Техническая информация
- '%TEMP%\bicabfechf.exe' 1-7-4-8-7-3-4-9-6-3-8 LklFPDYwLCksHSdSTj5IQkE5JxosRkRNU0dLSEU7Ny0YLj1FS01GQDQsLSo4MBwnPEZANCodJ09LSzxOQFBWQ0E1MC81LBksTzxMUz1RWFFKRTpka25tMi4ob11rcyprYmIlYGlsJV1ecFgoZmZlaBwnPElFOkVGPDxwMEMpQT4tTTZIOEMsLTJFQy4rMzxRSjAYKEEtNC0zLTMuLhgoQS40Jy4YLj0vNSYuHCY+MTUsKhwnPTI5JCsdJ09LSzxOQFBWSk9BVTo/UTYdK0dMTDxUPFBXPlJIODcdJ09LSzxOQFBWSD5FRDYcJz5VQVZPT0Q8GSs9UUJbOkdBREhHQTUZLERGTVFXQUtLT0xCTjQsHSdTQT1GRFZLTFlSSks2HCdPSjkpGiw8Uio5GChPUUVORkVEWFM9RUBLRD9GRUBAQU1LSTkXKUZLXktRRk1GSTw3cWp0XhwnS0JQTExLQU1AW01MQk5WPj5RUjYuGChFRTs/VTUwGStBTFxAUEg+RUg8Wz1HQE5QSlE9QzZiWWVwYRcpQUdWR0hHOkFbQEo6MTMnLignLy4rKC8sMBkrTEJKQTQrMSovMC4sMDM1FylBR1ZHSEc6QVtLQ0o9PCorMCgvLCgvJyk5LTIyKTYmR0c=
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81427462106.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81427462106.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81427462106.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsw2.tmp\jjff.dll
- %TEMP%\insHv27.bicabfechf
- %TEMP%\bicabfechf.zip
- %TEMP%\insHv27.exe
- %TEMP%\nsw2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81427462106.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\insHv27.exe в %TEMP%\bicabfechf.exe