirector6.sys в <DRIVERS>\gwredirector6.sys
- %TEMP%\gwtemp\gwendsecurity.dll в %PROGRAM_FILES%\Gateway\SSLVPN\gwendsecurity.dll
- %TEMP%\gwtemp\gwvsdctrl.dll в %PROGRAM_FILES%\Gateway\SSLVPN\gwvsdctrl.dll
- %TEMP%\gwtemp\ssleay32.dll в %PROGRAM_FILES%\Gateway\SSLVPN\ssleay32.dll
- %TEMP%\gwtemp\gwhook.sys в %PROGRAM_FILES%\Gateway\SSLVPN\gwhook.sys
- %TEMP%\gwtemp\gwstub.exe в %PROGRAM_FILES%\Gateway\SSLVPN\gwstub.exe
- %TEMP%\gwtemp\vsdagent.exe в %PROGRAM_FILES%\Gateway\SSLVPN\vsdagent.exe
- %TEMP%\gwtemp\gwieplugin.dll в %PROGRAM_FILES%\Gateway\SSLVPN\gwieplugin_1217310203.dll
- %TEMP%\gwtemp\gwuimng.dll в %PROGRAM_FILES%\Gateway\SSLVPN\gwuimng.dll
- %TEMP%\gwtemp\gwuninstall.exe в %PROGRAM_FILES%\Gateway\SSLVPN\gwuninstall.exe
- %TEMP%\gwtemp\gwupdater.exe в %PROGRAM_FILES%\Gateway\SSLVPN\gwupdater.exe
- %TEMP%\gwtemp\gwupdater.dll в %PROGRAM_FILES%\Gateway\SSLVPN\gwupdater.dll
- %TEMP%\gwtemp\gwclient.exe в %PROGRAM_FILES%\Gateway\SSLVPN\gwclient.exe
- %TEMP%\gwtemp\gwnetflt.inf в %PROGRAM_FILES%\Gateway\SSLVPN\gwnetflt.inf
- %TEMP%\gwtemp\gwnetflt.sys в %PROGRAM_FILES%\Gateway\SSLVPN\gwnetflt.sys
- %TEMP%\gwtemp\NetFltInstaller.exe в %PROGRAM_FILES%\Gateway\SSLVPN\NetFltInstaller.exe
- %TEMP%\gwtemp\gwnetflt_m.inf в %PROGRAM_FILES%\Gateway\SSLVPN\gwnetflt_m.inf
- %TEMP%\gwtemp\gwservice.exe в %PROGRAM_FILES%\Gateway\SSLVPN\gwservice.exe
- %TEMP%\gwtemp\gwsso.dll в %PROGRAM_FILES%\Gateway\SSLVPN\gwsso_121731029f.dll
- %TEMP%\gwtemp\gwvnic.inf в <DRIVERS>\gwvnic.inf
- %TEMP%\gwtemp\gwvnic.sys в <DRIVERS>\gwvnic.sys
- ClassName: 'Shell_TrayWnd' WindowName: ''