Техническая информация
- '%TEMP%\dcbcabfhefh.exe' 8-5-0-9-3-4-5-5-1-0-5 J0tJOzotKzQzMBsnTlU5TUU/OC8gKkZAVE5MTkZEQz0sGCpEQFBQRD88MTEwLjAXLD9EPzwwGydLUkZBUT5PXkk/NSw2Jy8vGypSRU1OQFJWUk5HOGd0b2g1LyZwbnEpQ0VOQyhURk0pPEtPLkRGQU8XLD9HREJLRDw4ICZBLTgoMCAqPC09JC4cKj8yPSgpGy87MTksGy5EMDUoMRcsTE1KQ1U+TFpQSUZSPD5YPRsnS1JGQVE+T15FUEQ8PRcsTE1KQ1U+TFpOOEpBOHBTb21qYG5rHStAU0RfUEpHPV9xcGs1Li9yb3IuW2xzaWduYV9may5abGkqcG9sallfcyZha3Jpa29cXG4vXWZoYChyaFxqZG5eLHFPanFyYGZvLSorMCksLWVzXSAyJx0rQFNEXz5FP0xAS0E4Gy5ISktPXzlPS1JORFI4KhsvS0U9SUZYT1BXUFJDOhwqUUw9LRgqREouORsqUVVJTERNPFxTQEdCT0g9RE04REFQTUs9GydEU1ZPUUlPSE1ANW9ybGIcKk1EVFBKSUlFRFtQTkRSWjw8WUo6LhsqR0k/PVM9KB0rRE5eRFRGPE1AQFtASUJSVEhPRTs6YlxncmUbJz9PTktISjxDX0RIODEvMiotLS0yLiopOSsdK09ETEU4KS8yLTYzMCw1MxsnP09OS0hKPENfT0FIRTQwKy0sLjIrKTAqMDcxNDUxMyVISA==
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81427229483.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81427229483.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81427229483.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsr2.tmp\nstnn.dll
- %TEMP%\qq49.dcbcabfhefh
- %TEMP%\dcbcabfhefh.zip
- %TEMP%\qq49.exe
- %TEMP%\nsr2.tmp\nsisunz.dll
- %TEMP%\81427229483.txt
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\tmp5.tmp
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\qq49.exe в %TEMP%\dcbcabfhefh.exe