每次关机 创建键值
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"afoio"=hex(2):25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,00,74,\
00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,52,00,\
75,00,6e,00,64,00,6c,00,6c,00,33,00,32,00,2e,00,65,00,78,00,65,00,20,00,25,\
00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,6f,00,6f,00,74,00,25,00,5c,00,\
73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,61,00,66,00,6f,00,69,\
00,6f,00,2e,00,64,00,6c,00,6c,00,2c,00,44,00,6c,00,6c,00,55,00,6e,00,72,00,\
65,00,67,00,69,00,73,00,74,00,65,00,72,00,53,00,65,00,72,00,76,00,65,00,72,\
00,00,00
%systemroot%\system32\Rundll32.exe %systemroot%\system32\afoio.dll,DllUnregisterServer
每次启动完毕后 此键自动被删除(正常模式,安全模式不会被删除,这个是在安全模式下找到的),关机时自动又创建,看注册表记录,曾经winlogon创建了这个键值。后来不知道是怎么回事了。我将这个dll删除,现在一直有加载不到这个模块的错误提示。
用记事本打开 其dll 发现 网址 http://www.pbqc.com/f2/up.dat?p=%s&g=%s
打开http://www.pbqc.com/ 只有 “hello” 一个词
http://www.pbqc.com/f2/up.dat?p=%s&g=%s 则出现一串乱码