Technical Information
- '<Current directory>\upd.exe' <Virus name>.exe
- '<Full path to virus>' (downloaded from the Internet)
- <Full path to virus>
- <Current directory>\upd.exe
- 'te##az.ru':80
- te##az.ru/launcher/Launcher.exe
- te##az.ru/launcher/check.php?ve#
- DNS ASK te##az.ru