Техническая информация
- '%TEMP%\egcabfbcabfc.exe' 6-9-8-1-1-8-3-3-7-7-8 KUdBQzwpNjAvLBgpSk1BT0FBOikZJ0g8TFZOSkhGPTYpHykob3FnYXJcbWZbZF08UV1malpgXRomPEhSTEZBNisvMSgqHy47RkE2KRgpR0pOQ01AUVhCPDcpLjgzKx0sTD5KUDxKXlRKSTphbWxqMScucmpzKz0+S0UkTE5PJT5NSSdBSD1HHy47SUY8REE+NBguQyk6KioZJz4pNSwwGCxBLDYlKxcnQzM1Ki4ZKDwvNCUwHydNT0g9TT1LV09RQVM+PFI1GiZIUU48UkBNWD1PQzk8HydNT0g9TT1LV01ARUI6GSg9UjxXVFFEOh0oPlA/VjtMQ0RGSz42GCk/R1JTVz9PSFBLP0k1NB8nUUU6R0NTRk1eVEpJOhkoTkc0Kh8uPFAuNhknTExGU0hFQlxQPkQ9RkVESEU+RD5OSkY0GC5IS1xPTkdMQ0Q9PHNqcmIZKEo/S01RTUFLRFhOSz9JV0NAUVA6KxknQkA8RFc1Lh0oQktZO1FNQEVGQFg+Rj1JUU9TPUE6X1pkbVwYLkNHVEtFSDk+VkFPPCkvNScqMSwlKTMtMDMdKE1BRzw1MDMqNTAsKS8vKhguQ0dUS0VIOT5WTEhMPToxKC8nLCcpNCkqNzArMystIUhM
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81428568207.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81428568207.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81428568207.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsi2.tmp\citkk.dll
- %TEMP%\1428321720.egcabfbcabfc
- %TEMP%\egcabfbcabfc.zip
- %TEMP%\1428321720.exe
- %TEMP%\nsi2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81428568207.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\1428321720.exe в %TEMP%\egcabfbcabfc.exe