Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rundll32.exe' = 'rundll32.exe vim.dll,Prkt'
- <SYSTEM32>\logonui.exe /status /shutdown
- <SYSTEM32>\cmd.exe /c ""%WINDIR%\sdel.bat" "<Полный путь к вирусу>""
- %WINDIR%\vim.dll
- %WINDIR%\sdel.bat
- %WINDIR%\buned.sys
- <DRIVERS>\etc\host7
- ClassName: 'StatusWindowClass' WindowName: ''