Техническая информация
- '%TEMP%\bhcabfcecda.exe' 0-8-7-5-3-2-3-3-5-8-4 L0hCPzo1MC0tGCtTTTtLRkI6LRsnSkVMUEpPSUZBOCgcLzxCTlFHQTosKzA2LxkqQEdBOisYK1BKSD9SQVFcRDw5MS4yLx0tUEJNTkFSV05NSTtlcW9oNi8nbGBvdCtxY10pYWhpKGFfcV4pYWpmZxkqQEpGQEZBQD0pMi8xMDMzMzAyICc9LDovMjM0KxwvPCs4Ki8dLD8rOS0pGSpBMjoqLBgrRC02KC4eLE1NR0BVO01aTVBGUzw7VT0YKEtPTUFSPkxbRU1FPDoeLE1NR0BVO01aSz9KQjgYK0VQPlpSUEk6GydBWD1YPkpCSUZJPTkgJ0FKUFJcP01HU1M9SzgvHixRQzlKS1FIUFxTT0k4GCtWRTYtHS1BUCw1HC9KTklRR0pCWk9BTDtISEJHSj5CPVFSRDYbLEdQXE1NSlRBRkA6cm9yYBgrUj1NUE9MRktCV1FTPUtaQT9WUDgqHC9AQj9CVjouGydFU1c9VEs/SkY+V0FOO0tUTVJCQTheXWxrXhssQkxUSURLQTxYRE07NDYpKTAzJjEyKzAwMRsnUElFPjguMi8tMDE0NCsrGyxCTFRJREtBPFhPRktCOiwnMy8qKSwyKC83Lyg2MyojPEo=
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81420610948.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81420610948.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsf2.tmp\jjff.dll
- %TEMP%\insHv10.bhcabfcecda
- %TEMP%\bhcabfcecda.zip
- %TEMP%\insHv10.exe
- %TEMP%\nsf2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\PerfStringBackup.TMP
- %TEMP%\tmp4.tmp
- %TEMP%\insHv10.bhcabfcecda
- %TEMP%\bhcabfcecda.zip
- %TEMP%\tmp3.tmp
- %TEMP%\insHv10.exe в %TEMP%\bhcabfcecda.exe