Техническая информация
- скрытых файлов
- %WINDIR%\syswow64\locationnotifications.exe
- %WINDIR%\syswow64\mrinfo.exe
- %WINDIR%\syswow64\openfiles.exe
- %WINDIR%\syswow64\rmactivate_ssp_isv.exe
- %WINDIR%\syswow64\locationnotifications.exe
- %WINDIR%\syswow64\mrinfo.exe
- %WINDIR%\syswow64\openfiles.exe
- D:\nnc
- D:\yyds\config.ini
- D:\nnc
- 'u.#.qq.com':443
- 'ca####s.digicert.cn':80
- 'vv.##deo.qq.com':443
- 'qi#####i.baidubce.com':80
- 'vv.##deo.qq.com':80
- 'qi##.baidu.com':80
- '11#.#4.35.32':80
- http://ca####s.digicert.cn/DigiCertGlobalRootG2.crt
- http://qi#####i.baidubce.com/ip/geo/v1/district?ip#
- http://vv.##deo.qq.com/checktime
- http://qi#####i.baidubce.com/ip/geo/v1/district?ip#############
- http://qi##.baidu.com/ip/local/geo/v1/district
- 'u.#.qq.com':443
- 'vv.##deo.qq.com':443
- DNS ASK u.#.qq.com
- DNS ASK ca####s.digicert.cn
- DNS ASK 20##.ip138.com
- DNS ASK vv.##deo.qq.com
- DNS ASK qi#####i.baidubce.com
- DNS ASK qi##.baidu.com
- '%WINDIR%\syswow64\locationnotifications.exe'
- '%WINDIR%\syswow64\mrinfo.exe'
- '%WINDIR%\syswow64\rmactivate_ssp_isv.exe'