Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe "%APPDATA%\3esazgklyrpcuajsqcpoft2g3hfkuwv2\csrss.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<Full path to virus>' = '<Full path to virus>:*:Enabled:ldrsoft'
- from <Full path to virus> to %APPDATA%\3esazgklyrpcuajsqcpoft2g3hfkuwv\csrss.exe
- 'cn##s.ru':80
- cn##s.ru/cnn/img.php?v=#########################################################
- DNS ASK cn##s.ru