Техническая информация
- '%TEMP%\bbhcabfedcbb.exe' 2-1-4-8-0-1-3-4-0-0-2 LU9FPD0wNTA3NB4tUlE6UEhBOTAgLUxEUE9PUUhFRD0vHi5AQVNTRkA9MjM2Ly8YL0JGQD0wHi1PTkdEVEBQX0lCOzEvMTI4HStTRVBURE5XVVFJOWh0cm45KydzZG9yLnRmYyxdaHAsYV10YSxnbWJnIC5ASElDSUdDORgvQy45LTEeLUMuNS0wHStEMzsrMBwnRDM6KTEgLUI0OSUxHyxMUk9CU0JQV1BRRlJBQ1c7HytIUk5BUUNUXUNUSDk9HyxMUk9CU0JQV05ASkE9U2NydGwYL0RVQV9VUEo8HCdFV0JbQ01CSkhKPT0fLERPU1JdQU5HV1JCTj0yHi1TRDlOSlZLVV9TUEs5GC9VSjkyIC1CUi01IC5PUU5UR0tEW09FS0BLTUVHS0BDPVVRSTkgL0dRXk5NTlNGSUU9cnB0YRgvUUJQVVJMR01DV1VSQk5fRD9XUjkqIC5FRURFVjswHCdJUlxAWU4/S0g/V0VNQE5ZUFJDQzleYWtwYSAvQk1WSkRPQEFbSVA7LzY0Jjc1Ky4wNCw0MRwnVEhKQT0xMjAwMDE1MzIyIC9CTVZKRE9AQVtUSUtDPC0nMTYsLjAxMygwLTI1LzcxNio/Sw==
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81431547866.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81431547866.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81431547866.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nsy2.tmp\you.dll
- %TEMP%\insHv28.bbhcabfedcbb
- %TEMP%\bbhcabfedcbb.zip
- %TEMP%\insHv28.exe
- %TEMP%\nsy2.tmp\nsisunz.dll
- %TEMP%\tmp5.tmp
- %TEMP%\81431547866.txt
- %TEMP%\tmp3.tmp
- %TEMP%\tmp4.tmp
- %TEMP%\insHv28.exe в %TEMP%\bbhcabfedcbb.exe