Техническая информация
- '%TEMP%\bcbicabedgcdi.exe' 0-9-9-1-3-9-5-0-6-6-8 L0dAQzopLjMaKUtVOUdIQTQrIClIPVRORlFIQD89KhonREBKU0Y7ODIuMCgxFyZCRjs4MBopSFJGO1RAS1pJPjcpNjArHyxKQFJQP0pfTElLOl9vdGo0Jy9qXHFzJW9oXydZcGckY15rXC5jaF5vFyZCSUA+S0M+NTAnMDY2LC4zLCopNyonOC4uMzMtLBgvOyg8S0xIQj9MJDAnMDY2LC4zLBonRCk0LC4XKkQtNyUxFyZDMTQoMRopPDU0JDAdJktSST5NQ0tWT09AUUE9UzUgJkdRTDtQQ05ZPVVDODwdJktSST5NQ0tWTT5EQD0aKT1YPFZUT0M4ICk/UEVWOkxBQ0ROPzcYLz9GUlFWPVJJUUtFSTQxHSZPSDtIQ1lGTF5SSUc9GilMSUQ8PC4rLDgzLTAxKC8fLE1IPSwaJ0RKKDwdJk1VSE5BTTxWVkJDPk9HP0FNOD5EUklHPRopQVNWSVRLS0RNPzdscmxcHyxJQFRPTEZJRT5eUkpAUlk+OVlKNDEdJkNJPj9QPSgXLkZKWkRTSDlNQDpeQkU+UlNKTEU7NGVeY25lGik8T05FS0w4P19OQ0VFNCgxLCgzLywqKTQhMDkvLzUzMiRITRcmQ0xOSUxJOzxfQEc8NispNS8oKzklKTE=
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81421631065.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81421631065.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81421631065.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsm2.tmp\ccf.dll
- %TEMP%\insHv21.bcbicabedgcdi
- %TEMP%\bcbicabedgcdi.zip
- %TEMP%\insHv21.exe
- %TEMP%\nsm2.tmp\nsisunz.dll
- %TEMP%\81421631065.txt
- %TEMP%\tmp5.tmp
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\bcbicabedgcdi.zip
- %TEMP%\insHv21.bcbicabedgcdi
- %TEMP%\tmp4.tmp
- %TEMP%\tmp3.tmp
- %TEMP%\insHv21.exe в %TEMP%\bcbicabedgcdi.exe