
 Magistr.b disinfection
 ----------------------

The virus uses ComputerName as key to encrypt victim file data. To disinfect
such files we need to get ComputerName. From database (from disinfection
routine) we can't use Win32 API function GetComputerNameA to do that.


Solved. Solution will be sent to AVP_Files list.

1. Run DISINF.EXE file.  It will create DISINF.INI file with different data in
it, including ComputerName.

2. Scan DISINF.INI file.  A routine in database will get computer name from
DISINF.INI file.

3. Scan machine and disinfect Magistr.  The disinfection routine will use
ComputerName from 2.


Note: the virus _does_not_ use ComputerName to encrypt files in two cases:

 if file length < 20000h 
 if file is infected on remote machine.

