Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'UPDATE' = '<SYSTEM32>\Install.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{7E5BEE95-0380-1578-D1DD-61AA249C9DF6}] 'StubPath' = '<SYSTEM32>\Install.exe'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\Install.exe
- 'su##.er1620.com':80
- DNS ASK su##.er1620.com