Affected OS: Win9x/NT/2000/XP/2003
Size: 157 184 bytes
Packed by: PE_Patch, ASProtect
HKEY_LOCAL_MACHINE\kSoftware\Ghisler\Windows Commander
HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager\Accounts
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
HKEY_LOCAL_MACHINE\Software\RimArts\B2\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\&RQ
HKEY_LOCAL_MACHINE\SOFTWARE\Miranda
HKEY_LOCAL_USER\SOFTWARE\RIT\The Bat!
HKEY_LOCAL_USER\SOFTWARE\Far\Plugins\FTP\Hosts
HKEY_LOCAL_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trillian\
CuteFTP
CuteFTP Pro
Edialer
Opera
Mozilla
The Bat!
WS_FTP
WS_FTP Home
Also computer name and OS version are both sent to the malefactor.
1. Run OS Windows in Safe Mode (F8 at the Windows' start)
2. Use either disc scanner Dr.Web® or free Dr.Web® CureIT! utility to scan computer local discs. Apply “Cure” to all infected files, which have been detected.
3. Recover registry from backup copy.
4. Attention! All registered passwords should be changed throughout system.