Technical Information
- [HKLM\System\CurrentControlSet\Services\mnkflgkzz] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\mnkflgkzz] 'ImagePath' = '<SYSTEM32>\feature.exe mnkflgkzz'
- 'mnkflgkzz' <SYSTEM32>\feature.exe mnkflgkzz
- %WINDIR%\syswow64\feature.exe
- from <Full path to file> to %WINDIR%\syswow64\wostmp\_596486325_527150128
- '1.###.248.27':27930
- '<LOCALNET>.36.130':27930
- '<LOCALNET>.0.54':27930
- '<LOCALNET>.36.129':27930
- '<LOCALNET>.0.53':27930
- '<LOCALNET>.36.128':27930
- '20#.71.0.93':27930
- '<LOCALNET>.0.52':27930
- '<LOCALNET>.0.63':27930
- '<LOCALNET>.36.127':27930
- '<LOCALNET>.36.126':27930
- '<LOCALNET>.0.51':27930
- '<LOCALNET>.36.125':27930
- '<LOCALNET>.0.49':27930
- '<LOCALNET>.36.124':27930
- '19#.#51.12.63':27930
- '<LOCALNET>.0.48':27930
- '<LOCALNET>.0.50':27930
- '<LOCALNET>.36.123':27930
- '<LOCALNET>.0.47':27930
- '20#.#35.34.69':27930
- '<LOCALNET>.36.131':27930
- '<LOCALNET>.36.138':27930
- '<LOCALNET>.0.62':27930
- '<LOCALNET>.36.137':27930
- '<LOCALNET>.0.61':27930
- '21#.#48.16.76':27930
- '<LOCALNET>.36.136':27930
- '<LOCALNET>.0.59':27930
- '<LOCALNET>.0.60':27930
- '<LOCALNET>.0.55':27930
- '<LOCALNET>.36.134':27930
- '<LOCALNET>.0.58':27930
- '<LOCALNET>.36.133':27930
- '<LOCALNET>.0.57':27930
- '<LOCALNET>.0.56':27930
- '<LOCALNET>.36.132':27930
- '<LOCALNET>.36.135':27930
- '<LOCALNET>.36.105':27930
- '<LOCALNET>.0.64':27930
- '<LOCALNET>.36.117':27930
- '<LOCALNET>.36.112':27930
- '<LOCALNET>.0.36':27930
- '18#.#2.112.114':27930
- '<LOCALNET>.36.111':27930
- '<LOCALNET>.0.35':27930
- '<LOCALNET>.36.110':27930
- '<LOCALNET>.0.34':27930
- '<LOCALNET>.36.121':27930
- '<LOCALNET>.36.109':27930
- '<LOCALNET>.36.108':27930
- '<LOCALNET>.0.32':27930
- '<LOCALNET>.0.31':27930
- '<LOCALNET>.36.107':27930
- '18#.#2.131.182':27930
- '<LOCALNET>.0.30':27930
- '<LOCALNET>.36.106':27930
- '<LOCALNET>.0.33':27930
- '<LOCALNET>.36.122':27930
- '<LOCALNET>.0.45':27930
- '<LOCALNET>.36.114':27930
- '<LOCALNET>.36.113':27930
- '<LOCALNET>.0.44':27930
- '<LOCALNET>.36.120':27930
- '19#.#5.222.155':27930
- '<LOCALNET>.0.46':27930
- '<LOCALNET>.36.119':27930
- '<LOCALNET>.0.43':27930
- '<LOCALNET>.0.38':27930
- '<LOCALNET>.36.118':27930
- '<LOCALNET>.0.37':27930
- '<LOCALNET>.0.40':27930
- '<LOCALNET>.36.116':27930
- '<LOCALNET>.0.39':27930
- '18#.#8.218.133':27930
- '<LOCALNET>.36.115':27930
- '<LOCALNET>.0.42':27930
- '<LOCALNET>.0.41':27930
- '<LOCALNET>.0.29':27930
- '<LOCALNET>.36.139':27930
- '<LOCALNET>.36.144':27930
- '<LOCALNET>.36.168':27930
- '<LOCALNET>.0.93':27930
- '<LOCALNET>.36.167':27930
- '<LOCALNET>.0.97':27930
- '<LOCALNET>.36.166':27930
- '<LOCALNET>.0.92':27930
- '<LOCALNET>.36.165':27930
- '<LOCALNET>.0.85':27930
- '<LOCALNET>.0.91':27930
- '<LOCALNET>.0.90':27930
- '<LOCALNET>.36.163':27930
- '<LOCALNET>.0.89':27930
- '<LOCALNET>.36.162':27930
- '<LOCALNET>.0.87':27930
- '<LOCALNET>.36.161':27930
- '<LOCALNET>.0.86':27930
- '<LOCALNET>.36.164':27930
