Техническая информация
- '%TEMP%\cdcabfeged.exe' 6-6-8-5-2-0-3-3-0-4-8 KUpBPzswHSxTUTpKQzw4LiAsS0VQT0lMQ0RCPS0dL0BBTU5BPzswHSxDRTw3KhgqTlJMQVU/TFlDPDguICxQRU5OP0xXUFBMOmV0cGg0KSduY3JzK3RkXSdbaGsrZF5xYSphaGBnGy1DSUZDR0E+NxgqQjE6KjEcJz4sNSgvICxBMzklKxonPzI9Ki4gKzwvNyUsHi9NT09ATT1OV0tQSVM+Q1U1GilITU1EUkBUWz1PRjk4Hi9NT09ATT1OV0k/TUI6ICs9Uj9XUFBMOh0vQVA/WTtIQkxGS0U5GClCR05SXz9PT1NLP0w1Kx4vUUVBSkNTSU1aU1JJOiArTkc3KhstRFAuPRwnTE9GT0dNQlxXQUQ9SUVAR00+REVRSkY3GCpHU1xPVUpMQ0c9OHJycmIgK0o/Tk1NTElLRF9RSz9MVz8/WVA6MhwnQkM8QFY9Lh0vRUtZPlFJP01GQF9BRj1MUUtSRUE6Zl1kbV8YKkJPVEtMSzk+WUFLOzE1NS41MCgwLykvICxRSUk9NyssLTA5NS0xNTAaKTxKVU5JTEFAV05DRUA7MiwwLy4oKy8iLzgxMzczNCJKRw==
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81423086668.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81423086668.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81423086668.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsy2.tmp\fzy.dll
- %TEMP%\rc31.cdcabfeged
- %TEMP%\cdcabfeged.zip
- %TEMP%\rc31.exe
- %TEMP%\nsy2.tmp\nsisunz.dll
- %TEMP%\81423086668.txt
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\PerfStringBackup.TMP
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\rc31.exe в %TEMP%\cdcabfeged.exe