Mal/Rorpian-D

Category: Viruses and Spyware Protection available since:27 Sep 2011 20:06:28 (GMT)
Type: Malicious behavior Last Updated:06 May 2013 03:51:38 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Mal/Rorpian-D include:

Example 1

File Information

Size
174K
SHA-1
0025dc5dad2e7098be623773511f9579eed97d8e
MD5
c554d885137c33f8beba871017d849b3
CRC-32
8ce28d2c
File type
Windows executable
First seen
2011-10-10

Example 2

File Information

Size
179K
SHA-1
00354fd1f697713a5357ef17408eea136c83b967
MD5
ba78e68f425090e5bac6e6e00862e8fc
CRC-32
1ca7b89e
File type
application/x-ms-dos-executable
First seen
2011-08-05

Example 3

File Information

Size
223K
SHA-1
003d9a35d053ba98d53c10c83922ca9f2075172a
MD5
c7467c2759d10276c54088d20b08e808
CRC-32
9a2b65a9
File type
application/x-ms-dos-executable
First seen
2012-01-16

Runtime Analysis

Registry Keys Modified
  • HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008
    PackedCatalogItem
    6d 73 77 73 6f 63 6b 2e 64 6c 6c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 73 00 77 00 0e 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 30 18 5f 8d 73 c2 cf 11 95 c8 00 80 5f 48 a1 92 ee 03 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 11 00 00 00 14 00 00 00 14 00 00 00 05 00 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 fa 00 00 00 00 00 00 4d 00 53 00 41 00 46 00 44 00 20 00 4e 00 65 00 74 00 42 00 49 00 4f 00 53 00 20 00 5b 00 5c 00 44 00 65 00 76 00 69 00 63 00 65 00 5c 00 4e 00 65 00 74 00 42 00 54 00 5f 00 54 00 63 00 70 00 69 00 70 00 5f 00 7b 00 32 00 38 00 36 00 31 00 42 00 30 00 46 00 39 00 2d 00 46 00 31 00 45 00 38 00 2d 00 34 00 41 00 31 00 41 00 2d 00 42 00 39 00 44 00 35 00 2d 00 30 00 38 00 46 00 42 00 33 00 45 00 35 00 39 00 35 00 42 00 32 00 38 00 7d 00 5d 00 20 00 53 00 45 00 51 00 50 00 41 00 43 00 4b 00 45 00 54 00 20 00 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  • HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013
    PackedCatalogItem
    6d 73 77 73 6f 63 6b 2e 64 6c 6c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 73 00 77 00 09 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 30 18 5f 8d 73 c2 cf 11 95 c8 00 80 5f 48 a1 92 f3 03 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 11 00 00 00 14 00 00 00 14 00 00 00 02 00 00 00 fe ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 fa 00 00 00 00 00 00 4d 00 53 00 41 00 46 00 44 00 20 00 4e 00 65 00 74 00 42 00 49 00 4f 00 53 00 20 00 5b 00 5c 00 44 00 65 00 76 00 69 00 63 00 65 00 5c 00 4e 00 65 00 74 00 42 00 54 00 5f 00 54 00 63 00 70 00 69 00 70 00 5f 00 7b 00 37 00 45 00 41 00 33 00 35 00 32 00 39 00 36 00 2d 00 37 00 45 00 32 00 38 00 2d 00 34 00 32 00 35 00 41 00 2d 00 39 00 41 00 35 00 43 00 2d 00 41 00 35 00 42 00 45 00 43 00 39 00 43 00 41 00 34 00 34 00 31 00 33 00 7d 00 5d 00 20 00 44 00 41 00 54 00 41 00 47 00 52 00 41 00 4d 00 20 00 32 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  • HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
    LibraryPath
    mswsock.dll
  • HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003
    PackedCatalogItem
