Техническая информация
- '%TEMP%\bccccabedhfh.exe' 9-7-7-3-6-6-8-5-6-1-8 JklCQTcqGCpNVDpHQj06KhonST9TT0ZLREY+NygbKUNBSk1CQTcqGCo9SDw0KRksSkxHP09CTFZCPToqGidOP1FOPEtYUkxGNWNuc2gxKChwX2xuKW5nXSRaaW0nXllvWy1hZV9oHSk9REQ9SkE7NhksPis1KCsfJzsrNiorGic/LTwlKBkoQS43JSwaLjwsNiYuGilITUlDTTpNWE1MQ048PVg1FyhJT0k+TT5OXj1MRTo6GilITUlDTTpNWEs7Rz04Gi49Tz5YUkxGNRspRFA8WDxKPkZBST88GCZBSFBOWTpNSVZLPEs2LRopTEM7TUNQSE5cT0xEOBouTEBGPjorLik0LDIvKC0uHSlQRTgsHyc7TCo6GilKUEhTQUQ+WFQ/RjtKR0RBRDpAQk9MRDgaLkFKWEtSSE5BSD88bGluXh0pTD1PT1FGQEdAXE9NPU1ZQzlQTDYvGilARD5EUDQqGSxDTVc/U005REI8XD9IO01TT0w8PTZjW2ZrYBouPEZQR0lJOzxaTkhFPDYqLyksKiosLykrIzE3LSwyLS8pOUQZKEFJUUZHSUA8VkJJOisyMCkzNyYtMCcuKyw=
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81422173465.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81422173465.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81422173465.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsa2.tmp\ooi.dll
- %TEMP%\insHv22.bccccabedhfh
- %TEMP%\bccccabedhfh.zip
- %TEMP%\insHv22.exe
- %TEMP%\nsa2.tmp\nsisunz.dll
- %TEMP%\81422173465.txt
- %TEMP%\tmp5.tmp
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\bccccabedhfh.zip
- %TEMP%\insHv22.bccccabedhfh
- %TEMP%\tmp4.tmp
- %TEMP%\tmp3.tmp
- %TEMP%\insHv22.exe в %TEMP%\bccccabedhfh.exe