Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\uvnc_service_autoit] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\uvnc_service_autoit] 'ImagePath' = '"%TEMP%\EZVNC\winvnc.exe" -service'
- %TEMP%\aut831c.tmp
- %TEMP%\ezvnc\winvnc.exe
- %TEMP%\aut83c9.tmp
- %TEMP%\ezvnc\ultravnc.ini
- %TEMP%\aut83e9.tmp
- %TEMP%\ezvnc\vnchooks.dll
- %TEMP%\aut83fa.tmp
- %TEMP%\ezvnc\pcgeek.bmp
- %TEMP%\aut840b.tmp
- %TEMP%\ezvnc\securevncplugin.dsm
- %TEMP%\aut844a.tmp
- %TEMP%\ezvnc\server_securevnc.pkey
- %TEMP%\aut831c.tmp
- %TEMP%\aut83c9.tmp
- %TEMP%\aut83e9.tmp
- %TEMP%\aut83fa.tmp
- %TEMP%\aut840b.tmp
- %TEMP%\aut844a.tmp
- 'ba#####ox.homeip.net':5500
- DNS ASK ba#####ox.homeip.net
- ClassName: 'WinVNC Tray Icon' WindowName: ''
- '%TEMP%\ezvnc\winvnc.exe' -install uvnc_service_autoit
- '%TEMP%\ezvnc\winvnc.exe' -service
- '%TEMP%\ezvnc\winvnc.exe' -service_run
- '%TEMP%\ezvnc\winvnc.exe' -autoreconnect -connect battlebox.homeip.net
- '%WINDIR%\syswow64\net.exe' start "uvnc_service_autoit"' (со скрытым окном)
- '%WINDIR%\syswow64\net.exe' start "uvnc_service_autoit"
- '%WINDIR%\syswow64\net1.exe' start "uvnc_service_autoit"
- '%WINDIR%\syswow64\sc.exe' delete uvnc_service_autoit