Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001] 'LibraryPath' = 'mswsock.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003] 'LibraryPath' = 'mswsock.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\.afd] 'ImagePath' = '\?'
- Windows Security Center
- '<SYSTEM32>\cmd.exe'
- <SYSTEM32>\cmd.exe
- <SYSTEM32>\winlogon.exe
- %WINDIR%\Explorer.EXE
- %WINDIR%\$NtUninstallKB27979$\4121336045\@
- %WINDIR%\$NtUninstallKB27979$\4121336045\L\alehhooo
- %WINDIR%\$NtUninstallKB27979$\4121336045\Desktop.ini
- '21#.#08.252.185':80
- 'pr####.fling.com':80
- http://le#####eecounters.com/5699002-2F6F334BF9ACF1B2401D3874A5B0C048/counter.img?th################################ via 21#.#08.252.185
- http://le#####eecounters.com/5699002-2F6F334BF9ACF1B2401D3874A5B0C048/counter.img?th############################### via 21#.#08.252.185
- http://pr####.fling.com/geo/txt/city.php
- DNS ASK �c#�
- DNS ASK �c#�l
- DNS ASK �c#�R
- DNS ASK �c#wA�
- DNS ASK �c#�)?
- DNS ASK �c#�
- DNS ASK �c#��W
- DNS ASK �c#.��
- DNS ASK pr####.fling.com
- DNS ASK �c#y:L
- DNS ASK �c#��e
- DNS ASK �c#\�
- '2.###.139.227':16471
- '74.##2.207.7':16471
- '19#.#64.137.228':16471
- '24.#08.16.9':16471
- '69.##.49.227':16471
- '74.##7.218.8':16471
- '66.##.18.232':16471
- '84.##2.52.233':16471
- '75.##1.135.233':16471
- '75.#09.15.7':16471
- '67.##.200.229':16471
- '98.##7.118.231':16471
- '12#.13.60.9':16471
- '99.##9.75.217':16471
- '72.##2.219.217':16471
- '75.##.24.218':16471
- '24.#4.6.216':16471
- '84.#.135.13':16471
- '17#.#6.54.13':16471
- '24.##0.72.10':16471
- '96.#.144.9':16471
- '11#.#04.90.9':16471
- '18#.#76.153.12':16471
- '74.##.227.220':16471
- '18#.#8.128.10':16471
- '18#.#4.216.6':16471
- '98.##3.157.2':16471
- '88.##2.236.244':16471
- '75.#5.110.2':16471
- '71.#6.13.6':16471
- '12#.#54.48.4':16471
- '20#.#02.200.2':16471
- '83.##3.242.245':16471
- '18#.#29.185.246':16471
- '79.##9.45.248':16471
- '76.##.135.245':16471
- '50.##.200.245':16471
- '74.##.242.245':16471
- '21#.#74.48.6':16471
- '72.##9.210.238':16471
- '59.##.172.239':16471
- '79.##4.16.240':16471
- '72.##.86.236':16471
- '46.##6.121.236':16471
- '49.##5.83.238':16471
- '76.##.23.242':16471
- '98.##4.45.242':16471
- '69.##.140.242':16471
- '67.#6.173.6':16471
- '74.#19.99.6':16471
- '70.##1.237.241':16471