Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\mqat8z4h.lnk
- '<SYSTEM32>\rundll32.exe' %TEMP%\h4z8taqm.jss,CCZ4
- '<SYSTEM32>\rundll32.exe' %ALLUSERSPROFILE%\Application Data\h4z8taqm.jss,CCZ0
- %ALLUSERSPROFILE%\Application Data\mqat8z4h.fee
- %TEMP%\h4z8taqm.jss
- %ALLUSERSPROFILE%\Application Data\h4z8taqm.jss