Техническая информация
- '%TEMP%\bcfcabffgig.exe' 5-4-1-6-0-1-4-8-4-3-5 KkxIPj0wNSkwLhsqT1Q8UEhANSwdKklBU1FPUUdBQDosGytDQ1NTRTw5LzAtMjcaL0JFPDktGypMUUlEVD9MW0Y/OC4zLjMwHCdPQk1RQVFZVVFINWRxb2s2LilzZG5uKnFjYClganAsYFlwXilkamVpIC4/REVARkRAPHFJNz8/LTFPRT41MkdTSEBDQUAsUVUrTB8rPC06KCwcLj4yPCkpHCw/LjksKyAuQCw5KiwbK0MvPSwtGCtNTUpAVD1UXkxKRVM8PlU8Gi9PTkdAUj5PW0RPTEA5GCtNTUpAVD1UXko5SUI4GytEUkVeUUpIOhsqQVc/X0JJPEhGSUA5HylITk9MWz9NSlNSP1I8LhgrUUM8SkpTT1RbTU5JOBsrVUc9MRwnQFAsOBwuTFVNUEFJQlpSQUs9T0xBQUk+QkBRUUY9HytBT1xNUEpTQ01EOWxucmAbK1E/VFRORkVLQlpRUj9SXkA5VVA4LRwuQklDQVA5LhsqRVJZRFhKOUlGPlpBTT1SWExMQUE4YV1rbWUfKzxLVElHS0A+X0hMNTAzKSwyNCgxODImLTUvGytTQ01EOSkwLy0sNTIqMzccJ0BMUklITjtEXlBBSUI4LCsxLy8xLCkxJyw1LzY0MTcmSEk=
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81422205054.txt bios get serialnumber
- %TEMP%\insHv41.exe
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\nsn2.tmp\nsisunz.dll
- %TEMP%\insHv41.bcfcabffgig
- %TEMP%\nsn2.tmp\jor.dll
- %TEMP%\bcfcabffgig.zip
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\tmp3.tmp
- %TEMP%\insHv41.exe в %TEMP%\bcfcabffgig.exe