    6d 73 77 73 6f 63 6b 2e 64 6c 6c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 73 00 77 00 66 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 a0 1a 0f e7 8b ab cf 11 8c a3 00 80 5f 48 a1 92 e9 03 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 00 00 00 10 00 00 00 10 00 00 00 01 00 00 00 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4d 00 53 00 41 00 46 00 44 00 20 00 54 00 63 00 70 00 69 00 70 00 20 00 5b 00 54 00 43 00 50 00 2f 00 49 00 50 00 5d 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  • HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007
    PackedCatalogItem
    6d 73 77 73 6f 63 6b 2e 64 6c 6c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 73 00 77 00 66 20 02 00 00 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 e0 a9 60 9d 7a 33 d0 11 bd 88 00 00 c0 82 e6 9a ed 03 00 00 01 00 00 00 88 01 1c 00 00 00 1c 00 08 00 00 00 00 00 00 00 8c fb a2 03 5c 0d 91 7c 00 00 1c 00 06 00 00 00 02 00 00 00 10 00 00 00 10 00 00 00 01 00 00 00 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 52 00 53 00 56 00 50 00 20 00 54 00 43 00 50 00 20 00 53 00 65 00 72 00 76 00 69 00 63 00 65 00 20 00 50 00 72 00 6f 00 76 00 69 00 64 00 65 00 72 00 00 00 28 cb a9 01 00 00 00 00 00 00 00 00 50 fb a2 03 b0 01 1c 00 08 00 00 00 c0 57 05 02 10 02 1c 00 f4 fb a2 03 20 cb a9 01 68 fb a2 03 00 00 00 00 07 00 00 00 20 cb a9 01 00 00 1c 00 00 00 c3 00 00 00 00 00 48 cb a9 01 5c 0d 91 7c 00 00 1c 00 91 0e 91 7c 08 06 1c 00 6d 05 91 7c c8 ca a9 01 00 00 00 00 08 00 00 00 00 00 c3 00 02 00 00 00 b0 d6 cb 02 03 00 00 00 50 cb a9 01 03 00 00 00 00 00 00 00 c8 ca a9 01 88 01 1c 00 80 15 07 02 48 e4 e4 02 10 02 1c 00 f0 2e ce 01 10 02 1c 00 00 00 00 00 08 00 00 00 f0 2e ce 01 08 00 00 00 02 00 00 00 00 00 08 00 18 02 1c 00 18 00 00 00 88 15 07 02 00 00 1c 00 02 00 00 00 5c 01 1c 00 18 02 1c 00 04 00 00 00 f8 2e ce 01 48 05 1c 00 00 00 1c 00 4f 6d 01 01 e4 ca a9 01 60 00 00 00 10 02 1c 00 00 00 00 00 80 15 07 02 3c fc a2 03 46 0f 91 7c 14 00 00 00 80 15 07 02 00 00 1c 00 50 12 07 02 00 00 00 00 10 fd a2 03 5c 0d 91 7c 00 00 1c 00 91 0e 91 7c 08 06 1c 00 6d 05 91 7c 78 7e f9 00 00 00 00 00 44 2b ce 01 00 00 c3 00 0f 00 00 00 50 12 07 02 00 00 00 00 00 00 00 00 4c 0a 00 00 00 00 00 00 58 12 07 02 00 00 00 00 00 00 00 00 00 00 00 00 4c 0a 00 00 dc fc a2 03 48 05 1c 00 4c 0a 00 00 04 00 00 00 03 00 00 00 58 12 07 02 48 05 1c 00 78 7e f9 00 30 03 00 00 44 2b ce 01 0c 00 0e 00 3c 56 5f 75 00 00 00 00 ac fc a2 03 44 2b ce 01 00 00 00 00 78 7e f9 00 04 fd a2 03 6c fb 90 7c 71 fb 90 7c 78 7e f9 00 00 00 00 00 44 2b ce 01 e0 fc a2 03
  • HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004
    PackedCatalogItem
    6d 73 77 73 6f 63 6b 2e 64 6c 6c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 73 00 77 00 09 06 02 00 00 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 a0 1a 0f e7 8b ab cf 11 8c a3 00 80 5f 48 a1 92 ea 03 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 00 00 00 10 00 00 00 10 00 00 00 02 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 bb ff 00 00 00 00 00 00 4d 00 53 00 41 00 46 00 44 00 20 00 54 00 63 00 70 00 69 00 70 00 20 00 5b 00 55 00 44 00 50 00 2f 00 49 00 50 00 5d 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  • HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006
    PackedCatalogItem
