paladin316

inst_buychannel_18_exe_2019-07-20_08_30.txt

Jul 20th, 2019
2,288
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 389.50 KB | None | 0 0
  1.  
  2. * MalFamily: "Adware"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "inst_buychannel_18.exe"
  7. * File Size: 1099376
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "d387414ac04f990c314c8f4e63a95f25d11b964fb844db63362edb06420bf168"
  10. * MD5: "c644f8b118f54d9c66e0ef84b25e7c84"
  11. * SHA1: "47bef7490093513689dd7dc57407f8da9b322172"
  12. * SHA512: "09e14598f421babc6ec957eb53ada28e6c77cc8f1df817d975227ef17f49ccb31d1c621b077c8730ed05596aa41b7dc4a368714dfa06414c4590a727416d6ee9"
  13. * CRC32: "5DD78F28"
  14. * SSDEEP: "24576:06JoReh51zUXshsU9fq0rZe+QK0ltXe9/6s63mpmXaLGxcUAS+TFnk4iO:YRu1AFUo0rI6Gu91LpmXAGKjS0N75"
  15.  
  16. * Process Execution:
  17. "inst_buychannel_18.exe",
  18. "ludashisetup.exe",
  19. "LdsHelper.exe",
  20. "LDSGameCenter.exe",
  21. "ComputerZTray.exe",
  22. "ComputerZService.exe",
  23. "RunDll.exe",
  24. "RunDll.exe",
  25. "RunDll.exe",
  26. "ComputerZService.exe",
  27. "RunDll.exe",
  28. "RunDll.exe",
  29. "RunDll.exe",
  30. "MobileDeviceSrv.exe",
  31. "ComputerZService.exe",
  32. "NavPlugin.exe",
  33. "NavProxy64.exe",
  34. "regsvr32.exe",
  35. "regsvr32.exe",
  36. "DumpUper.exe",
  37. "services.exe",
  38. "svchost.exe",
  39. "ComputerZTray.exe",
  40. "ComputerZ14.exe",
  41. "svchost.exe",
  42. "svchost.exe",
  43. "taskhost.exe",
  44. "explorer.exe"
  45.  
  46.  
  47. * Executed Commands:
  48. "C:\\Users\\user\\AppData\\Local\\Temp\\ludashisetup.exe --pid=\"buychannel_18\" /S /VerifyPhone /LOCKHP",
  49. "\"C:\\Program Files (x86)\\LuDaShi\\Utils\\LdsHelper.exe\"",
  50. "\"C:\\Program Files (x86)\\LuDaShi\\Utils\\LdsHelper.exe\" ",
  51. "\"C:\\Program Files (x86)\\LuDaShi\\gamecenter\\LDSGameCenter.exe\" --from=ludashiembed__buychannelall_inst_run --gameid=ms",
  52. "\"C:\\Program Files (x86)\\LuDaShi\\ComputerZTray.exe\" /from_inst /VerifyPhone",
  53. "\"C:\\Program Files (x86)\\LuDaShi\\ComputerZTray.exe\" /from_inst /VerifyPhone",
  54. "C:\\Windows\\SysWOW64\\svchost.exe -k netsvcs",
  55. "\"C:\\Program Files (x86)\\LuDaShi\\ComputerZTray.exe\" /frmsvc /autorun --from=svc --src=a07e4d8",
  56. "c:\\program files (x86)\\ludashi\\Utils\\ComputerZ14.exe",
  57. "\"C:\\Program Files (x86)\\LuDaShi\\ComputerZService.exe\"",
  58. "C:\\Program Files (x86)\\LuDaShi\\ComputerZService.exe ",
  59. "\"C:\\Program Files (x86)\\LuDaShi\\Utils\\MobileDeviceSrv.exe\" /from=ludashi",
  60. "\"C:\\Program Files (x86)\\LuDaShi\\Utils\\NavPlugin.exe\" /run /from=ludashi",
  61. "C:\\Program Files (x86)\\LuDaShi\\Utils\\NavPlugin.exe /run /from=ludashi",
  62. "\"regsvr32.exe\" \"C:\\Program Files (x86)\\LuDaShi\\ComputerZ7_x64.dll\" /s",
  63. "C:\\Program Files (x86)\\LuDaShi\\Utils\\mininews.exe /from=ludashi /data=CE76A57B-F783-4213-87E5-F3BE4605FDC7_ludashi_1 /ids=",
  64. "\"C:\\Program Files (x86)\\LuDaShi\\Utils\\RunDll.exe\" --dll=\"ComputerZ_HardwareDll.dll\" --entry=\"DirectXVersionProcess\" --wnd=393542",
  65. "\"C:\\Program Files (x86)\\LuDaShi\\Utils\\RunDll.exe\" --dll=\"ComputerZ_HardwareDll.dll\" --entry=\"OpenCLTestProcess\" --wnd=393542",
  66. "\"C:\\Program Files (x86)\\LuDaShi\\Utils\\RunDll.exe\" --dll=\"ComputerZ_HardwareDll.dll\" --entry=\"NvidiaMonitorSizeOfProcess\" --wnd=393542",
  67. "\"C:\\Program Files (x86)\\LuDaShi\\Utils\\mininews.exe\" /from=ludashi /data=CE76A57B-F783-4213-87E5-F3BE4605FDC7_ludashi_1 /ids=",
  68. "\"C:\\Program Files (x86)\\LuDaShi\\Utils\\RunDll.exe\" --dll=\"ComputerZ_HardwareDll.dll\" --entry=\"DirectXVersionProcess\" --wnd=328264",
  69. "\"C:\\Program Files (x86)\\LuDaShi\\Utils\\RunDll.exe\" --dll=\"ComputerZ_HardwareDll.dll\" --entry=\"OpenCLTestProcess\" --wnd=328264",
  70. "\"C:\\Program Files (x86)\\LuDaShi\\Utils\\RunDll.exe\" --dll=\"ComputerZ_HardwareDll.dll\" --entry=\"NvidiaMonitorSizeOfProcess\" --wnd=328264",
  71. "C:\\Program Files (x86)\\LuDaShi\\Utils\\NavProxy64.exe /64BitLauncher=Install",
  72. "C:\\Windows\\system32\\regsvr32.exe \"C:\\Program Files (x86)\\LuDaShi\\ComputerZ7_x64.dll\" /s"
  73.  
  74.  
  75. * Signatures Detected:
  76.  
  77. "Description": "Creates RWX memory",
  78. "Details":
  79.  
  80.  
  81. "Description": "A process attempted to delay the analysis task.",
  82. "Details":
  83.  
  84. "Process": "ComputerZTray.exe tried to sleep 418 seconds, actually delayed analysis time by 0 seconds"
  85.  
  86.  
  87. "Process": "LDSGameCenter.exe tried to sleep 360 seconds, actually delayed analysis time by 0 seconds"
  88.  
  89.  
  90. "Process": "ComputerZService.exe tried to sleep 759 seconds, actually delayed analysis time by 0 seconds"
  91.  
  92.  
  93.  
  94.  
  95. "Description": "Attempts to connect to a dead IP:Port (32 unique times)",
  96. "Details":
  97.  
  98. "IP": "1.192.194.229:80"
  99.  
  100.  
  101. "IP": "72.21.91.29:80"
  102.  
  103.  
  104. "IP": "104.193.88.77:443"
  105.  
  106.  
  107. "IP": "114.115.221.211:80"
  108.  
  109.  
  110. "IP": "139.129.105.182:80"
  111.  
  112.  
  113. "IP": "23.50.75.27:80"
  114.  
  115.  
  116. "IP": "118.190.124.241:80"
  117.  
  118.  
  119. "IP": "104.193.88.77:80"
  120.  
  121.  
  122. "IP": "72.21.81.240:80"
  123.  
  124.  
  125. "IP": "123.125.82.104:80"
  126.  
  127.  
  128. "IP": "36.51.254.234:80"
  129.  
  130.  
  131. "IP": "36.99.227.227:80"
  132.  
  133.  
  134. "IP": "120.52.140.47:80"
  135.  
  136.  
  137. "IP": "103.235.46.191:80"
  138.  
  139.  
  140. "IP": "104.192.108.17:80"
  141.  
  142.  
  143. "IP": "117.78.49.231:80"
  144.  
  145.  
  146. "IP": "124.232.170.86:80"
  147.  
  148.  
  149. "IP": "114.116.39.220:80"
  150.  
  151.  
  152. "IP": "114.115.218.83:80"
  153.  
  154.  
  155. "IP": "101.226.161.171:80"
  156.  
  157.  
  158. "IP": "54.230.192.100:80"
  159.  
  160.  
  161. "IP": "124.232.170.85:80"
  162.  
  163.  
  164. "IP": "115.28.112.133:80"
  165.  
  166.  
  167. "IP": "139.129.105.182:443"
  168.  
  169.  
  170. "IP": "124.232.169.218:80"
  171.  
  172.  
  173. "IP": "47.246.17.231:80"
  174.  
  175.  
  176. "IP": "1.193.188.220:80"
  177.  
  178.  
  179. "IP": "36.99.227.228:80"
  180.  
  181.  
  182. "IP": "124.232.169.220:80"
  183.  
  184.  
  185. "IP": "1.193.188.219:80"
  186.  
  187.  
  188. "IP": "1.193.188.218:80"
  189.  
  190.  
  191. "IP": "23.221.48.212:443"
  192.  
  193.  
  194.  
  195.  
  196. "Description": "Loads a driver",
  197. "Details":
  198.  
  199. "driver service name": "\\Registry\\Machine\\System\\CurrentControlSet\\Services\\WS2IFSL"
  200.  
  201.  
  202. "driver service name": "\\Registry\\Machine\\System\\CurrentControlSet\\Services\\HardwareProtect"
  203.  
  204.  
  205. "driver service name": "\\Registry\\Machine\\System\\CurrentControlSet\\Services\\ComputerZ_x64"
  206.  
  207.  
  208. "driver service name": "\\Registry\\Machine\\System\\CurrentControlSet\\Services\\WS2IFSL"
  209.  
  210.  
  211.  
  212.  
  213. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  214. "Details":
  215.  
  216. "ioc": "nc.1705"
  217.  
  218.  
  219. "ioc": "ept.1503"
  220.  
  221.  
  222. "ioc": "https://d.symcb.com/cps0"
  223.  
  224.  
  225. "ioc": "https://d.symcb.com/rpa0"
  226.  
  227.  
  228. "ioc": "http://www.symauth.com/cps0"
  229.  
  230.  
  231. "ioc": "http://www.symauth.com/rpa0"
  232.  
  233.  
  234. "ioc": "http://www.usertrust.com1"
  235.  
  236.  
  237. "ioc": "http://crl.usertrust.com/UTN-USERFirst-Object.crl0"
  238.  
  239.  
  240. "ioc": "http://crl.usertrust.com/UTN-USERFirst-Object.crl05"
  241.  
  242.  
  243. "ioc": "http://ocsp.usertrust.com"
  244.  
  245.  
  246. "ioc": "http://sf.symcb.com/sf.crl0a"
  247.  
  248.  
  249. "ioc": "http://sf.symcd.com0"
  250.  
  251.  
  252. "ioc": "http://sf.symcb.com/sf.crt0"
  253.  
  254.  
  255. "ioc": "https://www.globalsign.com/repository/03"
  256.  
  257.  
  258. "ioc": "http://crl.globalsign.net/root.crl0"
  259.  
  260.  
  261. "ioc": "https://www.globalsign.com/repository/0"
  262.  
  263.  
  264. "ioc": "http://crl.globalsign.com/gs/gstimestampingg2.crl0T"
  265.  
  266.  
  267. "ioc": "http://secure.globalsign.com/cacert/gstimestampingg2.crt0"
  268.  
  269.  
  270. "ioc": "http://th.symcb.com/th.crl0"
  271.  
  272.  
  273. "ioc": "http://th.symcd.com0"
  274.  
  275.  
  276. "ioc": "http://th.symcb.com/th.crt"
  277.  
  278.  
  279. "ioc": "nc.100."
  280.  
  281.  
  282. "ioc": "http://sf.symcb.com/sf.crl0f"
  283.  
  284.  
  285.  
  286.  
  287. "Description": "A named pipe was used for inter-process communication",
  288. "Details":
  289.  
  290. "Creates": "ComputerZService.exe(3740) Created Named Pipe computerzservice"
  291.  
  292.  
  293. "Interacts": "ComputerZService.exe(3740) reads/writes data to Named Pipe computerzservice"
  294.  
  295.  
  296. "Interacts": "ComputerZTray.exe(204) reads/writes data to Named Pipe computerzservice"
  297.  
  298.  
  299.  
  300.  
  301. "Description": "Starts servers listening on 0.0.0.0:19531, 127.0.0.1:7668",
  302. "Details":
  303.  
  304.  
  305. "Description": "Expresses interest in specific running processes",
  306. "Details":
  307.  
  308. "process": "ComputerZTray.exe"
  309.  
  310.  
  311. "process": "explorer.exe"
  312.  
  313.  
  314.  
  315.  
  316. "Description": "Reads data out of its own binary image",
  317. "Details":
  318.  
  319. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00000000, length: 0x00000168"
  320.  
  321.  
  322. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00000000, length: 0x000001a4"
  323.  
  324.  
  325. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00000000, length: 0x00004000"
  326.  
  327.  
  328. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00000000, length: 0x00008000"
  329.  
  330.  
  331. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0000016c, length: 0x00004e94"
  332.  
  333.  
  334. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000001b0, length: 0x0000b6e0"
  335.  
  336.  
  337. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00005000, length: 0x00008000"
  338.  
  339.  
  340. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0000b890, length: 0x00010000"
  341.  
  342.  
  343. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0000d000, length: 0x00010000"
  344.  
  345.  
  346. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0001b890, length: 0x00010000"
  347.  
  348.  
  349. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0001d000, length: 0x00010000"
  350.  
  351.  
  352. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0002b890, length: 0x00010000"
  353.  
  354.  
  355. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0002d000, length: 0x00010000"
  356.  
  357.  
  358. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0003b890, length: 0x00010000"
  359.  
  360.  
  361. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0003d000, length: 0x00010000"
  362.  
  363.  
  364. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0004b890, length: 0x00010000"
  365.  
  366.  
  367. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0004d000, length: 0x00008000"
  368.  
  369.  
  370. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00053890, length: 0x00010000"
  371.  
  372.  
  373. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00055000, length: 0x00008000"
  374.  
  375.  
  376. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0005b890, length: 0x00010000"
  377.  
  378.  
  379. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0005d000, length: 0x00010000"
  380.  
  381.  
  382. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0006b890, length: 0x00010000"
  383.  
  384.  
  385. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0006d000, length: 0x00010000"
  386.  
  387.  
  388. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0007b890, length: 0x00010000"
  389.  
  390.  
  391. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0007d000, length: 0x00010000"
  392.  
  393.  
  394. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0008b890, length: 0x00010000"
  395.  
  396.  
  397. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0008d000, length: 0x00010000"
  398.  
  399.  
  400. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0009b890, length: 0x00010000"
  401.  
  402.  
  403. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0009d000, length: 0x00008000"
  404.  
  405.  
  406. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000a3890, length: 0x00010000"
  407.  
  408.  
  409. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000a5000, length: 0x00008000"
  410.  
  411.  
  412. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000ab890, length: 0x00010000"
  413.  
  414.  
  415. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000ad000, length: 0x00008000"
  416.  
  417.  
  418. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000b3890, length: 0x00010000"
  419.  
  420.  
  421. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000b5000, length: 0x00008000"
  422.  
  423.  
  424. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000bb890, length: 0x00010000"
  425.  
  426.  
  427. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000bd000, length: 0x00008000"
  428.  
  429.  
  430. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000c3890, length: 0x00010000"
  431.  
  432.  
  433. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000c5000, length: 0x00008000"
  434.  
  435.  
  436. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000cb890, length: 0x00010000"
  437.  
  438.  
  439. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000cd000, length: 0x00008000"
  440.  
  441.  
  442. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000d3890, length: 0x00010000"
  443.  
  444.  
  445. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000d5000, length: 0x00008000"
  446.  
  447.  
  448. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000db890, length: 0x00010000"
  449.  
  450.  
  451. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000dd000, length: 0x00010000"
  452.  
  453.  
  454. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000eb890, length: 0x00010000"
  455.  
  456.  
  457. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000ed000, length: 0x00010000"
  458.  
  459.  
  460. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000fb890, length: 0x00010000"
  461.  
  462.  
  463. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x000fd000, length: 0x00010000"
  464.  
  465.  
