Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\2asbfcpg.bat
- '<SYSTEM32>\taskkill.exe' /f /im svchost.exe
- <SYSTEM32>\svchost.exe
- %TEMP%\2asbfcpg.bat
- <SYSTEM32>\2asbfcpg.bat
- nul
- %TEMP%\2asbfcpg.bat
- 'localhost':63691
- 'localhost':55195
- ClassName: '' WindowName: ''
- ClassName: '' WindowName: 'View Available Networks'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\2AsBfcpg.bat" "
- '<SYSTEM32>\cmd.exe' /S /D /c" echo %TEMP%\2AsBfcpg.bat "
- '<SYSTEM32>\find.exe' /i "<SYSTEM32>"
- '<SYSTEM32>\cmd.exe' /K "<SYSTEM32>\2AsBfcpg.bat"
- '<SYSTEM32>\cmd.exe' /S /D /c" echo <SYSTEM32>\2AsBfcpg.bat "
- '<SYSTEM32>\timeout.exe' /t 10
- '<SYSTEM32>\svchost.exe' -k DcomLaunch
- '<SYSTEM32>\svchost.exe' -k RPCSS
- '<SYSTEM32>\svchost.exe' -k LocalSystemNetworkRestricted