Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%HOMEPATH%\Templates\ngpnp.exe' = '%HOMEPATH%\Templates\ngpnp.exe:*:En...
- '%HOMEPATH%\Templates\ngpnp.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%HOMEPATH%\Templates\ngpnp.exe" "ngpnp.exe" ENABLE
- '<SYSTEM32>\schtasks.exe' /create /sc minute /mo 1 /tn "ngfinal" /tr "%HOMEPATH%\Templates\ngpnp.exe"
- %HOMEPATH%\Templates\ngpnp.exe
- 'mr#.#ytes.net':117
- DNS ASK mr#.#ytes.net