Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] '%TEMP%\WinVNC.exe' = '%TEMP%\WinVNC.exe:*:Enabled:WinVNC.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\WinVNC.exe' = '%TEMP%\WinVNC.exe:*:Enabled:WinVNC.exe'
- %TEMP%\WinVNC.exe -run
- [<HKCU>\Software\ORL\WinVNC3]
- [<HKLM>\Software\ORL\WinVNC3]
- %TEMP%\VNCHooks.dll
- %TEMP%\MSRC4Plugin_NoReg.dsm
- %TEMP%\rc4.key
- %TEMP%\operators.i1c
- %TEMP%\version.i1c
- %TEMP%\WinVNC.exe
- 'www.in####aticauno.it':80
- www.in####aticauno.it/AR/config/version.i1c
- www.in####aticauno.it/AR/config/operators.i1c
- DNS ASK in######icauno.homeip.net
- DNS ASK www.in####aticauno.it
- ClassName: 'Shell_TrayWnd' WindowName: ''