Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\PartMsg] 'Start' = '00000000'
- '<SYSTEM32>\cmd.exe' /c del <Полный путь к вирусу>
- %ALLUSERSPROFILE%\Application Data\Microsoft\Media Player\sqmnoopt01.sqm
- %ALLUSERSPROFILE%\Application Data\Microsoft\Media Player\sqmnoopt02.sqm
- <DRIVERS>\PartMsg.sys
- %ALLUSERSPROFILE%\Application Data\Microsoft\Media Player\sqmnoopt01.sqm.ini
- %ALLUSERSPROFILE%\Application Data\Microsoft\Media Player\sqmnoopt01.sqm.ini