    6d 73 77 73 6f 63 6b 2e 64 6c 6c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 73 00 77 00 09 26 02 00 00 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 e0 a9 60 9d 7a 33 d0 11 bd 88 00 00 c0 82 e6 9a ec 03 00 00 01 00 00 00 84 f8 a2 03 7c f8 a2 03 88 f9 a2 03 04 a4 60 75 4c 0a 00 00 a0 3c 5f 75 b0 f9 a2 03 06 00 00 00 02 00 00 00 10 00 00 00 10 00 00 00 02 00 00 00 11 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 bb ff 00 00 00 00 00 00 52 00 53 00 56 00 50 00 20 00 55 00 44 00 50 00 20 00 53 00 65 00 72 00 76 00 69 00 63 00 65 00 20 00 50 00 72 00 6f 00 76 00 69 00 64 00 65 00 72 00 00 00 01 00 00 00 e4 fb a2 03 01 00 00 00 30 ae cd 02 00 00 00 00 3d fb 90 7c 80 f9 a2 03 00 00 00 00 00 f9 a2 03 6c fb 90 7c 71 fb 90 7c 00 00 00 00 80 f9 a2 03 3d fb 90 7c dc f8 a2 03 2c f9 a2 03 48 f9 a2 03 18 ee 90 7c 78 fb 90 7c ff ff ff ff 71 fb 90 7c 18 6a dd 77 51 6a dd 77 b8 3c 5f 75 74 0a 00 00 74 0a 00 00 88 01 1c 00 74 0a 00 00 80 f9 a2 03 40 00 00 00 00 00 00 00 00 00 00 00 08 00 08 00 b8 3c 5f 75 5c 00 44 00 65 00 76 00 69 00 63 00 65 00 5c 00 7b 00 32 00 38 00 36 00 31 00 42 00 30 00 46 00 39 00 2d 00 46 00 31 00 45 00 38 00 2d 00 34 00 41 00 31 00 41 00 2d 00 42 00 39 00 44 00 35 00 2d 00 30 00 38 00 46 00 42 00 33 00 45 00 35 00 39 00 35 00 42 00 32 00 38 00 7d 00 00 00 46 00 42 00 33 00 45 00 35 00 39 00 35 00 42 00 32 00 38 00 7d 00 00 00 a2 03 74 6c dd 77 c0 f9 a2 03 96 15 91 7c eb 06 91 7c 58 fd a2 03 98 a3 ce 02 10 00 00 00 b2 8a 61 75 5e 6b dd 77 a0 04 00 00 f4 f9 a2 03 96 15 91 7c eb 06 91 7c 01 00 00 00 58 fd a2 03 04 00 00 00 00 00 00 00 00 00 c3 00 4c fa a2 03 96 15 91 7c eb 06 91 7c 01 00 00 00 58 fd a2 03 96 15 91 7c eb 06 91 7c 00 00 00 00 00 00 00 00 58 00 00 00 eb 06 91 7c 01 00 00 00 58 fd a2 03 01 00 00 00 00 00 00 00 28 00 00 00 40 48 05 02 d4 f1 a2 03 00 00 00 00 60 fe f4 02 80 07 aa 01 90 01 1c 00 00 00 00 00 45 00 4d 00 5c 00 43 00 75 00 72 00 72 00 65 00 0c 00 00 00 1c 00 00 00 88 01 1c 00 00 00 c3 00 96 15 91 7c 96 15 91 7c
  • HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010
    PackedCatalogItem
    6d 73 77 73 6f 63 6b 2e 64 6c 6c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 73 00 77 00 0e 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 30 18 5f 8d 73 c2 cf 11 95 c8 00 80 5f 48 a1 92 f0 03 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 11 00 00 00 14 00 00 00 14 00 00 00 05 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 fa 00 00 00 00 00 00 4d 00 53 00 41 00 46 00 44 00 20 00 4e 00 65 00 74 00 42 00 49 00 4f 00 53 00 20 00 5b 00 5c 00 44 00 65 00 76 00 69 00 63 00 65 00 5c 00 4e 00 65 00 74 00 42 00 54 00 5f 00 54 00 63 00 70 00 69 00 70 00 5f 00 7b 00 39 00 32 00 41 00 32 00 38 00 34 00 45 00 39 00 2d 00 34 00 33 00 42 00 32 00 2d 00 34 00 30 00 36 00 45 00 2d 00 41 00 32 00 34 00 45 00 2d 00 46 00 43 00 42 00 30 00 35 00 41 00 43 00 42 00 41 00 44 00 38 00 42 00 7d 00 5d 00 20 00 53 00 45 00 51 00 50 00 41 00 43 00 4b 00 45 00 54 00 20 00 31 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  • HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011
    PackedCatalogItem
