Техническая информация
- [<HKLM>\Software\Classes\WinNexus WDF file\shell\open\command] '' = '%ProgramFiles%\WinNexus\Desktop\bin\WinNexusLoader.exe %1'
- [<HKLM>\Software\Classes\winnexus\shell\open\command] '' = '"%ProgramFiles%\WinNexus\Desktop\bin\WinNexusLoader.exe" "%1"'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'ctcontrol' = '"%ProgramFiles%\WinNexus\Desktop\bin\tvnserver.exe" -controlservice -slave'
- [<HKLM>\System\CurrentControlSet\Services\WNSvc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\WNSvc] 'ImagePath' = '%ProgramFiles%\WinNexus\Desktop\bin\WNSvc.exe'
- [<HKLM>\System\CurrentControlSet\Services\WNPPDx64] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\WNPPDx64] 'ImagePath' = '%WINDIR%\SysWOW64\drivers\WNPPDx64.sys'
- [<HKLM>\System\CurrentControlSet\Services\ctserver] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\ctserver] 'ImagePath' = '"%ProgramFiles%\WinNexus\Desktop\bin\tvnserver.exe" -service'
- 'WNSvc' %ProgramFiles%\WinNexus\Desktop\bin\WNSvc.exe
- 'WNPPDx64' %WINDIR%\SysWOW64\drivers\WNPPDx64.sys
- 'ctserver' "%ProgramFiles%\WinNexus\Desktop\bin\tvnserver.exe" -service
- %TEMP%\is-fnr7e.tmp\<Имя файла>.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-qcs4h.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-ff84d.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-4hfde.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-u59ra.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-gbih4.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-s8s9u.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-g3b2b.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-q8iqf.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-hb335.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-e26db.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-ej46r.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-rr1j6.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-g227c.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-fhd3t.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-965m5.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-jbmnl.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-mjlgj.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-aqmir.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-ik0vh.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-960u4.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-slgqg.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-1luhd.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-1a868.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-bvf0s.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-35d6r.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-b846s.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-cp4mt.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-rn0nc.tmp
- %ProgramFiles%\winnexus\desktop\bin\client\deviceinfofile\0ac197c0-9270-11eb-a67b-606b644f3d37_hardware.json
- %ProgramFiles%\winnexus\desktop\bin\is-r5s85.tmp
- %ProgramFiles%\winnexus\desktop\bin\uuid.ct
- %ProgramFiles%\winnexus\desktop\bin\winnexuslog\desktop.log
- %ProgramFiles%\winnexus\desktop\bin\winnexuslog\error.log
- %ProgramFiles%\winnexus\desktop\bin\winnexuslog\info.log
- %ProgramFiles%\winnexus\desktop\bin\winnexuslog\action.log
- %WINDIR%\wnsvc.log
- %ProgramFiles%\winnexus\desktop\bin\globalhookdllx64.dll
- %ProgramFiles%\winnexus\desktop\bin\globalhookdll.dll
- %WINDIR%\wnsvcaction.log
- %WINDIR%\winnexusdesktopinstall.log
- %ProgramFiles%\winnexus\desktop\unins000.dat
- %ProgramFiles%\winnexus\desktop\bin\is-slbbl.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-ll81h.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-oi7cr.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-u0bbo.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-q5d08.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-dm6gk.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-m3iso.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-9nvf0.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-o27gn.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-l727n.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-ka5sb.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-3l0qn.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-rb262.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-tpa9c.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-tk1kg.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-vrj0s.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-hsaoh.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-r61u4.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-cdugm.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-5igik.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-m4ine.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-fv0te.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-8tb9t.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-jum88.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-0i2ri.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-69il9.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-als02.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-9n022.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-19ita.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-api9e.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-g945g.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-nk5oo.tmp
