Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'Manundoc' = '{81382A34-84C6-4852-9B3D-03EAF4C070B6}'
- [<HKLM>\SYSTEM\ControlSet001\Services\System Event Dispatcher] 'Start' = '00000002'
- '<SYSTEM32>\sgvrfy32.exe' -i
- <SYSTEM32>\svrltmgr.dll
- <SYSTEM32>\vdorctrl.dll
- <SYSTEM32>\nmcpusym.dll
- <SYSTEM32>\sgvrfy32.exe
- <SYSTEM32>\cmproxfr.dll
- <SYSTEM32>\svrltwp.dll
- %TEMP%\msvxrsc.dll
- %TEMP%\UUU1.tmp
- %TEMP%\UUU2.tmp
- %TEMP%\UUU3.tmp
- <SYSTEM32>\wzodlg32.dll
- %TEMP%\UUU3.tmp
- %TEMP%\msvxrsc.dll
- %TEMP%\UUU1.tmp
- %TEMP%\UUU2.tmp