Date: Wed, 04 Jun 2014 11:55:10 +0200 [05:55:10 EDT]
Subject: Shipping Confirmation : Order #002-1301707075-0206502025
| Your Orders | Amazon.com
Thank you for shopping with us. We'd like to let you know that Amazon has received your order, and is preparing it for shipment. Your estimated delivery date is below. If you would like to view the status of your order report is attached here.
This email was sent from a notification-only address that cannot accept incoming email. Please do not reply to this message.
Automated analysis tools    shows the malware altering system files and creating a fake csrss.exe and svhost.exe to run at startup.
The malware also attempts to phone home to two IP addresses at 18.104.22.168 and 22.214.171.124 hosted in Russia but controlled by a Ukranian person or entity PE Ivanov Vitaliy Sergeevich. These network blocks are well-known purveyors of crapware, and I recommend that you block the following: