Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Update Machine' = 'nieufa.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] 'Microsoft Update Machine' = 'nieufa.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Update Machine' = 'nieufa.exe'
- <LS_APPDATA>\Xenocode\Sandbox\aVest\aVest.1.2.3\2013.04.02T11.16\Native\STUBEXE\@SYSTEM@\nieufa.exe 348 "<Текущая директория>\rBot.exe"
- <LS_APPDATA>\Xenocode\Sandbox\aVest\aVest.1.2.3\2013.04.02T11.16\Virtual\STUBEXE\@APPDIR@\rBot.exe
- <SYSTEM32>\nieufa.exe
- <SYSTEM32>\nieufa.exe
- 'la###flash.com':6667
- DNS ASK la###flash.com
- ClassName: 'mIRC' WindowName: ''
- ClassName: 'Indicator' WindowName: ''