  466. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0010b890, length: 0x00010000"
  467.  
  468.  
  469. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0010d000, length: 0x00010000"
  470.  
  471.  
  472. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0011b890, length: 0x00010000"
  473.  
  474.  
  475. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0011d000, length: 0x00008000"
  476.  
  477.  
  478. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00123890, length: 0x00010000"
  479.  
  480.  
  481. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00125000, length: 0x00008000"
  482.  
  483.  
  484. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0012b890, length: 0x00010000"
  485.  
  486.  
  487. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0012d000, length: 0x00008000"
  488.  
  489.  
  490. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00133890, length: 0x00010000"
  491.  
  492.  
  493. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00135000, length: 0x00008000"
  494.  
  495.  
  496. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0013b890, length: 0x00010000"
  497.  
  498.  
  499. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0013d000, length: 0x00008000"
  500.  
  501.  
  502. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00143890, length: 0x00010000"
  503.  
  504.  
  505. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00145000, length: 0x00008000"
  506.  
  507.  
  508. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0014b890, length: 0x00010000"
  509.  
  510.  
  511. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0014d000, length: 0x00010000"
  512.  
  513.  
  514. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00153890, length: 0x00010000"
  515.  
  516.  
  517. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0015b890, length: 0x00010000"
  518.  
  519.  
  520. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0015d000, length: 0x00010000"
  521.  
  522.  
  523. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00163890, length: 0x00010000"
  524.  
  525.  
  526. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0016b890, length: 0x00010000"
  527.  
  528.  
  529. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0016d000, length: 0x00010000"
  530.  
  531.  
  532. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00173890, length: 0x00010000"
  533.  
  534.  
  535. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0017b890, length: 0x00010000"
  536.  
  537.  
  538. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0017d000, length: 0x00010000"
  539.  
  540.  
  541. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00183890, length: 0x00010000"
  542.  
  543.  
  544. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0018b890, length: 0x00010000"
  545.  
  546.  
  547. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0018d000, length: 0x00010000"
  548.  
  549.  
  550. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00193890, length: 0x00010000"
  551.  
  552.  
  553. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0019b890, length: 0x00010000"
  554.  
  555.  
  556. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0019d000, length: 0x00010000"
  557.  
  558.  
  559. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001ab890, length: 0x00010000"
  560.  
  561.  
  562. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001ad000, length: 0x00010000"
  563.  
  564.  
  565. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001bb890, length: 0x00010000"
  566.  
  567.  
  568. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001bd000, length: 0x00010000"
  569.  
  570.  
  571. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001cb890, length: 0x00010000"
  572.  
  573.  
  574. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001cd000, length: 0x00010000"
  575.  
  576.  
  577. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001d3890, length: 0x00010000"
  578.  
  579.  
  580. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001db890, length: 0x00010000"
  581.  
  582.  
  583. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001dd000, length: 0x00010000"
  584.  
  585.  
  586. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001e3890, length: 0x00010000"
  587.  
  588.  
  589. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001e5000, length: 0x00010000"
  590.  
  591.  
  592. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001eb890, length: 0x00010000"
  593.  
  594.  
  595. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001ed000, length: 0x00010000"
  596.  
  597.  
  598. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001fb890, length: 0x00010000"
  599.  
  600.  
  601. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x001fd000, length: 0x00010000"
  602.  
  603.  
  604. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00205000, length: 0x00010000"
  605.  
  606.  
  607. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0020b890, length: 0x00010000"
  608.  
  609.  
  610. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0020d000, length: 0x00010000"
  611.  
  612.  
  613. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0021b890, length: 0x00010000"
  614.  
  615.  
  616. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0021d000, length: 0x00010000"
  617.  
  618.  
  619. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0022b890, length: 0x00010000"
  620.  
  621.  
  622. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0022d000, length: 0x00010000"
  623.  
  624.  
  625. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0023b890, length: 0x00010000"
  626.  
  627.  
  628. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0023d000, length: 0x00010000"
  629.  
  630.  
  631. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0024b890, length: 0x00010000"
  632.  
  633.  
  634. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0024d000, length: 0x00010000"
  635.  
  636.  
  637. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0025b890, length: 0x00010000"
  638.  
  639.  
  640. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0025d000, length: 0x00010000"
  641.  
  642.  
  643. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0026b890, length: 0x00010000"
  644.  
  645.  
  646. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0026d000, length: 0x00010000"
  647.  
  648.  
  649. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0027b890, length: 0x00010000"
  650.  
  651.  
  652. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0027d000, length: 0x00010000"
  653.  
  654.  
  655. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0028b890, length: 0x00010000"
  656.  
  657.  
  658. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0028d000, length: 0x00010000"
  659.  
  660.  
  661. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00293890, length: 0x00010000"
  662.  
  663.  
  664. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0029b890, length: 0x00010000"
  665.  
  666.  
  667. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0029d000, length: 0x00010000"
  668.  
  669.  
  670. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002a3890, length: 0x00010000"
  671.  
  672.  
  673. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002ab890, length: 0x00010000"
  674.  
  675.  
  676. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002ad000, length: 0x00010000"
  677.  
  678.  
  679. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002bb890, length: 0x00010000"
  680.  
  681.  
  682. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002bd000, length: 0x00010000"
  683.  
  684.  
  685. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002cb890, length: 0x00010000"
  686.  
  687.  
  688. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002cd000, length: 0x00010000"
  689.  
  690.  
  691. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002d5000, length: 0x00010000"
  692.  
  693.  
  694. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002db890, length: 0x00010000"
  695.  
  696.  
  697. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002dd000, length: 0x00010000"
  698.  
  699.  
  700. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002e5000, length: 0x00010000"
  701.  
  702.  
  703. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002eb890, length: 0x00010000"
  704.  
  705.  
  706. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002ed000, length: 0x00010000"
  707.  
  708.  
  709. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002f5000, length: 0x00010000"
  710.  
  711.  
  712. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002fb890, length: 0x00010000"
  713.  
  714.  
  715. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x002fd000, length: 0x00010000"
  716.  
  717.  
  718. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00305000, length: 0x00010000"
  719.  
  720.  
  721. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0030b890, length: 0x00010000"
  722.  
  723.  
  724. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0030d000, length: 0x00010000"
  725.  
  726.  
  727. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00315000, length: 0x00010000"
  728.  
  729.  
  730. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0031b890, length: 0x00010000"
  731.  
  732.  
  733. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0031d000, length: 0x00010000"
  734.  
  735.  
  736. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0032b890, length: 0x00010000"
  737.  
  738.  
  739. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0032d000, length: 0x00010000"
  740.  
  741.  
  742. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0033b890, length: 0x00010000"
  743.  
  744.  
  745. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0033d000, length: 0x00010000"
  746.  
  747.  
  748. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00345000, length: 0x00010000"
  749.  
  750.  
  751. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0034b890, length: 0x00010000"
  752.  
  753.  
  754. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0034d000, length: 0x00010000"
  755.  
  756.  
  757. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00355000, length: 0x00010000"
  758.  
  759.  
  760. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0035b890, length: 0x00010000"
  761.  
  762.  
  763. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0035d000, length: 0x00010000"
  764.  
  765.  
  766. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00365000, length: 0x00010000"
  767.  
  768.  
  769. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0036b890, length: 0x00010000"
  770.  
  771.  
  772. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0036d000, length: 0x00010000"
  773.  
  774.  
  775. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00375000, length: 0x00010000"
  776.  
  777.  
  778. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0037b890, length: 0x00010000"
  779.  
  780.  
  781. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0037d000, length: 0x00010000"
  782.  
  783.  
  784. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00385000, length: 0x00010000"
  785.  
  786.  
  787. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0038b890, length: 0x00010000"
  788.  
  789.  
  790. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0038d000, length: 0x00010000"
  791.  
  792.  
  793. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00395000, length: 0x00010000"
  794.  
  795.  
  796. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0039b890, length: 0x00010000"
  797.  
  798.  
  799. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0039d000, length: 0x00010000"
  800.  
  801.  
  802. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003a3890, length: 0x00010000"
  803.  
  804.  
  805. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003a5000, length: 0x00010000"
  806.  
  807.  
  808. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003ab890, length: 0x00010000"
  809.  
  810.  
  811. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003ad000, length: 0x00010000"
  812.  
  813.  
  814. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003b5000, length: 0x00010000"
  815.  
  816.  
  817. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003bb890, length: 0x00010000"
  818.  
  819.  
  820. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003bd000, length: 0x00010000"
  821.  
  822.  
  823. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003c5000, length: 0x00010000"
  824.  
  825.  
  826. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003cb890, length: 0x00010000"
  827.  
  828.  
  829. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003cd000, length: 0x00010000"
  830.  
  831.  
  832. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003db890, length: 0x00010000"
  833.  
  834.  
  835. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003dd000, length: 0x00010000"
  836.  
  837.  
  838. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003eb890, length: 0x00010000"
  839.  
  840.  
  841. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003ed000, length: 0x00010000"
  842.  
  843.  
  844. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003fb890, length: 0x00010000"
  845.  
  846.  
  847. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x003fd000, length: 0x00010000"
  848.  
  849.  
  850. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0040b890, length: 0x00010000"
  851.  
  852.  
  853. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0040d000, length: 0x00010000"
  854.  
  855.  
  856. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00415000, length: 0x00010000"
  857.  
  858.  
  859. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0041b890, length: 0x00010000"
  860.  
  861.  
  862. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0041d000, length: 0x00010000"
  863.  
  864.  
  865. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00425000, length: 0x00010000"
  866.  
  867.  
  868. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0042b890, length: 0x00010000"
  869.  
  870.  
  871. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0042d000, length: 0x00010000"
  872.  
  873.  
  874. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00435000, length: 0x00010000"
  875.  
  876.  
  877. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0043b890, length: 0x00010000"
  878.  
  879.  
  880. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0043d000, length: 0x00010000"
  881.  
  882.  
  883. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00445000, length: 0x00010000"
  884.  
  885.  
  886. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0044b890, length: 0x00010000"
  887.  
  888.  
  889. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0044d000, length: 0x00010000"
  890.  
  891.  
  892. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00455000, length: 0x00010000"
  893.  
  894.  
  895. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0045b890, length: 0x00010000"
  896.  
  897.  
  898. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0045d000, length: 0x00010000"
  899.  
  900.  
  901. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00465000, length: 0x00010000"
  902.  
  903.  
  904. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0046b890, length: 0x00010000"
  905.  
  906.  
  907. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0046d000, length: 0x00010000"
  908.  
  909.  
  910. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00475000, length: 0x00010000"
  911.  
  912.  
  913. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0047b890, length: 0x00010000"
  914.  
  915.  
  916. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0047d000, length: 0x00010000"
  917.  
  918.  
  919. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00483890, length: 0x00010000"
  920.  
  921.  
  922. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00485000, length: 0x00010000"
  923.  
  924.  
  925. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0048b890, length: 0x00010000"
  926.  
  927.  
  928. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0048d000, length: 0x00010000"
  929.  
  930.  
  931. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00493890, length: 0x00010000"
  932.  
  933.  
  934. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00495000, length: 0x00010000"
  935.  
  936.  
  937. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0049b890, length: 0x00010000"
  938.  
  939.  
  940. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0049d000, length: 0x00010000"
  941.  
  942.  
  943. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004a3890, length: 0x00010000"
  944.  
  945.  
  946. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004ab890, length: 0x00010000"
  947.  
  948.  
  949. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004ad000, length: 0x00010000"
  950.  
  951.  
  952. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004b3890, length: 0x00010000"
  953.  
  954.  
  955. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004bb890, length: 0x00010000"
  956.  
  957.  
  958. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004bd000, length: 0x00010000"
  959.  
  960.  
  961. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004c5000, length: 0x00010000"
  962.  
  963.  
  964. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004cb890, length: 0x00010000"
  965.  
  966.  
  967. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004cd000, length: 0x00010000"
  968.  
  969.  
  970. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004db890, length: 0x00010000"
  971.  
  972.  
  973. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004dd000, length: 0x00010000"
  974.  
  975.  
  976. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004eb890, length: 0x00010000"
  977.  
  978.  
  979. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004ed000, length: 0x00004000"
  980.  
  981.  
  982. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004ed000, length: 0x00008000"
  983.  
  984.  
  985. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x004fb890, length: 0x00020000"
  986.  
  987.  
  988. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00513890, length: 0x00010000"
  989.  
  990.  
  991. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0051b890, length: 0x00020000"
  992.  
  993.  
  994. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00533890, length: 0x00010000"
  995.  
  996.  
  997. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0053b890, length: 0x00010000"
  998.  
  999.  
  1000. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00543890, length: 0x00010000"
  1001.  
  1002.  
  1003. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0054b890, length: 0x00010000"
  1004.  
  1005.  
  1006. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00553890, length: 0x00010000"
  1007.  
  1008.  
  1009. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0055b890, length: 0x00050000"
  1010.  
  1011.  
  1012. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x005a3890, length: 0x00010000"
  1013.  
  1014.  
  1015. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x005ab890, length: 0x00010000"
  1016.  
  1017.  
  1018. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x005b3890, length: 0x00010000"
  1019.  
  1020.  
  1021. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x005bb890, length: 0x00010000"
  1022.  
  1023.  
  1024. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x005c3890, length: 0x00010000"
  1025.  
  1026.  
  1027. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x005cb890, length: 0x00010000"
  1028.  
  1029.  
  1030. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x005d3890, length: 0x00010000"
  1031.  
  1032.  
  1033. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x005db890, length: 0x00010000"
  1034.  
  1035.  
  1036. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x005e3890, length: 0x00010000"
  1037.  
  1038.  
  1039. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x005eb890, length: 0x00010000"
  1040.  
  1041.  
  1042. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x005f3890, length: 0x00010000"
  1043.  
  1044.  
  1045. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x005fb890, length: 0x00010000"
  1046.  
  1047.  
  1048. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00603890, length: 0x00010000"
  1049.  
  1050.  
  1051. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0060b890, length: 0x00010000"
  1052.  
  1053.  
  1054. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00613890, length: 0x00010000"
  1055.  
  1056.  
  1057. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0061b890, length: 0x00050000"
  1058.  
  1059.  
  1060. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00665a40, length: 0x00004000"
  1061.  
  1062.  
  1063. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00665a40, length: 0x00004008"
  1064.  
  1065.  
  1066. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x0066b890, length: 0x00028008"
  1067.  
  1068.  
  1069. "self_read": "process: LDSGameCenter.exe, pid: 1248, offset: 0x00693a98, length: 0x00000008"
  1070.  
  1071.  
  1072. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00000000, length: 0x00000190"
  1073.  
  1074.  
  1075. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00000000, length: 0x000001cc"
  1076.  
  1077.  
  1078. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00000000, length: 0x00004000"
  1079.  
  1080.  
  1081. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00000000, length: 0x00008000"
  1082.  
  1083.  
  1084. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00000194, length: 0x0000003c"
  1085.  
  1086.  
  1087. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00000194, length: 0x00007af4"
  1088.  
  1089.  
  1090. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x000001d0, length: 0x00005c30"
  1091.  
  1092.  
  1093. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x000001d8, length: 0x0000fab8"
  1094.  
  1095.  
  1096. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00005e00, length: 0x00008000"
  1097.  
  1098.  
  1099. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00007c90, length: 0x00010000"
  1100.  
  1101.  
  1102. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0000de00, length: 0x00008000"
  1103.  
  1104.  
  1105. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0000fc90, length: 0x00010000"
  1106.  
  1107.  
  1108. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00015e00, length: 0x00008000"
  1109.  
  1110.  
  1111. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00017c90, length: 0x00010000"
  1112.  
  1113.  
  1114. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0001de00, length: 0x00008000"
  1115.  
  1116.  
  1117. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0001fc90, length: 0x00010000"
  1118.  
  1119.  
  1120. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00025e00, length: 0x00008000"
  1121.  
  1122.  
  1123. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00027c90, length: 0x00010000"
  1124.  
  1125.  
  1126. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0002de00, length: 0x00008000"
  1127.  
  1128.  
  1129. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0002fc90, length: 0x00010000"
  1130.  
  1131.  
  1132. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00035e00, length: 0x00010000"
  1133.  
  1134.  
  1135. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0003fc90, length: 0x00010000"
  1136.  
  1137.  
  1138. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00045e00, length: 0x00010000"
  1139.  
  1140.  
  1141. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0004fc90, length: 0x00010000"
  1142.  
  1143.  
  1144. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00055e00, length: 0x00010000"
  1145.  
  1146.  
  1147. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0005fc90, length: 0x00010000"
  1148.  
  1149.  
