Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'rzMuR' = 'C:\scyptf\rzMuRn\rzMuRneHf.vbs'
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- C:\scyptf\rzmurn\rzmurnehf.vbs
- C:\scyptf\rzmurn\rzmur.exe
- '45.##.148.152':3360
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'