Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'winap32' = '%APPDATA%\winap32.exe'
- ventrilo.exe
- %TEMP%\ventrilo.exe
- %TEMP%\ventrilo-3.0.1-windows-i386.exe
- %TEMP%\vbc.exe
- %CommonProgramFiles(x86)%\wise installation wizard\wis789289caf73a4a16a33154d498ce069f_3_0_1.msi
- %APPDATA%\winap32.exe
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\ventrilo.exe'
- '%TEMP%\ventrilo-3.0.1-windows-i386.exe'
- '%TEMP%\vbc.exe' -p01u79ob5df
- '%WINDIR%\syswow64\msiexec.exe' /I "%CommonProgramFiles(x86)%\Wise Installation Wizard\WIS789289CAF73A4A16A33154D498CE069F_3_0_1.MSI" WISE_SETUP_EXE_PATH="%TEMP%\ventrilo-3.0.1-windows-i386.exe"