  1150. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00065e00, length: 0x00010000"
  1151.  
  1152.  
  1153. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0006fc90, length: 0x00010000"
  1154.  
  1155.  
  1156. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00075e00, length: 0x00010000"
  1157.  
  1158.  
  1159. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0007fc90, length: 0x00010000"
  1160.  
  1161.  
  1162. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00085e00, length: 0x00010000"
  1163.  
  1164.  
  1165. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0008fc90, length: 0x00010000"
  1166.  
  1167.  
  1168. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00095e00, length: 0x00010000"
  1169.  
  1170.  
  1171. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0009fc90, length: 0x00010000"
  1172.  
  1173.  
  1174. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x000a5e00, length: 0x00010000"
  1175.  
  1176.  
  1177. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x000afc90, length: 0x00010000"
  1178.  
  1179.  
  1180. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x000b5e00, length: 0x00010000"
  1181.  
  1182.  
  1183. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x000bfc90, length: 0x00010000"
  1184.  
  1185.  
  1186. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x000c5e00, length: 0x00010000"
  1187.  
  1188.  
  1189. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x000cfc90, length: 0x00010000"
  1190.  
  1191.  
  1192. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x000d5e00, length: 0x00010000"
  1193.  
  1194.  
  1195. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x000dfc90, length: 0x00010000"
  1196.  
  1197.  
  1198. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x000e5e00, length: 0x00010000"
  1199.  
  1200.  
  1201. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x000efc90, length: 0x00010000"
  1202.  
  1203.  
  1204. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x000f5e00, length: 0x00010000"
  1205.  
  1206.  
  1207. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x000ffc90, length: 0x00010000"
  1208.  
  1209.  
  1210. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00105e00, length: 0x00010000"
  1211.  
  1212.  
  1213. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0010fc90, length: 0x00010000"
  1214.  
  1215.  
  1216. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00115e00, length: 0x00010000"
  1217.  
  1218.  
  1219. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0011fc90, length: 0x00010000"
  1220.  
  1221.  
  1222. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00125e00, length: 0x00010000"
  1223.  
  1224.  
  1225. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0012fc90, length: 0x00010000"
  1226.  
  1227.  
  1228. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00135e00, length: 0x00010000"
  1229.  
  1230.  
  1231. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0013fc90, length: 0x00010000"
  1232.  
  1233.  
  1234. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00145e00, length: 0x00018000"
  1235.  
  1236.  
  1237. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0014fc90, length: 0x00010000"
  1238.  
  1239.  
  1240. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0015de00, length: 0x00010000"
  1241.  
  1242.  
  1243. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0015fc90, length: 0x00010000"
  1244.  
  1245.  
  1246. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00167c90, length: 0x00010000"
  1247.  
  1248.  
  1249. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0016de00, length: 0x00010000"
  1250.  
  1251.  
  1252. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0016fc90, length: 0x00010000"
  1253.  
  1254.  
  1255. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0017de00, length: 0x00010000"
  1256.  
  1257.  
  1258. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0017fc90, length: 0x00010000"
  1259.  
  1260.  
  1261. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00185e00, length: 0x00010000"
  1262.  
  1263.  
  1264. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00187c90, length: 0x00010000"
  1265.  
  1266.  
  1267. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0018de00, length: 0x00010000"
  1268.  
  1269.  
  1270. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0018fc90, length: 0x00010000"
  1271.  
  1272.  
  1273. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00195e00, length: 0x00010000"
  1274.  
  1275.  
  1276. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00197c90, length: 0x00010000"
  1277.  
  1278.  
  1279. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0019de00, length: 0x00010000"
  1280.  
  1281.  
  1282. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0019fc90, length: 0x00010000"
  1283.  
  1284.  
  1285. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001a5e00, length: 0x00010000"
  1286.  
  1287.  
  1288. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001a7c90, length: 0x00010000"
  1289.  
  1290.  
  1291. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001ade00, length: 0x00010000"
  1292.  
  1293.  
  1294. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001afc90, length: 0x00010000"
  1295.  
  1296.  
  1297. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001b5e00, length: 0x00010000"
  1298.  
  1299.  
  1300. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001b7c90, length: 0x00010000"
  1301.  
  1302.  
  1303. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001bde00, length: 0x00010000"
  1304.  
  1305.  
  1306. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001bfc90, length: 0x00010000"
  1307.  
  1308.  
  1309. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001c5e00, length: 0x00010000"
  1310.  
  1311.  
  1312. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001c7c90, length: 0x00010000"
  1313.  
  1314.  
  1315. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001cfc90, length: 0x00010000"
  1316.  
  1317.  
  1318. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001d5e00, length: 0x00004000"
  1319.  
  1320.  
  1321. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001d7c90, length: 0x00010000"
  1322.  
  1323.  
  1324. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001dfc90, length: 0x00010000"
  1325.  
  1326.  
  1327. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001e7c90, length: 0x00010000"
  1328.  
  1329.  
  1330. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001efc90, length: 0x00010000"
  1331.  
  1332.  
  1333. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001f7c90, length: 0x00010000"
  1334.  
  1335.  
  1336. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x001ffc90, length: 0x00010000"
  1337.  
  1338.  
  1339. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00207c90, length: 0x00010000"
  1340.  
  1341.  
  1342. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0020fc90, length: 0x00010000"
  1343.  
  1344.  
  1345. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00217c90, length: 0x00010000"
  1346.  
  1347.  
  1348. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0021fc90, length: 0x00010000"
  1349.  
  1350.  
  1351. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00227c90, length: 0x00010000"
  1352.  
  1353.  
  1354. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0022fc90, length: 0x00010000"
  1355.  
  1356.  
  1357. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00237c90, length: 0x00010000"
  1358.  
  1359.  
  1360. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0023fc90, length: 0x00010000"
  1361.  
  1362.  
  1363. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00247c90, length: 0x00010000"
  1364.  
  1365.  
  1366. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0024fc90, length: 0x00010000"
  1367.  
  1368.  
  1369. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00257c90, length: 0x00010000"
  1370.  
  1371.  
  1372. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0025fc90, length: 0x00010000"
  1373.  
  1374.  
  1375. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00267c90, length: 0x00010000"
  1376.  
  1377.  
  1378. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0026fc90, length: 0x00010000"
  1379.  
  1380.  
  1381. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00277c90, length: 0x00010000"
  1382.  
  1383.  
  1384. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0027fc90, length: 0x00010000"
  1385.  
  1386.  
  1387. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00287c90, length: 0x00010000"
  1388.  
  1389.  
  1390. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0028fc90, length: 0x00010000"
  1391.  
  1392.  
  1393. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x00297c90, length: 0x00010000"
  1394.  
  1395.  
  1396. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x0029fc90, length: 0x00010000"
  1397.  
  1398.  
  1399. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x002a7c90, length: 0x00010000"
  1400.  
  1401.  
  1402. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x002afc90, length: 0x00010000"
  1403.  
  1404.  
  1405. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x002b7c90, length: 0x00010000"
  1406.  
  1407.  
  1408. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x002ba008, length: 0x00004000"
  1409.  
  1410.  
  1411. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x002ba008, length: 0x00004008"
  1412.  
  1413.  
  1414. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x002bfc90, length: 0x00010000"
  1415.  
  1416.  
  1417. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x002c7c90, length: 0x00008008"
  1418.  
  1419.  
  1420. "self_read": "process: ComputerZTray.exe, pid: 204, offset: 0x002cfe98, length: 0x00000008"
  1421.  
  1422.  
  1423.  
  1424.  
  1425. "Description": "Drops a binary and executes it",
  1426. "Details":
  1427.  
  1428. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\ludashisetup.exe"
  1429.  
  1430.  
  1431.  
  1432.  
  1433. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  1434. "Details":
  1435.  
  1436. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  1437.  
  1438.  
  1439. "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
  1440.  
  1441.  
  1442. "suspicious_request": "http://l.public.ludashi.com/pc/ud/dogsun"
  1443.  
  1444.  
  1445. "suspicious_request": "http://sf.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEEczu2CJ4y%2FNIk0OSd62Y9o%3D"
  1446.  
  1447.  
  1448. "suspicious_request": "http://www.ludashi.com/stat/pc.php?pid=buychannel_18&type=instnew&action=startpage_install&appver=5.1019.1060.717&modver=5.1019.1060.717&mid=db2c71648b5a939e38cf679b921b03dc&sign_name=pc&sign=b58d3571f87526269de1d72bde5244cc"
  1449.  
  1450.  
  1451. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=startpage_install"
  1452.  
  1453.  
  1454. "suspicious_request": "http://cdn-file-ssl-monidashi.ludashi.com/gamemaster/update/instpatch.cab"
  1455.  
  1456.  
  1457. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=call_hpsvc_dll_start"
  1458.  
  1459.  
  1460. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=free_hpsvc_dll_end"
  1461.  
  1462.  
  1463. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=call_hpsvc_dll_end"
  1464.  
  1465.  
  1466. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=free_hpsvc_dll_start"
  1467.  
  1468.  
  1469. "suspicious_request": "http://ocsp.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D"
  1470.  
  1471.  
  1472. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=inst_lsp_fail"
  1473.  
  1474.  
  1475. "suspicious_request": "http://th.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9%2BWQCtWAQU1A1lP3q9NMb%2BR%2BdMDcC98t4Vq3ECEB%2BRRV0JlxbvHSmZH0H4yIg%3D"
  1476.  
  1477.  
  1478. "suspicious_request": "http://ini.update.360safe.com/lds/update_patch.cab?t=201907201028"
  1479.  
  1480.  
  1481. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=sys_start_suc"
  1482.  
  1483.  
  1484. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=sys_inst_suc"
  1485.  
  1486.  
  1487. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=operate&action=install"
  1488.  
  1489.  
  1490. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=install_success"
  1491.  
  1492.  
  1493. "suspicious_request": "http://www.ludashi.com/stat/pc.php?pid=buychannel_18&type=instnew&action=install_success&appver=5.1019.1060.717&modver=5.1019.1060.717&mid=db2c71648b5a939e38cf679b921b03dc&sign_name=pc&sign=6ac9de34f73ee2c45dedacebf2a8bf15"
  1494.  
  1495.  
  1496. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=real_new_inst"
  1497.  
  1498.  
  1499. "suspicious_request": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.0.0.1001&type=helper&action=run&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee"
  1500.  
  1501.  
  1502. "suspicious_request": "http://s.ludashi.com/wan?type=install&action=start&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=1ba29166bea96c068cd8c97645aa5c50"
  1503.  
  1504.  
  1505. "suspicious_request": "http://s.ludashi.com/wan?type=setup_pid&action=ludashiembed__buychannel_18&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=f4e28e99d16e247a133370377be4409d"
  1506.  
  1507.  
  1508. "suspicious_request": "http://s.ludashi.com/wan?type=install&action=startpage_install&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=601b2fe6e14498bf4f28bbc10eb881b5"
  1509.  
  1510.  
  1511. "suspicious_request": "http://wan.ludashi.com/cms/install/getsetuppush.php?channel=ludashiembed__buychannel_18&version=1.2.6.1830"
  1512.  
  1513.  
  1514. "suspicious_request": "http://cdn-img.ludashi.com/a/201807/13/5b48531dd0754.ico"
  1515.  
  1516.  
  1517. "suspicious_request": "http://www.ludashi.com/api/service/cfg.php?from=ms&appver=5.1019.1060.717&pid=buychannel_18&modver=6.5019.1005.221&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&hash=&os=win7"
  1518.  
  1519.  
  1520. "suspicious_request": "http://s.ludashi.com/wan?type=install&action=add_game_dsk&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=f38fe438af16597a0f3ed30cb2429d22"
  1521.  
  1522.  
  1523. "suspicious_request": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.5019.1005.221&type=svc&action=ms_lah_start&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee"
  1524.  
  1525.  
  1526. "suspicious_request": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.5019.1005.221&type=svc&action=svc_init&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee"
  1527.  
  1528.  
  1529. "suspicious_request": "http://s.ludashi.com/wan?type=install&action=add_game_pin&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=0c3d79e910fb813e7525e07c638cfaf4"
  1530.  
  1531.  
  1532. "suspicious_request": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=1.5019.1005.221&type=unite&action=reject_from_svc&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&ex1=a07e4d8"
  1533.  
  1534.  
  1535. "suspicious_request": "http://s.ludashi.com/wan?type=install&action=new&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=e6965e577daafd3039758a1fc330b771"
  1536.  
  1537.  
  1538. "suspicious_request": "http://s.ludashi.com/wan?type=install&action=success&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=977622ec4befc6f58fcec391c704c289"
  1539.  
  1540.  
  1541. "suspicious_request": "http://s.ludashi.com/wan?type=startm&action=ludashiembed__buychannelall_inst_run&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=3c1cd7c407f4dccdaad2e7346fb8202c&from=ludashiembed__buychannelall_inst_run&forcetick=34734937"
  1542.  
  1543.  
  1544. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=xleh_shortcut_rate_low"
  1545.  
  1546.  
  1547. "suspicious_request": "http://wan.ludashi.com/cms/web/stat/domain_list.php?version=1.2.6.1830&channel=ludashiembed__buychannel_18"
  1548.  
  1549.  
  1550. "suspicious_request": "http://wan.ludashi.com/Getconfig?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36"
  1551.  
  1552.  
  1553. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=finish_close"
  1554.  
  1555.  
  1556. "suspicious_request": "http://wan.ludashi.com/ajax/Getdetailbygamename?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36"
  1557.  
  1558.  
  1559. "suspicious_request": "http://wan.ludashi.com/cms/app/message.php?version=1.2.6.1830&channel=ludashiembed__buychannel_18"
  1560.  
  1561.  
  1562. "suspicious_request": "http://s.ludashi.com/wan?type=show&action=ludashiembed__buychannelall_inst_run&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=012df18f03d9ef5ee28e9292b68d9ed5&from=ludashiembed__buychannelall_inst_run&forcetick=34797137"
  1563.  
  1564.  
  1565. "suspicious_request": "http://wan.ludashi.com/ajax/Getnewpush?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36&gameid=ms&from=ludashiembed__buychannelall_inst_run"
  1566.  
  1567.  
  1568. "suspicious_request": "http://wan.ludashi.com/getconfig/Jsbyversionandchannel?version=1.2.6.1830&insttime=2019-07-20%2010:28:36"
  1569.  
  1570.  
  1571. "suspicious_request": "http://wan.ludashi.com/getconfig/urlblack?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36"
  1572.  
  1573.  
  1574. "suspicious_request": "http://wan.ludashi.com/pageV2/index?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36"
  1575.  
  1576.  
  1577. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=trayrun"
  1578.  
  1579.  
  1580. "suspicious_request": "http://wan.ludashi.com/account/jump?channel=ludashiembed__buychannel_18&from=ldsxbtx_ms&game=ms&server=1318&version=1.2.6.1830"
  1581.  
  1582.  
  1583. "suspicious_request": "http://p10.qhimg.com/t0111d422c70cdbbc8c.png"
  1584.  
  1585.  
  1586. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.5019.1005.326&type=computerzservice&action=run"
  1587.  
  1588.  
  1589. "suspicious_request": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAilokbNS1yMg9cCtLurU0k%3D"
  1590.  
  1591.  
  1592. "suspicious_request": "http://status.rapidssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRhhZrQET0hvbSHUJmNfBKqR%2FiT7wQUU8oXWfxrwAMhLxqu5KqoHIJW2nUCEAdsKEeZF4BydNE94gKO3oA%3D"
  1593.  
  1594.  
  1595. "suspicious_request": "http://cdp.rapidssl.com/RapidSSLRSACA2018.crl"
  1596.  
  1597.  
  1598. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=suspendrun"
  1599.  
  1600.  
  1601. "suspicious_request": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1030&type=pop&action=start&app=ludashi"
  1602.  
  1603.  
  1604. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1005.509&type=suspend&action=show"
  1605.  
  1606.  
  1607. "suspicious_request": "http://cdn-file.ludashi.com/cms/project_16/cfg_center/mod_list.js?t=2019072010:25"
  1608.  
  1609.  
  1610. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=boot&action=tray_actived"
  1611.  
  1612.  
  1613. "suspicious_request": "http://sf.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CECYnnw8vEZcNzPY%2Buojy1MQ%3D"
  1614.  
  1615.  
  1616. "suspicious_request": "http://wan.ludashi.com/account?game=ms&channel=ludashiembed__buychannel_18&from=ldsxbtx_ms"
  1617.  
  1618.  
  1619. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=from_user"
  1620.  
  1621.  
