Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\rddwzj06] 'Start' = '00000000'
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\xpiztx.dll"
- <SYSTEM32>\rddwzj06.dll
- <DRIVERS>\rddwzj06.sys
- %TEMP%\tmp1.CAB
- %TEMP%\tmp2.CAB
- %TEMP%\tmp2.CAB
- %TEMP%\tmp1.CAB
- from <SYSTEM32>\rddwzj06.dll to <SYSTEM32>\xpiztx.dll