Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows_Update' = '<Full path to virus>'
- %WINDIR%\IE6 Erro Log.txt
- <Full path to virus>
- 'la####.com.sapo.pt':80
- 'localhost':1037
- http://la####.com.sapo.pt/fotinha.html
- DNS ASK la####.com.sapo.pt