****************************************************************************************
		   :
			I-Worm.BleBla.b
			I-Worm.Navidad
			I-Worm.Sircam
			I-Worm.Goner
			I-Worm.Klez.a,e,f,g,h
			Win32.Elkern.c
			I-Worm.Lentin.a,b,c,d,e,f,g,h,i,j,k,l,m,n,o,p
			I-Worm.Tanatos.a,b
			Worm.Win32.Opasoft.a,b,c,d,e,f,g,h,i,j,k,l,m,n,o,p
			I-Worm.Avron.a,b,c,d,e
			I-Worm.LovGate.a,b,c,d,e,f,g,h,i,j,k,l
			I-Worm.Fizzer
			I-Worm.Magold.a,b,c,d,e
			Worm.Win32.Lovesan
			Worm.Win32.Welchia
			I-Worm.Sobig.f
			I-Worm.Dumaru.a-m
			Trojan.Win32.SilentLog.a-b
			Backdoor.Small.d
			I-Worm.Swen
			Backdoor.Afcore.l-ad
			I-Worm.Sober.a,c
			I-Worm.Mydoom.a-b,e
			I-Worm.Torvil.d
			I-Worm.NetSky.b-d
			TrojanDownloader.Win32.Agent.a-j,n-r
			I-Worm.Bagle.a-j
			Worm.Win32.Sasser.a-c
 10.1.2.1   (C) Kaspersky Lab 2000-2004.   .
****************************************************************************************
 :
	/s[n] -   .     
		   I-Worm.Klez.a(e,f,g,h)    .
		n -     .
	/y -      .
	/i -      .
	/nr -       
	/Rpt[ao][=<   >] -   
		a -   
		o -   ( /  )
 :
	0 -   .
	1 -     .
	2 -       .
	3 -          
		  .
	4 -   .
****************************************************************************************

I-Worm.BleBla.b
---------------
	   HKEY_CLASSES_ROOT\rnjfile    , :
     
	HKEY_CLASSES_ROOT\rnjfile
	HKEY_CLASSES_ROOT\.lha
          
	HKEY_CLASSES_ROOT\.jpg to jpegfile
	HKEY_CLASSES_ROOT\.jpeg to jpegfile
	HKEY_CLASSES_ROOT\.jpe to jpegfile
	HKEY_CLASSES_ROOT\.bmp to Paint.Picture
	HKEY_CLASSES_ROOT\.gif to giffile
	HKEY_CLASSES_ROOT\.avi to avifile
	HKEY_CLASSES_ROOT\.mpg to mpegfile
	HKEY_CLASSES_ROOT\.mpeg to mpegfile
	HKEY_CLASSES_ROOT\.mp2 to mpegfile
	HKEY_CLASSES_ROOT\.wmf to empty
	HKEY_CLASSES_ROOT\.wma to wmafile
	HKEY_CLASSES_ROOT\.wmv to wmvfile
	HKEY_CLASSES_ROOT\.mp3 to mp3file
	HKEY_CLASSES_ROOT\.vqf to empty
	HKEY_CLASSES_ROOT\.doc to word.document.8 or wordpad.document.1
	HKEY_CLASSES_ROOT\.xls to excel.sheet.8
	HKEY_CLASSES_ROOT\.zip to winzip
	HKEY_CLASSES_ROOT\.rar to winrar
	HKEY_CLASSES_ROOT\.arj to archivefile or winzip
	HKEY_CLASSES_ROOT\.reg to regfile
	HKEY_CLASSES_ROOT\.exe to exefile
   
	c:\windows\sysrnj.exe

I-Worm.Navidad
--------------
	   HKEY_CURRENT_USER\Software\Navidad,
HKEY_CURRENT_USER\Software\xxxxmas or HKEY_CURRENT_USER\Software\Emanuel    
 :
     
	HKEY_CURRENT_USER\Software\Navidad
	HKEY_CURRENT_USER\Software\xxxxmas
	HKEY_CURRENT_USER\Software\Emanuel
	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
			Win32BaseServiceMOD
          
	HKEY_CLASSES_ROOT\exefile\shell\open\command to "%1" %*
   
	winsvrc.vxd
	winfile.vxd
	wintask.exe

I-Worm.Sircam
-------------
	   find HKEY_LOCAL_MACHINE\Software\SirCam    
, "@win \recycled\sirc32.exe"  autoexec.bat   \windows\run32.exe     
\windows\rundll32.exe     Delphi :
     
	HKEY_LOCAL_MACHINE\Software\SirCam
	Software\Microsoft\Windows\CurrentVersion\RunServices
			Driver32
          
	HKEY_CLASSES_ROOT\exefile\shell\open\command to "%1" %*
   
	%Windows drive%:\RECYCLED\SirC32.exe
	%Windows directory%\ScMx32.exe
	%Windows system directory%\SCam32.exe
	%Windows startup directory%\"Microsoft Internet Office.exe"
	%Windows drive%:\windows\rundll32.exe
   
	%Windows drive%:\windows\Run32.exe to 
			%Windows drive%:\windows\RunDll32.exe
   
	autoexec.bat

  
--------------------
	      ,     ,  
   Hook          
            
            .
	        ,   
 .        .
	     /s      ( 
         /sn)   .
	         -  (
       )        
         
.
	     , 
 :
	autoexec.bat
		win %infected file%
	win.ini   [Windows]
		run=< >
	system.ini   [boot]
		shell=< >
	   
		HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
		HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
		HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
		HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
		HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
			
			AppInit_DLLs
			Run
		HKEY_CLASSES_ROOT\\txtfile\\shell\\open\\command (txt )
			   notepad.exe 
		HKEY_CLASSES_ROOT\exefile\shell\open\command (exe )
			  "%1" %* 
		HKEY_CLASSES_ROOT\comfile\shell\open\command (com )
			  "%1" %* 
		HKEY_CLASSES_ROOT\batfile\shell\open\command (bat )
			  "%1" %* 
		HKEY_CLASSES_ROOT\piffile\shell\open\command (pif )
			  "%1" %* 
		HKEY_CLASSES_ROOT\cmdfile\shell\open\command (cmd )
			  "%1" %* 
		HKEY_CLASSES_ROOT\scrfile\shell\open\command (scr )
			  "%1" /S 
		HKEY_CLASSES_ROOT\scrfile\shell\config\command (scr )
			  "%1" 
		HKEY_CLASSES_ROOT\regfile\shell\open\command (reg )
			  regedit.exe "%1" 
	 NT 
	  mIRC
		< Program Files>\Mirc\script.ini
		< Program Files>\Mirc32\script.ini
	  Pirch
		< Program Files>\Pirch98\events.ini
