Техническая информация
- '%TEMP%\bcecabffgbab.exe' 8-8-2-0-2-0-8-5-3-9-1 J0hHRDsxMSwxKB8nS1NCTkk8OC0XLkY9UldNUkNEQTQwGCdCSVFUQT86KTQqLzAgLUNBPzonHydIUE9CVTtPXEBDNSoyNDEzGCpQPFFOPVBfU1JEOGVrc2gyLS9xZWpxK2tnXSVfcG4tXFxxWC1hZmRvHi87R0Y6SkE8O3cxMCg9M0JVTT1EUjRERENEODdILkdINiAnPy40TU1FQEVQICc/LzQsKRgtRDE9JSwdJkMsNSsxHi88MDokMBgnTlJNRE0+UVZPSkFUQUFZNRssR1FHPFNDUl89UEk4PBgnTlJNRE0+UVZNOUVDPURsWW5lHDEoTW5kX3RdbR0mRFA9XVVQTDVjcWtvMictZG55Ki13LzJqZTF6cy5bZ2xsY15qbW5yLmZgcSZhbWZibGNzJ29vXGBrbXBlXWZoa29mLj5kX3NmMiZgdVwfJz1WRV1DRT9JQE09NR4vRk9LT1w5UUdPUUVQPSobLEtHOUZJWU1VV1BPQzwYJ1RNOzIYKkFKMDVGP01DICdNUkVTQUVDX1VFRD5MRERBRT9HQ1VKRzoXLkFLXVJTTkxESjw8bGpzZR4vSkBRTFFGQUxHXVVLQE9WQzlRUT0wICdDRjtEUDUvIC1JS1pBUE05RUdDXUVGPk9QT0w9Qj1kYWRuYhcuPEdVTkpPOT9cQE81MC4uNjImMjUlMC4sHi9SSUVAOigzKiovMzQxKDEdJkNHT0xMTUE8WlFATD01Ly8wNCctLSg0IjE4NDY6KjEnR0w=
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81422147903.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81422147903.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81422147903.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nss2.tmp\xor.dll
- %TEMP%\insHv41.bcecabffgbab
- %TEMP%\bcecabffgbab.zip
- %TEMP%\insHv41.exe
- %TEMP%\nss2.tmp\nsisunz.dll
- %TEMP%\81422147903.txt
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\PerfStringBackup.TMP
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\insHv41.exe в %TEMP%\bcecabffgbab.exe