Техническая информация
- '%TEMP%\beddfbgfca.exe' 7)1)7)4)6)6)2)7)3)1)8 KE9CQDcrNywzMhgoUk4+SkNCNi0fJ0dETVNJTElCQTwpHjEpbGxpYm5gc2ZabF45TF9nZl5mXRkuPUVNTkc9OjEvMDArHCk9Rz06LxgoT0tLPk9BTVxIPDYxLzUuLR4oUERKT0RLW09MSjZlc2xpOSgrbWx0J0FES0QsTUtKJz9JTS1BR0VIHCk9SkJASkE9PBkrPis7Ji4fJz0xNikrGi09MDwlKh8oQC43KyodLjwuPCYtGilOS0xDTTxTWExMQ1Q6QFg1GS5JTkk+UzxRXj1OSzo5GilOS0xDTTxTWEo7R0M2HS49UURYUUxGOxksRFA+XjxJPkZHR0I8GChHSE9OWUBLTFZLPlE2MRopUkE+TUNSTk5bT0xKNh0uTkY8KxwpPlEqOh8nS1RHUENHQ1hUREQ8TkZBQ0c/QEJUSkU8GStDTV1LUk1MQkw+OW5sc14dLko+U05OSENMQFxUSz5RWEA7U1E2Lx8nQUg9QVI3LxksSEtYQ1JKO0dHPFxERjxRUkxOP0I2Y2BkbGQZKz5JVUdJTjk9XkJMNys1MCs4LicwMi0oLDIwHS5MQkw+OSsuMSwyMSsvMDIcKT5NUEtLRzpDWFBDR0M2My4tKDEpLS8kMzMtLzIqOCNMRw==
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81433540944.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81433540944.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81433540944.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsi2.tmp\pxmmwos.dll
- %TEMP%\beddfbgfca.gfcabfbcagj
- %TEMP%\gfcabfbcagj.zip
- %TEMP%\beddfbgfca.exe
- %TEMP%\nsi2.tmp\ZipDLL.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81433540944.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- ClassName: '#32770' WindowName: ''