Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'mspgsrv' = 'rundll32.exe "%HOMEPATH%\Library\mspgsrv.dll", Launch'
- '<SYSTEM32>\cmd.exe' /c del "<Full path to virus>" > nul
- '<SYSTEM32>\rundll32.exe' "%HOMEPATH%\Library\mspgsrv.dll", Launch
- %HOMEPATH%\Library\mspgsrv.dll
- '<Private IP address>':80
- ClassName: 'Indicator' WindowName: ''