Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\byebyedpi.exe.lnk
- <SYSTEM32>\tasks\byebyedpi
- [HKLM\System\CurrentControlSet\Services\GoodbyeDPI_Default] 'ImagePath' = '"C:\ByeByeDPI\goodbyedpi.exe" -9 -m -r --max-payload 136 --fake-resend 2 --auto-ttl --fake-with-sni fonts.google.com -...
- [HKLM\System\CurrentControlSet\Services\WinDivert] 'ImagePath' = 'C:\ByeByeDPI\WinDivert64.sys'
- 'GoodbyeDPI_Default' "C:\ByeByeDPI\goodbyedpi.exe" -9 -m -r --max-payload 136 --fake-resend 2 --auto-ttl --fake-with-sni fonts.google.com --fake-gen 10 --fake-from-hex b2afc124e5 --blacklist "C:\ByeByeDPI\russia-bl...
- 'WinDivert' C:\ByeByeDPI\WinDivert64.sys
- '<SYSTEM32>\taskkill.exe' /f /im GoodByeDPIService.exe
- '<SYSTEM32>\taskkill.exe' /f /im ByeByeDPI.exe
- C:\byebyedpi\uninstall.cmd
- C:\byebyedpi\alternative\config_adv6.cmd
- C:\byebyedpi\alternative\config_adv5.cmd
- C:\byebyedpi\alternative\config_adv4.cmd
- C:\byebyedpi\alternative\config_adv3.cmd
- C:\byebyedpi\alternative\config_adv2.cmd
- C:\byebyedpi\alternative\config_adv1.cmd
- C:\byebyedpi\alternative\autohostlist.txt
- C:\byebyedpi\alternative\windivert64.sys
- C:\byebyedpi\alternative\russia-youtube.txt
- C:\byebyedpi\alternative\windivert.dll
- C:\byebyedpi\alternative\tls_clienthello_iana_org.bin
- C:\byebyedpi\alternative\tls_clienthello_drive_google_com.bin
- C:\byebyedpi\alternative\tls_clienthello_4.bin
- C:\byebyedpi\alternative\tls_clienthello_3.bin
- C:\byebyedpi\alternative\tls_clienthello_2.bin
- C:\byebyedpi\alternative\tls_clienthello_1.bin
- C:\byebyedpi\alternative\russia-youtube-rtmps.txt
- C:\byebyedpi\alternative\russia-youtubeq.txt
- C:\byebyedpi\alternative\tls_clienthello_www_google_com.bin
- C:\byebyedpi\alternative\russia-youtubegv.txt
- C:\byebyedpi\alternative\config_adv7.cmd
- C:\byebyedpi\alternative\config_uni3.cmd
- C:\byebyedpi\alternative\tls_clienthello_7.bin
- C:\byebyedpi\alternative\tls_clienthello_6.bin
- C:\byebyedpi\alternative\tls_clienthello_5.bin
- C:\byebyedpi\alternative\tls_clienthello_2n.bin
- C:\byebyedpi\alternative\mycdnlist.txt
- C:\byebyedpi\alternative\ipset-cloudflare.txt
- C:\byebyedpi\alternative\config_uni6.cmd
- C:\byebyedpi\alternative\config_uni5.cmd
- C:\byebyedpi\alternative\config_agr2.cmd
- C:\byebyedpi\alternative\config_agr1.cmd
- C:\byebyedpi\alternative\config_uni2.cmd
- C:\byebyedpi\alternative\config_uni1.cmd
- C:\byebyedpi\alternative\config_alt10.cmd
- C:\byebyedpi\alternative\config_agr8.cmd
- C:\byebyedpi\alternative\config_agr7.cmd
- C:\byebyedpi\alternative\config_agr6.cmd
- C:\byebyedpi\alternative\tls_clienthello_chat_deepseek_com.bin
- C:\byebyedpi\alternative\config_alt9.cmd
- C:\byebyedpi\alternative\config_uni4.cmd
- C:\byebyedpi\alternative\russia-discord-ipset.txt
- C:\byebyedpi\alternative\russia-discord.txt
- C:\byebyedpi\alternative\quic_pl_by_ori.bin
- C:\byebyedpi\alternative\config_alt4.cmd
- C:\byebyedpi\alternative\config_alt3.cmd
- C:\byebyedpi\alternative\config_alt2.cmd
- C:\byebyedpi\alternative\config_alt1.cmd
- C:\byebyedpi\alternative\config_agr5.cmd
- C:\byebyedpi\alternative\config_agr4.cmd
- C:\byebyedpi\alternative\config_agr3.cmd
