Jump to content

A question about the WinVNC payload


Recommended Posts

Posted

I saw that a program called services.exe installs the WinVNC app as a service. My question is, what does it exactly do, and is the source code available?

This is because I am making my own payload, and services.exe is the only program that is still detected by my AV (trying to make a pyload that doesn't need to kill any antiviruses)

EDIT: i got it working without using services.exe, topic can be locked or whatever

Posted

I am talking about the services.exe in the winvnc payload. This is probably a different program with the same name, because I don't think that antivirus software would detect a legit windows application..

Posted

yeah but he wants to make a stick that install's vnc , without the need for a av kill and without the virus detectors going off ...

Posted

it can be done, I was just lazy to do it, look at the hacksaw, follow the same struckture and use a registry in the run registery to auto run the winvnc. Its not hard, I jsut did it that way cuz I was in a rush

Posted

Can you tell me which registry entries are created/modified??

EDIT: nevermind guys, I've found a way to do it without even using services.exe

Posted
Can you tell me which registry entries are created/modified??

EDIT: nevermind guys, I've found a way to do it without even using services.exe

can u release wot u've got ?

Posted

Yeah sure. I used regmon to to check what registry entries were created when the services.exe would be used, and I saw that they were exactly the same as those in vncdmp2.reg, meaning that the entire services.exe component was not necessary..

So I deleted services.exe, and removed it from services.bat in the VNCInstallfiles dir. I tried it out, and it worked just like it used to, without my antivirus going crazy :D

  • 2 months later...
Posted

lol, I forgot I made this topic :P

I do have to say that the installation doesn't occur correctly without the services.exe, not sure what the reason is though

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...