Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Tamer' = '<SYSTEM32>\mirc.exe'
- C:\wizzard.exe
- <SYSTEM32>\mirc.exe
- C:\wizzard.exe (загружен из сети Интернет)
- %WINDIR%\regedit.exe /S <SYSTEM32>\\mirc.dll
- %WINDIR%\regedit.exe /s flk23.reg
- %WINDIR%\msagent\agentsvr.exe -Embedding
- <SYSTEM32>\mshta.exe "<SYSTEM32>\aa.hta"
- <SYSTEM32>\wscript.exe "c:\net.vbs"
- C:\net.vbs
- <SYSTEM32>\remote.ini
- <SYSTEM32>\msn.ico
- C:\wizzard.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\mirc[1].exe
- <SYSTEM32>\flk23.reg
- <SYSTEM32>\intikam.txt
- <SYSTEM32>\demo.xt
- <SYSTEM32>\aa.hta
- <SYSTEM32>\mirc.ini
- <SYSTEM32>\mirc.exe
- <SYSTEM32>\mirc.dll
- <SYSTEM32>\flk23.reg
- 'www.in###am.info':80
- 'www.mi#c.tc':80
- 'localhost':1036
- www.in###am.info/sikimiyee.txt
- www.mi#c.tc/mirc.exe
- DNS ASK www.in###am.info
- DNS ASK www.mi#c.tc
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''