Техническая информация
- '%TEMP%\bbicabfdibgc.exe' 4-1-4-4-0-8-3-9-2-3-0 K09FQD0oHSZRUkJMSEA5MBgsRUNRV0tRR0VENS0XLUFJT1NFQD0oHSZBRkQ5LxwrUEpMO1NAVFtIQDkwGCxKQ09WQVFbUVJEOl9ycXA2LitvZWpzJXJlZSlgbGwtXF5rXytpamVrHC87SUBBSElAPBwrRCk6JC8dL0AxOSkxGCw7MTotLR8rQDQ1KigeLEQxPCktICdNSU1BVT9TW0xSQVM4QVY9HC5MTk88UjpSXEVRSz05ICdNSU1BVT9TW0pBRUI0HixFVERbUVJEOhctQlhBXj9JRERGRUM6ICtHS09UVz9JTVRTQVE5LCAnUT8/S0tVTlFbVUpJNB4sVkk8LhwvPFAoOx0vTlRKUElFQlZVQkw/TklBSUU+PkNSUkg8HCtJS1xJU0tURUxBOXRqclweLFJBU1FOTkFLPl1SU0FRW0BBUVA0MB0vREhAQVg1LhctRlNbQ1VKQUVGOl1CTj9RVUxUPUE0ZF5sb2QcK0RHVEVKTEFAXkVMPS8vJS8rMTU1Ki04LB0mUkZNQTwtMDIpMi81MzIuHytAT09LQ00+RFtTRUlFNS4mLzUvLi8tMSopNyk1NzAuKUxJ
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81421601550.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81421601550.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81421601550.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsk2.tmp\day.dll
- %TEMP%\insHv23.bbicabfdibgc
- %TEMP%\bbicabfdibgc.zip
- %TEMP%\insHv23.exe
- %TEMP%\nsk2.tmp\nsisunz.dll
- %TEMP%\81421601550.txt
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\PerfStringBackup.TMP
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\insHv23.exe в %TEMP%\bbicabfdibgc.exe