Техническая информация
- '%TEMP%\bcdbcabebbbfb.exe' 9-4-7-4-4-2-1-7-8-0-4 JkxCQDkxLysqICtKUTtMRUI8KRgvSjxQUEtOSUg9NTAcJkBCT1BHQzYpNzMsHCg/RUI8KRgvTElLPVE/Ul5CPD0tLTUtHCtRREtORU5WUUtIOWZzbWg6KyZvXm5yLHNhXS1dZ2wmYF1yYCdhbmJmHCg/SEdCREFEOVFzXVRSblk9KW1WO1ZkVkBma1JLMWdQaU5zSFJRZlJUZ2tLUEEuS3gqY1lQYnVGQFV4WU05d1Y7QRkrQC88KiwzLywwGStAMDwmKSArOy82KS0eLj0sPSkoHChAMTssKhgvTElLPVE/Ul5JSklSOD9SORwtT0tHRFE6UFhBUUpANhgvTElLPVE/Ul5HOU1BNBwoQVRDXk5KTDkXKz5UQV1CRjxMRUVBNhwrRk5MTF8+SUtQT0FQPCkYL1A/PUdHVU1UWE1SSDQcKFBFS0Q2KTQuJywqMTAxLxknVkk0LhkrQFEwNhgvTkxKTUVJQ15QPUw/Rkk+RUk/Rj5NUkg0HChFT11RTkZURURBNnBuc2QZJ1JBS1FLSkVMRlhNU0FJWz09VVE8KxgvREBAPlQ5Lx8oQVNbO1VHPUlHQlg9Tj9JVUlQQUI8X1lsb1wcKEBLVU1FR0FAVlBCSUE7MCsnMy0mLiktMCg3MywzNiwsIz1JHi49R1dKQ0s6QFtHTzYxNCopMCsqLjMwJykxLg==
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81420028048.txt bios get version
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81420028048.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81420028048.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsn2.tmp\aal.dll
- %TEMP%\insHv3.bcdbcabebbbfb
- %TEMP%\bcdbcabebbbfb.zip
- %TEMP%\insHv3.exe
- %TEMP%\nsn2.tmp\nsisunz.dll
- %TEMP%\81420028048.txt
- %TEMP%\tmp5.tmp
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\bcdbcabebbbfb.zip
- %TEMP%\insHv3.bcdbcabebbbfb
- %TEMP%\tmp4.tmp
- %TEMP%\tmp3.tmp
- %TEMP%\insHv3.exe в %TEMP%\bcdbcabebbbfb.exe