Техническая информация
- '%TEMP%\ejcabfbcide.exe' 7-2-6-4-9-5-2-7-2-8-4 KE5DQDQyMSkwGCtMUzxMQD87KR4nSj5SUUtJRkc9OygcKEJDT0tEQjYvLS4vNRorOkRCNi4YK0lQSUBMPlJYRzw5KzcrMxcqUT5QTkFLXU9OQzhmbXJoNigtbW5tKUI+UUMpTU1KKThLTidHRkJIHik/Q0RBREc8OSs1KzMqLy8vMi8cKEIrOSksMC4yGCs9MDcpKBstPTE1KSoeKUArOCsqHidALjsnLRcqTktNPFE8UllMSURUOkFRORktSk5GP1M8UldBTko7ORcqTktNPFE8UllKOEhDNh4nQVFDWVFJRzsZLT1UPl09STtHR0dDNRwoRklPS1pAS01PTz5QNywXKlJBP0ZHUk1PW0xNSjYeJ1JGOywcJj9RKjsYK0tTSFBASENYVT1IPE1HQUBIP0BDTU5FOxorQE5dS1NGUEJLPzlrbXNeHidOPlJPTkVETEBdTU8+UFlAOFRRNjAYK0FHPkFPOC8ZLUFPWEJTSjhIRzxdPUo8UFNMS0BCNmRZaGxjGis7SlVHSkc9PV1DTDQsLjAsKTMxLCwsJykwKTUYK01HR0E0LDIrNi0zKzYuMxcqQkhVRkhIPz5bS0RLPjssKzItLCwoMCgyOCwzMzAxJjhI
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81428588969.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81428588969.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81428588969.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsb2.tmp\junaf.dll
- %TEMP%\1428570128.ejcabfbcide
- %TEMP%\ejcabfbcide.zip
- %TEMP%\1428570128.exe
- %TEMP%\nsb2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81428588969.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\1428570128.exe в %TEMP%\ejcabfbcide.exe