Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'asfeader' = 'rundll32 "%APPDATA%\api-nect\Auxithlp.dll",DllRegisterServer'
- <SYSTEM32>\svchost.exe
- %WINDIR%\explorer.exe
- iexplore.exe
- firefox.exe
- Процесс firefox.exe, модуль nss3.dll
- [HKCU\Software\Microsoft\Internet Account Manager]
- [HKLM\Software\Microsoft\Windows Mail]
- [HKCU\Software\Microsoft\Windows Mail]
- [HKCU\Software\Microsoft\Windows Live Mail]
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\]
- %APPDATA%\api-nect\auxithlp.dll
- %APPDATA%\mozilla\firefox\profiles\apc2n9d1.default-release\prefs.js
- DNS ASK va#####vnoedos9302.ru
- ClassName: 'ProgMan' WindowName: ''
- '<SYSTEM32>\svchost.exe'