  1622. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=hpl&action=qh_app0_lds_hp0"
  1623.  
  1624.  
  1625. "suspicious_request": "http://www.ludashi.com/cms/pc_mobile/news.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702"
  1626.  
  1627.  
  1628. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=trayrun&action=trayinfo_1_1_0"
  1629.  
  1630.  
  1631. "suspicious_request": "http://www.ludashi.com/cms/pcDaoliang/mergeAll.php?from=ludashi&pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=1.0.1.1035&modver=1.0.1.1035&mod=pc_pop_outside"
  1632.  
  1633.  
  1634. "suspicious_request": "http://cdn-file.ludashi.com/pc/device/deviceid.ini"
  1635.  
  1636.  
  1637. "suspicious_request": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1005.505&type=wd&action=reg_succ&app=ludashi"
  1638.  
  1639.  
  1640. "suspicious_request": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=screen_resolution_change&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1"
  1641.  
  1642.  
  1643. "suspicious_request": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1005.505&type=wd&action=start&app=ludashi"
  1644.  
  1645.  
  1646. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=band&action=bandinfo_0_1_0_1"
  1647.  
  1648.  
  1649. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=band&action=succ_vista_x64"
  1650.  
  1651.  
  1652. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=tray&action=bandrun_succ"
  1653.  
  1654.  
  1655. "suspicious_request": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_init&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1"
  1656.  
  1657.  
  1658. "suspicious_request": "http://cdn-wan.ludashi.com/assets/supercss/login.css?v=20181120"
  1659.  
  1660.  
  1661. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/recommend.dat?t=10"
  1662.  
  1663.  
  1664. "suspicious_request": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_start&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1"
  1665.  
  1666.  
  1667. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=active"
  1668.  
  1669.  
  1670. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=tray_1"
  1671.  
  1672.  
  1673. "suspicious_request": "http://www.ludashi.com/cms/pc/tray_switch.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702"
  1674.  
  1675.  
  1676. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=trayinfo_1_1_0"
  1677.  
  1678.  
  1679. "suspicious_request": "http://media.ludashi.com/n/mini?pid=buychannel_18&appver=5.1019.1060.717&modver=1.5019.1015.617&from=ludashi&iever=ie8&os=win7&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&manual=0&showpro=&awake=0&screentype=0&screesize=1920_962&instdate=2019-07-20%2010:28:36&atdate=&m_ver=3.0.0.1085"
  1680.  
  1681.  
  1682. "suspicious_request": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_regpopmgr_succ&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1"
  1683.  
  1684.  
  1685. "suspicious_request": "http://cdn-file.ludashi.com/pc/common/cdn_common.json?t=201907201028"
  1686.  
  1687.  
  1688. "suspicious_request": "http://s.ludashi.com/bizhi?pid=ludashi&mid=db2c71648b5a939e38cf679b921b03dc&appver=&modver=1.0.0.85&type=ludashi&action=navguide_show"
  1689.  
  1690.  
  1691. "suspicious_request": "http://l.public.ludashi.com/pc/updata/diskdump?ver=1002"
  1692.  
  1693.  
  1694. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/navextend.dat"
  1695.  
  1696.  
  1697. "suspicious_request": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D"
  1698.  
  1699.  
  1700. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/ico/hao.360.cn.ico"
  1701.  
  1702.  
  1703. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/navspread.dat"
  1704.  
  1705.  
  1706. "suspicious_request": "http://cdn-img.ludashi.com/a/201812/06/5c08c9afc9173.ico"
  1707.  
  1708.  
  1709. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/ico/www.baidu.com.ico"
  1710.  
  1711.  
  1712. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/ico/wan.ludashi.com.ico"
  1713.  
  1714.  
  1715. "suspicious_request": "http://cdn-file-ssl-pc.ludashi.com/bizhi/ico/xiaoshuo.png"
  1716.  
  1717.  
  1718. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/ico/www.tmall.com.ico"
  1719.  
  1720.  
  1721. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/ico/www.taobao.com.ico"
  1722.  
  1723.  
  1724. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/ico/www.jd.com.ico"
  1725.  
  1726.  
  1727. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/ico/weibo.com.ico"
  1728.  
  1729.  
  1730. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/ico/www.sina.com.cn.ico"
  1731.  
  1732.  
  1733. "suspicious_request": "http://weibo.com/"
  1734.  
  1735.  
  1736. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/ico/www.qunar.com.ico"
  1737.  
  1738.  
  1739. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/ico/www.iqiyi.com.ico"
  1740.  
  1741.  
  1742. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/ico/www.qq.com.ico"
  1743.  
  1744.  
  1745. "suspicious_request": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D"
  1746.  
  1747.  
  1748. "suspicious_request": "http://cdn-file.ludashi.com/bizhi/ico/58.com.ico"
  1749.  
  1750.  
  1751. "suspicious_request": "http://weibo.com/us"
  1752.  
  1753.  
  1754. "suspicious_request": "http://www.baidu.com/favicon.ico"
  1755.  
  1756.  
  1757. "suspicious_request": "http://weibo.com/favicon.ico"
  1758.  
  1759.  
  1760. "suspicious_request": "http://www.ludashi.com/api/ppwin/params.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702&si=0"
  1761.  
  1762.  
  1763. "suspicious_request": "http://cdn-file.ludashi.com/pc/hao/external.dat?t=10"
  1764.  
  1765.  
  1766. "suspicious_request": "http://l3.public.ludashi.com/pc/updata/hwinfov2"
  1767.  
  1768.  
  1769. "suspicious_request": "http://cdn-file.ludashi.com/pc/hao/invalidhp.dat"
  1770.  
  1771.  
  1772. "suspicious_request": "http://update.ludashi.com/update/pc/?mid=db2c71648b5a939e38cf679b921b03dc&version=5.1019.1060.717&pid=buychannel_18&m2=b9eced82243023931d3c446e4d355e5cd84c59932bee&t=35463646"
  1773.  
  1774.  
  1775. "suspicious_request": "http://ssl-hw-pc.ludashi.com/c/201904/01/noUpdate.cab"
  1776.  
  1777.  
  1778. "suspicious_request": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_first_pop&ex4=a07e4d85e0340169b0718f4436b93b54&ex1=653&ex5=1"
  1779.  
  1780.  
  1781. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=tray&action=inst_lsp_fail"
  1782.  
  1783.  
  1784. "suspicious_request": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D"
  1785.  
  1786.  
  1787.  
  1788.  
  1789. "Description": "Performs some HTTP requests",
  1790. "Details":
  1791.  
  1792. "url": "http://s1.ludashi.com/url2?pid=buychannel_18&type=instonline&action=run&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc"
  1793.  
  1794.  
  1795. "url": "http://s1.ludashi.com/url2?pid=buychannel_18&type=instonline&action=down_start&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc"
  1796.  
  1797.  
  1798. "url": "http://dl.360safe.com/ludashi/ludashi_buy.exe"
  1799.  
  1800.  
  1801. "url": "http://s.ludashi.com/url2?pid=buychannel_18&type=instonline&action=run&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc"
  1802.  
  1803.  
  1804. "url": "http://s.ludashi.com/url2?pid=buychannel_18&type=instonline&action=down_start&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc"
  1805.  
  1806.  
  1807. "url": "http://s1.ludashi.com/url2?pid=buychannel_18&type=instonline&action=down_success&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc"
  1808.  
  1809.  
  1810. "url": "http://s.ludashi.com/url2?pid=buychannel_18&type=instonline&action=down_success&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc"
  1811.  
  1812.  
  1813. "url": "http://s1.ludashi.com/url2?pid=buychannel_18&type=instonline&action=down_exec&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc"
  1814.  
  1815.  
  1816. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=run"
  1817.  
  1818.  
  1819. "url": "http://s.ludashi.com/url2?pid=buy&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=res_pid"
  1820.  
  1821.  
  1822. "url": "http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X%2B%2BhEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECECUM6OAwYS6fK4n3BU18%2BP0%3D"
  1823.  
  1824.  
  1825. "url": "http://s.ludashi.com/url2?pid=buychannel_18&type=instonline&action=down_exec&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc"
  1826.  
  1827.  
  1828. "url": "http://www.ludashi.com/stat/pc.php?pid=buychannel_18&type=instnew&action=run&appver=5.1019.1060.717&modver=5.1019.1060.717&mid=db2c71648b5a939e38cf679b921b03dc&sign_name=pc&sign=a9457a79aebd07c1df73674c1f26535c"
  1829.  
  1830.  
  1831. "url": "http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D"
  1832.  
  1833.  
  1834. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=setup_pid"
  1835.  
  1836.  
  1837. "url": "http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEFG9XY5FuCoCEPF%2F5MUjNGg%3D"
  1838.  
  1839.  
  1840. "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
  1841.  
  1842.  
  1843. "url": "http://www.ludashi.com/cms/pc_mobile/quickxiaolu.php?channel=buychannel_18&s=0&q=0&k=0&h=0"
  1844.  
  1845.  
  1846. "url": "http://l.public.ludashi.com/pc/ud/dogsun"
  1847.  
  1848.  
  1849. "url": "http://sf.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEEczu2CJ4y%2FNIk0OSd62Y9o%3D"
  1850.  
  1851.  
  1852. "url": "http://www.ludashi.com/stat/pc.php?pid=buychannel_18&type=instnew&action=startpage_install&appver=5.1019.1060.717&modver=5.1019.1060.717&mid=db2c71648b5a939e38cf679b921b03dc&sign_name=pc&sign=b58d3571f87526269de1d72bde5244cc"
  1853.  
  1854.  
  1855. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=startpage_install"
  1856.  
  1857.  
  1858. "url": "http://cdn-file-ssl-monidashi.ludashi.com/gamemaster/update/instpatch.cab"
  1859.  
  1860.  
  1861. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=call_hpsvc_dll_start"
  1862.  
  1863.  
  1864. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=free_hpsvc_dll_end"
  1865.  
  1866.  
  1867. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=call_hpsvc_dll_end"
  1868.  
  1869.  
  1870. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=free_hpsvc_dll_start"
  1871.  
  1872.  
  1873. "url": "http://ocsp.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D"
  1874.  
  1875.  
  1876. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=inst_lsp_fail"
  1877.  
  1878.  
  1879. "url": "http://th.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9%2BWQCtWAQU1A1lP3q9NMb%2BR%2BdMDcC98t4Vq3ECEB%2BRRV0JlxbvHSmZH0H4yIg%3D"
  1880.  
  1881.  
  1882. "url": "http://ini.update.360safe.com/lds/update_patch.cab?t=201907201028"
  1883.  
  1884.  
  1885. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=sys_start_suc"
  1886.  
  1887.  
  1888. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=sys_inst_suc"
  1889.  
  1890.  
  1891. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=operate&action=install"
  1892.  
  1893.  
  1894. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=install_success"
  1895.  
  1896.  
  1897. "url": "http://www.ludashi.com/stat/pc.php?pid=buychannel_18&type=instnew&action=install_success&appver=5.1019.1060.717&modver=5.1019.1060.717&mid=db2c71648b5a939e38cf679b921b03dc&sign_name=pc&sign=6ac9de34f73ee2c45dedacebf2a8bf15"
  1898.  
  1899.  
  1900. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=real_new_inst"
  1901.  
  1902.  
  1903. "url": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.0.0.1001&type=helper&action=run&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee"
  1904.  
  1905.  
  1906. "url": "http://s.ludashi.com/wan?type=install&action=start&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=1ba29166bea96c068cd8c97645aa5c50"
  1907.  
  1908.  
  1909. "url": "http://s.ludashi.com/wan?type=setup_pid&action=ludashiembed__buychannel_18&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=f4e28e99d16e247a133370377be4409d"
  1910.  
  1911.  
  1912. "url": "http://s.ludashi.com/wan?type=install&action=startpage_install&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=601b2fe6e14498bf4f28bbc10eb881b5"
  1913.  
  1914.  
  1915. "url": "http://wan.ludashi.com/cms/install/getsetuppush.php?channel=ludashiembed__buychannel_18&version=1.2.6.1830"
  1916.  
  1917.  
  1918. "url": "http://cdn-img.ludashi.com/a/201807/13/5b48531dd0754.ico"
  1919.  
  1920.  
  1921. "url": "http://www.ludashi.com/api/service/cfg.php?from=ms&appver=5.1019.1060.717&pid=buychannel_18&modver=6.5019.1005.221&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&hash=&os=win7"
  1922.  
  1923.  
  1924. "url": "http://s.ludashi.com/wan?type=install&action=add_game_dsk&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=f38fe438af16597a0f3ed30cb2429d22"
  1925.  
  1926.  
  1927. "url": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.5019.1005.221&type=svc&action=ms_lah_start&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee"
  1928.  
  1929.  
  1930. "url": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.5019.1005.221&type=svc&action=svc_init&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee"
  1931.  
  1932.  
  1933. "url": "http://s.ludashi.com/wan?type=install&action=add_game_pin&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=0c3d79e910fb813e7525e07c638cfaf4"
  1934.  
  1935.  
  1936. "url": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=1.5019.1005.221&type=unite&action=reject_from_svc&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&ex1=a07e4d8"
  1937.  
  1938.  
  1939. "url": "http://s.ludashi.com/wan?type=install&action=new&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=e6965e577daafd3039758a1fc330b771"
  1940.  
  1941.  
  1942. "url": "http://s.ludashi.com/wan?type=install&action=success&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=977622ec4befc6f58fcec391c704c289"
  1943.  
  1944.  
  1945. "url": "http://s.ludashi.com/wan?type=startm&action=ludashiembed__buychannelall_inst_run&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=3c1cd7c407f4dccdaad2e7346fb8202c&from=ludashiembed__buychannelall_inst_run&forcetick=34734937"
  1946.  
  1947.  
  1948. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=xleh_shortcut_rate_low"
  1949.  
  1950.  
  1951. "url": "http://wan.ludashi.com/cms/web/stat/domain_list.php?version=1.2.6.1830&channel=ludashiembed__buychannel_18"
  1952.  
  1953.  
  1954. "url": "http://wan.ludashi.com/Getconfig?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36"
  1955.  
  1956.  
  1957. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=finish_close"
  1958.  
  1959.  
  1960. "url": "http://wan.ludashi.com/ajax/Getdetailbygamename?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36"
  1961.  
  1962.  
  1963. "url": "http://wan.ludashi.com/cms/app/message.php?version=1.2.6.1830&channel=ludashiembed__buychannel_18"
  1964.  
  1965.  
  1966. "url": "http://s.ludashi.com/wan?type=show&action=ludashiembed__buychannelall_inst_run&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=012df18f03d9ef5ee28e9292b68d9ed5&from=ludashiembed__buychannelall_inst_run&forcetick=34797137"
  1967.  
  1968.  
  1969. "url": "http://wan.ludashi.com/ajax/Getnewpush?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36&gameid=ms&from=ludashiembed__buychannelall_inst_run"
  1970.  
  1971.  
  1972. "url": "http://wan.ludashi.com/getconfig/Jsbyversionandchannel?version=1.2.6.1830&insttime=2019-07-20%2010:28:36"
  1973.  
  1974.  
  1975. "url": "http://wan.ludashi.com/getconfig/urlblack?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36"
  1976.  
  1977.  
  1978. "url": "http://wan.ludashi.com/pageV2/index?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36"
  1979.  
  1980.  
  1981. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=trayrun"
  1982.  
  1983.  
  1984. "url": "http://wan.ludashi.com/account/jump?channel=ludashiembed__buychannel_18&from=ldsxbtx_ms&game=ms&server=1318&version=1.2.6.1830"
  1985.  
  1986.  
  1987. "url": "http://p10.qhimg.com/t0111d422c70cdbbc8c.png"
  1988.  
  1989.  
  1990. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.5019.1005.326&type=computerzservice&action=run"
  1991.  
  1992.  
  1993. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAilokbNS1yMg9cCtLurU0k%3D"
  1994.  
  1995.  
  1996. "url": "http://status.rapidssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRhhZrQET0hvbSHUJmNfBKqR%2FiT7wQUU8oXWfxrwAMhLxqu5KqoHIJW2nUCEAdsKEeZF4BydNE94gKO3oA%3D"
  1997.  
  1998.  
  1999. "url": "http://cdp.rapidssl.com/RapidSSLRSACA2018.crl"
  2000.  
  2001.  
  2002. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=suspendrun"
  2003.  
  2004.  
  2005. "url": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1030&type=pop&action=start&app=ludashi"
  2006.  
  2007.  
  2008. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1005.509&type=suspend&action=show"
  2009.  
  2010.  