- %ProgramFiles%\winnexus\desktop\bin\language\errormessage\is-vnrlc.tmp
- %ProgramFiles%\winnexus\desktop\bin\language\errormessage\is-88o15.tmp
- %ProgramFiles%\winnexus\desktop\bin\language\source\is-jnq8e.tmp
- %ProgramFiles%\winnexus\desktop\bin\language\source\is-6nibb.tmp
- %ProgramFiles%\winnexus\desktop\bin\language\source\is-skmep.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-cp8nn.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-m3gr5.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-58j19.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-lsbiv.tmp
- %ProgramFiles%\winnexus\desktop\bin\is-skfsb.tmp
- %ProgramFiles%\winnexus\desktop\is-ir8js.tmp
- %TEMP%\is-j8s8e.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-j8s8e.tmp\_isetup\_setup64.tmp
- %ProgramFiles%\winnexus\desktop\bin\language\errormessage\is-1r410.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-jrr5a.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-ohmbg.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-aaivu.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-iu1sl.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-1vuo5.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-0jtvt.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-e4crg.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-pd5ms.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-vc0l6.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-3q8r3.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-mqan4.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-o2c3c.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-vjavg.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-91llo.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-5602l.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-a5ses.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-khg9g.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-je8p4.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-4bc6b.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-fka4e.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-sbqot.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-0ps2e.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-0hved.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-l183e.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-1ehgg.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-vr92v.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-nvtb3.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-cn99p.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-09n6c.tmp
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-cenem.tmp
- %ProgramFiles%\winnexus\desktop\bin\client\deviceinfofile\0ac197c0-9270-11eb-a67b-606b644f3d37_hardware.zip
- %ProgramFiles%\winnexus\desktop\bin\tmpcmdkey.exe
- %ProgramFiles%\winnexus\desktop\bin\tmpglobalhookdll.dll
- %ProgramFiles%\winnexus\desktop\bin\tmpglobalhookdllx64.dll
- %TEMP%\is-j8s8e.tmp\_isetup\_setup64.tmp
- %TEMP%\is-j8s8e.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-fnr7e.tmp\<Имя файла>.tmp
- %ProgramFiles%\winnexus\desktop\bin\client\deviceinfofile\0ac197c0-9270-11eb-a67b-606b644f3d37_hardware.json
- %ProgramFiles%\winnexus\desktop\bin\client\deviceinfofile\0ac197c0-9270-11eb-a67b-606b644f3d37_hardware.zip
- %ProgramFiles%\winnexus\desktop\is-ir8js.tmp в %ProgramFiles%\winnexus\desktop\unins000.exe
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-e26db.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\mainapplication.ico
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-ej46r.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\mainabout.ico
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-rr1j6.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\desktop.png
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-fhd3t.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\desktop.ico
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-cp4mt.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\cv-01_131655730552736099.ico
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-965m5.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\about.png
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-jbmnl.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\77777-01_131655724859755184.ico
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-mjlgj.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\6666-01_131655724747408550.ico
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-aqmir.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\666-01_131655724583341725.ico
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-ik0vh.tmp в %ProgramFiles%\winnexus\desktop\bin\res\eng\stop.ico
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-hb335.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\mainfiletype.ico
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-960u4.tmp в %ProgramFiles%\winnexus\desktop\bin\res\eng\run.ico
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-1luhd.tmp в %ProgramFiles%\winnexus\desktop\bin\res\eng\new.ico
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-1a868.tmp в %ProgramFiles%\winnexus\desktop\bin\res\eng\networktab_enable.ico
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-bvf0s.tmp в %ProgramFiles%\winnexus\desktop\bin\res\eng\networktab.ico