    6d 73 77 73 6f 63 6b 2e 64 6c 6c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 73 00 77 00 09 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 30 18 5f 8d 73 c2 cf 11 95 c8 00 80 5f 48 a1 92 f1 03 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 11 00 00 00 14 00 00 00 14 00 00 00 02 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 fa 00 00 00 00 00 00 4d 00 53 00 41 00 46 00 44 00 20 00 4e 00 65 00 74 00 42 00 49 00 4f 00 53 00 20 00 5b 00 5c 00 44 00 65 00 76 00 69 00 63 00 65 00 5c 00 4e 00 65 00 74 00 42 00 54 00 5f 00 54 00 63 00 70 00 69 00 70 00 5f 00 7b 00 39 00 32 00 41 00 32 00 38 00 34 00 45 00 39 00 2d 00 34 00 33 00 42 00 32 00 2d 00 34 00 30 00 36 00 45 00 2d 00 41 00 32 00 34 00 45 00 2d 00 46 00 43 00 42 00 30 00 35 00 41 00 43 00 42 00 41 00 44 00 38 00 42 00 7d 00 5d 00 20 00 44 00 41 00 54 00 41 00 47 00 52 00 41 00 4d 00 20 00 31 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  • HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009
    PackedCatalogItem
    6d 73 77 73 6f 63 6b 2e 64 6c 6c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 73 00 77 00 09 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 30 18 5f 8d 73 c2 cf 11 95 c8 00 80 5f 48 a1 92 ef 03 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 11 00 00 00 14 00 00 00 14 00 00 00 02 00 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 fa 00 00 00 00 00 00 4d 00 53 00 41 00 46 00 44 00 20 00 4e 00 65 00 74 00 42 00 49 00 4f 00 53 00 20 00 5b 00 5c 00 44 00 65 00 76 00 69 00 63 00 65 00 5c 00 4e 00 65 00 74 00 42 00 54 00 5f 00 54 00 63 00 70 00 69 00 70 00 5f 00 7b 00 32 00 38 00 36 00 31 00 42 00 30 00 46 00 39 00 2d 00 46 00 31 00 45 00 38 00 2d 00 34 00 41 00 31 00 41 00 2d 00 42 00 39 00 44 00 35 00 2d 00 30 00 38 00 46 00 42 00 33 00 45 00 35 00 39 00 35 00 42 00 32 00 38 00 7d 00 5d 00 20 00 44 00 41 00 54 00 41 00 47 00 52 00 41 00 4d 00 20 00 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  • HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012
    PackedCatalogItem
    6d 73 77 73 6f 63 6b 2e 64 6c 6c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 73 00 77 00 0e 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 30 18 5f 8d 73 c2 cf 11 95 c8 00 80 5f 48 a1 92 f2 03 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 11 00 00 00 14 00 00 00 14 00 00 00 05 00 00 00 fe ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 fa 00 00 00 00 00 00 4d 00 53 00 41 00 46 00 44 00 20 00 4e 00 65 00 74 00 42 00 49 00 4f 00 53 00 20 00 5b 00 5c 00 44 00 65 00 76 00 69 00 63 00 65 00 5c 00 4e 00 65 00 74 00 42 00 54 00 5f 00 54 00 63 00 70 00 69 00 70 00 5f 00 7b 00 37 00 45 00 41 00 33 00 35 00 32 00 39 00 36 00 2d 00 37 00 45 00 32 00 38 00 2d 00 34 00 32 00 35 00 41 00 2d 00 39 00 41 00 35 00 43 00 2d 00 41 00 35 00 42 00 45 00 43 00 39 00 43 00 41 00 34 00 34 00 31 00 33 00 7d 00 5d 00 20 00 53 00 45 00 51 00 50 00 41 00 43 00 4b 00 45 00 54 00 20 00 32 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  • HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
    LibraryPath
    mswsock.dll
  • HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005
    PackedCatalogItem
    6d 73 77 73 6f 63 6b 2e 64 6c 6c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 73 00 77 00 09 06 02 00 00 00 00 00 00 00 00 00 00 00 00 00 0c 00 00 00 a0 1a 0f e7 8b ab cf 11 8c a3 00 80 5f 48 a1 92 eb 03 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 00 00 00 10 00 00 00 10 00 00 00 03 00 00 00 00 00 00 00 ff 00 00 00 00 00 00 00 00 00 00 00 bb ff 00 00 00 00 00 00 4d 00 53 00 41 00 46 00 44 00 20 00 54 00 63 00 70 00 69 00 70 00 20 00 5b 00 52 00 41 00 57 00 2f 00 49 00 50 00 5d 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Processes Created