  2011. "url": "http://cdn-file.ludashi.com/cms/project_16/cfg_center/mod_list.js?t=2019072010:25"
  2012.  
  2013.  
  2014. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=boot&action=tray_actived"
  2015.  
  2016.  
  2017. "url": "http://sf.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CECYnnw8vEZcNzPY%2Buojy1MQ%3D"
  2018.  
  2019.  
  2020. "url": "http://wan.ludashi.com/account?game=ms&channel=ludashiembed__buychannel_18&from=ldsxbtx_ms"
  2021.  
  2022.  
  2023. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=from_user"
  2024.  
  2025.  
  2026. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=hpl&action=qh_app0_lds_hp0"
  2027.  
  2028.  
  2029. "url": "http://www.ludashi.com/cms/pc_mobile/news.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702"
  2030.  
  2031.  
  2032. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=trayrun&action=trayinfo_1_1_0"
  2033.  
  2034.  
  2035. "url": "http://www.ludashi.com/cms/pcDaoliang/mergeAll.php?from=ludashi&pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=1.0.1.1035&modver=1.0.1.1035&mod=pc_pop_outside"
  2036.  
  2037.  
  2038. "url": "http://cdn-file.ludashi.com/pc/device/deviceid.ini"
  2039.  
  2040.  
  2041. "url": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1005.505&type=wd&action=reg_succ&app=ludashi"
  2042.  
  2043.  
  2044. "url": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=screen_resolution_change&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1"
  2045.  
  2046.  
  2047. "url": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1005.505&type=wd&action=start&app=ludashi"
  2048.  
  2049.  
  2050. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=band&action=bandinfo_0_1_0_1"
  2051.  
  2052.  
  2053. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=band&action=succ_vista_x64"
  2054.  
  2055.  
  2056. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=tray&action=bandrun_succ"
  2057.  
  2058.  
  2059. "url": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_init&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1"
  2060.  
  2061.  
  2062. "url": "http://cdn-wan.ludashi.com/assets/supercss/login.css?v=20181120"
  2063.  
  2064.  
  2065. "url": "http://cdn-file.ludashi.com/bizhi/recommend.dat?t=10"
  2066.  
  2067.  
  2068. "url": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_start&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1"
  2069.  
  2070.  
  2071. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=active"
  2072.  
  2073.  
  2074. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=tray_1"
  2075.  
  2076.  
  2077. "url": "http://www.ludashi.com/cms/pc/tray_switch.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702"
  2078.  
  2079.  
  2080. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=trayinfo_1_1_0"
  2081.  
  2082.  
  2083. "url": "http://media.ludashi.com/n/mini?pid=buychannel_18&appver=5.1019.1060.717&modver=1.5019.1015.617&from=ludashi&iever=ie8&os=win7&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&manual=0&showpro=&awake=0&screentype=0&screesize=1920_962&instdate=2019-07-20%2010:28:36&atdate=&m_ver=3.0.0.1085"
  2084.  
  2085.  
  2086. "url": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_regpopmgr_succ&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1"
  2087.  
  2088.  
  2089. "url": "http://cdn-file.ludashi.com/pc/common/cdn_common.json?t=201907201028"
  2090.  
  2091.  
  2092. "url": "http://s.ludashi.com/bizhi?pid=ludashi&mid=db2c71648b5a939e38cf679b921b03dc&appver=&modver=1.0.0.85&type=ludashi&action=navguide_show"
  2093.  
  2094.  
  2095. "url": "http://l.public.ludashi.com/pc/updata/diskdump?ver=1002"
  2096.  
  2097.  
  2098. "url": "http://cdn-file.ludashi.com/bizhi/navextend.dat"
  2099.  
  2100.  
  2101. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D"
  2102.  
  2103.  
  2104. "url": "http://cdn-file.ludashi.com/bizhi/ico/hao.360.cn.ico"
  2105.  
  2106.  
  2107. "url": "http://cdn-file.ludashi.com/bizhi/navspread.dat"
  2108.  
  2109.  
  2110. "url": "http://cdn-img.ludashi.com/a/201812/06/5c08c9afc9173.ico"
  2111.  
  2112.  
  2113. "url": "http://cdn-file.ludashi.com/bizhi/ico/www.baidu.com.ico"
  2114.  
  2115.  
  2116. "url": "http://cdn-file.ludashi.com/bizhi/ico/wan.ludashi.com.ico"
  2117.  
  2118.  
  2119. "url": "http://cdn-file-ssl-pc.ludashi.com/bizhi/ico/xiaoshuo.png"
  2120.  
  2121.  
  2122. "url": "http://cdn-file.ludashi.com/bizhi/ico/www.tmall.com.ico"
  2123.  
  2124.  
  2125. "url": "http://cdn-file.ludashi.com/bizhi/ico/www.taobao.com.ico"
  2126.  
  2127.  
  2128. "url": "http://cdn-file.ludashi.com/bizhi/ico/www.jd.com.ico"
  2129.  
  2130.  
  2131. "url": "http://cdn-file.ludashi.com/bizhi/ico/weibo.com.ico"
  2132.  
  2133.  
  2134. "url": "http://cdn-file.ludashi.com/bizhi/ico/www.sina.com.cn.ico"
  2135.  
  2136.  
  2137. "url": "http://weibo.com/"
  2138.  
  2139.  
  2140. "url": "http://cdn-file.ludashi.com/bizhi/ico/www.qunar.com.ico"
  2141.  
  2142.  
  2143. "url": "http://cdn-file.ludashi.com/bizhi/ico/www.iqiyi.com.ico"
  2144.  
  2145.  
  2146. "url": "http://cdn-file.ludashi.com/bizhi/ico/www.qq.com.ico"
  2147.  
  2148.  
  2149. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D"
  2150.  
  2151.  
  2152. "url": "http://cdn-file.ludashi.com/bizhi/ico/58.com.ico"
  2153.  
  2154.  
  2155. "url": "http://weibo.com/us"
  2156.  
  2157.  
  2158. "url": "http://www.baidu.com/favicon.ico"
  2159.  
  2160.  
  2161. "url": "http://weibo.com/favicon.ico"
  2162.  
  2163.  
  2164. "url": "http://www.ludashi.com/api/ppwin/params.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702&si=0"
  2165.  
  2166.  
  2167. "url": "http://cdn-file.ludashi.com/pc/hao/external.dat?t=10"
  2168.  
  2169.  
  2170. "url": "http://l3.public.ludashi.com/pc/updata/hwinfov2"
  2171.  
  2172.  
  2173. "url": "http://cdn-file.ludashi.com/pc/hao/invalidhp.dat"
  2174.  
  2175.  
  2176. "url": "http://update.ludashi.com/update/pc/?mid=db2c71648b5a939e38cf679b921b03dc&version=5.1019.1060.717&pid=buychannel_18&m2=b9eced82243023931d3c446e4d355e5cd84c59932bee&t=35463646"
  2177.  
  2178.  
  2179. "url": "http://ssl-hw-pc.ludashi.com/c/201904/01/noUpdate.cab"
  2180.  
  2181.  
  2182. "url": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_first_pop&ex4=a07e4d85e0340169b0718f4436b93b54&ex1=653&ex5=1"
  2183.  
  2184.  
  2185. "url": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=tray&action=inst_lsp_fail"
  2186.  
  2187.  
  2188. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D"
  2189.  
  2190.  
  2191.  
  2192.  
  2193. "Description": "The binary likely contains encrypted or compressed data.",
  2194. "Details":
  2195.  
  2196. "section": "name: .rsrc, entropy: 7.82, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x0009e000, virtual_size: 0x0009de84"
  2197.  
  2198.  
  2199.  
  2200.  
  2201. "Description": "Queries information on disks, possibly for anti-virtualization",
  2202. "Details":
  2203.  
  2204.  
  2205. "Description": "Tries to suspend Cuckoo threads to prevent logging of malicious activity",
  2206. "Details":
  2207.  
  2208. "Process": "LDSGameCenter.exe (1248)"
  2209.  
  2210.  
  2211.  
  2212.  
  2213. "Description": "Forces a created process to be the child of an unrelated process",
  2214. "Details":
  2215.  
  2216.  
  2217. "Description": "Tries to unhook or modify Windows functions monitored by Cuckoo",
  2218. "Details":
  2219.  
  2220. "unhook": "function_name: CLSIDFromProgID, type: modification"
  2221.  
  2222.  
  2223. "unhook": "function_name: CoGetClassObject, type: modification"
  2224.  
  2225.  
  2226. "unhook": "function_name: CreateProcessInternalW, type: modification"
  2227.  
  2228.  
  2229.  
  2230.  
  2231. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  2232. "Details":
  2233.  
  2234. "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 4575936 times"
  2235.  
  2236.  
  2237.  
  2238.  
  2239. "Description": "Steals private information from local Internet browsers",
  2240. "Details":
  2241.  
  2242. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\History"
  2243.  
  2244.  
  2245. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Preferences"
  2246.  
  2247.  
  2248. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Secure Preferences"
  2249.  
  2250.  
  2251. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  2252.  
  2253.  
  2254.  
  2255.  
  2256. "Description": "Network activity contains more than one unique useragent.",
  2257. "Details":
  2258.  
  2259. "Process": "inst_buychannel_18.exe"
  2260.  
  2261.  
  2262. "User-Agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)"
  2263.  
  2264.  
  2265. "Process": "ludashisetup.exe"
  2266.  
  2267.  
  2268. "User-Agent": ""
  2269.  
  2270.  
  2271.  
  2272.  
  2273. "Description": "Installs itself for autorun at Windows startup",
  2274. "Details":
  2275.  
  2276. "service name": "HardwareProtect"
  2277.  
  2278.  
  2279. "service path": "C:\\Program Files (x86)\\LuDaShi\\HardwareProtect_x64.sys"
  2280.  
  2281.  
  2282. "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSvc\\ImagePath"
  2283.  
  2284.  
  2285. "data": "%SystemRoot%\\System32\\svchost.exe -k netsvcs"
  2286.  
  2287.  
  2288. "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ComputerZ_x64\\ImagePath"
  2289.  
  2290.  
  2291. "data": "\\??\\C:\\Program Files (x86)\\LuDaShi\\ComputerZ_x64.sys"
  2292.  
  2293.  
  2294. "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HardwareProtect\\ImagePath"
  2295.  
  2296.  
  2297. "data": "\\??\\C:\\Program Files (x86)\\LuDaShi\\HardwareProtect_x64.sys"
  2298.  
  2299.  
  2300. "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSvc\\Parameters\\ServiceDll"
  2301.  
  2302.  
  2303. "data": "C:\\Program Files (x86)\\LuDaShi\\lpi\\HpSvc.dll"
  2304.  
  2305.  
  2306. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\34B3C588-D06C-4F92-929C-2C3A0BC7F821\\InprocServer32\\(Default)"
  2307.  
  2308.  
  2309. "data": "C:\\Program Files (x86)\\LuDaShi\\ComputerZ7_x64.dll"
  2310.  
  2311.  
  2312.  
  2313.  
  2314. "Description": "Exhibits possible ransomware file modification behavior",
  2315. "Details":
  2316.  
  2317. "file_modifications": "Performs 245 file moves indicative of a potential file encryption process"
  2318.  
  2319.  
  2320.  
  2321.  
  2322. "Description": "Collects information about installed applications",
  2323. "Details":
  2324.  
  2325. "Program": "Microsoft Office Shared 64-bit MUI 2013"
  2326.  
  2327.  
  2328. "Program": "Google Update Helper"
  2329.  
  2330.  
  2331.  
  2332.  
  2333.  
  2334.  
  2335. "Program": "Microsoft Excel MUI 2013"
  2336.  
  2337.  
  2338. "Program": "Microsoft Outlook MUI 2013"
  2339.  
  2340.  
  2341.  
  2342.  
  2343. "Program": "Google Chrome"
  2344.  
  2345.  
  2346.  
  2347.  
  2348. "Program": "Notepad++"
  2349.  
  2350.  
  2351. "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xc3\\xb1ol"
  2352.  
  2353.  
  2354. "Program": "Adobe Flash Player 29 ActiveX"
  2355.  
  2356.  
  2357.  
  2358.  
  2359. "Program": "Microsoft Access MUI 2013"
  2360.  
  2361.  
  2362. "Program": "Microsoft Office 64-bit Components 2013"
  2363.  
  2364.  
  2365. "Program": "Microsoft Office Proofing Tools 2013 - English"
  2366.  
  2367.  
  2368. "Program": "Adobe Flash Player 29 NPAPI"
  2369.  
  2370.  
  2371. "Program": "Adobe Acrobat Reader DC"
  2372.  
  2373.  
  2374. "Program": "Adobe Refresh Manager"
  2375.  
  2376.  
  2377. "Program": "Microsoft Publisher MUI 2013"
  2378.  
  2379.  
  2380. "Program": "Microsoft DCF MUI 2013"
  2381.  
  2382.  
  2383.  
  2384.  
  2385. "Program": "Microsoft Office Shared MUI 2013"
  2386.  
  2387.  
  2388. "Program": "Microsoft Office OSM MUI 2013"
  2389.  
  2390.  
  2391. "Program": "Microsoft InfoPath MUI 2013"
  2392.  
  2393.  
  2394. "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
  2395.  
  2396.  
  2397. "Program": "Outils de v\\xc3\\xa9rification linguistique 2013 de Microsoft Office\\xc2\\xa0- Fran\\xc3\\xa7ais"
  2398.  
  2399.  
  2400. "Program": "Microsoft Word MUI 2013"
  2401.  
  2402.  
  2403.  
  2404.  
  2405.  
  2406.  
  2407.  
  2408.  
  2409. "Program": "\\xe9\\xb2\\x81\\xe5\\xa4\\xa7\\xe5\\xb8\\x88"
  2410.  
  2411.  
  2412. "Program": "Microsoft Groove MUI 2013"
  2413.  
  2414.  
  2415. "Program": "Oracle VM VirtualBox Guest Additions 6.0.2"
  2416.  
  2417.  
  2418.  
  2419.  
  2420.  
  2421.  
  2422. "Program": "Microsoft Office Shared 64-bit Setup Metadata MUI 2013"
  2423.  
  2424.  
  2425. "Program": "Microsoft Access Setup Metadata MUI 2013"
  2426.  
  2427.  
  2428. "Program": "Microsoft Office OSM UX MUI 2013"
  2429.  
  2430.  
  2431. "Program": "Java Auto Updater"
  2432.  
  2433.  
  2434. "Program": "Microsoft PowerPoint MUI 2013"
  2435.  
  2436.  
  2437. "Program": "Microsoft Office Professional Plus 2013"
  2438.  
  2439.  
  2440. "Program": "Microsoft OneDrive"
  2441.  
  2442.  
  2443. "Program": "Java 8 Update 201"
  2444.  
  2445.  
  2446. "Program": "Microsoft Office Proofing 2013"
  2447.  
  2448.  
  2449. "Program": "Microsoft Lync MUI 2013"
  2450.  
  2451.  
  2452.  
  2453.  
  2454.  
  2455.  
  2456. "Program": "Microsoft OneNote MUI 2013"
  2457.  
  2458.  
  2459.  
  2460.  
  2461. "Description": "Detects VirtualBox through the presence of a file",
  2462. "Details":
  2463.  
  2464. "file": "C:\\Windows\\sysnative\\VBoxDisp.dll"
  2465.  
  2466.  
  2467. "file": "C:\\Windows\\sysnative\\drivers\\VBoxVideo.sys"
  2468.  
  2469.  
  2470.  
  2471.  
  2472. "Description": "Detects VirtualBox through the presence of a registry key",
  2473. "Details":
  2474.  
  2475.  
  2476. "Description": "Attempts to modify proxy settings",
  2477. "Details":
  2478.  
  2479.  
  2480. "Description": "Attempts to modify browser security settings",
  2481. "Details":
  2482.  
  2483.  
  2484. "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
  2485. "Details":
  2486.  
  2487. "dropped": "clamav:Win.Trojan.Downloader-65962, sha256:d00d9447f658a3d227121a76e0feb0ab23852b6d295459e3df9b505c9b1e0b21 , guest_paths:C:\\Program Files (x86)\\LuDaShi\\aapt.exe, type:PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows"
  2488.  
  2489.  
  2490.  
  2491.  
  2492. "Description": "Attempts to create or modify system certificates",
  2493. "Details":
  2494.  
  2495.  
  2496. "Description": "Created a service that was not started",
  2497. "Details":
  2498.  
  2499. "service": "WS2IFSL"
  2500.  
  2501.  
  2502.  
  2503.  
  2504.  
