Техническая информация
- '%TEMP%\bbfcabfdgbia.exe' 5-3-5-2-8-0-5-0-0-0-4 Kk1EQjUzKzIyICtOUj1OQUQ4MCAvSkBRUk1KS0REPTAcKkFEUUxJPz0yMC40NBstO0k/PTAgK0tPSkJNQ09fSUQ5LDM0MhgvTkVSVkFNXFBQRD1jdHRwNiosbmNqdil0aGUpXG1rK1xhb2EuaWphbBstO0xEQ0tJQDh0QTBOOUlHQjIwLEhGLj1IQk5OVDNKLSseJ0QsPTM2MS8yLR4nRC09LTEcKkEuOyUxGy9ENDkoLhstPDU4LTEgK0tPSkJNQ09fUFJFUT4+VzUgKlBST0BQQE9dPVVHQT0gK0tPSkJNQ09fTkFJQDobLT1YQF9VUkg4HSpDUEVaQ01ESERLQDsYL0NPU1RbPU9KVUtFTT0yICtPRTxMQ1lKVV9VTkc6Gy1OTTgyIC9ATi44HidSUE5USUlAXFJDRENKTUVJSTxEQFNKTDggL0lPWk9QTExJSEU9dG5wYhstSkVPVVJORUlEWlNLRU1fREFVTjotHidIRERFWDksHSpHS18/WU5BSURAWkNGQ01ZUFRBPzphX2RzYCAvREtSS0dNOURaSVA9LSswKTAqNik3NC4tLjEbLUxJSEU9MTAtLi02KDcsMiAvQEpUSUpHQT9fVElJQDosLSk1KjIwMTElLi04KTE1NTIqPUg=
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81423249401.txt bios get serialnumber
- %TEMP%\insHv21.exe
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\nsj2.tmp\nsisunz.dll
- %TEMP%\insHv21.bbfcabfdgbia
- %TEMP%\nsj2.tmp\raw.dll
- %TEMP%\bbfcabfdgbia.zip
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\tmp3.tmp
- %TEMP%\insHv21.exe в %TEMP%\bbfcabfdgbia.exe