Техническая информация
- [HKLM\System\CurrentControlSet\Services\WinVNC4] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\WinVNC4] 'ImagePath' = '"C:\PROGRA~2\R-CONT~1\winvnc4.exe" -service'
- 'WinVNC4' "C:\PROGRA~2\R-CONT~1\winvnc4.exe" -service
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%programfiles%\R-controled\winvnc4.exe' = '%programfiles%\R-controle...
- %TEMP%\glc2828.tmp
- %TEMP%\glg2a8b.tmp
- %ProgramFiles(x86)%\r-controled\~glh0000.tmp
- %ProgramFiles(x86)%\r-controled\~glh0001.tmp
- %ProgramFiles(x86)%\r-controled\~glh0002.tmp
- %ProgramFiles(x86)%\r-controled\~glh0003.tmp
- %ProgramFiles%\r-cont~1\install.log
- %TEMP%\glg2a8b.tmp
- %TEMP%\glc2828.tmp
- %ProgramFiles(x86)%\r-controled\~glh0000.tmp в %ProgramFiles(x86)%\r-controled\unwise.exe
- %ProgramFiles(x86)%\r-controled\~glh0001.tmp в %ProgramFiles(x86)%\r-controled\logmessages.dll
- %ProgramFiles(x86)%\r-controled\~glh0002.tmp в %ProgramFiles(x86)%\r-controled\wm_hooks.dll
- %ProgramFiles(x86)%\r-controled\~glh0003.tmp в %ProgramFiles(x86)%\r-controled\winvnc4.exe
- '%ProgramFiles%\r-cont~1\winvnc4.exe' -register' (со скрытым окном)