Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'kcdsa' = '\kcdsaui.exe -boo'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\KCDCDRH] 'start' = '00000001'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\KCDCDRH] 'ImagePath' = 'system32\Drivers\KCDCDRH.sys'
- ClassName: '#32770' WindowName: 'Guard-Z Client'
- ClassName: '#32770' WindowName: 'Guard-Z UserInterface'