Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{90EAB2F7-BBE6-4265-AF34-010DB8F155A1}' = '%PROGRAMDATA%\scrvs\scrvs'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '{EBB76DB8-FCB0-44EF-B541-DF828297E0EB}' = '%PROGRAMDATA%\scrvs\scrvs'
- %WINDIR%\explorer.exe
- %PROGRAMDATA%\scrvs\scrvs
- 'rs###.mooo.com':9889
- DNS ASK rs###.mooo.com
- '<SYSTEM32>\svchost.exe'
- '%WINDIR%\explorer.exe'