Windows Sockets 2 Parameters

Under the Key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters there are two enteries (usually) :

Their should be a respective sub key folder matching the two value data values.

Each of which should have a sub-key :

There are squencially numbered decimal sub-keys under each Catalog_Enteries sub-key 12 Digits long under each of which is either a PackedCatalogItem Value and/or a other values representing the entry. The items of interest to a Spy/Trogen hunter are the Value which is referenced in LibraryFile and/or the first few bytes of value data for the value PackedCatalogItem bytes of the PackedCatalogItem value data.

Return