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-35d6r.tmp в %ProgramFiles%\winnexus\desktop\bin\res\eng\filetypetab_enable.ico
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-b846s.tmp в %ProgramFiles%\winnexus\desktop\bin\res\eng\filetypetab.ico
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-ll81h.tmp в %ProgramFiles%\winnexus\desktop\bin\res\eng\edit.ico
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-r61u4.tmp в %ProgramFiles%\winnexus\desktop\bin\res\eng\applicationtab_enable.ico
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-a5ses.tmp в %ProgramFiles%\winnexus\desktop\bin\res\eng\applicationtab.ico
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-ohmbg.tmp в %ProgramFiles%\winnexus\desktop\bin\res\eng\add.ico
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-iu1sl.tmp в %ProgramFiles%\winnexus\desktop\bin\res\eng\abouttab_enable.ico
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-slgqg.tmp в %ProgramFiles%\winnexus\desktop\bin\res\eng\remove.ico
- %ProgramFiles%\winnexus\desktop\bin\is-tpa9c.tmp в %ProgramFiles%\winnexus\desktop\bin\launchrdp.exe
- %ProgramFiles%\winnexus\desktop\bin\is-oi7cr.tmp в %ProgramFiles%\winnexus\desktop\bin\libcurl.dll
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-s8s9u.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\slidebar.jpg
- %ProgramFiles%\winnexus\desktop\bin\is-rn0nc.tmp в %ProgramFiles%\winnexus\desktop\bin\appexec.exe
- %ProgramFiles%\winnexus\desktop\bin\is-u0bbo.tmp в %ProgramFiles%\winnexus\desktop\bin\virtreg.dll
- %ProgramFiles%\winnexus\desktop\bin\is-q5d08.tmp в %ProgramFiles%\winnexus\desktop\bin\winnexusloader.exe
- %ProgramFiles%\winnexus\desktop\bin\is-dm6gk.tmp в %ProgramFiles%\winnexus\desktop\bin\winnexuscommandrunas.exe
- %ProgramFiles%\winnexus\desktop\bin\is-m3iso.tmp в %ProgramFiles%\winnexus\desktop\bin\7za.exe
- %ProgramFiles%\winnexus\desktop\bin\is-9nvf0.tmp в %ProgramFiles%\winnexus\desktop\bin\log4cplus.dll
- %ProgramFiles%\winnexus\desktop\bin\is-o27gn.tmp в %ProgramFiles%\winnexus\desktop\bin\log4clpus.cfg
- %ProgramFiles%\winnexus\desktop\bin\is-l727n.tmp в %ProgramFiles%\winnexus\desktop\bin\desktopinstall.exe
- %ProgramFiles%\winnexus\desktop\bin\is-ka5sb.tmp в %ProgramFiles%\winnexus\desktop\bin\syssoftcfg.ct
- %ProgramFiles%\winnexus\desktop\bin\is-3l0qn.tmp в %ProgramFiles%\winnexus\desktop\bin\agentcfg.ct
- %ProgramFiles%\winnexus\desktop\bin\res\eng\is-1vuo5.tmp в %ProgramFiles%\winnexus\desktop\bin\res\eng\abouttab.ico
- %ProgramFiles%\winnexus\desktop\bin\is-rb262.tmp в %ProgramFiles%\winnexus\desktop\bin\wnsvc.exe
- %ProgramFiles%\winnexus\desktop\bin\is-tk1kg.tmp в %ProgramFiles%\winnexus\desktop\bin\wnagent.exe
- %ProgramFiles%\winnexus\desktop\bin\is-r5s85.tmp в %ProgramFiles%\winnexus\desktop\bin\getsysteminfo.exe
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-hsaoh.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\tabbar_setting_loginmsg.bmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-vrj0s.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\tabbar_setting.bmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-g227c.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\tabbar_login.bmp
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-qcs4h.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\tabbar2.jpg
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-ff84d.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\tabbar120.jpg
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-4hfde.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\tabbar.jpg
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-u59ra.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\tabbar-01.jpg
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-gbih4.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\slidebar120.jpg
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-q8iqf.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\mainnetwork.ico
- %ProgramFiles%\winnexus\desktop\bin\res\common\is-g3b2b.tmp в %ProgramFiles%\winnexus\desktop\bin\res\common\rrrr-01.png
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-0jtvt.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\stop.png
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-cenem.tmp в %ProgramFiles%\winnexus\desktop\bin\res\chs\stop.ico
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-m4ine.tmp в %ProgramFiles%\winnexus\desktop\bin\res\chs\new.ico
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-fv0te.tmp в %ProgramFiles%\winnexus\desktop\bin\res\chs\networktab_enable.ico
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-8tb9t.tmp в %ProgramFiles%\winnexus\desktop\bin\res\chs\networktab.ico
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-jum88.tmp в %ProgramFiles%\winnexus\desktop\bin\res\chs\filetypetab_enable.ico
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-0i2ri.tmp в %ProgramFiles%\winnexus\desktop\bin\res\chs\filetypetab.ico
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-69il9.tmp в %ProgramFiles%\winnexus\desktop\bin\res\chs\edit.ico
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-als02.tmp в %ProgramFiles%\winnexus\desktop\bin\res\chs\applicationtab_enable.ico
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-9n022.tmp в %ProgramFiles%\winnexus\desktop\bin\res\chs\applicationtab.ico
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-19ita.tmp в %ProgramFiles%\winnexus\desktop\bin\res\chs\add.ico