- C:\byebyedpi\alternative\config_alt6.cmd
- C:\byebyedpi\byebyedpi.xml
- C:\byebyedpi\windivert64.sys
- C:\byebyedpi\windivert.dll
- C:\byebyedpi\russia-youtube.txt
- C:\byebyedpi\russia-blacklist.txt
- C:\byebyedpi\manual.cmd
- C:\byebyedpi\install.cmd
- C:\byebyedpi\hosts.txt
- C:\byebyedpi\byebyedpi.exe
- C:\byebyedpi\goodbyedpi.exe
- C:\byebyedpi\alternative\config_alt7.cmd
- C:\byebyedpi\alternative\config_alt5.cmd
- C:\byebyedpi\alternative\config_alt8.cmd
- C:\byebyedpi\alternative\quic_initial_www_google_com.bin
- C:\byebyedpi\alternative\list-discord.txt
- C:\byebyedpi\alternative\quic_3.bin
- C:\byebyedpi\alternative\quic_2.bin
- C:\byebyedpi\alternative\quic_1.bin
- C:\byebyedpi\alternative\netrogat.txt
- C:\byebyedpi\alternative\myhostlist.txt
- C:\byebyedpi\alternative\mdig.exe
- C:\byebyedpi\alternative\logfile.log
- C:\byebyedpi\alternative\list-general.txt
- C:\byebyedpi\alternative\killall.exe
- C:\byebyedpi\alternative\cygwin1.dll
- C:\byebyedpi\alternative\ipset-youtube.txt
- C:\byebyedpi\alternative\ipset-discord.txt
- C:\byebyedpi\alternative\ip2net.exe
- C:\byebyedpi\alternative\goodbyedpi_des.exe
- C:\byebyedpi\alternative\goodbyedpi_dalt.exe
- C:\byebyedpi\alternative\goodbyedpi_alt.exe
- C:\byebyedpi\alternative\goodbyedpi.exe
- C:\byebyedpi\alternative\cygwin2.dll
- C:\byebyedpi\alternative\quic_4.bin
- C:\byebyedpi\hosts.acl
- C:\byebyedpi\hosts.acl
- 'se####.kakpidar.ru':3333
- 'se####.kakpidar.ru':3333
- DNS ASK se####.kakpidar.ru
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- 'C:\byebyedpi\goodbyedpi.exe' -9 -m -r --max-payload 136 --fake-resend 2 --auto-ttl --fake-with-sni fonts.google.com --fake-gen 10 --fake-from-hex b2afc124e5 --blacklist "C:\ByeByeDPI\russia-blacklist.txt" --blacklist "C:\B...
- 'C:\byebyedpi\byebyedpi.exe'
- '<SYSTEM32>\cmd.exe' /c schtasks.exe /create /xml "ByeByeDPI.xml" /TN "ByeByeDPI"
- '<SYSTEM32>\sc.exe' description "GoodbyeDPI_Default" "Passive Deep Packet Inspection blocker and Active DPI circumvention utility (Default mode)"
- '<SYSTEM32>\sc.exe' create "GoodbyeDPI_Default" binPath= "\"C:\ByeByeDPI\goodbyedpi.exe\" -9 -m -r --max-payload 136 --fake-resend 2 --auto-ttl --fake-with-sni fonts.google.com --fake-gen 10 --fake-from-hex b2afc1...
- '<SYSTEM32>\sc.exe' delete "GoodbyeDPI_Aggressive"
- '<SYSTEM32>\sc.exe' stop "GoodbyeDPI_Aggressive"
- '<SYSTEM32>\sc.exe' delete "GoodbyeDPI_Default"
- '<SYSTEM32>\sc.exe' stop "GoodbyeDPI_Default"
- '<SYSTEM32>\sc.exe' delete "GoodbyeDPI"
- '<SYSTEM32>\sc.exe' start "GoodbyeDPI_Default"
- '<SYSTEM32>\sc.exe' stop "GoodbyeDPI"
- '<SYSTEM32>\attrib.exe' +r "<DRIVERS>\etc\hosts"
- '<SYSTEM32>\attrib.exe' -r -h -s "<DRIVERS>\etc\hosts"
- '<SYSTEM32>\icacls.exe' "<DRIVERS>\etc\hosts" /reset
- '<SYSTEM32>\takeown.exe' /a /f "<DRIVERS>\etc\hosts"
- '<SYSTEM32>\icacls.exe' "<DRIVERS>\etc\hosts" /save hosts.acl
- '<SYSTEM32>\cmd.exe' /c ""C:\ByeByeDPI\install.cmd" "
- '<SYSTEM32>\schtasks.exe' /create /xml "ByeByeDPI.xml" /TN "ByeByeDPI"
- '<SYSTEM32>\icacls.exe' "<DRIVERS>\etc" /restore hosts.acl
- '%WINDIR%\syswow64\cmd.exe' /c rd C:\ByeByeDPI_old /s /q (со скрытым окном)