Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'gcodec_update.exe' = '%PROGRAM_FILES%\gCodec\gcodec_update.exe'
- %PROGRAM_FILES%\gCodec\gcodec_update.exe
- %PROGRAM_FILES%\gCodec\gcodec_update.exe (загружен из сети Интернет)
- <SYSTEM32>\regsvr32.exe /s "%PROGRAM_FILES%\gCodec\FLVSplitter\RLOFRDEC.AX"
- <SYSTEM32>\regsvr32.exe /s "%PROGRAM_FILES%\gCodec\FLVSplitter\FLVSplitter.ax"
- <SYSTEM32>\schtasks.exe /create /sc onlogon /tn "Multimdia Great Codec Lite(Video/Audio)" /tr "\"%PROGRAM_FILES%\gCodec\gcodec_update.exe"\" /rl highest
- %PROGRAM_FILES%\gCodec\FLVSplitter\RLOFRDEC.AX
- %TEMP%\00000B2400400000.bin
- %PROGRAM_FILES%\gCodec\FLVSplitter\FLVSplitter.ax
- %PROGRAM_FILES%\gCodec\gcodec_update.exe
- %PROGRAM_FILES%\gCodec\gcodec_uninstall.exe
- %TEMP%\00000B2400400000.bin
- 'gc##ec.com':80
- gc##ec.com/pgm/FLVSplitter.ax
- gc##ec.com/pgm/RLOFRDEC.AX
- gc##ec.com/Z/program_check.php?f=################################
- gc##ec.com/Z/version.php
- gc##ec.com/pgm/gcodec_update.exe
- gc##ec.com/pgm/gcodec_uninstall.exe
- DNS ASK gc##ec.com
- ClassName: 'MS_WINHELP' WindowName: ''