Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'Winipdat' = '{241F3DBC-80E5-4ED7-A0EF-DEC6F0A4487B}'
- [<HKLM>\SYSTEM\ControlSet001\Services\System Event Dispatcher] 'ImagePath' = '%WINDIR%\winipbin\sgvrfy32.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\System Event Dispatcher] 'Start' = '00000002'
- %WINDIR%\winipbin\bissimo.dll
- %WINDIR%\winipbin\svrltmgr.dll
- %WINDIR%\winipbin\quasimo.dll
- %WINDIR%\winipbin\mossimo.dll
- %WINDIR%\winipbin\sgvrfy32.exe
- %TEMP%\ra.dll
- %WINDIR%\winipbin\eanipw.dll
- %WINDIR%\winipbin\cmproxfr.dll
- %WINDIR%\winipbin\rcxaemap.dll
- %TEMP%\MSVxRsc.dll
- %TEMP%\UUU2.tmp
- %WINDIR%\Logs\splog.txt
- %TEMP%\UUU1.tmp
- %WINDIR%\winipbin\svrltwp.dll
- %WINDIR%\winipbin\vdorctrl.dll
- %WINDIR%\winipbin\secuxsys32.dll
- %TEMP%\UUU3.tmp
- %TEMP%\ra.dll
- %TEMP%\MSVxRsc.dll
- %TEMP%\UUU3.tmp
- %TEMP%\UUU1.tmp
- %TEMP%\UUU2.tmp
- '<LOCALNET>.0.2':16773
- '%WINDIR%\winipbin\sgvrfy32.exe'
- '%WINDIR%\winipbin\sgvrfy32.exe' -i