Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '%ALLUSERSPROFILE%\22CC6C32.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '%ALLUSERSPROFILE%\22CC6C32.exe'
- %WINDIR%\explorer.exe
- %ALLUSERSPROFILE%\22cc6c32.exe
- from <Full path to file> to %ALLUSERSPROFILE%\yo3jzo4jzp4.exe