Техническая информация
- '%TEMP%\bedddedgja.exe' 1/7/8/1/7/2/2/0/4/7/7 LklBQzY2NTUtGShSTjpPQkI7MBwoR0RNT05LSUdEOSoZLj1BUk1HQj0uLiw0MhguPEdCPSwZKE9LR0NOQVJfRT02MS0tNDEeLVNBS09ES1dUS0o7aHBtaTkoJ3JrdCxEQUxELE1HTyY/TlAqQkdFSBguPEpHQ0dCPTwZJ0MqOysxHCg9MTYlMBktQjM5JiofKDwzNisvICs9LjwmKR8oTlBPQE48U1hIUUJUP0NVNhkuSUpOPVNBVFs+Tks6NR8oTlBPQE48U1hGQEZDOyArPlFEWE1RRTseL0FRPl48RUNFR0xFORkoR0hLU1hAUE9TTD5RNiofKFJGQUpEUk5OV1RLSjsgK09GPCsYLj1RLz0cKEtUR0xIRkNdV0FFPE5GPUhGP0VFUUtFPBknSExdUFVKTUJMPjVza3NjICtLPlNOSk1CTEVfUUw+UVg8QFJROzIcKEFIPT1XNi8eL0VMWENSRkBGR0FfQUc8UVJIUz5CO2ZdZWxkGSdDSFVMTEs6PV5CSDwqMDQuLiotLTIwLTEvHi9QQkZENikzLDExNDQsMjEZJ0NIVUxMSzo9Xk1BTD47NC8vKCsvKi0pLTgvOTYuKylJRQ==
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81433360822.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81433360822.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81433360822.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nss2.tmp\lqapqwc.dll
- %TEMP%\bedddedgja.gdcabfjaja
- %TEMP%\gdcabfjaja.zip
- %TEMP%\bedddedgja.exe
- %TEMP%\nss2.tmp\ZipDLL.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81433360822.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- ClassName: '#32770' WindowName: ''