Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'rro' = '%ProgramFiles%\Microsoft\rundll132.exe'
- %ProgramFiles%\microsoft\rundll132.exe
- %WINDIR%\syswow64\rodll.dll
- ClassName: 'RavMonClass' WindowName: 'RavMon.exe'