Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'PorJat' = '<Full path to virus>'
- %APPDATA%\pc.id
- <Current directory>\icc.cur
- '17#.#0.122.118':80
- http://17#.#0.122.118/2016.txt
- ClassName: 'Button' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'ShellTray Wnd' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''