Техническая информация
- '%TEMP%\bcbjcabedgcce.exe' 9-6-4-3-9-2-7-5-6-4-7 JkpFQTQvLCsrLxkmTVE/R0c9OCocKEU/UFRGUEREPjkpFylARkpSQj83Li0tMzUdJkFCPzcsGSZKTkw7UzxPWUU9NCwwLSsxGSpNQUtNP05cTFBFOGJwbWc0KyxqY2txKHBhXCddbWcrXVxuXSdgaGJsFy08R0M/REA+OTAsMls0XixdJDFdLSkrLTAsMSYvMjVjJDEwMywzMCdgL2MnXxkqPi02KBorQSk7JiwaKz0qNykuFy09LzcpKhcpQDI0KyobKUxLRj5RQEtdSU1DUjo6UzkdJk5LSj5RPEtZQVJDPzYbKUxLRj5RQEtdRzxHQTYXKUFVPF1OTUY5GSY/VEJWQUY/RkVHPDccLD9NTE9ZPktGUU9CSTsrGylQQThIR1ZGU1hQTEg2FylQRkRDNiwuLTEwMy0xKTUZKlBJNikaK0FKLzZoXG8mXS4sHSZQTklORUY8WVNCQ0FISD9FRjhBQVJJSjYbKUVMVkxRS0tHRkA3cGtsXxwsSUNNUExKQkVBW1JKQ0taPj1SSjcuHSZGQj8/VDYoGitGSl09VEg9RkA9W0JFQUtUSlA+OzdiXmNxXhspQEhOSEhMOEJYT0NJPjQrLiwoNygtKi0tISsuNyg1MysxJklEGitBRlVHR0k9PVZDTDosLicsLTInLzEqLyc3
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81429495027.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81429495027.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81429495027.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsv2.tmp\ccf.dll
- %TEMP%\insHv21.bcbjcabedgcce
- %TEMP%\bcbjcabedgcce.zip
- %TEMP%\insHv21.exe
- %TEMP%\nsv2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81429495027.txt
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\tmp4.tmp
- %TEMP%\insHv21.bcbjcabedgcce
- %TEMP%\bcbjcabedgcce.zip
- %TEMP%\tmp3.tmp
- %TEMP%\insHv21.exe в %TEMP%\bcbjcabedgcce.exe