Техническая информация
- '%TEMP%\bcbjcabedgcaa.exe' 9-5-9-9-6-5-6-9-1-2-8 JktAOzcsLScwMRgmTkw5SkQ+NC8eJ0VAS05JTUVAQzsoFyo7QE1PQzs8MCwtNDAXKT5DOzwuGCZLSUY+UD1LXkc8NC0rJy4uGiZSQ0pNQElWT01GNGdybGc1JiZtYGxtLXJgXChYZ2ooXlhzXyZgaV1mGio9Q0hBQ0A/NFwvXzInZDFcJC9aXDIoLl04ZCUwYVwrJzJgWS8wLShhXSsqLRomQy81KBsmOyw4JygfLTwqOCQoGio+KzwrKRcqOyw3KCsXLk5KRj9MOk5aSklIVDk6VDQXKUtMRkNTO0taPExGPDcXLk5KRj9MOk5aSDhMQzUXKjxPP1pPSUs7GCZATzxZPkc7S0dGPDgXJkJKTUteQEpGUko8TDgsFy5SQDhJQlBJUFlMUUo1FypLQEdANygzLzAwLy8vLjIaJlVLNSkbJjtNLDdkYXElXS8nFylNT0VTR0U8Wk48Rj5JRERHRThCPExMRzcXLkdLVk1MRU5ERzw8cmpsYBcmTEBOTFFMQUVCVkxNQExWQz9RSjgpFylDQztEVjUoGyZATVo+UE0/RUA+VjxIPkxQT1I9OzhdWGZuXxcuQkdOSUNGOz9ZS0hLPTQsKSYrNCkpLy8sISwpMSwyNCk2KDlEGyY7SVJIQ04/PFZERzQsLygoNS4mKSwwJSsrMQ==
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81420499286.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81420499286.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81420499286.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsn2.tmp\ccf.dll
- %TEMP%\insHv21.bcbjcabedgcaa
- %TEMP%\bcbjcabedgcaa.zip
- %TEMP%\insHv21.exe
- %TEMP%\nsn2.tmp\nsisunz.dll
- %TEMP%\81420499286.txt
- %TEMP%\tmp5.tmp
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\bcbjcabedgcaa.zip
- %TEMP%\insHv21.bcbjcabedgcaa
- %TEMP%\tmp4.tmp
- %TEMP%\tmp3.tmp
- %TEMP%\insHv21.exe в %TEMP%\bcbjcabedgcaa.exe