Technical Information
- [HKLM\SYSTEM\CurrentControlSet\services\fmohdpaa] 'Start' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\services\fmohdpaa] 'ImagePath' = 'system32\drivers\GCtplhNJ.sys'
- <SYSTEM32>\lsass.exe
- <SYSTEM32>\svchost.exe
- <DRIVERS>\gctplhnj.sys