Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001] 'LibraryPath' = 'mswsock.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003] 'LibraryPath' = 'mswsock.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008] 'PackedCatalogItem' = ''
- <SYSTEM32>\cmd.exe
- <SYSTEM32>\services.exe
- %WINDIR%\Explorer.EXE
- C:\RECYCLER\S-1-5-18\$2ebe1c2e2a38cb36436c4d1cb8c2630c\n
- %WINDIR%\assembly\GAC\Desktop.ini
- C:\RECYCLER\S-1-5-18\$2ebe1c2e2a38cb36436c4d1cb8c2630c\@
- C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\$2ebe1c2e2a38cb36436c4d1cb8c2630c\@
- C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\$2ebe1c2e2a38cb36436c4d1cb8c2630c\n
- '21#.#08.252.185':80
- 'pr####.fling.com':80
- 21#.#08.252.185/5699145-24B8EBEDAA47374020E664A2406FB684/counter.img?th###############################
- pr####.fling.com/geo/txt/city.php
- DNS ASK $�#��6
- DNS ASK $�#�I��
- DNS ASK $�#�;��
- DNS ASK $�#��l
- DNS ASK $�#6o
- DNS ASK $�#��
- DNS ASK pr####.fling.com
- DNS ASK $�#�e�
- DNS ASK $�#��q
- DNS ASK $�#��
- '70.##7.62.244':16471
- '10#.#4.113.244':16471
- '84.##8.251.244':16471
- '21#.#12.140.241':16471
- '74.##.210.243':16471
- '89.##0.41.244':16471
- '78.##6.29.253':16471
- '95.##.79.253':16471
- '79.##9.190.253':16471
- '98.##2.44.246':16471
- '97.##.225.246':16471
- '88.##.154.251':16471
- '60.##.180.240':16471
- '23.##.80.208':16471
- '89.##6.34.212':16471
- '46.##6.253.254':16471
- '17#.#5.9.206':16471
- '10#.#8.118.206':16471
- '20#.#8.234.206':16471
- '93.##7.152.235':16471
- '11#.#03.119.236':16471
- '24.##5.248.238':16471
- '17#.#8.93.232':16471
- '76.##4.161.234':16471
- '46.##1.231.234':16471
- '80.##.221.253':16471
- '89.##4.253.254':16471
- '22#.#44.253.254':16471
- '76.##0.213.220':16471
- '99.##9.253.254':16471
- '74.##2.253.254':16471
- '10#.#43.253.254':16471
- '11#.#5.91.91':16471
- '24.##8.101.83':16471
- '89.#7.70.69':16471
- '24.##0.76.171':16471
- '20#.6.61.67':16471
- '98.##3.216.117':16471
- '15#.#38.253.254':16471
- '20#.#40.60.254':16471
- '75.##.75.254':16471
- '75.##.79.254':16471
- '69.##7.228.253':16471
- '17#.#95.0.254':16471
- '15#.#4.43.254':16471
- '11#.#88.214.254':16471
- '88.##9.253.254':16471
- '19#.#32.253.254':16471
- '67.##.123.254':16471
- '24.##.133.254':16471
- '18#.#.206.254':16471