Техническая информация
- %WINDIR%\bfsvc.exe
- %ALLUSERSPROFILE%\benzin.ttf
- %ALLUSERSPROFILE%\zona-pro.ttf
- %ALLUSERSPROFILE%\icomoon.ttf
- %ALLUSERSPROFILE%\icons.ttf
- %ALLUSERSPROFILE%\china.ttf
- 'localhost':49692
- 'ap#.###st-cheats.com':443
- 'cr#.#ectigo.com':80
- 'oc##.#ectigo.com':80
- 'localhost':49702
- http://oc##.#ectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ1uniq7DyFGBEstPHKBOv5qa%2FqfAQUgVlIybrlAG%2Fft%2F9Qxavv3ebkrpACECZgyVkEgNolw58qRNe765s%3D
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33##############
- 'localhost':49692
- 'localhost':49693
- 'ap#.###st-cheats.com':443
- 'localhost':49702
- 'localhost':49703
- DNS ASK ap#.###st-cheats.com
- DNS ASK cr#.#ectigo.com
- DNS ASK oc##.#ectigo.com
- '<SYSTEM32>\cmd.exe' /c sc stop faceit
- '<SYSTEM32>\sc.exe' stop faceit
- '<SYSTEM32>\cmd.exe' /c cls
- '%WINDIR%\bfsvc.exe'