Техническая информация
- '<SYSTEM32>\net.exe' stop "uvnc_service"
- %TEMP%\HZ$D.399.1069\winvnc.exe
- %TEMP%\HZ$D.399.1069\ultravnc.ini
- %TEMP%\HZ$D.399.1069\nircmd.exe
- %TEMP%\HZ$D.399.1069\kycken.exe
- %TEMP%\1.tmp\kycken.bat
- ClassName: 'WinVNC Tray Icon' WindowName: ''
- '%TEMP%\HZ$D.399.1069\winvnc.exe' -kill
- '%TEMP%\HZ$D.399.1069\nircmd.exe' closeprocess winvnc.exe
- '%TEMP%\HZ$D.399.1069\nircmd.exe' wait 3000
- '%TEMP%\HZ$D.399.1069\nircmd.exe' wait 1000
- '%TEMP%\HZ$D.399.1069\kycken.exe'
- '%TEMP%\HZ$D.399.1069\nircmd.exe' win min title "~$folder.nircmd$\kycken.exe"
- '%TEMP%\HZ$D.399.1069\winvnc.exe' -stopservice
- '<SYSTEM32>\net1.exe' stop "uvnc_service"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\kycken.bat""