Техническая информация
- '%TEMP%\bcgcabfecccc.exe' 6-0-6-7-4-0-2-6-0-7-4 KVBDPTk0MTAzGStNVTxJRUQ7KiAoSj9UUUhOS0c+PSocKURDTFBJQjcyLjEsMhooP0lCNzAZK0pSST1RQ1JZST05LDQxKi0gLU1FS1I/UllOTkw7YnRtbDQvKWxhcnQodGFhJ2FqaSlkX25hJ2VoZmkZK0NKQ0NERT49GihAMTsnMRkrPjI3Ji0gLT4zNikrICk9MD0rKyAoQC89JyocL05MTz1RPVRZSU5JVDtDUjkaL0pLS0RTPVRYQU9MOzYcL05MTz1RPVRZRz1NQzdLRk9KaV1oITIuKzAnLCgzGihBWENZVUtINyApPlRFXT1NPUhDTj82HC9GSVNNWzxSSVBPRVA3MhkrTkg7R0dZTU9fTk5GPWJtcHA4KS9pbHBsY2dhLmFpbShdXXRjb110Z2luKFNjbl5oc3M2KGhtaWYgKU9JPTAaLz1PKz1lZm9wZ11vGStMVUhNRU1DWVc+SD1PRz5FTT9BRU5ORj0aKEVTXUxVR1BDTT82cHJzXyAoTj9UT0tKSUxBX05PP1JZPT1ZUTcyGStCST4+VD0vGi9CT1lEU0c9TUc9Xz5KPVJTSVBFQjdmWmhtZRooQE9VSExIPT5fQ0k5Mi4rLiowKy4rKzAuLy0gKFBDTT82LTQwLDIyLC81KxkrRE1RTkVLO0RZTUVNQzcxKC4wLywpLTUoLjotLjQzKyNMTQ==
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81431461226.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81431461226.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81431461226.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsv2.tmp\vdo.dll
- %TEMP%\insHv27.bcgcabfecccc
- %TEMP%\bcgcabfecccc.zip
- %TEMP%\insHv27.exe
- %TEMP%\nsv2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81431461226.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\insHv27.exe в %TEMP%\bcgcabfecccc.exe