Техническая информация
- '%TEMP%\bchcabfdccej.exe' 6-0-3-2-1-6-2-3-2-8-4 KVBGQjwrNjYyKBwpU1JAT0NCOi4YK0hFUVVOTElGQjUtGi9BR1JOR0E7KjEqOS8eLj1HQTsoHClQT01DT0FRXUFANzIxMDYyHixRPU5QRU9dVExKOmZscGo6LC1yX3BzLGxkXy1ebm8nYl5yWSpjbmNtHylBSUc7R0NEOh4uPi86LhgrPjI6KzAaLUExNSkrICxCMzcrLh4nQC89Ki8fKU5PTTxRPVRcTlFDVD5BUTkaL01QTj5TQFJXQU9MPjsfKU5PTTxRPVRcTEBHQzpIWXJbJS8uUW9scWdlYR8yLUNtcGdvbWZpX25xHi4/VkJdTU5GPWVyc2o4LC1ZbGpzcHJgbmdgMF5gLnNiM2RnLHAxJl1nYXdtbVt1cCxba2cvZ3BkJzVyNCgpcWlrYm5xcSpnLTQwLmJ2ZBotQlY9Wz1NQUpISEM6HidESVNRXUFMTVRRPU43Mh0tU0I/S0lRS09fUlBLNx4sVEU5LCAsQlIrOy4yKi4tODUxNC83NDUpKC0wLTArT1EpX15iZjI2MCstMTIqZ15oLDM2Kz1mb21lYSY0Ni9jXDE0NSs0XGUuMGMrYi8vWTAwYTA2Yi1kMWBZLCZzcmBoXjsuLioyLDBcNWAsMC8vLF4qNmE2ZV9kYmQuMC8xMTBiL182ZFouXTMdLVFPTFFHRUFZV0JKQklLQkdFPUFFUlBLNx4sR0tbTFVLUkhHQzpyanFfICxQRE5TT0xBSkFfUlFETF1BP1FPNzIdLUdDQkJWNS0aL0ZRXj5XSz9FRT1fQkxCTFdNUj1AN2ZeanJfHixCR1NITEw/Q1lHTTspNC4uLjEtMSwwLxgrTklKQzwrMi8wKzQyMzM1HylCTFVGSElBQV1TQ0tCOykrLDcsMC8rMyc1MjEsOjE1KUpL
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81427268725.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81427268725.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81427268725.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nss2.tmp\qaz.dll
- %TEMP%\insHv17.bchcabfdccej
- %TEMP%\bchcabfdccej.zip
- %TEMP%\insHv17.exe
- %TEMP%\nss2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81427268725.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\insHv17.exe в %TEMP%\bchcabfdccej.exe