Technical Information
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '%APPDATA%\Winlock.exe'
- %APPDATA%\winlock.exe
- %APPDATA%\unlock.exe
- \device\harddiskvolume1\boot\bcd.log
- \device\harddiskvolume1\boot\bcd
- '%APPDATA%\winlock.exe'
- '<SYSTEM32>\cmd.exe' /c sc start BlockAllAccess
- '<SYSTEM32>\sc.exe' start BlockAllAccess