Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RWLN] 'Startup' = 'WLEventStartup'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RWLN] 'Logon' = 'WLEventLogon'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RWLN] 'DllName' = 'RWLN.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\RManService] 'ImagePath' = '%ProgramFiles%\Install\NETWork.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\RManService] 'Start' = '00000002'
- '%ProgramFiles%\Install\NETWork.exe' /start
- '%ProgramFiles%\Install\NETWork.exe'
- '%ProgramFiles%\Install\NETWork.exe' /firewall
- '%WINDIR%\regedit.exe' /s "%ProgramFiles%\Install\regedit.reg"
- '%ProgramFiles%\Install\NETWork.exe' /silentinstall
- %ProgramFiles%\Install\vp8encoder.dll
- %ProgramFiles%\Install\vp8decoder.dll
- %ProgramFiles%\Install\Logs\rms_log_2017-04.html
- %ProgramFiles%\Install\settings.ini
- %ProgramFiles%\Install\NETWork.exe
- %ProgramFiles%\Install\regedit.reg
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'AutoHotkey' WindowName: '<Полный путь к файлу>'