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-api9e.tmp в %ProgramFiles%\winnexus\desktop\bin\res\chs\abouttab_enable.ico
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-5igik.tmp в %ProgramFiles%\winnexus\desktop\bin\res\chs\remove.ico
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-g945g.tmp в %ProgramFiles%\winnexus\desktop\bin\res\chs\abouttab.ico
- %ProgramFiles%\winnexus\desktop\bin\language\errormessage\is-1r410.tmp в %ProgramFiles%\winnexus\desktop\bin\language\errormessage\desktop_cht.mwm
- %ProgramFiles%\winnexus\desktop\bin\language\errormessage\is-88o15.tmp в %ProgramFiles%\winnexus\desktop\bin\language\errormessage\desktop_chs.mwm
- %ProgramFiles%\winnexus\desktop\bin\language\source\is-jnq8e.tmp в %ProgramFiles%\winnexus\desktop\bin\language\source\eng.ct
- %ProgramFiles%\winnexus\desktop\bin\language\source\is-6nibb.tmp в %ProgramFiles%\winnexus\desktop\bin\language\source\cht.ct
- %ProgramFiles%\winnexus\desktop\bin\language\source\is-skmep.tmp в %ProgramFiles%\winnexus\desktop\bin\language\source\chs.ct
- %ProgramFiles%\winnexus\desktop\bin\is-cp8nn.tmp в %ProgramFiles%\winnexus\desktop\bin\wnmonitor.exe
- %ProgramFiles%\winnexus\desktop\bin\is-m3gr5.tmp в %ProgramFiles%\winnexus\desktop\bin\tmpglobalhookdllx64.dll
- %ProgramFiles%\winnexus\desktop\bin\is-58j19.tmp в %ProgramFiles%\winnexus\desktop\bin\tmpglobalhookdll.dll
- %ProgramFiles%\winnexus\desktop\bin\is-lsbiv.tmp в %ProgramFiles%\winnexus\desktop\bin\wnxuninstall.exe
- %ProgramFiles%\winnexus\desktop\bin\is-skfsb.tmp в %ProgramFiles%\winnexus\desktop\bin\tmpcmdkey.exe
- %ProgramFiles%\winnexus\desktop\bin\language\errormessage\is-vnrlc.tmp в %ProgramFiles%\winnexus\desktop\bin\language\errormessage\desktop_eng.mwm
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-fka4e.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\filetypetab.ico
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-pd5ms.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\run.ico
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-cdugm.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\abouttab .png
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-vc0l6.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\rin.png
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-3q8r3.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\remove.png
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-mqan4.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\remove.ico
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-o2c3c.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\new.png
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-vjavg.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\new.ico
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-91llo.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\networktab_enable.ico
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-5602l.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\networktab_b_enable.png
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-khg9g.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\networktab.ico
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-jrr5a.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\filetypetab_enable.png
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-je8p4.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\filetypetab_enable.ico
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-e4crg.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\stop.ico
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-4bc6b.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\filetypetab.png
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-sbqot.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\edit.ico
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-0ps2e.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\applicationtab_enable.png
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-0hved.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\applicationtab_enable.ico
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-l183e.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\applicationtab.png
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-1ehgg.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\applicationtab.ico
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-vr92v.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\add.png
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-nvtb3.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\add.ico
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-cn99p.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\abouttab_enable.png
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-09n6c.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\abouttab_enable.ico
- %ProgramFiles%\winnexus\desktop\bin\res\cht\is-aaivu.tmp в %ProgramFiles%\winnexus\desktop\bin\res\cht\abouttab.ico
- %ProgramFiles%\winnexus\desktop\bin\res\chs\is-nk5oo.tmp в %ProgramFiles%\winnexus\desktop\bin\res\chs\run.ico
- %ProgramFiles%\winnexus\desktop\bin\is-slbbl.tmp в %ProgramFiles%\winnexus\desktop\bin\tvnserver.exe
- 'wi#####s.ct-cloud.cn':8080
- 'wi#####s.ct-cloud.cn':3000
- 'localhost':45464
- http://wi######.ct-cloud.cn:8080/api/1/preprocess?ty#############################################################################################################################################...
