Техническая информация
- '%TEMP%\bbecabfgcgj.exe' 7-6-7-6-1-6-2-0-0-0-5 KEpCPjwrNjA4MhsoTU48T0NCPTAgKkc/TVFOTElJRD0sGSk9Q1JOR0Q9Mi8xLDIaLj1HRD0wGyhKS0lDT0FUX0k/NiwsLDAxHi9TRU1PP0tZVExKPWh0b2k0KClyX3B2LnRjXidaam8nYmF0YSliaF9pHylBTElDRkI+NhouPi89LTEbKD4rNywrHi9EMzgmKxkpQy47LTEgKj0vNicwGi1QUk8/Tj1NWU9MR1ZBQ1Q2GihKUUlCVUNUWj5PRTs8Gi1QUk8/Tj1NWU07S0U9U2pnYWsaLj9WRV9VTUU3YW5zajgvL3BhJ15lXXVjci5jb2gobSgsLiwtaWRwYSZcXmFoaG4wMTB1KjNdXGFdLjNmNzMvL10wMjEuMDk5Ly4vXSthXTJhYjUoaG9tJzQuYDY3OWEyKl4wYSsyLjQ1My0sLCoxJ2tzaWUoYl5pYC4sMDg2OSsmMDAsMjEuLXNvaWBsJ3Roah4vRVhAWD1GPktDTEU9ICpBSUxOXjxQT1dTQEs3KRouTkZBTktUSE9YT1FGO2h0dGszKShuZ1tsa3MuXV5hYmgtanBvL2lpXV9xKG9ibj9kbThsaWdhcShgZWdpaSdqa2klaml3PUJAQENHSlFJJHBnPU5oaGBsJWllPVNFSh9ua11qY2I9MCZcX2BiXjwqJGt3PSsfamZeNDckaW5zb1pmZV9xNzcgL1ZINiwZKUNNLz1CRUJCSEkqMCpYMTlkXVtdKS1lMTY2NWQxLDEpKjgzMjU1ZCxbXS1bYS8eL1JVSU1DRj9eUUNMQ09IPkNGO0Y/U1JMPRsoQ0xZUU9MVElNQDZua29kGi1SRVRQS0hCSEZZU1NFUlo9O1JNPCweL0hJPz5SNisfKUdTX0RURztGQ0JZQ05DUlRJTj4+PGBfbHNlGyg+SFFNRk1BRF9ESTcyLS0rNjkuMy0nKy0wHylSSU
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81421257456.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81421257456.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsv2.tmp\raw.dll
- %TEMP%\insHv47.bbecabfgcgj
- %TEMP%\bbecabfgcgj.zip
- %TEMP%\insHv47.exe
- %TEMP%\nsv2.tmp\nsisunz.dll
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- <SYSTEM32>\PerfStringBackup.TMP
- %TEMP%\tmp3.tmp
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\insHv47.exe в %TEMP%\bbecabfgcgj.exe