Техническая информация
- '%TEMP%\bedfhebddf.exe' 8]3]5]9]1]1]7]8]4]8]0 J01EOzwvGSdPTUJIRj80Lx8oRkFMV0dPRkBDPCkYKzxJS1FEOzwvGSc/QUQ1LRsmT1FIPFE7VFdGPzQvHyhLQUpWPU9aTFFLNmBwbHAyLCpqcXUnPEFLSyVRSkcsQElIKkFOPkwbJkJLQjtHQUQ1HSo7MDwmKRwnRCo6KCgfLj0...
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81437547744.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81437547744.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81437547744.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsv2.tmp\rqhmrkm.dll
- %TEMP%\bedfhebddf.fddb
- %TEMP%\fddb.zip
- %TEMP%\bedfhebddf.exe
- %TEMP%\nsv2.tmp\ZipDLL.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81437547744.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- ClassName: '#32770' WindowName: ''