Техническая информация
- '%TEMP%\dcecabfhdbfj.exe' 4-0-2-7-6-2-3-6-5-7-3 K1BHPTcvMDArKx0rU1M7SkdBNysZLEpFUlBJUEhDPzYuHC9CQk1SRj44Ky0zNzcZKUFGPjgpHStQUEg+U0BOWkJBOTE3Mi8zHSlOPk9SRVBYT1BJN2NtcWw6LShtcHMoPz5QRy1SSEorPkpLJ0ZKRk0ZKUFJQz5ERkA9Hig+LzonLBksQDI7JiseLD4uNiotIC09LjsqKxsoQTE9KyoaLU1MSj1SP1RdSUxHUzs+UjocL05LSUJSPU9YQlFMPzYaLU1MSj1SP1RdRztLQjdDWmBnX1JoaWodKUBRQltVUEU3Hiw/Uz5cP01CRUNMQjcbKEVLU1JYPFBMUU4+TzkyHihORj5IRlJMUV9TS0Y7HSlRRjouIC09TS86GipLUkpUR0Y/XVQ/RzxMSUVHRjtFQk9NRTocL0dMWVBSSE9CSkE9cmtvYx0pTT5RUVJMQkhFXE9OPk9bRD9STTsvGipBRkBFVjYrHixDTlhBVU4/RkNBXD9JPE9VUFI+PjtjW2dsYhwvQkhRTElJPD1cRVA7KioyKywvLCs1MywxGi1RQ0g+Oi00MDAsMS0yMCkdK0RNUEhKTDs/WFFFTUM2LS0vLiorLS01KDI0Li00MCknTE0=
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81427467024.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81427467024.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81427467024.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsc2.tmp\kabwz.dll
- %TEMP%\jj49.dcecabfhdbfj
- %TEMP%\dcecabfhdbfj.zip
- %TEMP%\jj49.exe
- %TEMP%\nsc2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81427467024.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\jj49.exe в %TEMP%\dcecabfhdbfj.exe