Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'NetWork' = '%TEMP%\csrs-.exe'
- %TEMP%\csrs-.exe \melt "<Full path to virus>"
- %TEMP%\csrs-.exe
- %TEMP%\csrs-.exe
- 'sc####.no-ip.biz':100
- DNS ASK sc####.no-ip.biz