Technical Information
- <SYSTEM32>\services.exe
- %WINDIR%\Explorer.EXE
- C:\RECYCLER\S-1-5-18\$2ebe1c2e2a38cb36436c4d1cb8c2630c\@
- C:\RECYCLER\S-1-5-18\$2ebe1c2e2a38cb36436c4d1cb8c2630c\n
- C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\$2ebe1c2e2a38cb36436c4d1cb8c2630c\@
- C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\$2ebe1c2e2a38cb36436c4d1cb8c2630c\n
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- 'localhost':80
- 'j.###mind.com':80
- fo#####-counters.com/5699145-24B8EBEDAA47374020E664A2406FB684/counter.img?th###############################
- j.###mind.com/app/geoip.js
- DNS ASK ��#�6�
- DNS ASK ��#v�k}
- DNS ASK ��#�` �
- DNS ASK ��#i�H:
- DNS ASK ��#p�^
- DNS ASK j.###mind.com
- DNS ASK ��#�K
- DNS ASK ��#�>C