Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001] 'LibraryPath' = 'mswsock.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003] 'LibraryPath' = 'mswsock.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Google Update ❤' = '"<LS_APPDATA>\Google\Desktop\Install\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\❤≸⋙\Ⱒ☠⍨\ﯹ๛\{2ebe1c2e-2a38-cb36-436c-4d1...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008] 'PackedCatalogItem' = '{6d,73,77,73,6f,63,6b,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,...
- [<HKLM>\SYSTEM\ControlSet001\Services\etadpug] 'ImagePath' = '"%ProgramFiles%\Google\Desktop\Install\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\ \ \ﯹ๛\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\G...
- [<HKLM>\SYSTEM\ControlSet001\Services\etadpug] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\cmd.exe'
- <SYSTEM32>\cmd.exe
- <SYSTEM32>\services.exe
- %ProgramFiles%\Google\Desktop\Install\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\ \ \ﯹ๛\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\@
- %WINDIR%\assembly\GAC\Desktop.ini
- %ProgramFiles%\Google\Desktop\Install\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\ \ \ﯹ๛\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\GoogleUpdate.exe
- <LS_APPDATA>\Google\Desktop\Install\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\❤≸⋙\Ⱒ☠⍨\ﯹ๛\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\GoogleUpdate.exe
- <LS_APPDATA>\Google\Desktop\Install\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\❤≸⋙\Ⱒ☠⍨\ﯹ๛\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\@
- 'j.###mind.com':80
- http://j.###mind.com/app/geoip.js
- DNS ASK ߡc#�!l
- DNS ASK ߡc#�
- DNS ASK ߡc#��d
- DNS ASK ߡc#R�
- DNS ASK ߡc#T"
- DNS ASK ߡc# �%
- DNS ASK ߡc#qS�
- DNS ASK ߡc#\�
- DNS ASK j.###mind.com
- DNS ASK ߡc#��
- DNS ASK ߡc#T�?
- DNS ASK ߡc# 8
- '10#.#63.249.246':16471
- '10#.#63.249.245':16471
- '10#.#63.249.247':16471
- '20#.#26.221.79':16471
- '68.##.147.245':16471
- '10#.#63.253.248':16471
- '11#.#98.223.221':16471
- '10#.#63.249.244':16471
- '12#.#11.104.243':16471
- '22#.#47.245.215':16471
- '93.##.135.40':16471
- '87.##5.151.203':16471
- '20#.#16.219.33':16471
- '10#.#63.249.249':16471
- '10#.#63.249.248':16471
- '10#.#63.253.247':16471
- '85.##1.175.200':16471
- '66.##8.253.238':16471
- '19#.#3.214.120':16471
- '69.##7.145.9':16471
- '11#.#5.72.36':16471
- '84.##.12.102':16471
- '72.#.168.141':16471
- '10#.7.52.1':16471
- '71.#2.5.122':16471
- '17#.#8.143.6':16471
- '37.##.254.148':16471
- '66.##.228.74':16471
- '96.#0.69.67':16471
- '15#.#5.216.70':16471
- '13#.#28.99.73':16471
- '17#.#38.139.217':16471
- '68.##1.128.87':16471
- '18#.#5.71.92':16471
- '21#.#30.41.63':16471
- '17#.#19.9.40':16471
- '11#.#.66.253':16471
- '10#.#63.253.252':16471
- '17#.#50.193.253':16471
- '89.##.104.253':16471
- '10#.#63.249.252':16471
- '66.##.70.143':16471
- '10#.#63.253.250':16471
- '10#.#63.253.251':16471
- '67.##7.250.254':16471
- '13#.#54.253.254':16471
- '20#.#54.253.254':16471
- '15#.#54.253.254':16471
- '22#.#54.253.254':16471
- '16#.#54.253.254':16471
- '18#.#54.253.254':16471
- '68.##1.119.254':16471
- '11#.#54.253.254':16471
- '19#.#54.253.254':16471
- '76.#4.64.36':16471
- '76.##5.93.34':16471
- '95.##1.118.14':16471
- '10#.#63.249.251':16471
- '17#.#70.17.37':16471
- '74.##0.191.36':16471
- '58.#46.1.37':16471
- '71.##.241.31':16471
- '98.##2.109.33':16471
- '12#.#1.194.26':16471
- '67.##7.179.10':16471
- '76.#8.83.27':16471
- '24.##2.76.10':16471
- '71.##0.61.25':16471
- '10#.#63.249.250':16471
- '17#.#3.151.14':16471
- '24.#.252.13':16471
- '17#.#23.45.19':16471