Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VmmSrv] 'Startup' = 'StartProcessAtStartup'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VmmSrv] 'DllName' = 'VmmReg.dll'
- %WINDIR%\Explorer.EXE
- %TEMP%\~WRS9876.tmp
- <SYSTEM32>\VmmReg.dll
- %TEMP%\~WRS9876.tmp