Техническая информация
- '%TEMP%\agabcabfbbbc.exe' 8-5-5-7-7-6-2-8-6-4-6 J0tEPTYqHidNUTxIRD82KRotRj9QUUdNRkI9Ny4YKUBDS09EPTYqHic9RT41KxsoSUxNPE8/TldEPzYpGi1LP05QPU1aTktGO2BucGoyKipsXmx0Jm5kXyVca2kmXl9sWypjZmFqGSg9SkE9R0M8OBsoPSs7JSscKTwtOCYqGi08LTknKRsqPS03KykaKz4tOCgqGSlOSklATztPWklLQ1Q5PVU3GCpLS0g+UztOWz9NRzw2GSlOSklATztPWkc6R0M1Gis/UEBaTktGOxgpQVI9Wj5GPUZHRj85GidDSkxNWUBKSVNNPU04KxkpUkA7SkVRSlBYTkxKNRorUEU4LRkoPlEpNxwpSlBJTUJHQ1dRQUY7Skg+Qkc/Pz9RTEQ4GyhCTV1KT0pOQUhANm1sc10aK0w9T1BLR0NMP1lRTT1NWj06U1E1LBwpQEQ/PlE3LxgpRU1XP1RHOkdHO1lBSDtNVElNP0I1YF1ma2AbKD1JVUZGSzs8WkRJNiswLygsKCgpLBkoTkdFPzkrLC0rLiwxNiorHCk8SlJHRUk/PFlQQ0VAOCkvKS4pKS4qKTAlKTI0Myg0Lis=
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81420550050.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81420550050.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsh2.tmp\jjff.dll
- %TEMP%\insHv3.agabcabfbbbc
- %TEMP%\agabcabfbbbc.zip
- %TEMP%\insHv3.exe
- %TEMP%\nsh2.tmp\nsisunz.dll
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\insHv3.agabcabfbbbc
- %TEMP%\agabcabfbbbc.zip
- %TEMP%\tmp3.tmp
- %TEMP%\insHv3.exe в %TEMP%\agabcabfbbbc.exe