Техническая информация
- '%TEMP%\bhcabfcceb.exe' 8-0-0-9-4-4-6-4-4-1-3 J1BJOzkxMzMsHyxLVUJHRUA3LBwuSz1UV0ZOR0NAOTAdJ0RJSlBFPjk0OC4qIC86RUA3LBwuTUpPREw/UFlFQDwwKDczFytPP05SRE9XVVJDOWRucGw5LCdzZWlyKm5kYSxeaHAtW11wWyplbWNnIC86SEU9R0VDOmRheCg/RVFxcWRERG4tWXRQPD0/Rkk/ZXhHbm9kX2ZLRHFJTkVQPW9JUEgtRGpnb0hmPzFKaGQ6TU1sX2ZqZ0IfLDwxPSQtHClALjwqKSAvOy85Jy0cLkEsPS0oHCs+MTksLhgvUElLQE8/UF5NSklWOD9VNxwrT09HRFU6UFs/UUhAOhgvUElLQE8/UF5LOU1FNBwrP1RBXlJKTD0XK0FSQVtCSjxMSUVBORorRE5QTF9CSUtTTUFOPC0YL1Q/PUpFVUtUXE1STDQcK1BJOTEdJ0RTKDkcKU5RTVFBTUVWU0FGP0tMQkFNQT5BUUxIOR8sQVNfSVFKTkVJRDpscnVcHCtMQVBUT0ZJTj5bUU1BTl5BOVlTNC4cKURFQ0JQPTEXK0VNW0BYSzlNSTpbQUg/TlhNTEVENGJdZm9hHyw8T1dFSEs7QFtITTUzNyUtNDEqLjIzJjE2JxwrTkVJRDopNDInMi0rNTM2HSdET05KSEk9QF5RQU1FNC0rMSsuLy4tKjYxLjI0LTMpPkU=
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81421033223.txt bios get version
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81421033223.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81421033223.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsr2.tmp\jjff.dll
- %TEMP%\insHMad.bhcabfcceb
- %TEMP%\bhcabfcceb.zip
- %TEMP%\insHMad.exe
- %TEMP%\nsr2.tmp\nsisunz.dll
- %TEMP%\81421033223.txt
- %TEMP%\tmp5.tmp
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\bhcabfcceb.zip
- %TEMP%\insHMad.bhcabfcceb
- %TEMP%\tmp4.tmp
- %TEMP%\tmp3.tmp
- %TEMP%\insHMad.exe в %TEMP%\bhcabfcceb.exe