Техническая информация
- '%TEMP%\chcabfcbcei.exe' 7-3-3-6-5-2-5-5-2-4-9 KE1GPjgwLi4eK0pOP01DPzsrGy1KPE1UTExGRz84LhwmPUZQTkRCOC0zMycqHSw9REI4Kx4rR0tMQU8+UlpEQjkoLzYxGipRQE1UQUlYUk9GOGZvb242JihwYmxxLG9jYylYaW0qXlxyXClnal1oHSw9R0c+RkdANCktNTAtMDIyMiwoMjIxLjAvLjM0LxcoQS43KC8bKkIuNCYuHSk/MTgoLxwmPTE6JyweKj8zOSQqHSxKTU0/UEFQVklPRlA8QVQ4HitHS0xBTz5SWkBTSDg2HSxKTU0/UEFQVkc+Sj84HipAVkFWTk9JNxstQFNDWzpGQUlDSUM4Gy1ERkxRXDxNTVJOQ040LB0sTkM/SUZXS0xYUk9GOB4qUUs5KRksQU0sOxsqUFFFTUZKP1pVQEdBS0Q+Rko7QkNQTUo5FyhGUFlNU0lPR0k8NnFvb2AeKk1DUExLS0ZIQl1QTkNOVj0+Vk04MBsqRkU7PlU6KxstRE5dQFBHPkpDPl1ASUFOUElRQj44ZFxncWEXKEFMUUlKSjxCW0BJOjQzKS8yKywxLCcuNiobLU9ES0E0KjEvLS01MzIxLxcoQUxRSUpKPEJbS0JKQjctLTIqMCwoLicwNCwwNSwxJjhG
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81423613523.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81423613523.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81423613523.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsb2.tmp\fat.dll
- %TEMP%\rc7.chcabfcbcei
- %TEMP%\chcabfcbcei.zip
- %TEMP%\rc7.exe
- %TEMP%\nsb2.tmp\nsisunz.dll
- %TEMP%\81423613523.txt
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\PerfStringBackup.TMP
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\rc7.exe в %TEMP%\chcabfcbcei.exe