Техническая информация
- '%TEMP%\cjcabfebba.exe' 0-5-3-0-0-4-5-9-0-7-4 L0tGRD0tLic3LBwvTlJCUEU/NDAZK05AUVdPTkZARDYsICpBSVNQRDs9KzA4MjQgLz9EOz0pHC9LT09EUT5LX0JAPS4wMjUcKkpFS1JFTVxVUkg4X3RtbDoqLHNlbnEldGFhLVxtcC1gXGthJ2VuYWwgLz9HQENERUQ4ajkxLEJZQ21nehssRDE5SUxNO0FSGyxEMjkoKCAoQDM4KjEgKz8rPSYtICpBNT0pLBcvSU5PP1JDVFtLSUlPPUNUOiAvTE1GRE4/VFpCVUw9OBcvSU5PP1JDVFtJOE0+OSAqQlhFW1BJTDYcL0BVRV8/SDtMQkpFOB0vSEtOS187Tk9SUEVSOS0XL01EQUlIWU9RWkxSRTkgKlNNPS4bJkRMLT0bLFJVSk9ATT5bV0BJQ09JQEBNOkNFUE9MPRwqQFNYTlVJUUlNQThrcm5hICpPRVRRTUVJR0NfUFBFUls/OFlMOTIbLEhJQEBPPSocL0RQX0RVSThNQj9fQEtDUlVLS0U9OWZcaXNlHCo7T1BKTEo+RF9FSzQxMDUuMDAuMS8yJTIwHC9PRk1FOSwrMiwxMS4wNDYcKjtPUEpMSj5EX1BEREU2Li80LDIwLTAhODMuMjUvNipMSA==
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81428511572.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81428511572.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp3.tmp
- %TEMP%\81428511572.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp5.tmp
- %TEMP%\cjcabfebba.zip
- %TEMP%\nsm2.tmp\ngz.dll
- %TEMP%\rc26.cjcabfebba
- %TEMP%\nsm2.tmp\System.dll
- %TEMP%\rc26.exe
- %TEMP%\nsm2.tmp\nsisunz.dll
- %TEMP%\tmp3.tmp
- %TEMP%\nsm2.tmp\System.dll
- %TEMP%\tmp4.tmp
- %TEMP%\81428511572.txt
- %TEMP%\tmp5.tmp
- %TEMP%\rc26.cjcabfebba
- %TEMP%\cjcabfebba.exe
- %TEMP%\cjcabfebba.zip
- %TEMP%\nsm2.tmp\nsisunz.dll
- %TEMP%\nsm2.tmp\ngz.dll
- %TEMP%\rc26.exe в %TEMP%\cjcabfebba.exe