Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\NPF] 'Start' = '00000001'
- <SYSTEM32>\shutdown.exe /r /t 0
- <SYSTEM32>\reg.exe IMPORT %TEMP%\reg.reg
- <DRIVERS>\npf.sys
- %TEMP%\reg.reg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\194.8.251[1].htm
- '19#.#.251.170':80
- 19#.#.251.170/