Техническая информация
- '%TEMP%\bcicabfeccbb.exe' 4-7-3-9-2-9-6-5-6-5-9 K0lGOzsoLS0wMBcrTFI5TkA+OCobJko+UU5NSUVEPjgoHChBQFFLQz83LC81MC0XLTpDPzcrFytJT0ZCTD1PWUQ7OSo1KDAwGipNQElSPk9WU0lGOGJva2wzLCZxXGxxKG9fYSZeZ24kXlxuXCVlZ2NmHiY9R0M+QkU9OhctOys4LC0XKz0vNCsoGio+LjQpKh0mQis3KCsbJkAuOiQvFylLTEo7UTxRVk5JQ1E7PlA5GSxHUEY+UD1PVkFOSTg7FylLTEo7UTxRVkw4R0A3aWBqY15WcVhhXFlraWtYc1xwamNqaFopWypcXXBcXxspQE9BWFJJSjQaKj9TPFs8SjtKQEhANxsmREhQS105TEpRTjxONi8XLUtCPEhGUEtOXExQQzcbKVFEOSsdJkJKKzgaKklRR1FASzxZUj9HOktGQkBLOEFAT01DORksQFFWTFBIT0BJPjprcGxfGylNPFBOT0VHRUFaT048TlhBOFdKNy0aKj9FPUJPOygaKkNOVkBSSzhLQD1aP0k6TlJNS0M7N2FbZ2phGSw7TU5IR0k8O1tCTTQ3LCgtLislNSorKDUqGipORERBNi4rMCkuLywzKC0ZLDtNTkhHSTw7W01GREM0KyosMyYuKS4sKCgrNSorMS0qJzhL
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81423277587.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81423277587.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81423277587.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsf2.tmp\qaz.dll
- %TEMP%\insHv27.bcicabfeccbb
- %TEMP%\bcicabfeccbb.zip
- %TEMP%\insHv27.exe
- %TEMP%\nsf2.tmp\nsisunz.dll
- %TEMP%\81423277587.txt
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\PerfStringBackup.TMP
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\insHv27.exe в %TEMP%\bcicabfeccbb.exe