Техническая информация
- '%TEMP%\dbbccabebbbc.exe' 4-1-0-6-1-0-6-2-2-0-8 K09JPjwwGi1RVTpMSEQ3LyApTENUT0tRS0NDPSoeLURBT1NJPjwwGi1BSTw5LyApT1JJQlNDTFtIRDcvIClRQ1JOQVFfT1FMN2ZydGg2Li9tZHJwLHJoXSlgcGosZFtyXy5hamVvGi5DRkdBS0FAPCApQzE3Ky8gJ0AxPScwIClCMT0lLR8vPjM9Jy8eLzwxPC0rHy9KUE1ETT9TX0pRSVA/QVk1HC5QTE5ET0FSXz1RS0E3Hy9KUE1ETT9TX0hATT87Hi89VERfT1FMNx4tRVBBXkNHQ0xDTEM9GCtHT01TXzxQTVdLQVE9LB8vTkY/TkNVTlVZVFJGOx4vTEVMRTcwNCwuLjIqNDQxGi5WRzswICdAUjE3Hy9MU0xUQUlEX1FETD1NS0VBSUBHP1RSRjseL0FPXlJPTVRDS0M9bG50ZRouUj9SU1JGRU1HWVRTP1BdRDlVUj0sHy9CR0JFUDkwIClIU1lCV045SUhDWUROPVBXUExBQz1gYGxtYx4vPEtWTkZOQT5dUklFQTwzKy4xLC0wMCkwKTEqOTQxODExGCtDT1FNTEk/Ql9BTDwxLDYuKiwuLik=
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81420037104.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81420037104.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81420037104.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsi2.tmp\yyq.dll
- %TEMP%\insHv3.dbbccabebbbc
- %TEMP%\dbbccabebbbc.zip
- %TEMP%\insHv3.exe
- %TEMP%\nsi2.tmp\nsisunz.dll
- %TEMP%\81420037104.txt
- %TEMP%\tmp5.tmp
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\dbbccabebbbc.zip
- %TEMP%\insHv3.dbbccabebbbc
- %TEMP%\tmp4.tmp
- %TEMP%\tmp3.tmp
- %TEMP%\insHv3.exe в %TEMP%\dbbccabebbbc.exe