Technical Information
- '%APPDATA%\csrss.exe' <Full path to virus>
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 5
- %TEMP%\tmp3.tmp
- %TEMP%\uio4.tmp
- %TEMP%\tmp5.tmp
- %TEMP%\nsh2.tmp\System.dll
- %APPDATA%\csrss.exe
- %PROGRAM_FILES%\MirDisk\ver.ini
- %WINDIR%\Downloaded Program Files\MirDiskCtrl.dll
- %TEMP%\tmp5.tmp
- %APPDATA%\csrss.exe
- %TEMP%\uio4.tmp
- %TEMP%\nsh2.tmp\System.dll
- %TEMP%\tmp3.tmp
- '20#.#24.194.233':9090