Техническая информация
- '%TEMP%\bbecabfecbah.exe' 8-4-5-8-5-9-7-5-0-0-8 J0xEPDguLDQyICdLUT1IRDs2KyAvRj1QUkdNQkI/PTEYJ0BES09APTgxMCgwLxsnPkA9ODAgJ0hOSjxQOk1aSUQ1MTEtLRsmTEBSVj1KW1BKRzRhb3RwMicrbl1tbSdvaGUlWWxrJV9YbVwuaWZeaxsnPkNCPktJPDUcKjwsNCYsIC88KjkoKRsmPS49LSkYKz8sOCQqGy9ELTUpLBgqR0tKRFU7TFtLSkRNOj5ZPRgnTE1HP0w8T19FTUQ9OBgqR0tKRFU7TFtJOUg8NhsvRVA9W1BKRzQZKkVYPVc/SDxHQEdAPSAnQEtOTFo5S0pXUz1KOS0YKktBPE5LUUdRWk1NQzYbL1ZFNS4bJz9KKjggL0pNSk9BSDxYUkVMO0dJQEFIOEBAVVJENRwqQU5WS1BOVEFFQThsbWxeGy9SPUxRTUZERUBaVVM9Sls/OVRKNi0gL0BBQEBQOCgZKklTVzxVSTlIQDxaRU47SlVLTEA7NmFhbGtdHCo8Sk5HR09BPFdFSzU0KycsMjMmKi8wJjAwGSpUSUU9OSwsLSgrMTY1LSgcKjxKTkdHT0E8V1BERUA0KioxNCcqLCwtJS8zLDU6LSgmS0U=
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81423235943.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81423235943.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81423235943.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsd2.tmp\raw.dll
- %TEMP%\insHv27.bbecabfecbah
- %TEMP%\bbecabfecbah.zip
- %TEMP%\insHv27.exe
- %TEMP%\nsd2.tmp\nsisunz.dll
- %TEMP%\81423235943.txt
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\tmp5.tmp
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\insHv27.exe в %TEMP%\bbecabfecbah.exe