Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'AdVantage' = '%APPDATA%\advantage\AdVantage.exe'
- <SYSTEM32>\systeminfo.exe
- %APPDATA%\advantage\AdVantage.exe
- %APPDATA%\Microsoft\Sze\hqhmp
- ClassName: ' 8 78 ' WindowName: '2 '
- ClassName: '55341' WindowName: '25'
- ClassName: ' 8 78 ' WindowName: '1297'
- ClassName: 'Indicator' WindowName: ''
- ClassName: '1297' WindowName: '19401'
- ClassName: '0454 04' WindowName: '7279'
- ClassName: '0454 04' WindowName: '3'
- ClassName: '08 18 ' WindowName: ' 21101 '
- ClassName: '08 18 ' WindowName: '05 8 4'
- ClassName: ' 3972' WindowName: ' 51'