Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Tamer' = '%WINDIR%\mirc.exe'
- 'C:\wizzard.exe'
- '%WINDIR%\mirc.exe'
- 'C:\wizzard.exe' (загружен из сети Интернет)
- '%WINDIR%\regedit.exe' /S %WINDIR%\\mirc.dll
- '%WINDIR%\regedit.exe' /s flk23.reg
- '<SYSTEM32>\wscript.exe' "c:\net.vbs"
- '<SYSTEM32>\mshta.exe' "%WINDIR%\aa.hta"
- '%WINDIR%\msagent\agentsvr.exe' -Embedding
- C:\net.vbs
- %WINDIR%\remote.ini
- %WINDIR%\msn.ico
- C:\wizzard.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\mirc[1].exe
- %WINDIR%\flk23.reg
- %WINDIR%\intikam.txt
- %WINDIR%\demo.xt
- %WINDIR%\aa.hta
- %WINDIR%\mirc.ini
- %WINDIR%\mirc.exe
- %WINDIR%\mirc.dll
- %WINDIR%\flk23.reg
- 'www.tr##ik.org':80
- 'www.mi#c.tc':80
- 'localhost':1036
- www.tr##ik.org/ControL.txt
- www.mi#c.tc/mirc.exe
- DNS ASK www.tr##ik.org
- DNS ASK www.mi#c.tc
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'