Technical Information
- [<HKLM>\SYSTEM\CONTROLSET003\Services\ohthdz] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet002\Services\ohthdz] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\ohthdz] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k ohthdz
- <SYSTEM32>\gxpcyp.dll
- <SYSTEM32>\0004ab91.sys
- 'we####ue.3322.org':90
- DNS ASK we####ue.3322.org