Техническая информация
- '%TEMP%\acaccabfbbbc.exe' 5-2-0-7-3-2-6-7-6-1-1 Kk5JPTouGihNVEFLR0Q2LR4pRz9TVkpQS0JBOyoZKUNITlJJPTouGig9SEM4LiAoTVBJPU9CU1pHRDYtHilMP1FVQFBfTk9KN2Fuc281LS9sYnBwJ25nZChfcGkqYlttWy1oaWRvGSxBRkI9Skg/OyAoQS83JisfLj8wPSYuHik9LTwsLB4vPTE7JyoaLkMwOy0qHS1KS0lDVD5SX0lPR1A6PVg8Gy1QS0xCTzxOXkRQSkE2HS1KS0lDVD5SX0c+Sz82Gi5EU0NfTk9KNxkpRFdAXUNGQUpDRz88HypGT0xRXTxLSVZSQFA9Kx0tTkE7TUpUTVVYUlBGNhouVUg7MhksQk0qNx8uTVNOTUZLP1hRREs+TU0+Rks7QD9UUUc7IChGUVlLT01TREtFNnFwb14aLlFAUlVLS0dIQFlUUkBQXz0+V002LB8uQ0dEPlU7KxkpSFJaQllHPktDPFlETT5QWUlRQz42YGBrbmMgKEFNUUdGTkA/XUlJOi8sMCgvLSssMRksUkNGPzwwLzAyMTM0LiksHy4/TVdHSU07PVlTSEhDPSkvLSorKTEvLDMqKTU4Lik0LzE=
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81422879970.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81422879970.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81422879970.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsd2.tmp\9tm.dll
- %TEMP%\rc3.acaccabfbbbc
- %TEMP%\acaccabfbbbc.zip
- %TEMP%\rc3.exe
- %TEMP%\nsd2.tmp\nsisunz.dll
- %TEMP%\81422879970.txt
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\PerfStringBackup.TMP
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\rc3.exe в %TEMP%\acaccabfbbbc.exe