- http://wi######.ct-cloud.cn:3000/socket.io/?EI#################################### via wi#####s.ct-cloud.cn
- http://wi######.ct-cloud.cn:8080/api/1/service_report via wi#####s.ct-cloud.cn
- DNS ASK wi#####s.ct-cloud.cn
- '%TEMP%\is-fnr7e.tmp\<Имя файла>.tmp' /SL5="$120220,3686807,56832,<Полный путь к файлу>"
- '%ProgramFiles%\winnexus\desktop\bin\desktopinstall.exe' /install
- '%ProgramFiles%\winnexus\desktop\bin\wnsvc.exe'
- '%ProgramFiles%\winnexus\desktop\bin\wnagent.exe' /startup
- '%ProgramFiles%\winnexus\desktop\bin\wnmonitor.exe' 45464
- '%ProgramFiles%\winnexus\desktop\bin\tvnserver.exe' -install -silent
- '%ProgramFiles%\winnexus\desktop\bin\tvnserver.exe' -start -silent
- '%ProgramFiles%\winnexus\desktop\bin\tvnserver.exe' -service
- '%ProgramFiles%\winnexus\desktop\bin\tvnserver.exe' -controlservice -slave
- '%ProgramFiles%\winnexus\desktop\bin\getsysteminfo.exe' /initAllInfoNoProcess "%ProgramFiles%\WinNexus\Desktop\bin\Client\DeviceInfoFile\0ac197c0-9270-11eb-a67b-606b644f3d37_Hardware.json"
- '%ProgramFiles%\winnexus\desktop\bin\7za.exe' a -tzip "%ProgramFiles%\WinNexus\Desktop\bin\Client\DeviceInfoFile\0ac197c0-9270-11eb-a67b-606b644f3d37_Hardware.zip" "%ProgramFiles%\WinNexus\Desktop\bin\Client\DeviceInfoFile\0ac197c0-9270-11...
- '%ProgramFiles%\winnexus\desktop\bin\desktopinstall.exe' /install' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c sc stop WNPPDx64' (со скрытым окном)
- '%ProgramFiles%\winnexus\desktop\bin\tvnserver.exe' -install -silent' (со скрытым окном)
- '%ProgramFiles%\winnexus\desktop\bin\tvnserver.exe' -start -silent' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c sc stop WNPPDx64
- '<SYSTEM32>\cmd.exe' icacls "<SYSTEM32>\WpdMtpUS.dll" /grant users:F
- '<SYSTEM32>\cmd.exe' icacls "<SYSTEM32>\WpdMtpUS.dll" /grant administrators:F
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\WpdMtpUS.dll"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\WpdMtp.dll" /grant users:F
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\WpdMtp.dll" /grant administrators:F
- '%WINDIR%\syswow64\net1.exe' start bthserv
- '<SYSTEM32>\cmd.exe' takeown /f "<SYSTEM32>\WpdMtpUS.dll"
- '<SYSTEM32>\cmd.exe' icacls "<SYSTEM32>\WpdMtp.dll" /grant users:F
- '<SYSTEM32>\cmd.exe' icacls "<SYSTEM32>\WpdMtp.dll" /grant administrators:F
- '%WINDIR%\syswow64\net.exe' start bthserv
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\bthserv.dll" /grant users:F
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\bthserv.dll" /grant administrators:F
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\WpdMtp.dll"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\WpdMtpUS.dll" /grant administrators:F
- '<SYSTEM32>\cmd.exe' takeown /f "<SYSTEM32>\WpdMtp.dll"
- '<SYSTEM32>\svchost.exe' -k bthsvcs
- '<SYSTEM32>\cmd.exe' icacls "<SYSTEM32>\bthserv.dll" /grant users:F
- '<SYSTEM32>\cmd.exe' icacls "<SYSTEM32>\bthserv.dll" /grant administrators:F
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\bthserv.dll"
- '<SYSTEM32>\cmd.exe' takeown /f "<SYSTEM32>\bthserv.dll"
- '%WINDIR%\syswow64\icacls.exe' "%WINDIR%\WinSxS" /grant administrators:F
- '%WINDIR%\syswow64\sc.exe' start WNPPDx64
- '%WINDIR%\syswow64\takeown.exe' /f "%WINDIR%\WinSxS"
- '%WINDIR%\syswow64\cmd.exe' /c sc start WNPPDx64
- '%WINDIR%\syswow64\sc.exe' create WNPPDx64 binPath= "%WINDIR%\SysWOW64\drivers\WNPPDx64.sys" type= "kernel" start= "auto" Displayname= "WNPPDx64"
- '%WINDIR%\syswow64\cmd.exe' /c sc create WNPPDx64 binPath= "%WINDIR%\SysWOW64\drivers\WNPPDx64.sys" type= "kernel" start= "auto" Displayname= "WNPPDx64"
- '%WINDIR%\syswow64\cmd.exe' /c takeown /f "%WINDIR%\WinSxS" && icacls "%WINDIR%\WinSxS" /grant administrators:F
- '%WINDIR%\syswow64\sc.exe' stop WNPPDx64
- '%WINDIR%\syswow64\cmd.exe' net start bthserv
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\WpdMtpUS.dll" /grant users:F