Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,"%LOCALAPPDATA%\Pic1fPBkmq\LOHejsSdpL.exe" -s'
- %TEMP%\1chta5z1gx.exe
- %LOCALAPPDATA%\pic1fpbkmq\lohejssdpl.exe
- %TEMP%\a9524d72-c5d8-430f-b24c-f57a905ee15a\agiledotnetrt64.dll
- <Current directory>\rasphone.pbk
- %LOCALAPPDATA%\pic1fpbkmq\lohejssdpl.exe
- '%TEMP%\1chta5z1gx.exe'