  • c:\windows\system32\cmd.exe
HTTP Requests
  • http://promos.fling.com/geo/txt/city.php
IP Connections
  • 105.130.187.103:34354
  • 105.134.11.132:34354
  • 107.10.49.132:34354
  • 107.25.48.218:34354
  • 107.9.3.167:34354
  • 109.185.188.48:34354
  • 109.52.198.157:34354
  • 109.52.70.128:34354
  • 124.179.7.5:34354
  • 134.114.53.13:34354
  • 137.112.114.69:34354
  • 149.140.95.209:34354
  • 149.169.164.73:34354
  • 172.132.9.74:34354
  • 173.16.21.63:34354
  • 173.170.152.161:34354
  • 173.172.222.246:34354
  • 173.175.88.166:34354
  • 173.177.140.204:34354
  • 173.2.185.226:34354
  • 173.217.223.177:34354
  • 174.100.11.118:34354
  • 174.101.10.254:34354
  • 174.101.208.55:34354
  • 174.101.25.145:34354
  • 174.102.216.160:34354
  • 174.49.134.253:34354
  • 174.54.161.95:34354
  • 174.55.206.247:34354
  • 174.55.58.20:34354
  • 174.71.109.102:34354
  • 174.71.113.66:34354
  • 174.74.81.253:34354
  • 176.8.169.30:34354
  • 178.25.243.153:34354
  • 184.162.86.66:34354
  • 184.57.121.220:34354
  • 184.59.196.252:34354
  • 184.76.226.236:34354
  • 184.77.161.203:34354
  • 186.59.75.93:34354
  • 186.65.227.246:34354
  • 187.106.151.226:34354
  • 187.11.56.37:34354
  • 187.41.35.101:34354
  • 190.199.65.106:34354
  • 190.32.138.13:34354
  • 190.72.214.164:34354
  • 2.192.240.203:34354
  • 200.127.90.208:34354
  • 200.220.211.213:34354
  • 200.82.181.154:34354
  • 201.188.199.110:34354
  • 201.231.106.105:34354
  • 204.210.141.139:34354
  • 207.204.105.227:34354
  • 216.121.203.198:34354
  • 216.121.241.184:34354
  • 216.195.6.167:34354
  • 24.1.77.106:34354
  • 24.102.228.210:34354
  • 24.103.56.213:34354
  • 24.107.160.175:34354
  • 24.115.130.242:34354
  • 24.131.217.25:34354
  • 24.14.143.134:34354
  • 24.160.165.214:34354
  • 24.167.215.254:34354
  • 24.177.158.180:34354
  • 24.180.201.33:34354
  • 24.185.240.125:34354
  • 24.186.210.179:34354
  • 24.211.252.2:34354
  • 24.22.44.176:34354
  • 24.243.42.157:34354
  • 24.27.80.52:34354
  • 24.30.29.101:34354
  • 24.37.89.191:34354
  • 24.46.150.203:34354
  • 24.61.120.227:34354
  • 24.63.109.0:34354
  • 24.79.1.132:34354
  • 24.90.69.159:34354
  • 24.96.207.40:34354
  • 24.99.94.246:34354
  • 31.147.115.172:34354
  • 46.100.169.228:34354
  • 46.72.153.217:34354
  • 50.10.146.189:34354
  • 50.132.3.154:34354
  • 50.52.244.151:34354
  • 50.83.130.185:34354
  • 50.88.158.44:34354
  • 65.184.27.189:34354
  • 66.168.220.206:34354
  • 66.169.249.199:34354
  • 66.176.195.151:34354
  • 66.214.38.173:34354
  • 66.229.242.198:34354
  • 66.74.142.104:34354
  • 66.90.149.170:34354
  • 67.177.191.138:34354
  • 67.181.12.124:34354
  • 67.184.52.38:34354
  • 67.186.206.117:34354
  • 67.80.234.73:34354
  • 67.86.125.112:34354
  • 67.86.73.151:34354
  • 68.0.56.148:34354
  • 68.108.238.132:34354
  • 68.13.140.167:34354
  • 68.13.3.159:34354
  • 68.14.95.198:34354
  • 68.174.233.26:34354
  • 68.188.222.173:34354
  • 68.195.123.67:34354
  • 68.197.113.124:34354
  • 68.213.106.161:34354
  • 68.228.166.58:34354
  • 68.48.111.52:34354
  • 68.58.138.203:34354
  • 68.69.252.243:34354
  • 68.7.24.113:34354
