Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Kris' = '<Full path to virus>'
- %WINDIR%\svchest138886412041280.exe
- %WINDIR%\svchest138886412041280.exe
- %WINDIR%\BJ.exe
- %WINDIR%\svchest138886412041280.exe
- 'aa###3.3322.org':1379
- DNS ASK aa###3.3322.org
- '<Private IP address>':1038