Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\Antdule.lnk
- %TEMP%\uplog.tmp
- <LS_APPDATA>\MicroSoft Update1\svServiceUpdate.exe
- %TEMP%\ID56SD.tmp
- %TEMP%\stass
- %TEMP%\<File name>.docx
- '14#.#4.145.32':21
- '<LS_APPDATA>\MicroSoft Update1\svServiceUpdate.exe'