Техническая информация
- '%TEMP%\efcabfieh.exe' 2-2-8-2-0-0-3-0-7-9-2 LU5BQj0zLTIrFy1RUzpOSUQ6MBkmTENST01SS0ZENiceLUJBUVRJQT0rJzA3NRgtQ0lBPSkXLU5QR0JVQ1FfQjs7LzQxMiAvUEVLTUNQXU1QTD1ldG1nOC0ta3B2LkFFTEIrUk1IK0FQTS5CRURNHidBTElAS0I7O3VKKUhWQjRCTj0vPzQsREkwSUlCPElJSRgtRDE6My8sMjMwGC1EMjotKhctQjE1KzEgLEQtNCsvHidCNT0qMRkmTlBNPFNDVFxQS0BUP0FROyAvTVJIO1NBUldDVUw+PRkmTlBNPFNDVFxOOkRDOx4nQ1hFXFVLQzseLT1WRV9ATT1DR0xDNR4vSExTTVZAUE1PUUVSOjMZJlJGP0ZJWU9SX05JSjseJ1RNPS8gKDtRLzsYLVJVS1RCRENdVT1KQ09KRUJEP0VDTVBMPR0vQkpdUFNGUklNQj1taXNjHidQRVRSUkdATEVdTVFFUlxEOlBROzAYLUhJQUVRNC8eLUFRX0RWTjpER0FdPUxDUlZQTTxCO2RZanNlHS89RlVMSkc/RF9GUDYqNSwvLDIuMTE0JyguMx4nUklNQj0qKzA2MCo1NzAuICg7TVVMRE1BRFxUQkRDOzInMy8yLTEuITc4My04MDEnQUY=
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81430482623.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81430482623.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81430482623.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsb2.tmp\bblcj.dll
- %TEMP%\1428224484.efcabfieh
- %TEMP%\efcabfieh.zip
- %TEMP%\1428224484.exe
- %TEMP%\nsb2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81430482623.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\1428224484.exe в %TEMP%\efcabfieh.exe