Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'AdVantage' = '%APPDATA%\advantage\AdVantage.exe'
- <SYSTEM32>\systeminfo.exe
- %APPDATA%\advantage\AdVantage.exe
- %APPDATA%\Microsoft\Sze\hqhmp
- ClassName: '0 35' WindowName: '0 35'
- ClassName: '523380' WindowName: '37714 '
- ClassName: '1 936' WindowName: '1599 '
- ClassName: '927' WindowName: '8235 '
- ClassName: 'Indicator' WindowName: ''
- ClassName: '7' WindowName: ' 2 2 '
- ClassName: '0 2710' WindowName: '0 2710'
- ClassName: '911 0' WindowName: '898 60833'
- ClassName: ' 5 5 6' WindowName: '06 '
- ClassName: '690 ' WindowName: '690 '
- ClassName: ' 20 ' WindowName: '4 37155'
- ClassName: '9' WindowName: '807'
- ClassName: '2' WindowName: ' 05'
- ClassName: '37714 ' WindowName: '4 37155'