Техническая информация
- '%TEMP%\eccabfbbjcfd.exe' 8-5-0-5-6-7-1-0-7-5-0 J0tJPzcpHy9MUEJIREQ4KhkuTj5PV0dNS0Q+Ni8gKD9JS09JPzcpHy88REQ1KyAqSktORE4+VFdERDgqGS5TPk1WPU1fUExFPGhtb3AyKi9ubG8tRD5OSyVPT0snOk9QJ0ROPkogKj1FSENEREQ1Gy8/KzYsMRkqRCo4LSwaKEMzNigxGCpELzcmMCAoPzU1KDEbKUlRTz1QQ0xaUE1DT0BDUjggJ0tSSj5OQlRYQFVEPD0bKUlRTz1QQ0xaTjxHPjwgKEBYPVpVTUY2Hy8+U0VXPk0/RkJNRTYbL0BKU09ZO1FPUE5FSjgyGylNR0FHRllHUF9QTEU8IChRTTUtICo+TDA9GSpSTUlUREc+Xlc+R0NHSEVERzpGRU5NTDUbL0RNWFFVR09JRUA9b2xuZCAoTUVMUFJJQ0dGX05ORUpaRDxTTDwyGSpIQT9FUzcqHy9CTl88VE48R0JCXz5JQ0pUUE8/PTxmWmdzXRsvP0lQTUxIPERXRFA4LycxOCcsNDEpNjAaKFNJRkA9KS8yMjMwNTUxMyAnP09SSEVOQT1aVEFIRTguKDEvKysxLSUxLTQpODotMypISA==
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81427989085.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81427989085.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81427989085.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nst2.tmp\aallf.dll
- %TEMP%\1427973457.eccabfbbjcfd
- %TEMP%\eccabfbbjcfd.zip
- %TEMP%\1427973457.exe
- %TEMP%\nst2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81427989085.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\1427973457.exe в %TEMP%\eccabfbbjcfd.exe