For those who downloaded the malware:
Kill the process csrss.exe (the bigger)
then directly windchp.exe
after it delete the startup key Win DHCP "windchp.exe" (use msconfig with command-line)
and delete file here: C:\Users\YOURNAME\AppData\Roaming\Windows\DCHP\ HERE IS MALWARES
You can also block this ip/port: 212.7.208.87:5604