Техническая информация
- '%TEMP%\dgcabfdhcbg.exe' 8-6-0-5-9-0-1-8-1-6-0 J0pJPzQxMig2LSAnTVU9R0lDNS8aL0Y/VFJGUkpBQzcwGClEREpUSDw8LDQwMTcbJkNIPDwqICdKUko7VUJMXkNENS0zLSwgLktETFY9TF9QSUw8YHNucDIpL25ccnUmc2JlJVtwayRkYGxgKGlmYG8bJkNLQUJFSTw3eTAoMDdoVjBVLBovPyg9TU1MPEVKGi8/KT0sKR8pRCs3LSwXL0MsPCcxGClEMDQtMBguSlJHPlU+S19PSkhQQTtTPRsmUFFHQ09DTFlFUENBPBguSlJHPlU+S19NOUw/PRgpRVM8X1RKSzcgJz9YQFZDTDxLQ049NyAqP09STF48UkdRU0BJPTEYLk5IOUhLVEZVXk1RRj0YKVZINDIfJ0NNMTUaL01MTlNBTD9fTz9MPkZNREFMO0c9T1JHNCAuQVJZUk1IVERERTxscW9lGClSQEtVUUZISEdXT1NASV9DOVhNPSoaL0NARERQPCsgJ0NTWjtZTTlMQ0NXP04+SVlPTEQ+PV5bbG5cIC48TlFORElBP1ZJTzUwMjImLzMpKzEtMTAaL0xDTUA0MTMqNDA1LTMyLRcvQ0dWSExHO0RaS0lMPTwtLy4pMisoNSkrOS0yMioyJUdN
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81429362128.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81429362128.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81429362128.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsv2.tmp\byvlo.dll
- %TEMP%\ic22.dgcabfdhcbg
- %TEMP%\dgcabfdhcbg.zip
- %TEMP%\ic22.exe
- %TEMP%\nsv2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81429362128.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\ic22.exe в %TEMP%\dgcabfdhcbg.exe