Техническая информация
- '%TEMP%\bccjcabeddc.exe' 4-9-5-6-4-7-5-9-8-8-3 K0dEPjkqLicpKx0rSlA8TEI/NCgYLEo8T1FLS0ZAPDUtHCY/Q09NRDs1KjEyMDQaKzxEOzUoHStHTUlATj5LV0FBOSkvKjAsGyZLPU9SPE1ZUUtHNGBscWwxKilvXm1tJmxlYSRcamwmX1hsWStlZWFpHCg+Q0E7SEU7OCouKSxZXTFiKVozMjUmLycrXio0LTQyKTIxWigrYi0rLiowKhsmPCk6LRcqPi42KCgYJ0EvNCgrHCg/KzUlLhwmPy85JiwXJ0hPSztQPVBYS0lBTj4/UDgaK0lNRjxNQFBWQE9IOjgXJ0hPSztQPVBYSThFPTocJkBSQVhQSUQ1HSs8Uz9bPEg7REFLQTQbKURITktXOk9LTk4/TjYtFydMRT1FRlNLTlpMSkQ6HCZPQ0k+OCgsKTY0Li0tLDEbJk5FOi4XKj5PKjhkWmsqYisrGitLUEVMQUpBVlI/SDxKRD1BSj0+QE9ORTgXJ0FQW0lQSFBCSDw1bG9xXBspTj5PTEpGRko+Wk9PPk1WPDlWTzQtGitBRDs9UDotFypDT1g/UEY5SkU6Wj9KPE1QSExCQDRhW2hsYBcnPExTRUdJPT1aS0FFQjkoLSkuMiopKCkxJis1LzQzLS8iSEocJj9JU0dHRjk8XEVHOCwwJy0rLyYuLykpLC4v
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81420544763.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81420544763.txt bios get serialnumber
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\81420544763.txt
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\tmp3.tmp
- %TEMP%\nso2.tmp\ddv.dll
- %TEMP%\insHv18.bccjcabeddc
- %TEMP%\bccjcabeddc.zip
- %TEMP%\insHv18.exe
- %TEMP%\nso2.tmp\nsisunz.dll
- %TEMP%\81420544763.txt
- %TEMP%\tmp5.tmp
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %TEMP%\bccjcabeddc.zip
- %TEMP%\insHv18.bccjcabeddc
- %TEMP%\tmp4.tmp
- %TEMP%\tmp3.tmp
- %TEMP%\insHv18.exe в %TEMP%\bccjcabeddc.exe