  2505. * Started Service:
  2506. "HpSvc",
  2507. "HardwareProtect",
  2508. "ws2ifsl",
  2509. "ComputerZ_x64"
  2510.  
  2511.  
  2512. * Mutexes:
  2513. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 996",
  2514. "Q360ComputerzInstMutextName",
  2515. "Q360ComputerZSetupMutext",
  2516. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 1696",
  2517. "ComputerZLspMutex",
  2518. "LDSGameCenterSetupMutext",
  2519. "7695ED83-8472-43b1-BB55-F1B9A954CE0D",
  2520. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 3048",
  2521. "CheckHpRunFlag",
  2522. "IESQMMUTEX_0_208",
  2523. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 2216",
  2524. "LDSHELPER_BCB0A953-7579-48b3-84DC-79A9438F3D79",
  2525. "Instance_B2C1AD70-3ADA-4a52-8960-F639D18485CB",
  2526. "Q360ComputerZTrayMutex",
  2527. "Q360ComputerZTrayMutex_InstBridge",
  2528. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 2436",
  2529. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 2296",
  2530. "Instance_C56AF683-9BE1-46c9-8470-EABC58EC9E44",
  2531. "LdsComputerZ14Mutex",
  2532. "CicLoadWinStaWinSta0",
  2533. "Local\\MSCTF.CtfMonitorInstMutexDefault1",
  2534. "Local\\_!MSFTHISTORY!_",
  2535. "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
  2536. "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
  2537. "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
  2538. "Local\\WininetStartupMutex",
  2539. "Local\\WininetConnectionMutex",
  2540. "Local\\WininetProxyRegistryMutex",
  2541. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 1248",
  2542. "Global\\LDSGAMECENTER_AB23A043-615D-4e3c-A185-C3BA7BCD4A15",
  2543. "Local\\!IETld!Mutex",
  2544. "MSIMGSIZECacheMutex",
  2545. "_!SHMSFTHISTORY!_",
  2546. "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!mshist012019072020190721!",
  2547. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 204",
  2548. "ConfigCenterSinlgeInstance_1F6A1256-2BEA-4b8c-84C0-2854AF25958D",
  2549. "Q360ComputerZMonitorMutex",
  2550. "Global\\6382752C-943D-42a3-ABF8-B2A739B0E578",
  2551. "PopMgrSinlgeInstance_E711BCBD-2D7C-4b66-AD6A-11F0DF413257",
  2552. "LOCALLOG",
  2553. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 972",
  2554. "Global\\7F4B17DD-4CB8-4737-B64E-FAE0A0B7E6F3",
  2555. "Global\\9F682656-2107-4196-B6C1-5412D789E589",
  2556. "DBWinMutex",
  2557. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 2312",
  2558. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 676",
  2559. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 1788",
  2560. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 3740",
  2561. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 3764",
  2562. "MobileDeviceSrvMutexRunner",
  2563. "Global\\MobileDeviceSrv04222EB7-0C2D-4049-A37F-069DA12CB403_Mutext",
  2564. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 3880",
  2565. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 4008",
  2566. "Instance_6E884C97-464D-489d-9311-846F7B7E256D",
  2567. "NavPluginMutex",
  2568. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 3316",
  2569. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 1960",
  2570. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 3452",
  2571. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 3704",
  2572. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 4040",
  2573. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 324",
  2574. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 1760"
  2575.  
  2576.  
  2577. * Modified Files:
  2578. "\\??\\PhysicalDrive0",
  2579. "\\??\\8C8DAC1D-0390-4B59-BF93-EC6C9E68D36A",
  2580. "C:\\Users\\user\\AppData\\Local\\Temp\\19EDA4A1-B7CB-4c9b-806E-426EC9152906.tf",
  2581. "C:\\Users\\user\\AppData\\Local\\Temp\\lud1946.tmp",
  2582. "C:\\Users\\user\\AppData\\Local\\Temp\\360Base.dll",
  2583. "C:\\Users\\user\\AppData\\Local\\Temp\\82D2A230-1B01-4337-8FA5-D76A4A2C4460.tf",
  2584. "C:\\Users\\user\\AppData\\Local\\Temp\\lud1A13.tmp",
  2585. "C:\\Users\\user\\AppData\\Local\\Temp\\360net.dll",
  2586. "C:\\Users\\user\\AppData\\Local\\Temp\\E3E8ED8A-16B3-4609-9B60-963E9042197B.tf",
  2587. "C:\\Users\\user\\AppData\\Local\\Temp\\ludashisetup.exe",
  2588. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\url21.txt",
  2589. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\url22.txt",
  2590. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\url21.txt",
  2591. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\url21.txt",
  2592. "C:\\Users\\user\\AppData\\Local\\Temp\\6FE71CCB-7D99-471b-8EDB-F7B0B976D802.tf",
  2593. "C:\\Users\\user\\AppData\\Local\\Temp\\8BE4B769-D4FD-40a6-9BC2-DB2A665DA8DC.tmp",
  2594. "C:\\Users\\user\\AppData\\Local\\Temp\\496D2ADE-58D2-4f8a-AF6C-E70F4509A904.tmp\\7z.dll",
  2595. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\D47DBD2F9E3365FBBE008D71FB06716F_D33192D58AA9CA2B9097E848E9FE86DE",
  2596. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\D47DBD2F9E3365FBBE008D71FB06716F_D33192D58AA9CA2B9097E848E9FE86DE",
  2597. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\url21.txt",
  2598. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\url22.txt",
  2599. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6",
  2600. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6",
  2601. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\pc1.php",
  2602. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\7B8944BA8AD0EFDF0E01A43EF62BECD0_FF4B5EF27F9B55A4B2ABD52FA5FB9610",
  2603. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\7B8944BA8AD0EFDF0E01A43EF62BECD0_FF4B5EF27F9B55A4B2ABD52FA5FB9610",
  2604. "C:\\Users\\user\\AppData\\Local\\Temp\\CabCFF4.tmp",
  2605. "C:\\Users\\user\\AppData\\Local\\Temp\\TarCFF5.tmp",
  2606. "C:\\Users\\user\\AppData\\Local\\Temp\\CabD025.tmp",
  2607. "C:\\Users\\user\\AppData\\Local\\Temp\\TarD026.tmp",
  2608. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
  2609. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
  2610. "C:\\Users\\user\\AppData\\Local\\Temp\\CabD3C1.tmp",
  2611. "C:\\Users\\user\\AppData\\Local\\Temp\\TarD3C2.tmp",
  2612. "C:\\Users\\user\\AppData\\Local\\Temp\\057A3FC4-6FA3-470c-A616-639B97DAF151.tmp",
  2613. "C:\\Users\\user\\AppData\\Local\\Temp\\CD8BEA5A-6372-4592-99D9-B9EC0F6F40D6.tmp\\360NetUL.dll",
  2614. "C:\\Users\\user\\AppData\\Roaming\\360NetUL\\ludashisetup.netul.log",
  2615. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\9A19ADAD9D098E039450ABBEDD5616EB_CE18D35E70C72FBD424F3A4C77930458",
  2616. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\9A19ADAD9D098E039450ABBEDD5616EB_CE18D35E70C72FBD424F3A4C77930458",
  2617. "C:\\Users\\user\\AppData\\Local\\Temp\\403632C1-B0BF-4135-8F46-B89562FF20BE.tmp",
  2618. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\8CD3B058-E34B-4f83-8FA7-46E7DCBC68BE.tf",
  2619. "C:\\Users\\user\\AppData\\Local\\Temp\\114A869B-0E34-428f-8290-9976852A6B25.tmp",
  2620. "C:\\Users\\user\\AppData\\Local\\Temp\\112F94FE-0F30-4f67-BA94-B25EBC651756.tmp",
  2621. "C:\\Users\\user\\AppData\\Local\\Temp\\703B0350-B30B-4d8e-A5EF-A53DCD592433.tmp\\FileList.xml",
  2622. "C:\\Users\\user\\AppData\\Local\\Temp\\703B0350-B30B-4d8e-A5EF-A53DCD592433.tmp\\LDS.LDSPRJ",
  2623. "C:\\Users\\user\\AppData\\Local\\Temp\\703B0350-B30B-4d8e-A5EF-A53DCD592433.tmp\\UninstallRootDirFileList.xml",
  2624. "C:\\Program Files (x86)\\LuDaShi\\5C60A749-8816-4f0c-83EC-6941219B91ED.tf",
  2625. "C:\\Program Files (x86)\\LuDaShi\\40B76D01-9B26-468e-8690-7C722EC4B794.tf",
  2626. "C:\\Program Files (x86)\\LuDaShi\\lds_setup.log",
  2627. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\BenchmarkData\\core.spk",
  2628. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\BenchmarkData\\lds.spk",
  2629. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\BenchmarkData\\shaders_sm_3_0.cache",
  2630. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\BenchmarkData\\shaders_sm_5_0.cache",
  2631. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\deviceid.ini",
  2632. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\360LibDrvmgr.dat",
  2633. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\config\\config.xml",
  2634. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\config\\defaultskin\\defaultskin.ui",
  2635. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\config\\defaultskin\\MiniUI.xml",
  2636. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\feedback\\LuDaShiFeedback.ui",
  2637. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\feedback\\LuDaShiFeedBack.xml",
  2638. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\gameidentify.dat",
  2639. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\gameidentify_inc.dat",
  2640. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\ModeIdentify.dat",
  2641. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\widef.dat",
  2642. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Monitors.dat",
  2643. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\NNET.DAT",
  2644. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\BrowserBasic.tpi",
  2645. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\CleanTip.tpi",
  2646. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\MasterHeadline.tpi",
  2647. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\NetShield.tpi",
  2648. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\PopMgr.tpi",
  2649. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\pc1.php",
  2650. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\RunExtention.tpi",
  2651. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ProcSpecial.dat",
  2652. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\SchemeLib.dat",
  2653. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\RubbishCleanEngine.dat",
  2654. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\SysSweeper.dat",
  2655. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\tracesweeper.dat",
  2656. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\WhiteList.dat",
  2657. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\BenchmarkPage\\BenchmarkPage_theme.ui",
  2658. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\BenchmarkPage\\BenchmarkPage_theme.xml",
  2659. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\CleanPage\\CleanPage_Theme.ui",
  2660. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\CleanPage\\clean_page_theme.xml",
  2661. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\default_theme.ui",
  2662. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\DownMgr\\DownMgr_theme.ui",
  2663. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\DownMgr\\downmgr_theme.xml",
  2664. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\GamePage\\GamePage_Theme.ui",
  2665. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\GamePage\\GamePage_theme.xml",
  2666. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\LdsLite\\LdsLite_theme.ui",
  2667. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\LdsLite\\LdsLite_theme.xml",
  2668. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\updatecfg.ini",
  2669. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\gamecenter.json",
  2670. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LuDaShiPreview.ui",
  2671. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LuDaShiPreview.xml",
  2672. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\navskin.ui",
  2673. "C:\\Program Files (x86)\\LuDaShi\\BenchmarkData\\core.spk",
  2674. "C:\\Program Files (x86)\\LuDaShi\\BenchmarkData\\lds.spk",
  2675. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\360Base.dll",
  2676. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\360Base64.dll",
  2677. "C:\\Program Files (x86)\\LuDaShi\\BenchmarkData\\shaders_sm_3_0.cache",
  2678. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\360Common.dll",
  2679. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\360Conf.dll",
  2680. "C:\\Program Files (x86)\\LuDaShi\\BenchmarkData\\shaders_sm_5_0.cache",
  2681. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\360net.dll",
  2682. "C:\\Program Files (x86)\\LuDaShi\\deviceid.ini",
  2683. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\360P2SP.dll",
  2684. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\360LibDrvmgr.dat",
  2685. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\aapt.exe",
  2686. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\adb.exe",
  2687. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\config\\config.xml",
  2688. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\AdbWinApi.dll",
  2689. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\AdbWinUsbApi.dll",
  2690. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\atiags32.dll",
  2691. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\config\\defaultskin\\defaultskin.ui",
  2692. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerMonZ.dll",
  2693. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\config\\defaultskin\\MiniUI.xml",
  2694. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ.sys",
  2695. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\feedback\\LuDaShiFeedback.ui",
  2696. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ1.dll",
  2697. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ10.dll",
  2698. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\feedback\\LuDaShiFeedBack.xml",
  2699. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ11.dll",
  2700. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ2.dll",
  2701. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ4.dll",
  2702. "C:\\Program Files (x86)\\LuDaShi\\game\\gameidentify.dat",
  2703. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ4_x64.dll",
  2704. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ5.dll",
  2705. "C:\\Program Files (x86)\\LuDaShi\\game\\gameidentify_inc.dat",
  2706. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ7.dll",
  2707. "C:\\Program Files (x86)\\LuDaShi\\game\\ModeIdentify.dat",
  2708. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ7_x64.dll",
  2709. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZBrowser.exe",
  2710. "C:\\Program Files (x86)\\LuDaShi\\game\\widef.dat",
  2711. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZHelper_x64.exe",
  2712. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZService.exe",
  2713. "C:\\Program Files (x86)\\LuDaShi\\Monitors.dat",
  2714. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZTinyTray.exe",
  2715. "C:\\Program Files (x86)\\LuDaShi\\nBench\\NNET.DAT",
  2716. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZTray.exe",
  2717. "C:\\Program Files (x86)\\LuDaShi\\Plugin\\BrowserBasic.tpi",
  2718. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ_Accelerator.dll",
  2719. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ_CN.exe",
  2720. "C:\\Program Files (x86)\\LuDaShi\\Plugin\\CleanTip.tpi",
  2721. "C:\\Program Files (x86)\\LuDaShi\\Plugin\\MasterHeadline.tpi",
  2722. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ_HardwareDll.dll",
  2723. "C:\\Program Files (x86)\\LuDaShi\\Plugin\\NetShield.tpi",
  2724. "C:\\Program Files (x86)\\LuDaShi\\Plugin\\PopMgr.tpi",
  2725. "C:\\Program Files (x86)\\LuDaShi\\Plugin\\RunExtention.tpi",
  2726. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ_PowerSaveDll.dll",
  2727. "C:\\Program Files (x86)\\LuDaShi\\ProcSpecial.dat",
  2728. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ_x64.sys",
  2729. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DataMgr.dll",
  2730. "C:\\Program Files (x86)\\LuDaShi\\SchemeLib.dat",
  2731. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DataMgr_x64.dll",
  2732. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\RubbishCleanEngine.dat",
  2733. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\360NetBase.dll",
  2734. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\360NetUL.dll",
  2735. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\SysSweeper.dat",
  2736. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\7za.dll",
  2737. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\cloudcom2.dll",
  2738. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\tracesweeper.dat",
  2739. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\DIFxAPI_x86.dll",
  2740. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\DownloadMgr.dll",
  2741. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\DrvInst64.exe",
  2742. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\WhiteList.dat",
  2743. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\DrvMgr.exe",
  2744. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\DrvmgrCore.dll",
  2745. "C:\\Program Files (x86)\\LuDaShi\\Themes\\Default\\BenchmarkPage\\BenchmarkPage_theme.ui",
  2746. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\DrvMgrUI.dll",
  2747. "C:\\Program Files (x86)\\LuDaShi\\Themes\\Default\\BenchmarkPage\\BenchmarkPage_theme.xml",
  2748. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\dynlenv.dll",
  2749. "C:\\Program Files (x86)\\LuDaShi\\Themes\\Default\\CleanPage\\CleanPage_Theme.ui",
  2750. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\feedback\\360ScreenCapture.exe",
  2751. "C:\\Program Files (x86)\\LuDaShi\\Themes\\Default\\CleanPage\\clean_page_theme.xml",
  2752. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\feedback\\DrvMgrFeedBack.exe",
  2753. "C:\\Program Files (x86)\\LuDaShi\\Themes\\Default\\default_theme.ui",
  2754. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\feedback\\LdsMMFeedback.exe",
  2755. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\feedback\\LuDaShiFeedBack.exe",
  2756. "C:\\Program Files (x86)\\LuDaShi\\Themes\\Default\\DownMgr\\DownMgr_theme.ui",
