Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001] 'LibraryPath' = 'mswsock.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003] 'LibraryPath' = 'mswsock.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007] 'PackedCatalogItem' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008] 'PackedCatalogItem' = ''
- <SYSTEM32>\services.exe
- %WINDIR%\Installer\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\n
- %WINDIR%\assembly\GAC\Desktop.ini
- %WINDIR%\Installer\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\@
- <LS_APPDATA>\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\@
- <LS_APPDATA>\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\n
- %WINDIR%\Installer\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\@
- %WINDIR%\Installer\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\n
- <LS_APPDATA>\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\@
- <LS_APPDATA>\{2ebe1c2e-2a38-cb36-436c-4d1cb8c2630c}\n
- '18#.#72.204.122':80
- 'pr####.fling.com':80
- 18#.#72.204.122/count.php?id#######################
- 18#.#72.204.122/count.php?id######################
- pr####.fling.com/geo/txt/city.php
- 18#.#72.204.122/count.php?id#####################
- DNS ASK ��#��
- DNS ASK ��#���
- DNS ASK ��#��U
- DNS ASK ��#)3=M
- DNS ASK ��#�j�%
- DNS ASK ��#���
- DNS ASK pr####.fling.com
- DNS ASK ��#���
- DNS ASK ��#�F��
- '22#.#15.168.174':16471
- '68.##.108.174':16471
- '24.##1.250.174':16471
- '17#.#09.129.176':16471
- '89.##9.241.225':16471
- '68.##.251.168':16471
- '10#.#26.140.168':16471
- '69.##7.165.170':16471
- '67.##4.240.230':16471
- '74.##.174.170':16471
- '70.##.140.178':16471
- '92.##7.143.189':16471
- '18#.#5.1.186':16471
- '17#.#2.234.189':16471
- '49.##7.63.215':16471
- '68.#.164.190':16471
- '66.##1.52.219':16471
- '75.##6.146.180':16471
- '80.##7.254.181':16471
- '11#.#0.147.183':16471
- '67.##.29.216':16471
- '59.##.108.231':16471
- '17#.#38.10.145':16471
- '74.##.206.144':16471
- '18#.#4.164.145':16471
- '68.##5.150.147':16471
- '17#.#33.5.146':16471
- '11#.#41.41.142':16471
- '20#.#50.86.138':16471
- '14#.#6.129.142':16471
- '17#.#9.60.144':16471
- '16#.#48.16.144':16471
- '72.##3.12.148':16471
- '24.#0.3.164':16471
- '70.#1.23.11':16471
- '11#.#32.219.164':16471
- '18#.#2.70.168':16471
- '65.##.13.165':16471
- '71.##.70.159':16471
- '74.##1.178.153':16471
- '19#.#63.128.159':16471
- '11#.#18.203.161':16471
- '15#.#3.80.160':16471
- '71.##6.137.192':16471
- '11#.#85.253.20':16471
- '13#.#90.4.117':16471
- '76.##8.172.100':16471
- '69.##9.92.237':16471
- '80.##2.208.97':16471
- '82.##.203.172':16471
- '19#.#.113.228':16471
- '17#.#03.133.168':16471
- '78.##.104.121':16471
- '93.##.105.162':16471
- '75.#5.45.8':16471
- '76.##.239.44':16471
- '17#.#8.173.53':16471
- '19#.#54.192.34':16471
- '62.##.208.22':16471
- '11#.91.1.25':16471
- '20#.#08.77.80':16471
- '19#.#6.197.82':16471
- '24.##9.184.59':16471
- '61.##.104.54':16471
- '82.##1.167.55':16471
- '24.##.75.176':16471
- '68.##9.102.201':16471
- '20#.#32.98.201':16471
- '24.##.144.201':16471
- '68.##.53.203':16471
- '24.##8.241.201':16471
- '24.##5.144.194':16471
- '68.##0.179.192':16471
- '12#.#01.134.195':16471
- '81.##.135.197':16471
- '68.##3.149.196':16471
- '11#.#5.144.205':16471
- '71.##.90.192':16471
- '67.##.90.214':16471
- '69.##7.186.182':16471
- '11#.#87.224.180':16471
- '75.##0.21.217':16471
- '24.##6.61.209':16471
- '11#.#34.51.208':16471
- '74.##6.83.209':16471
- '24.##6.41.214':16471
- '11#.#7.218.212':16471