Техническая информация
- '%TEMP%\bcfcabffgbhg.exe' 8-0-1-1-1-8-2-4-4-9-8 J1BIQzwpNy0wKBgnU1RBT0FCOSwXJ0ZFU1ZOSklFQDQpGC9DSFJMR0A5KS0qNjcfLjtHQDknGCdQUU5DTUFQW0A8NTIzMzIpHitPPEpORVFeVEpKOWRrbGg6Li5yXXByKmtgXS1gb28lYl1wWCZhbmVuHydBSEU6Q0FEPHZBQUdRUUNOMTE1UjJCSkQsTEw+OThANxgtQC00JSkgLkMxNSstHCY8Kz0sMB8nQjA5JCkYL0M0PCUvHCtHSkdEVEJTV05ORU05O1k8Hy5IUEtATDtMX0RUSzk7HCtHSkdEVEJTV0w9STw1GC9EV0RXU05INBgnRVdEXjtLQEhARj09Hy5HR1FQWzlKR1dSRFE1MBwrS0A5TkpYTk1dUU5DNRgvVUw8Kh4rQEopNSAuUVRGUkVJPFdPRUtCTkVDRUk4Pz1VUUs8GC1FT1ZKTU5TSEw9O3BubF0YL1FEU01QSkVFP1dVUkRRV0I9VUo1KiAuR0g8Q1Q5KBgnSVJeQ1FMPUlAO1dFTUJRUU5QQTs1XmFrcmQYLUBLTkZET0BDXkFOOTElKTE2LTAtKTA1HCZMQU1EPDAsMC4tLC0uMi8fLjxNU0pDRzlEXlNIRUM5LSYqLS8xLzAtKC82KCsyNC8pQEU=
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81422167709.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81422167709.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81422167709.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsh2.tmp\xor.dll
- %TEMP%\insHv41.bcfcabffgbhg
- %TEMP%\bcfcabffgbhg.zip
- %TEMP%\insHv41.exe
- %TEMP%\nsh2.tmp\nsisunz.dll
- %TEMP%\81422167709.txt
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\PerfStringBackup.TMP
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\insHv41.exe в %TEMP%\bcfcabffgbhg.exe