Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe "%CommonProgramFiles%\lsass.exe"'
- %CommonProgramFiles%\lsass.exe
- 'cn###.vicp.cc':1213
- DNS ASK cn###.vicp.cc
- '%CommonProgramFiles%\lsass.exe'