Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001] 'LibraryPath' = 'mswsock.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003] 'LibraryPath' = 'mswsock.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008] 'PackedCatalogItem' = ''
- <SYSTEM32>\cmd.exe
- <SYSTEM32>\services.exe
- %WINDIR%\Explorer.EXE
- C:\RECYCLER\S-1-5-18\$2ebe1c2e2a38cb36436c4d1cb8c2630c\n
- %WINDIR%\assembly\GAC\Desktop.ini
- C:\RECYCLER\S-1-5-18\$2ebe1c2e2a38cb36436c4d1cb8c2630c\@
- C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\$2ebe1c2e2a38cb36436c4d1cb8c2630c\@
- C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\$2ebe1c2e2a38cb36436c4d1cb8c2630c\n
- 'localhost':80
- 'j.###mind.com':80
- fo#####-counters.com/5699145-24B8EBEDAA47374020E664A2406FB684/counter.img?th###############################
- j.###mind.com/app/geoip.js
- DNS ASK $�#�X�G
- DNS ASK $�#[��
- DNS ASK $�#B��
- DNS ASK $�#nsg
- DNS ASK $�#���
- DNS ASK $�#�*�u
- DNS ASK j.###mind.com
- DNS ASK $�# ��w
- DNS ASK $�#�s�
- DNS ASK $�#]���
- '18#.#.149.239':16471
- '11#.#44.188.241':16471
- '82.##6.50.239':16471
- '24.##5.12.239':16471
- '74.##.30.239':16471
- '18#.#6.93.250':16471
- '58.##3.41.252':16471
- '75.##.56.250':16471
- '18#.#88.192.241':16471
- '18#.#40.176.243':16471
- '17#.#07.58.237':16471
- '18#.#6.232.8':16471
- '17#.#77.97.9':16471
- '11#.#8.163.10':16471
- '68.#4.244.9':16471
- '59.##6.139.238':16471
- '18#.#0.221.3':16471
- '10#.#21.197.5':16471
- '11#.#0.173.237':16471
- '88.#91.88.8':16471
- '88.##2.253.254':16471
- '95.##2.253.254':16471
- '79.##2.253.254':16471
- '27.##2.253.254':16471
- '71.##2.253.254':16471
- '18#.#53.253.254':16471
- '88.##4.253.254':16471
- '16#.#53.253.254':16471
- '17#.#52.253.254':16471
- '18#.#52.253.254':16471
- '79.##.68.253':16471
- '21#.#97.188.253':16471
- '94.#3.2.253':16471
- '85.##8.90.252':16471
- '17#.#00.161.252':16471
- '88.##1.253.254':16471
- '98.##1.253.254':16471
- '18#.#50.253.254':16471
- '69.##6.223.253':16471
- '17#.#9.144.254':16471