Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\htnhslOd.dll] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\htnhslOd.dll] 'ImagePath' = '<SYSTEM32>\regsvr32.exe "<SYSTEM32>\AaAAgOGuaCBKD\htnhslOd.dll"'
- 'htnhslOd.dll' <SYSTEM32>\regsvr32.exe "<SYSTEM32>\AaAAgOGuaCBKD\htnhslOd.dll"
- из <Полный путь к файлу> в <SYSTEM32>\aaaagoguacbkd\htnhslod.dll
- '16#.#0.222.65':443
- '14#.#02.108.116':8080
- '<SYSTEM32>\regsvr32.exe' "<SYSTEM32>\AaAAgOGuaCBKD\htnhslOd.dll"