Technical Information
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '7938' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '7035' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '18979' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '3100' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '2942' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '30352' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '13605' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '4874' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '20048' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '30613' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '5108' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '8890' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '159' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '23515' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '28038' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '7809' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '27498' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '31278' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '24000' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '3996' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '12382' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '15394' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '12934' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '9273' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '22249' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '3941' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '10047' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '693' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '18047' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '19535' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '22489' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '514' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '25479' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '13632' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '5611' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '4251' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '19935' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '12907' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '19285' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '28655' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '5387' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '10429' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '29435' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '280' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '5927' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '31579' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '8289' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '13982' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '1671' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '8869' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '29271' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '11313' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '30728' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '1546' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '30793' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '923' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '21381' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '1397' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '21113' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '26314' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '24818' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '28540' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '22984' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '14504' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '8262' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '20257' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '10320' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '26232' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '18624' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '71' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '2068' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '24987' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '23044' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '9610' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '5010' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '19465' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '3019' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '19744' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '9649' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '15372' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '16775' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '2539' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '28664' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '4819' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '8492' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '31132' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '21260' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '15181' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '5059' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '23891' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '25980' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '21681' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '2390' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '24016' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '25255' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '13621' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '4895' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '26548' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '16256' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '10652' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '15138' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '9534' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '7482' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '1327' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '3079' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '26930' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '31011' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '17604' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '13277' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '18265' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '31378' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '26842' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '29277' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '14805' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '22853' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '25588' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '7117' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '25048' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '21250' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '171' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '21174' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '31442' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '26712' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '22221' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '13769' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '27322' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '21991' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '14734' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '21860' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '3280' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '20202' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '12181' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '24338' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '26505' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '225' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '25855' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '15973' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '11957' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '16999' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '3237' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '6850' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '12497' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '5381' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '14859' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '20552' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '8241' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '1922' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '22728' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '27911' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '25828' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '17430' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '23782' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '18232' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '13851' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '10330' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '32480' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '918' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '186' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '650' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '25103' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '4355' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '27328' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '8256' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '13293' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '26302' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '19046' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '28360' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '25021' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '3896' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '30422' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '17146' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '7815' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '25063' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '24960' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '28027' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '21135' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '10080' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '21550' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '20983' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '5545' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '5359' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '21757' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '29347' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '28746' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '31460' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '11613' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '10172' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '4366' = '<Full path to file>'
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run] '32660' = '<Full path to file>'
- [HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- C:\lsass.exe
- '81.##6.224.25':3128
- '12#.#04.17.18':3128
- '87.##8.19.66':3128
- '12#.#45.92.210':3128
- '22#.#9.252.37':3128
- '89.##5.21.236':3128
- '41.##1.165.132':3128
- '11#.#17.227.164':3128
- '19#.#48.146.122':3128
- '19#.#46.106.12':3128
- '16#.#6.228.56':3128
- '89.##8.93.24':3128
- '19#.#17.97.218':3128
- '24.##.62.190':3128
- '89.##5.21.229':3128
- '93.##4.201.226':3128
- '21#.#2.242.130':3128
- '11#.#34.28.12':3128
- '11#.#34.29.177':3128
- '22#.#65.120.116':3128
- '12#.#68.4.96':3128
- '11#.#17.186.231':3128
- '19#.#17.45.181':3128
- '59.##3.155.205':3128
- '21#.#58.95.136':3128
- '41.##0.11.88':3128
- '89.##8.102.246':3128
- '11#.#58.95.112':3128
- '93.##4.80.225':3128
- '21#.#74.143.206':3128
- '82.##8.148.6':3128
- '94.##9.185.44':3128
- '95.##.139.191':3128
- '19#.#48.146.31':3128
- '82.##6.163.238':3128
- '89.##5.10.162':3128
- '58.#8.34.59':3128
- '19#.#48.69.120':3128
- '81.##1.192.103':3128
- '59.##.200.52':3128
- '11#.47.8.40':3128
- '14#.#27.180.200':3128
- '11#.#92.139.142':3128
- '59.##.210.80':3128
- '14#.#17.69.132':3128
- '12#.#3.105.87':3128
- '11#.#98.167.99':3128
- '11#.#55.69.23':3128
- '11#.#34.29.91':3128
- '41.##0.18.235':3128
- '19#.#17.51.210':3128
- '86.##5.240.217':3128
- '19#.#17.100.239':3128
- '41.##0.163.21':3128
- '58.#48.5.2':3128
- '20#.#08.151.226':3128
- '20#.#49.82.184':3128
- '11#.#33.65.99':3128
- '85.##.185.143':3128
- '19#.#06.184.63':3128
- '77.##.173.135':3128
- '11#.#32.246.128':3128
- '19#.#48.35.199':3128
- '11#.#34.29.93':3128
- '19#.#78.102.65':3128
- '59.##.18.183':3128
- '12#.#68.7.25':3128
- '11#.#9.179.121':3128
- '88.##5.169.190':3128
- '18#.#93.208.52':3128
- '11#.#1.227.148':3128
- '12#.#31.186.241':3128
- '20#.#60.148.167':3128
- '18#.#58.11.246':3128
- '11#.#7.7.151':3128
- '59.##1.64.115':3128
- '41.##4.158.76':3128
- '11#.#41.40.164':3128
- '11#.#59.81.154':3128
- '20#.#34.18.157':3128
- '12#.#60.167.200':3128
- '89.##.88.140':3128
- '89.##5.26.221':3128
- '20#.#6.171.5':3128
- '12#.#2.55.239':3128
- '85.##7.57.116':3128
- '20#.68.50.2':3128
- '18#.#2.97.32':3128
- '95.##.150.109':3128
- '22#.#65.9.203':3128
- '20#.#3.233.211':3128
- '88.##5.71.68':3128
- '95.##6.129.220':3128
- '41.##3.25.20':3128
- '10.#.1.254':3128
- '95.##6.131.89':3128
- '11#.#05.144.151':3128
- '88.##3.125.206':3128
- '21#.#0.232.183':3128
- '11#.#59.83.95':3128
- '61.#.20.9':3128
- '83.##.81.250':3128
- '89.##5.44.119':3128
- '18#.#58.11.113':3128
- '19#.#17.203.6':3128
- '95.##6.132.79':3128
- '95.##.157.15':3128
- '22#.#41.102.175':3128
- '12#.#36.22.172':3128
- '59.##.228.138':3128
- '88.##3.179.180':3128
- '95.##.169.67':3128
- '78.##.124.174':3128
- '86.##.125.152':3128
- '60.##.129.136':3128
- '18#.#58.3.133':3128
- '11#.#41.40.47':3128
- '95.##.184.217':3128
- '93.##3.67.210':3128
- '79.#.186.199':3128
- '22#.#65.120.96':3128
- '20#.#53.206.21':3128
- '11#.#55.3.189':3128
- '12#.#57.20.183':3128
- '62.##3.38.134':3128
- '12#.#68.99.211':3128
- '12#.#33.206.123':3128
- '19#.#06.186.17':3128
- '11#.#93.46.246':3128
- '59.##.190.60':3128
- '20#.#66.18.32':3128
- '85.##5.205.250':3128
- '18#.#6.72.22':3128
- '16#.#46.210.174':3128
- '21#.#16.162.1':3128
- '82.##2.0.141':3128
- '59.#5.21.75':3128
- '20#.#67.215.225':3128
- '95.##.132.212':3128
- '21#.#4.68.214':3128
- '11#.#17.231.109':3128
- '18#.#5.159.151':3128
- '88.##8.204.30':3128
- '88.##0.143.38':3128
- '81.##.192.93':3128
- '11#.#86.29.18':3128
- '78.##4.134.7':3128
- '83.##0.228.151':3128
- '19#.#.103.42':3128
- '18#.#9.68.85':3128
- '22#.#52.0.163':3128
- '11#.#34.30.64':3128
- '89.##2.145.50':3128
- '11#.#7.20.143':3128
- '59.##.40.186':3128
- '14#.#08.141.130':3128
- '21#.#09.162.104':3128
- '19#.#17.50.8':6667
- '89.##.88.140':6667
- '11#.#58.92.75':6667
- '82.##1.37.107':6667
- 'C:\lsass.exe' exe <Full path to file>
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "<Full path to file>"