File of spyware.
Default path: C:\WINDOWS\SYSTEM32\DRIVERS\RINLD.SYS %System%\Ravdm.exe %System%\drivers\Rinld.sys
This virus adds a few items in the startup registry [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] "9"="%System%\Ravdm.exe" |