Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Explorer' = '%CommonProgramFiles%\ODBC\services.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\winlogon.exe
- %CommonProgramFiles%\ODBC\Au_333.dll
- %CommonProgramFiles%\ODBC\Au_444.dll
- %CommonProgramFiles%\ODBC\Au_Qvod.dll
- %CommonProgramFiles%\ODBC\services.exe
- <SYSTEM32>\reg.exe ADD "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v Explorer /t REG_SZ /d "%CommonProgramFiles%\ODBC\services.exe"
- <SYSTEM32>\cmd.exe /c mybat.bat
- %CommonProgramFiles%\ODBC\au_muti.au
- %CommonProgramFiles%\ODBC\Au_333.dll
- %CommonProgramFiles%\ODBC\Au_444.TMP
- <Текущая директория>\mybat.bat
- %CommonProgramFiles%\ODBC\Au_444.dll
- %CommonProgramFiles%\ODBC\Au_Qvod.dll
- %CommonProgramFiles%\ODBC\Au_Qvod.TMP
- %CommonProgramFiles%\ODBC\Au_222.TMP
- %CommonProgramFiles%\ODBC\Au_333.TMP
- %CommonProgramFiles%\ODBC\services.exe
- %CommonProgramFiles%\ODBC\Au_333.TMP
- %CommonProgramFiles%\ODBC\Au_444.TMP
- %CommonProgramFiles%\ODBC\Au_Qvod.TMP
- %CommonProgramFiles%\ODBC\Au_222.TMP
- 'dl##.tzxfhq.cn':8
- DNS ASK dl##.tzxfhq.cn
- ClassName: 'Shell_TrayWnd' WindowName: ''