Technical Information
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,<SYSTEM32>\userlogon.exe'
- <SYSTEM32>\userlogon.cpl
- <SYSTEM32>\userlogon.exe
- %TEMP%\tmpf5d2.tmp
- %TEMP%\tmpf5d2.tmp
- from <PATH_SAMPLE>.cpl to \:vlttld߾
- '52.##.240.119':1080
- '74.##9.147.209':4145
- '18.##5.133.116':3128
- '65.##9.38.73':26592
- '15#.#5.186.46':10012