- '<LOCALNET>.36.160':27930
- '<LOCALNET>.0.94':27930
- '<LOCALNET>.0.102':27930
- '<LOCALNET>.0.103':27930
- '<LOCALNET>.36.177':27930
- '<LOCALNET>.0.106':27930
- '<LOCALNET>.36.176':27930
- '<LOCALNET>.0.100':27930
- '<LOCALNET>.36.175':27930
- '<LOCALNET>.0.99':27930
- '<LOCALNET>.0.95':27930
- '<LOCALNET>.36.169':27930
- '<LOCALNET>.36.173':27930
- '<LOCALNET>.0.98':27930
- '<LOCALNET>.36.172':27930
- '<LOCALNET>.0.101':27930
- '<LOCALNET>.36.171':27930
- '<LOCALNET>.0.96':27930
- '<LOCALNET>.36.170':27930
- '<LOCALNET>.36.174':27930
- '<LOCALNET>.36.140':27930
- '<LOCALNET>.0.68':27930
- '<LOCALNET>.36.158':27930
- '<LOCALNET>.0.72':27930
- '<LOCALNET>.0.76':27930
- '<LOCALNET>.36.147':27930
- '<LOCALNET>.0.71':27930
- '<LOCALNET>.36.146':27930
- '<LOCALNET>.0.70':27930
- '<LOCALNET>.36.145':27930
- '<LOCALNET>.36.148':27930
- '<LOCALNET>.0.73':27930
- '<LOCALNET>.0.88':27930
- '<LOCALNET>.36.143':27930
- '<LOCALNET>.0.67':27930
- '<LOCALNET>.36.142':27930
- '<LOCALNET>.0.66':27930
- '<LOCALNET>.36.141':27930
- '<LOCALNET>.0.65':27930
- '<LOCALNET>.0.69':27930
- '<LOCALNET>.36.159':27930
- '<LOCALNET>.36.149':27930
- '<LOCALNET>.0.79':27930
- '<LOCALNET>.36.154':27930
- '<LOCALNET>.36.157':27930
- '<LOCALNET>.0.82':27930
- '<LOCALNET>.36.156':27930
- '<LOCALNET>.0.81':27930
- '<LOCALNET>.0.84':27930
- '<LOCALNET>.36.155':27930
- '<LOCALNET>.0.83':27930
- '<LOCALNET>.0.74':27930
- '<LOCALNET>.36.150':27930
- '<LOCALNET>.36.153':27930
- '<LOCALNET>.0.77':27930
- '<LOCALNET>.36.152':27930
- '<LOCALNET>.0.80':27930
- '<LOCALNET>.36.151':27930
- '<LOCALNET>.0.75':27930
- '<LOCALNET>.0.78':27930
- '<LOCALNET>.0.28':27930
- '<LOCALNET>.36.104':27930
- '<LOCALNET>.0.27':27930
- '<LOCALNET>.36.43':27930
- '22#.#1.122.230':27930
- '<LOCALNET>.36.42':27930
- '<LOCALNET>.36.41':27930
- '<LOCALNET>.36.40':27930
- '<LOCALNET>.36.39':27930
- '<LOCALNET>.36.45':27930
- '<LOCALNET>.36.38':27930
- '<LOCALNET>.36.37':27930
- '<LOCALNET>.36.36':27930
- '<LOCALNET>.36.35':27930
- '<LOCALNET>.36.34':27930
- '18#.#8.212.176':27930
- '<LOCALNET>.36.33':27930
- '<LOCALNET>.36.32':27930
- '18#.#1.63.214':27930
- '<LOCALNET>.36.31':27930
- '<LOCALNET>.36.61':27930
- '<LOCALNET>.36.30':27930
- '<LOCALNET>.36.60':27930
- '<LOCALNET>.36.59':27930
- '82.##.198.189':27930
- '<LOCALNET>.36.58':27930
- '<LOCALNET>.36.57':27930
- '<LOCALNET>.36.56':27930
- '<LOCALNET>.36.55':27930
- '58.##.147.71':27930
- '<LOCALNET>.36.46':27930
- '<LOCALNET>.36.53':27930
- '<LOCALNET>.36.52':27930
- '<LOCALNET>.36.51':27930
- '59.##.201.97':27930
- '<LOCALNET>.36.50':27930
- '<LOCALNET>.36.49':27930
- '<LOCALNET>.36.48':27930
- '<LOCALNET>.36.54':27930
- '<LOCALNET>.36.47':27930
- '61.##4.50.237':27930
- '<LOCALNET>.36.29':27930
- '<LOCALNET>.36.22':27930
- '<LOCALNET>.36.11':27930
- '<LOCALNET>.36.10':27930
- '17#.16.8.40':27930
- '<LOCALNET>.36.9':27930
- '<LOCALNET>.36.8':27930
- '<LOCALNET>.36.7':27930
- '<LOCALNET>.36.13':27930
- '<LOCALNET>.36.6':27930
