Техническая информация
- '%TEMP%\bcdbcabeegcdh.exe' 2-7-7-8-3-5-9-8-9-5-2 LUlCPDosKiguLh4tTE46TUQ7NScbLUw+TU9MTUJBOzguHig9QVBPQDw0LTI0KSoYLD5APDQrHi1JS0dBUDpMVkRCOyovMTEbJks8TVRDS1hNT0c0YGtvbjgoKGtibW0ma2NjK1ppaCpfWGxYKWdsX2gYLD5DQTpGR0I2YlsuK2U/Sy50chkoPC44RU1EPUNQGSg8LzgkKRcqQjE2JikdKjssNCgvHig9LTooKBgmS1BNPU47UVpHSkBRP0FSNhgsS0lHO1BBUlg+TUk8NBgmS1BNPU47UVpFOURAOx4oPlBCWkxKQzgeLT5RPVw+RDxDRExDNhknRUpKTFY9UE1QTD1POCkYJk9GP0dEUUxQVk1JRzseKE1BSkA0KSstLi4pMCwwKxcnTUg7MBkoPFAsNBgmTVNMTUJFQlpOPUM+TUs+QkU+QjxNSUc7HihCS1xNTEZLREtDNm1qcmAXJ0lAUlNLR0FLQlZNSkBQXT06UVA4KRgmQ0dCPlE1LhsmQUpaQldHOkVGPlY9RT5QV0lNPUE4XVljbmMeKD1HVElDRzg/XVJCRj06LCknKiwtMCkqLCcxMSsnNTEuIzpFHSo7R05JSk06PVdGSzQxLSkwNCcyMSssKDA=
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81428131470.txt bios get version
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81428131470.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81428131470.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsw2.tmp\aal.dll
- %TEMP%\insHv31.bcdbcabeegcdh
- %TEMP%\bcdbcabeegcdh.zip
- %TEMP%\insHv31.exe
- %TEMP%\nsw2.tmp\nsisunz.dll
- %TEMP%\81428131470.txt
- %TEMP%\tmp5.tmp
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\bcdbcabeegcdh.zip
- %TEMP%\insHv31.bcdbcabeegcdh
- %TEMP%\tmp4.tmp
- %TEMP%\tmp3.tmp
- %TEMP%\insHv31.exe в %TEMP%\bcdbcabeegcdh.exe