Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'apisroxy' = '%APPDATA%\Microsoft\Api-gIME\audinput.exe'
- <SYSTEM32>\control.exe
- %WINDIR%\explorer.exe
- <SYSTEM32>\rundll32.exe
- iexplore.exe
- firefox.exe
- firefox.exe process, nss3.dll module
- mailslot\msl0
- %APPDATA%\microsoft\api-gime\audinput.exe
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\prefs.js
- ClassName: 'ProgMan' WindowName: ''
- '<SYSTEM32>\control.exe' /?
- '<SYSTEM32>\rundll32.exe' Shell32.dll,Control_RunDLL /?
- '<SYSTEM32>\cmd.exe' /C "nslookup myip.opendns.com resolver1.opendns.com > %TEMP%\AE2C.bi1"
- '<SYSTEM32>\cmd.exe' /C "nslookup myip.opendns.com resolver1.opendns.com > %TEMP%\E854.bi1"
- '<SYSTEM32>\nslookup.exe' myip.opendns.com resolver1.opendns.com
- '<SYSTEM32>\cmd.exe' /C "echo -------- >> %TEMP%\E854.bi1"
- '<SYSTEM32>\rundll32.exe' Shell32.dll,Control_RunDLL /?' (with hidden window)