Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'tvncontrol' = '"%WINDIR%\tvnserver.exe" -controlservice -slave'
- [<HKLM>\SYSTEM\ControlSet001\Services\tvnserver] 'Start' = '00000002'
- '%WINDIR%\tvnserver.exe' -start -silent
- '%WINDIR%\tvnserver.exe' -service
- '%WINDIR%\tvnserver.exe' -controlservice -slave
- '%TEMP%\ae18234\setup.exe' -d "<Текущая директория>"
- '%WINDIR%\TTProxy.exe' -o
- '%WINDIR%\tvnserver.exe' -install -silent
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 1 -w 100
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "SoftwareSASGeneration" /t "REG_DWORD" /d "1" /f
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\°ІЧ°.bat""
- %WINDIR%\ttvnc.ini
- %WINDIR%\TTProxy.log
- %WINDIR%\°ІЧ°.bat
- %WINDIR%\tvnserver.exe
- %WINDIR%\TTProxy.exe
- %TEMP%\ae18234\јтМеЦРОД.dat
- %TEMP%\ae18234\setup.exe
- %TEMP%\ae18234\setup.ini
- %TEMP%\ae18234\setup.zip
- ClassName: 'Shell_TrayWnd' WindowName: ''