Техническая информация
- '%TEMP%\dcbcabfhdcaf.exe' 1-1-5-7-4-4-5-4-0-9-0 Lk9EPTkuLS0gJlNUQUtCQDkrHC9FRVNWSktHRT85MRcvQ0hOTUVAOC40LTAwHyo8RUA4LCAmUFFOP04/UFpFRDQxNTgvGStPQE5WPFJeVE1FOWRvcHAxLy5ybW8qQEBPSyRUTk8oOkxMKUVOPU8fLj5FRT9GRUQ0Mi9TMzpKL0hWMVg4TXdePy9oS01GRTF4eWRiSCwrLC4XL0MwOCozMjE0MRcvQzE4Ki4xNC8xFy9DMjgmLRwqQDQ0LTAfKj0xOSgtICZQUU4/Tj9QWkxSQFZAQlQ2HCtLTk87VUJTWj5RSDw5ICZQUU4/Tj9QWkpBREU8Hyo+VEFaUVJDPR8uQFFBWz5JRENJTUQ4GStESk9UVkJRTlJMQU44LiAmVEdASURVS1BbVUlMPB8qT0k5LRwvO1MwPBsoTlFJUElERV5WQEU/S0hBSURBRkRQS0g5GytJSl9RVElNRUlAOXRpdWQfKktBUFBOTkBORl5QTEFOWkBBUFM8MRsoREU/QVg0MR8uRExbQFRKQURJQl5ARz9OVExUPEQ8ZVxlb2EbK0RGV01LSjpAW0RMPSg4Mi0sLSotKzMuKTcfLk9CSUE4LTQpNjgzKyosLxsrREZXTUtKOkBbT0VNPD0yLi0qKy4rLTUhMTE5LC42LC4mUEQ=
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81427241724.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81427241724.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81427241724.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nss2.tmp\xmsyj.dll
- %TEMP%\qq49.dcbcabfhdcaf
- %TEMP%\dcbcabfhdcaf.zip
- %TEMP%\qq49.exe
- %TEMP%\nss2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81427241724.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\qq49.exe в %TEMP%\dcbcabfhdcaf.exe