Техническая информация
- '%TEMP%\cccabfhfdb.exe' 3-1-8-1-8-2-5-3-8-6-3 LE9BQzUwLjAYKVBSQUhIPDsrHSdIQlFWR1FDRz86KBosQUhLU0FCOC8sMC0uHydCQUI4LRgpTU9OPFQ7UlpGPDcuMzgsHydRQE9OP09cVEpLNWZvcWg0LCxyXXFuLG9lXSdebW8lY1lyXCthaGNsHydCREc+SEE+Oi0vMC8wMzEtMCouNjIwMy02MzUvLh0sQyk8KC4zLTAvMy03YWJnbDgwGClBLzwlMBgtPzA1Jy4dLjwzNSssHSc+MjosKR8nTk1MPE9AUV5IUUFUPEBRNx0sT0pOPFM+UVc/UklANR8nTk1MPE9AUV5GQEVDOB0nP1VCXk1RRDsbLD1SQlxCRUNER0lCNRosRU5LU1dATUxPTUJPPCofJ1JDPkZFVkxUV1RKSjgdJ1BKOjEYLjxRLDoYKU9STUxIRUNaVD1GQExMPUhFP0JCTUxJOh8nSEtdTVJGTkZKRDVzanNgHSdMQlFUSk1BTEJcTU1CT148QFFROC8YKUVGQz1XNS8bLEFNXEFYRkBFRz5cPUhAT1hIUz1COGNZZnBiHydDR1VJSUc7QVxISDwvNSkvMSgwNC0qMikeKlFBR0I6MCwxKjcsNiwwNB0uPE5PTEdMOT5cUUhFRDUwKi8nLC0uNCIwKTgtMTIsNCdPRQ==
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81427791866.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81427791866.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81427791866.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsn2.tmp\7tm.dll
- %TEMP%\rc60.cccabfhfdb
- %TEMP%\cccabfhfdb.zip
- %TEMP%\rc60.exe
- %TEMP%\nsn2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81427791866.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\rc60.exe в %TEMP%\cccabfhfdb.exe