  • 68.83.4.135:34354
  • 69.117.10.157:34354
  • 69.117.199.30:34354
  • 69.118.232.207:34354
  • 69.118.240.220:34354
  • 69.118.34.93:34354
  • 69.126.230.254:34354
  • 69.126.6.121:34354
  • 69.138.221.143:34354
  • 69.139.110.9:34354
  • 69.139.23.251:34354
  • 69.141.162.15:34354
  • 69.141.254.225:34354
  • 69.154.100.158:34354
  • 69.19.254.160:34354
  • 69.204.120.136:34354
  • 69.204.42.156:34354
  • 69.246.56.59:34354
  • 69.248.253.117:34354
  • 69.249.186.166:34354
  • 69.47.235.228:34354
  • 70.124.68.56:34354
  • 70.124.84.110:34354
  • 70.125.70.181:34354
  • 70.172.199.224:34354
  • 70.67.238.186:34354
  • 70.80.212.14:34354
  • 71.201.194.93:34354
  • 71.22.247.114:34354
  • 71.225.9.221:34354
  • 71.226.208.41:34354
  • 71.58.174.233:34354
  • 71.7.237.86:34354
  • 71.72.160.247:34354
  • 71.8.52.10:34354
  • 71.81.65.13:34354
  • 71.88.184.190:34354
  • 72.102.192.242:34354
  • 72.136.12.116:34354
  • 72.179.130.174:34354
  • 72.182.152.67:34354
  • 72.191.118.14:34354
  • 72.213.216.12:34354
  • 74.192.84.65:34354
  • 74.193.43.231:34354
  • 74.219.195.28:34354
  • 74.50.106.232:34354
  • 74.65.13.112:34354
  • 74.65.207.245:34354
  • 74.81.153.243:34354
  • 74.88.33.242:34354
  • 74.92.244.33:34354
  • 75.110.156.26:34354
  • 75.133.163.61:34354
  • 75.185.32.102:34354
  • 75.199.74.247:34354
  • 75.209.194.225:34354
  • 75.215.214.188:34354
  • 75.240.15.142:34354
  • 75.243.61.165:34354
  • 75.249.164.141:34354
  • 75.250.150.167:34354
  • 75.46.204.183:34354
  • 75.53.45.78:34354
  • 75.64.143.20:34354
  • 75.66.195.12:34354
  • 75.67.118.195:34354
  • 75.75.42.95:34354
  • 75.85.47.163:34354
  • 76.109.65.87:34354
  • 76.114.138.106:34354
  • 76.125.98.79:34354
  • 76.127.224.126:34354
  • 76.14.243.130:34354
  • 76.16.153.131:34354
  • 76.182.116.39:34354
  • 76.182.15.43:34354
  • 76.189.203.181:34354
  • 76.189.204.133:34354
  • 76.205.126.183:34354
  • 76.214.61.95:34354
  • 76.23.184.123:34354
  • 76.24.3.232:34354
  • 76.241.94.9:34354
  • 76.25.253.161:34354
  • 76.4.240.11:34354
  • 76.90.211.38:34354
  • 77.120.147.28:34354
  • 78.26.139.169:34354
  • 79.116.243.98:34354
  • 79.118.115.156:34354
  • 79.118.37.250:34354
  • 79.18.187.8:34354
  • 8.8.8.8:53
  • 80.218.70.108:34354
  • 84.1.168.149:34354
  • 84.231.186.190:34354
  • 85.225.137.214:34354
  • 86.0.93.20:34354
  • 88.147.45.171:34354
  • 89.106.121.97:34354
  • 89.231.69.125:34354
  • 91.137.169.122:34354
  • 92.83.197.60:34354
  • 95.156.55.102:34354
  • 96.24.168.186:34354
  • 96.41.165.2:34354
  • 97.104.196.203:34354
  • 97.82.243.13:34354
  • 97.88.192.21:34354
  • 97.92.154.177:34354
  • 98.122.103.254:34354
  • 98.157.204.233:34354
  • 98.166.21.249:34354
  • 98.197.177.162:34354
  • 98.199.171.186:34354
  • 98.206.0.239:34354
  • 98.211.16.242:34354
  • 98.212.32.190:34354
  • 98.213.251.15:34354
  • 98.215.86.19:34354
  • 98.216.151.74:34354
  • 98.220.205.178:34354
  • 98.223.89.209:34354
  • 98.235.47.8:34354
  • 98.239.177.190:34354
  • 98.242.181.218:34354
  • 98.249.118.220:34354
  • 98.252.39.197:34354
  • 98.253.217.83:34354
  • 98.254.89.112:34354
  • 98.26.140.203:34354
  • 98.85.7.131:34354
  • 99.250.123.171:34354
DNS Requests
  • promos.fling.com

download Try Sophos products for free
Download now