Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\baby] 'ImagePath' = '<SYSTEM32>\PastFOlIQ.sys'
- ClassName: 'pediy06', WindowName: ''
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'OLLYDBG', WindowName: ''
- <SYSTEM32>\PastFOlIQ.sys
- <SYSTEM32>\PastFOlIQ.sys