Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '<Virus name>' = '%WINDIR%\\<Virus name>.exe'
- <Current directory>\MSWINSCK.ocx
- '67.##5.160.76':80
- 67.##5.160.76http://login.yahoo.com/config/login?lo###################################
- DNS ASK lo###.yahoo.com
- ClassName: 'Indicator' WindowName: ''