Technical Information
- '%WINDIR%\syswow64\net.exe' stop npf
- %TEMP%\nsw363d.tmp
- %TEMP%\~nsu.tmp\au_.exe
- %TEMP%\nsr3b9a.tmp
- %TEMP%\nsr3b9b.tmp\nsexec.dll
- %TEMP%\nsr3b9b.tmp\system.dll
- %TEMP%\nsr3b9b.tmp\nsexec.dll
- %TEMP%\nsr3b9b.tmp\system.dll
- '%TEMP%\~nsu.tmp\au_.exe' _?=<Current directory>\
- '%WINDIR%\syswow64\net.exe' stop npf' (with hidden window)
- '%WINDIR%\syswow64\net1.exe' stop npf