  2757. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\ScriptExecute.exe",
  2758. "C:\\Program Files (x86)\\LuDaShi\\Themes\\Default\\DownMgr\\downmgr_theme.xml",
  2759. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\360GameIdentify.dll",
  2760. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\360WebIdentify.dll",
  2761. "C:\\Program Files (x86)\\LuDaShi\\Themes\\Default\\GamePage\\GamePage_Theme.ui",
  2762. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\GamePage.dll",
  2763. "C:\\Program Files (x86)\\LuDaShi\\Themes\\Default\\GamePage\\GamePage_theme.xml",
  2764. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\GameTray.dll",
  2765. "C:\\Program Files (x86)\\LuDaShi\\Themes\\Default\\LdsLite\\LdsLite_theme.ui",
  2766. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\ModeIdentify.dll",
  2767. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\HardwareProtectEx.sys",
  2768. "C:\\Program Files (x86)\\LuDaShi\\Themes\\Default\\LdsLite\\LdsLite_theme.xml",
  2769. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\HardwareProtectEx_x64.sys",
  2770. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\HardwareProtectSlim.sys",
  2771. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\HardwareProtectSlim_x64.sys",
  2772. "C:\\Program Files (x86)\\LuDaShi\\updatecfg.ini",
  2773. "C:\\Program Files (x86)\\LuDaShi\\Utils\\gamecenter.json",
  2774. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ipc\\ipcservice.dll",
  2775. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\LDSBenchmark.dll",
  2776. "C:\\Program Files (x86)\\LuDaShi\\Utils\\LuDaShiPreview.ui",
  2777. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\LdsLite.exe",
  2778. "C:\\Program Files (x86)\\LuDaShi\\Utils\\LuDaShiPreview.xml",
  2779. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\LiteUninst.exe",
  2780. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\LiveUpd360.dll",
  2781. "C:\\Program Files (x86)\\LuDaShi\\Utils\\navskin.ui",
  2782. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\LiveUpdate360.exe",
  2783. "C:\\Program Files (x86)\\LuDaShi\\360Base.dll",
  2784. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\lpi\\CheckHp.dll",
  2785. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\lpi\\HpSvc.dll",
  2786. "C:\\Program Files (x86)\\LuDaShi\\360Base64.dll",
  2787. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\lpi\\TmSvc.dll",
  2788. "C:\\Program Files (x86)\\LuDaShi\\360Common.dll",
  2789. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\MiniUI.dll",
  2790. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ModuleUpdate.exe",
  2791. "C:\\Program Files (x86)\\LuDaShi\\360Conf.dll",
  2792. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\BenchmarkLauncher.exe",
  2793. "C:\\Program Files (x86)\\LuDaShi\\360net.dll",
  2794. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\BenchmarkLauncher_x64.exe",
  2795. "C:\\Program Files (x86)\\LuDaShi\\360P2SP.dll",
  2796. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\BenchmarkPage.dll",
  2797. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\BenchmarkSuite.dll",
  2798. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\ComputerZ_Bench.dll",
  2799. "C:\\Program Files (x86)\\LuDaShi\\aapt.exe",
  2800. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\ComputerZ_Bench_x64.dll",
  2801. "C:\\Program Files (x86)\\LuDaShi\\adb.exe",
  2802. "C:\\Program Files (x86)\\LuDaShi\\AdbWinApi.dll",
  2803. "C:\\Program Files (x86)\\LuDaShi\\AdbWinUsbApi.dll",
  2804. "C:\\Program Files (x86)\\LuDaShi\\atiags32.dll",
  2805. "C:\\Program Files (x86)\\LuDaShi\\ComputerMonZ.dll",
  2806. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ.sys",
  2807. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ1.dll",
  2808. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ10.dll",
  2809. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ11.dll",
  2810. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ2.dll",
  2811. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ4.dll",
  2812. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ4_x64.dll",
  2813. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ5.dll",
  2814. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ7.dll",
  2815. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ7_x64.dll",
  2816. "C:\\Program Files (x86)\\LuDaShi\\ComputerZBrowser.exe",
  2817. "C:\\Program Files (x86)\\LuDaShi\\ComputerZHelper_x64.exe",
  2818. "C:\\Program Files (x86)\\LuDaShi\\ComputerZService.exe",
  2819. "C:\\Program Files (x86)\\LuDaShi\\ComputerZTinyTray.exe",
  2820. "C:\\Program Files (x86)\\LuDaShi\\ComputerZTray.exe",
  2821. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\D3DCompiler_43.dll",
  2822. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ_Accelerator.dll",
  2823. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\d3dx11_43.dll",
  2824. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\D3DX9_43.dll",
  2825. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ_CN.exe",
  2826. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\Display3DEx.exe",
  2827. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\OCLBenchmark.dll",
  2828. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ_HardwareDll.dll",
  2829. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ_PowerSaveDll.dll",
  2830. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ_x64.sys",
  2831. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\net\\netload.dll",
  2832. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\NetBridge.dll",
  2833. "C:\\Program Files (x86)\\LuDaShi\\DataMgr.dll",
  2834. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\PDown.dll",
  2835. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\ConfigCenter.dll",
  2836. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\ConfigCenterStub.dll",
  2837. "C:\\Program Files (x86)\\LuDaShi\\DataMgr_x64.dll",
  2838. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\PopMgrStub.dll",
  2839. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\360NetBase.dll",
  2840. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\PowerSaveZ.sys",
  2841. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\PowerSaveZ_x64.sys",
  2842. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Safelive.dll",
  2843. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\SignHelper.dll",
  2844. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sites.dll",
  2845. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\360NetUL.dll",
  2846. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\SiteUIHelper.dll",
  2847. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\7za.dll",
  2848. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\softmgr\\DownMgr.dll",
  2849. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\softmgr\\SoftMgr.dll",
  2850. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\cloudcom2.dll",
  2851. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\softmgr\\SoftMgrInst.exe",
  2852. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\softmgr\\SoftMgrPage.dll",
  2853. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\DIFxAPI_x86.dll",
  2854. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sqlite3.dll",
  2855. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\CleanHelper64.exe",
  2856. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\DownloadMgr.dll",
  2857. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\CleanPage.dll",
  2858. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\DrvInst64.exe",
  2859. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\CleanPageEngine.dll",
  2860. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\ComputerZS1.dll",
  2861. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\DrvMgr.exe",
  2862. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\HardwareCleaner.dll",
  2863. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\heavygate.dll",
  2864. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\DrvmgrCore.dll",
  2865. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\MemoryOptimizer.exe",
  2866. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\DrvMgrUI.dll",
  2867. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\SysSweeper.dll",
  2868. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\TEngine.dll",
  2869. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\dynlenv.dll",
  2870. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\Tracehelper.exe",
  2871. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\TrashClean.dll",
  2872. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\feedback\\360ScreenCapture.exe",
  2873. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\TrayHelper.exe",
  2874. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\uninst.exe",
  2875. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\update.exe",
  2876. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\feedback\\DrvMgrFeedBack.exe",
  2877. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\arctrl.dll",
  2878. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\feedback\\LdsMMFeedback.exe",
  2879. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ComputerZ12.dll",
  2880. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ComputerZ12_x64.dll",
  2881. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\feedback\\LuDaShiFeedBack.exe",
  2882. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ComputerZ14.exe",
  2883. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ComputerZ8.dll",
  2884. "C:\\Program Files (x86)\\LuDaShi\\DrvMgr\\ScriptExecute.exe",
  2885. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ComputerZ8_x64.dll",
  2886. "C:\\Program Files (x86)\\LuDaShi\\game\\360GameIdentify.dll",
  2887. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\DisPatchMini.dll",
  2888. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\Down.exe",
  2889. "C:\\Program Files (x86)\\LuDaShi\\game\\360WebIdentify.dll",
  2890. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\DumpUper.exe",
  2891. "C:\\Program Files (x86)\\LuDaShi\\game\\GamePage.dll",
  2892. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\guardhp.exe",
  2893. "C:\\Program Files (x86)\\LuDaShi\\game\\GameTray.dll",
  2894. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ie\\LdsIeView.exe",
  2895. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\iosdb.exe",
  2896. "C:\\Program Files (x86)\\LuDaShi\\game\\ModeIdentify.dll",
  2897. "C:\\Program Files (x86)\\LuDaShi\\HardwareProtectEx.sys",
  2898. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\iosdb64.exe",
  2899. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\KitTip.dll",
  2900. "C:\\Program Files (x86)\\LuDaShi\\HardwareProtectEx_x64.sys",
  2901. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\Launcher.del.exe",
  2902. "C:\\Program Files (x86)\\LuDaShi\\HardwareProtectSlim.sys",
  2903. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LDSBasic.dll",
  2904. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LdsBridgeEx.exe",
  2905. "C:\\Program Files (x86)\\LuDaShi\\HardwareProtectSlim_x64.sys",
  2906. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LdsDrvInst32.exe",
  2907. "C:\\Program Files (x86)\\LuDaShi\\ipc\\ipcservice.dll",
  2908. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LdsDrvInst64.exe",
  2909. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ldsgamecenter_ludashiembed.dll",
  2910. "C:\\Program Files (x86)\\LuDaShi\\LDSBenchmark.dll",
  2911. "C:\\Program Files (x86)\\LuDaShi\\LdsLite.exe",
  2912. "C:\\Program Files (x86)\\LuDaShi\\LiteUninst.exe",
  2913. "C:\\Program Files (x86)\\LuDaShi\\LiveUpd360.dll",
  2914. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\Ldshelper.exe",
  2915. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LdsMobile.exe",
  2916. "C:\\Program Files (x86)\\LuDaShi\\LiveUpdate360.exe",
  2917. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LdsVolumeCtrl.dll",
  2918. "C:\\Program Files (x86)\\LuDaShi\\lpi\\CheckHp.dll",
  2919. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LdsWebView.dll",
  2920. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LuDaShiHelper.dll",
  2921. "C:\\Program Files (x86)\\LuDaShi\\lpi\\HpSvc.dll",
  2922. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LuDaShiPreview.exe",
  2923. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\MedalWall.exe",
  2924. "C:\\Program Files (x86)\\LuDaShi\\lpi\\TmSvc.dll",
  2925. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\mininews.exe",
  2926. "C:\\Program Files (x86)\\LuDaShi\\MiniUI.dll",
  2927. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\MininewsPlugin.dll",
  2928. "C:\\Program Files (x86)\\LuDaShi\\ModuleUpdate.exe",
  2929. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\MobileDeviceSrv.exe",
  2930. "C:\\Program Files (x86)\\LuDaShi\\nBench\\BenchmarkLauncher.exe",
  2931. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\NavAd.dll",
  2932. "C:\\Program Files (x86)\\LuDaShi\\nBench\\BenchmarkLauncher_x64.exe",
  2933. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\NavLauncher.dll",
  2934. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\NavLauncher64.dll",
  2935. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\NavPlugin.exe",
  2936. "C:\\Program Files (x86)\\LuDaShi\\nBench\\BenchmarkPage.dll",
  2937. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\NavProxy64.exe",
  2938. "C:\\Program Files (x86)\\LuDaShi\\nBench\\BenchmarkSuite.dll",
  2939. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\PageMgr.dll",
  2940. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\Pop.dll",
  2941. "C:\\Program Files (x86)\\LuDaShi\\nBench\\ComputerZ_Bench.dll",
  2942. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\PopEx.dll",
  2943. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\RunDll.exe",
  2944. "C:\\Program Files (x86)\\LuDaShi\\nBench\\ComputerZ_Bench_x64.dll",
  2945. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\SoulDancer.exe",
  2946. "C:\\Program Files (x86)\\LuDaShi\\nBench\\D3DCompiler_43.dll",
  2947. "C:\\Program Files (x86)\\LuDaShi\\nBench\\d3dx11_43.dll",
  2948. "C:\\Program Files (x86)\\LuDaShi\\nBench\\D3DX9_43.dll",
  2949. "C:\\Program Files (x86)\\LuDaShi\\nBench\\Display3DEx.exe",
  2950. "C:\\Program Files (x86)\\LuDaShi\\nBench\\OCLBenchmark.dll",
  2951. "C:\\Program Files (x86)\\LuDaShi\\net\\netload.dll",
  2952. "C:\\Program Files (x86)\\LuDaShi\\NetBridge.dll",
  2953. "C:\\Program Files (x86)\\LuDaShi\\PDown.dll",
  2954. "C:\\Program Files (x86)\\LuDaShi\\Plugin\\ConfigCenter.dll",
  2955. "C:\\Program Files (x86)\\LuDaShi\\Plugin\\ConfigCenterStub.dll",
  2956. "C:\\Program Files (x86)\\LuDaShi\\Plugin\\PopMgrStub.dll",
  2957. "C:\\Program Files (x86)\\LuDaShi\\PowerSaveZ.sys",
  2958. "C:\\Program Files (x86)\\LuDaShi\\PowerSaveZ_x64.sys",
  2959. "C:\\Program Files (x86)\\LuDaShi\\Safelive.dll",
  2960. "C:\\Program Files (x86)\\LuDaShi\\SignHelper.dll",
  2961. "C:\\Program Files (x86)\\LuDaShi\\sites.dll",
  2962. "C:\\Program Files (x86)\\LuDaShi\\SiteUIHelper.dll",
  2963. "C:\\Program Files (x86)\\LuDaShi\\softmgr\\DownMgr.dll",
  2964. "C:\\Program Files (x86)\\LuDaShi\\softmgr\\SoftMgr.dll",
  2965. "C:\\Program Files (x86)\\LuDaShi\\softmgr\\SoftMgrInst.exe",
  2966. "C:\\Program Files (x86)\\LuDaShi\\softmgr\\SoftMgrPage.dll",
  2967. "C:\\Program Files (x86)\\LuDaShi\\sqlite3.dll",
  2968. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\CleanHelper64.exe",
  2969. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\CleanPage.dll",
  2970. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\CleanPageEngine.dll",
  2971. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\ComputerZS1.dll",
  2972. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\HardwareCleaner.dll",
  2973. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\heavygate.dll",
  2974. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\MemoryOptimizer.exe",
  2975. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\SysSweeper.dll",
  2976. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\TEngine.dll",
  2977. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\Tracehelper.exe",
  2978. "C:\\Program Files (x86)\\LuDaShi\\sweeper\\TrashClean.dll",
  2979. "C:\\Program Files (x86)\\LuDaShi\\TrayHelper.exe",
  2980. "C:\\Program Files (x86)\\LuDaShi\\uninst.exe",
  2981. "C:\\Program Files (x86)\\LuDaShi\\update.exe",
  2982. "C:\\Program Files (x86)\\LuDaShi\\Utils\\arctrl.dll",
  2983. "C:\\Program Files (x86)\\LuDaShi\\Utils\\ComputerZ12.dll",
  2984. "C:\\Program Files (x86)\\LuDaShi\\Utils\\ComputerZ12_x64.dll",
  2985. "C:\\Program Files (x86)\\LuDaShi\\Utils\\ComputerZ14.exe",
  2986. "C:\\Program Files (x86)\\LuDaShi\\Utils\\ComputerZ8.dll",
  2987. "C:\\Program Files (x86)\\LuDaShi\\Utils\\ComputerZ8_x64.dll",
  2988. "C:\\Program Files (x86)\\LuDaShi\\Utils\\DisPatchMini.dll",
  2989. "C:\\Program Files (x86)\\LuDaShi\\Utils\\Down.exe",
  2990. "C:\\Program Files (x86)\\LuDaShi\\Utils\\DumpUper.exe",
  2991. "C:\\Program Files (x86)\\LuDaShi\\Utils\\guardhp.exe",
  2992. "C:\\Program Files (x86)\\LuDaShi\\Utils\\ie\\LdsIeView.exe",
  2993. "C:\\Program Files (x86)\\LuDaShi\\Utils\\iosdb.exe",
  2994. "C:\\Program Files (x86)\\LuDaShi\\Utils\\iosdb64.exe",
  2995. "C:\\Program Files (x86)\\LuDaShi\\Utils\\KitTip.dll",
  2996. "C:\\Program Files (x86)\\LuDaShi\\Utils\\Launcher.del.exe",
  2997. "C:\\Program Files (x86)\\LuDaShi\\Utils\\LDSBasic.dll",
  2998. "C:\\Program Files (x86)\\LuDaShi\\Utils\\LdsBridgeEx.exe",
  2999. "C:\\Program Files (x86)\\LuDaShi\\Utils\\LdsDrvInst32.exe",
