****************************************************************************************
		   :
		I-Worm.Zafi.b
		I-Worm.Bagle.at,au,cx-dw
		Virus.Win32.Implinker.a
		Not-a-virus.AdWare.Visiter
		Trojan.Win32.Krotten
		Email-Worm.Win32.Brontok.n
		Backdoor.Win32.Allaple.a
		Trojan-Spy.Win32.Goldun.mg
		Email-Worm.Win32.Warezov
 12.0.0.13   (C) Kaspersky Lab, Antropov Alexey, Vitaly Kamluk 2000-2006.   
.
****************************************************************************************
 :
	/s[n] -         .
		n -     .
	/y -      .
	/i -      .
	/nr -        
	/Rpt[ao][=<   >] -   
		a -   
		o -   ( /  )
 :
	0 -   .
	1 -     .
	2 -       .
	3 -          
		  .
	4 -   .
****************************************************************************************
 :         :
		I-Worm.Zafi.b
		I-Worm.Bagle.at,au,cx-dw
		Virus.Win32.Implinker.a
		Not-a-virus.AdWare.Visiter
		Trojan.Win32.Krotten 
		Email-Worm.Win32.Brontok.n
****************************************************************************************
	
	         ,   
  ,     Hook     
(      )     
  /       ,   
     .

	 ,  c   /    
     klwk.com     , 
   ,       (/s[n]). 
       .

	 ,        -  (
       ),       
          
(   ).

	     , 
 :
	autoexec.bat
		win %infected file%
	win.ini   [Windows]
		run=< >
	system.ini   [boot]
		shell=< >
	   
		HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
		HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
		HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
		HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
		HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
		HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
			:
				AppInit_DLLs
				Run 				
		HKEY_CLASSES_ROOT\\txtfile\\shell\\open\\command (txt )
			   notepad.exe 
		HKEY_CLASSES_ROOT\exefile\shell\open\command (exe )
			  "%1" %* 
		HKEY_CLASSES_ROOT\comfile\shell\open\command (com )
			  "%1" %* 
		HKEY_CLASSES_ROOT\batfile\shell\open\command (bat )
			  "%1" %* 
		HKEY_CLASSES_ROOT\piffile\shell\open\command (pif )
			  "%1" %* 
		HKEY_CLASSES_ROOT\cmdfile\shell\open\command (cmd )
			  "%1" %* 
		HKEY_CLASSES_ROOT\scrfile\shell\open\command (scr )
			  "%1" /S 
		HKEY_CLASSES_ROOT\scrfile\shell\config\command (scr )
			  "%1" 
		HKEY_CLASSES_ROOT\regfile\shell\open\command (reg )
			  regedit.exe "%1" 
	 NT 
	  mIRC
		< Program Files>\Mirc\script.ini
		< Program Files>\Mirc32\script.ini
	  Pirch
		< Program Files>\Pirch98\events.ini
