Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\gdd] 'ImagePath' = 'system32\drivers\uos.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\uos] 'Start' = '00000000'
- %WINDIR%\Explorer.EXE
- <DRIVERS>\gdd.sys
- <SYSTEM32>\tlcpz.dll
- <DRIVERS>\gdd.sys в <DRIVERS>\uos.sys