azz...
è grave... mcc.exe sfugge anche a
http://hijackthis.de/index.php
Name: Mojuo.w32
Type: Trojan
File Name: mcc.exe
Found: 06.23.2004
Packer: UPX based
Installation: Copies itself to "Windows\System32" and registers itself in autostartup key [HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ CurrentVersion\ Run] "Multimedia Codecs" = “%system%\mcc.exe”
Size (bytes): 36864
Components: mcc.exe
Additional Information: Connects to ****://ww*.3uz.net/links/index.php/1089121197 to download and save a file to %temppath%/links.tmp, which contains parameters that are stored in [HKEY_CURRENT_USER\Software\Multimedia Codecs\06072004]: Delay, GoTypeN, LastIndex, Run, StartTime, Total, along with a few subkeys LinkN with the following parameters
****://ww*.deep-anal.us/?wm=443
****://ww*.teenygirlshome.com/?ref=414
****://ww*.pussypool.net/?siteid=334
****://ww*.18access.com/main.php?w=100103&m=1****://ww*.allpornclub.com/main.php?w=100103&m=1****://ww*.hentaidatabase.com/main.php?w=100103&m=1