Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\lcczw] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\lcczw] 'ImagePath' = '<DRIVERS>\lcczw.sys'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\lcczw] 'ImagePath' = 'system32\drivers\lcczw.sys'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\lcczw] 'Start' = '00000000'
- 'lcczw' <DRIVERS>\lcczw.sys
- %WINDIR%\syswow64\drivers\lcczw.sys
- %WINDIR%\syswow64\kzufy.dll
- '%WINDIR%\syswow64\rundll32.exe' "<SYSTEM32>\kzufy",DllUnregisterServer