- '<LOCALNET>.36.5':27930
- '<LOCALNET>.36.4':27930
- '<LOCALNET>.36.3':27930
- '<LOCALNET>.36.2':27930
- '14.#92.2.37':27930
- '<LOCALNET>.36.1':27930
- '<LOCALNET>.36.0':27930
- '17#.16.8.50':27930
- '12#.#60.154.252':27930
- '<LOCALNET>.36.62':27930
- '<LOCALNET>.36.12':27930
- '<LOCALNET>.36.28':27930
- '<LOCALNET>.36.27':27930
- '<LOCALNET>.36.26':27930
- '11#.#10.212.150':27930
- '<LOCALNET>.36.25':27930
- '<LOCALNET>.36.24':27930
- '<LOCALNET>.36.23':27930
- '<LOCALNET>.36.14':27930
- '17#.#6.48.221':27930
- '<LOCALNET>.36.21':27930
- '<LOCALNET>.36.20':27930
- '<LOCALNET>.36.19':27930
- '<LOCALNET>.36.18':27930
- '17#.#6.12.203':27930
- '<LOCALNET>.36.17':27930
- '<LOCALNET>.36.16':27930
- '10#.#16.52.20':27930
- '<LOCALNET>.36.15':27930
- '<LOCALNET>.36.44':27930
- '91.#87.99.3':27930
- '<LOCALNET>.0.18':27930
- '12#.#47.83.95':27930
- '<LOCALNET>.36.94':27930
- '<LOCALNET>.0.17':27930
- '<LOCALNET>.36.93':27930
- '<LOCALNET>.0.16':27930
- '<LOCALNET>.36.92':27930
- '<LOCALNET>.0.15':27930
- '<LOCALNET>.36.87':27930
- '<LOCALNET>.36.95':27930
- '12#.#8.33.17':27930
- '<LOCALNET>.36.90':27930
- '<LOCALNET>.0.13':27930
- '<LOCALNET>.0.12':27930
- '<LOCALNET>.36.89':27930
- '<LOCALNET>.0.11':27930
- '<LOCALNET>.36.88':27930
- '<LOCALNET>.0.14':27930
- '<LOCALNET>.36.91':27930
- '12#.#60.58.206':27930
- '<LOCALNET>.0.21':27930
- '<LOCALNET>.36.100':27930
- '<LOCALNET>.36.103':27930
- '<LOCALNET>.0.26':27930
- '<LOCALNET>.36.102':27930
- '<LOCALNET>.0.25':27930
- '<LOCALNET>.36.101':27930
- '<LOCALNET>.0.24':27930
- '18#.#1.168.237':27930
- '<LOCALNET>.0.22':27930
- '<LOCALNET>.36.96':27930
- '<LOCALNET>.36.99':27930
- '<LOCALNET>.0.20':27930
- '<LOCALNET>.36.98':27930
- '<LOCALNET>.0.19':27930
- '<LOCALNET>.36.97':27930
- '<LOCALNET>.0.23':27930
- '16#.#94.189.141':27930
- '<LOCALNET>.0.10':27930
- '<LOCALNET>.0.9':27930
- '<LOCALNET>.36.63':27930
- '<LOCALNET>.36.75':27930
- '11#.#8.238.194':27930
- '<LOCALNET>.36.74':27930
- '<LOCALNET>.36.73':27930
- '<LOCALNET>.36.72':27930
- '<LOCALNET>.36.71':27930
- '<LOCALNET>.36.77':27930
- '11#.#93.17.179':27930
- '<LOCALNET>.36.69':27930
- '<LOCALNET>.36.68':27930
- '<LOCALNET>.36.67':27930
- '10#.#4.137.178':27930
- '<LOCALNET>.36.66':27930
- '<LOCALNET>.36.65':27930
- '<LOCALNET>.36.64':27930
- '<LOCALNET>.36.70':27930
- '<LOCALNET>.0.0':27930
- '<LOCALNET>.36.76':27930
- '<LOCALNET>.36.78':27930
- '<LOCALNET>.36.86':27930
- '<LOCALNET>.0.5':27930
- '<LOCALNET>.0.8':27930
- '<LOCALNET>.36.85':27930
- '<LOCALNET>.0.7':27930
- '<LOCALNET>.36.84':27930
- '<LOCALNET>.0.6':27930
- '11#.#19.252.204':27930
- '<LOCALNET>.36.83':27930
- '<LOCALNET>.36.82':27930
- '<LOCALNET_GATEWAY>':27930
- '<LOCALNET>.0.4':27930
- '<LOCALNET>.36.81':27930
- '<LOCALNET>.0.3':27930
- '<LOCALNET>.36.80':27930
- '<LOCALNET>.0.2':27930
- '11#.#3.15.166':27930
- '<LOCALNET>.36.79':27930
- '<LOCALNET>.0.104':27930
- '<LOCALNET>.36.178':27930
- '%WINDIR%\syswow64\feature.exe' mnkflgkzz