Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'esven' = '%APPDATA%\esven.exe'
- schost32.exe
- %TEMP%\schost32.exe
- %TEMP%\ventrilo-3.0.1-windows-i386.exe
- %CommonProgramFiles(x86)%\wise installation wizard\wis789289caf73a4a16a33154d498ce069f_3_0_1.msi
- %APPDATA%\esven.exe
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\ventrilo-3.0.1-windows-i386.exe'
- '%TEMP%\schost32.exe'
- '%WINDIR%\syswow64\msiexec.exe' /I "%CommonProgramFiles(x86)%\Wise Installation Wizard\WIS789289CAF73A4A16A33154D498CE069F_3_0_1.MSI" WISE_SETUP_EXE_PATH="%TEMP%\ventrilo-3.0.1-Windows-i386.exe"