Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WinDefend' = '%WINDIR%\Wolcipo.exe'
- %PROGRAM_FILES%\Zaqer\Mopeloi\szagram.exe NULL
- %PROGRAM_FILES%\Zaqer\Mopeloi\214.exe NULL
- <SYSTEM32>\msiexec.exe /V
- <SYSTEM32>\msiexec.exe /I "%CommonProgramFiles%\Wise Installation Wizard\WIS789289CAF73A4A16A33154D498CE069F_2_1_4.MSI" WISE_SETUP_EXE_PATH="%PROGRAM_FILES%\Zaqer\Mopeloi\214.exe"
- ClassName: 'TibiaClient' WindowName: ''
- %CommonProgramFiles%\Wise Installation Wizard\WIS789289CAF73A4A16A33154D498CE069F_2_1_4.MSI
- %WINDIR%\Wolcipo.exe
- %TEMP%\1b39b.msi
- %PROGRAM_FILES%\Zaqer\Mopeloi\214.exe
- %PROGRAM_FILES%\Zaqer\Mopeloi\ferggdfgdfgdgsfg.btj
- %PROGRAM_FILES%\Zaqer\Mopeloi\szagram.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''