Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\491vag.lnk
- '<SYSTEM32>\rundll32.exe' %TEMP%\gav194.dss,FFZ4
- '<SYSTEM32>\rundll32.exe' %ALLUSERSPROFILE%\Application Data\gav194.dss,FFZ0
- %ALLUSERSPROFILE%\Application Data\491vag.bxx
- %TEMP%\gav194.dss
- %ALLUSERSPROFILE%\Application Data\gav194.dss