  3000. "C:\\Program Files (x86)\\LuDaShi\\Utils\\LdsDrvInst64.exe",
  3001. "C:\\Program Files (x86)\\LuDaShi\\Utils\\ldsgamecenter_ludashiembed.dll",
  3002. "C:\\Program Files (x86)\\LuDaShi\\Utils\\Ldshelper.exe",
  3003. "C:\\Program Files (x86)\\LuDaShi\\Utils\\LdsMobile.exe",
  3004. "C:\\Program Files (x86)\\LuDaShi\\Utils\\LdsVolumeCtrl.dll",
  3005. "C:\\Program Files (x86)\\LuDaShi\\Utils\\LdsWebView.dll",
  3006. "C:\\Program Files (x86)\\LuDaShi\\Utils\\LuDaShiHelper.dll",
  3007. "C:\\Program Files (x86)\\LuDaShi\\Utils\\LuDaShiPreview.exe",
  3008. "C:\\Program Files (x86)\\LuDaShi\\Utils\\MedalWall.exe",
  3009. "C:\\Program Files (x86)\\LuDaShi\\Utils\\mininews.exe",
  3010. "C:\\Program Files (x86)\\LuDaShi\\Utils\\MininewsPlugin.dll",
  3011. "C:\\Program Files (x86)\\LuDaShi\\Utils\\MobileDeviceSrv.exe",
  3012. "C:\\Program Files (x86)\\LuDaShi\\Utils\\NavAd.dll",
  3013. "C:\\Program Files (x86)\\LuDaShi\\Utils\\NavLauncher.dll",
  3014. "C:\\Program Files (x86)\\LuDaShi\\Utils\\NavLauncher64.dll",
  3015. "C:\\Program Files (x86)\\LuDaShi\\Utils\\NavPlugin.exe",
  3016. "C:\\Program Files (x86)\\LuDaShi\\Utils\\NavProxy64.exe",
  3017. "C:\\Program Files (x86)\\LuDaShi\\Utils\\PageMgr.dll",
  3018. "C:\\Program Files (x86)\\LuDaShi\\Utils\\Pop.dll",
  3019. "C:\\Program Files (x86)\\LuDaShi\\Utils\\PopEx.dll",
  3020. "C:\\Program Files (x86)\\LuDaShi\\Utils\\RunDll.exe",
  3021. "C:\\Program Files (x86)\\LuDaShi\\Utils\\SoulDancer.exe",
  3022. "C:\\Program Files (x86)\\LuDaShi\\Utils\\7z.dll",
  3023. "C:\\Users\\user\\AppData\\Local\\Temp\\03383774-198D-42dd-86FB-2C0B25D1E8B3.tmp",
  3024. "\\??\\PIPE\\srvsvc",
  3025. "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\\\xe9\\xb2\\x81\\xe5\\xa4\\xa7\\xe5\\xb8\\x88\\\\xe9\\xb2\\x81\\xe5\\xa4\\xa7\\xe5\\xb8\\x88.lnk",
  3026. "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\\\xe9\\xb2\\x81\\xe5\\xa4\\xa7\\xe5\\xb8\\x88\\\\xe5\\x8d\\xb8\\xe8\\xbd\\xbd\\xe9\\xb2\\x81\\xe5\\xa4\\xa7\\xe5\\xb8\\x88.lnk",
  3027. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ.set",
  3028. "C:\\Windows\\System32\\netload.dll",
  3029. "\\Device\\NamedPipe\\Winsock2\\CatalogChangeListener-2cc-0",
  3030. "\\Device\\NamedPipe\\Winsock2\\CatalogChangeListener-190-0",
  3031. "\\Device\\NamedPipe\\Winsock2\\CatalogChangeListener-300-0",
  3032. "\\Device\\NamedPipe\\Winsock2\\CatalogChangeListener-388-0",
  3033. "\\Device\\NamedPipe\\Winsock2\\CatalogChangeListener-1f8-0",
  3034. "\\Device\\NamedPipe\\Winsock2\\CatalogChangeListener-200-0",
  3035. "C:\\Windows\\System32\\~ld1706.tmp",
  3036. "C:\\Program Files (x86)\\LuDaShi\\HardwareProtect.sys",
  3037. "C:\\Program Files (x86)\\LuDaShi\\HardwareProtect_x64.sys",
  3038. "\\??\\ComputerZLock",
  3039. "\\??\\HardwareProtect",
  3040. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\955CAB6FF6A24D5820D50B5BA1CF79C7_AD9E7615297A3A83320AACE5801A04F9",
  3041. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\955CAB6FF6A24D5820D50B5BA1CF79C7_AD9E7615297A3A83320AACE5801A04F9",
  3042. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\8E4E510F44A56B8C8ECFEC352907C373_7A3A58029C2269D89D3EA1039BD4EC4D",
  3043. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\8E4E510F44A56B8C8ECFEC352907C373_7A3A58029C2269D89D3EA1039BD4EC4D",
  3044. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\pc1.php",
  3045. "C:\\Users\\user\\AppData\\Local\\Temp\\88724052-5C4D-43c2-AB79-E651A86D9696.tf",
  3046. "C:\\Users\\user\\AppData\\Local\\Temp\\F680EEB1-D32A-4b08-A7B4-4A620EDC24E1.tmp",
  3047. "C:\\Users\\user\\AppData\\Local\\Temp\\44D9C318-3C96-48bd-BEE2-728DCA60EA2D.tmp\\7z.dll",
  3048. "C:\\Users\\user\\AppData\\Local\\Temp\\7D25400F-C0D1-4d61-87A1-CDC3A014119A.tmp",
  3049. "C:\\Users\\user\\AppData\\Local\\Temp\\FD8D1A97-F266-46d4-AB52-A1B1B57B1017.tmp\\360Base.dll",
  3050. "C:\\Users\\user\\AppData\\Local\\Temp\\80FF0FC4-B660-4c6c-A9AC-9C65D281DB03.tmp",
  3051. "C:\\Users\\user\\AppData\\Local\\Temp\\DEBA4A05-2CC6-413e-8EEA-2759284E21F1.tmp\\360NetUL.dll",
  3052. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\wan1.txt",
  3053. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\D57D6E48-A965-4e2e-81DC-EE49583A0A7B.tf",
  3054. "C:\\Users\\user\\AppData\\Local\\Temp\\85C79456-8BF5-4b02-804D-994FF98CC5BE.tmp",
  3055. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\wan1.txt",
  3056. "C:\\Users\\user\\AppData\\Local\\Temp\\14978C02-BFC3-4dc7-842F-44DB140EF4D7.tmp\\FileList.xml",
  3057. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\alarm.mp3",
  3058. "C:\\Users\\user\\AppData\\Local\\Temp\\14978C02-BFC3-4dc7-842F-44DB140EF4D7.tmp\\LDSGAMECENTER-DLL.LDSPRJ",
  3059. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\skin.ui",
  3060. "C:\\Users\\user\\AppData\\Local\\Temp\\14978C02-BFC3-4dc7-842F-44DB140EF4D7.tmp\\UninstallRootDirFileList.xml",
  3061. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\updatecfg.ini",
  3062. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\cdnconfig.dat",
  3063. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\fullscreengames.json",
  3064. "C:\\Users\\user\\AppData\\Local\\GDIPFONTCACHEV1.DAT",
  3065. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\gamefixconfig.json",
  3066. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\JS\\css.js",
  3067. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\JS\\event.js",
  3068. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\JS\\ie6.js",
  3069. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\JS\\jquery.min.js",
  3070. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\JS\\json2.js",
  3071. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\JS\\utils.js",
  3072. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\GAI.dll",
  3073. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\gameuninst.exe",
  3074. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\A240931B-FB7B-47e6-8FB1-EB12452FD297.tf",
  3075. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\ie\\LdsIeView.exe",
  3076. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\A9D7717C-BBA4-4b59-AFCB-1267BC3C64B7.tf",
  3077. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\LDSGameCenter.exe",
  3078. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\LdsVolumeCtrl.dll",
  3079. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\LdsWebView.dll",
  3080. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\fancygame.ocx",
  3081. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\LDSGameMasterLoader.exe",
  3082. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\ZMQActiveX.ocx",
  3083. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\ZMQLaunch.exe",
  3084. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\wan1.txt",
  3085. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\alarm.mp3",
  3086. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\skin.ui",
  3087. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\updatecfg.ini",
  3088. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\cdnconfig.dat",
  3089. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\fullscreengames.json",
  3090. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\gamefixconfig.json",
  3091. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\JS\\css.js",
  3092. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\JS\\event.js",
  3093. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\JS\\ie6.js",
  3094. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\JS\\jquery.min.js",
  3095. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\JS\\json2.js",
  3096. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\JS\\utils.js",
  3097. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\GAI.dll",
  3098. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\gameuninst.exe",
  3099. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\ie\\LdsIeView.exe",
  3100. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\LDSGameCenter.exe",
  3101. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\LdsVolumeCtrl.dll",
  3102. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\LdsWebView.dll",
  3103. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\fancygame.ocx",
  3104. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\LDSGameMasterLoader.exe",
  3105. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\ZMQActiveX.ocx",
  3106. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\ZMQLaunch.exe",
  3107. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\Log\\install.log",
  3108. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\7z.dll",
  3109. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\buytry\\\\xe4\\xb8\\xad\\xe5\\x8f\\x98\\xe4\\xbc\\xa0\\xe5\\xa5\\x87\\xe7\\x81\\xad\\xe7\\xa5\\x9e.ico",
  3110. "C:\\Users\\Public\\Desktop\\\\xe4\\xb8\\xad\\xe5\\x8f\\x98\\xe4\\xbc\\xa0\\xe5\\xa5\\x87\\xe7\\x81\\xad\\xe7\\xa5\\x9e.lnk",
  3111. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\TaskBar\\\\xe4\\xb8\\xad\\xe5\\x8f\\x98\\xe4\\xbc\\xa0\\xe5\\xa5\\x87\\xe7\\x81\\xad\\xe7\\xa5\\x9e.lnk",
  3112. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\\\xe4\\xb8\\xad\\xe5\\x8f\\x98\\xe4\\xbc\\xa0\\xe5\\xa5\\x87\\xe7\\x81\\xad\\xe7\\xa5\\x9e.lnk",
  3113. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenterSpecLog\\Log\\\\xe7\\x89\\x88\\xe6\\x9c\\xac\\xe5\\x9b\\x9e\\xe6\\xbb\\x9a\\xe9\\x97\\xae\\xe9\\xa2\\x98.log",
  3114. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\wan1.txt",
  3115. "C:\\Windows\\sysnative\\LogFiles\\Scm\\5869f1c1-01d7-41f7-84b7-715672259fa8",
  3116. "C:\\program files (x86)\\LuDaShi\\ComputerZ.set",
  3117. "C:\\program files (x86)\\LuDaShi\\lpi\\svc.dat",
  3118. "C:\\Windows\\System32\\config\\systemprofile\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\3RUXGK2R\\url31.txt",
  3119. "C:\\Windows\\System32\\config\\systemprofile\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\2N9ZM3JC\\url31.txt",
  3120. "C:\\Users\\user\\AppData\\Roaming\\Ludashi\\ComputerZ.set",
  3121. "C:\\Program Files (x86)\\LuDaShi\\computerz.set",
  3122. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\url31.txt",
  3123. "C:\\Users\\user\\AppData\\Roaming\\lds\\lds.set",
  3124. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab48CE.tmp",
  3125. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar48CF.tmp",
  3126. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\url31.txt",
  3127. "C:\\Users\\user\\AppData\\Roaming\\360NetUL\\ComputerZ14.netul.log",
  3128. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
  3129. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
  3130. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
  3131. "C:\\Users\\user\\AppData\\Roaming\\Ludashi\\invaildhp_temp.dat",
  3132. "C:\\Users\\user\\AppData\\Roaming\\Ludashi\\external.dat",
  3133. "C:\\Users\\user\\AppData\\Roaming\\lockhomepage\\LockHomePage.ini",
  3134. "C:\\Users\\user\\AppData\\Roaming\\Ludashi\\invalidhp.dat",
  3135. "C:\\Users\\user\\AppData\\Roaming\\360NetUL\\LDSGameCenter.netul.log",
  3136. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\AppConfig.json",
  3137. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\Log\\LDSGameCenter.log",
  3138. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\skin.ui",
  3139. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\user.db",
  3140. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\user.db-journal",
  3141. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\gameinfocachev2.json",
  3142. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\Sound\\9D47159D-1428-4017-B08F-500E0C5EB70C.snd",
  3143. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\Utils\\URLConfig.json",
  3144. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\GlobalConfig.ini",
  3145. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\gameid_cmd_ms.json",
  3146. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\Log\\gameinfo_resp_de.json",
  3147. "C:\\Users\\user\\AppData\\Local\\Temp\\35833978c51cea5689c58a27df3e4687.png",
  3148. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  3149. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  3150. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\jump1.txt",
  3151. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\B398B80134F72209547439DB21AB308D_CCF564BE5A3C924B17DDEBDEB5236E12",
  3152. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\B398B80134F72209547439DB21AB308D_CCF564BE5A3C924B17DDEBDEB5236E12",
  3153. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\Log\\gameinfo_saved_de.json",
  3154. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\Log\\gameinfo_full_resp.json",
  3155. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\AF3BA1CDD96BBC740C9CE3754F348BED_642AE79D681B45657F4188CA5687E56D",
  3156. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\AF3BA1CDD96BBC740C9CE3754F348BED_642AE79D681B45657F4188CA5687E56D",
  3157. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\dnserrordiagoff_webOC1",
  3158. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\ErrorPageTemplate1",
  3159. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\1694560B0C737E58D6701D2EF2176C07",
  3160. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\1694560B0C737E58D6701D2EF2176C07",
  3161. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\errorPageStrings1",
  3162. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts1",
  3163. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts2",
  3164. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\info_481",
  3165. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\background_gradient1",
  3166. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\background_gradient2",
  3167. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\bullet1",
  3168. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\down1",
  3169. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\MSIMGSIZ.DAT",
  3170. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012019072020190721\\index.dat",
  3171. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\navcancl1",
  3172. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\ErrorPageTemplate1",
  3173. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\errorPageStrings1",
  3174. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\httpErrorPagesScripts1",
  3175. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\info_482",
  3176. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\bullet1",
  3177. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\account1.txt",
  3178. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\login1.css",
  3179. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab55BE.tmp",
  3180. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar55CF.tmp",
  3181. "\\??\\PIPE\\computerzservice",
  3182. "C:\\Users\\user\\AppData\\Roaming\\360NetUL\\ComputerZTray.netul.log",
  3183. "C:\\Users\\user\\AppData\\Local\\Temp\\LDSGameCenter\\Log\\GameTray.log",
  3184. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\url31.txt",
  3185. "C:\\Users\\user\\AppData\\Roaming\\Ludashi\\computerz.set",
  3186. "C:\\Users\\user\\AppData\\Roaming\\Ludashi\\cdn_common.json",
  3187. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\9A19ADAD9D098E039450ABBEDD5616EB_BF3C396B99A52B1CFA1CE8F3E6C2A5B9",
  3188. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\9A19ADAD9D098E039450ABBEDD5616EB_BF3C396B99A52B1CFA1CE8F3E6C2A5B9",
  3189. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\url41.txt",
  3190. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\url31.txt",
  3191. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\url22.txt",
  3192. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\url41.txt",
  3193. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\url41.txt",
  3194. "C:\\Users\\user\\AppData\\Roaming\\Ludashi\\switch.json",
  3195. "C:\\Users\\user\\AppData\\Local\\Temp\\WebHistory\\chrome_history.db",
  3196. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\url41.txt",
  3197. "C:\\Program Files (x86)\\LuDaShi\\update\\~282E.cab",
  3198. "C:\\Users\\user\\AppData\\Roaming\\360Safe\\LiveUpdateLog\\P2SP_computerztray.log",
  3199. "C:\\Program Files (x86)\\LuDaShi\\update\\~282E.cab.~p2s",
  3200. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\noUpdate1.cab",
  3201. "C:\\Program Files (x86)\\LuDaShi\\update\\update.ini",
  3202. "C:\\Windows\\System32\\~ld5923.tmp",
  3203. "C:\\Program Files (x86)\\LuDaShi\\log\\ComputerZ_HardwareDll.log",
  3204. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab6270.tmp",
  3205. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar6271.tmp",
  3206. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ.dat",
  3207. "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf",
  3208. "\\??\\PIPE\\samr",
  3209. "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
  3210. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
  3211. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
  3212. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
  3213. "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
  3214. "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
  3215. "C:\\Windows\\sysnative\\Tasks\\ComputerZ-Tray",
  3216. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
  3217. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab80B6.tmp",
  3218. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar80C7.tmp",
  3219. "\\??\\ComputerZ",
  3220. "C:",
  3221. "\\??\\PhysicalDrive1",
  3222. "\\??\\PhysicalDrive2",
  3223. "\\??\\PhysicalDrive3",
  3224. "\\??\\PhysicalDrive4",
  3225. "\\??\\PhysicalDrive5",
  3226. "\\??\\PhysicalDrive6",
  3227. "\\??\\PhysicalDrive7",
  3228. "\\??\\PhysicalDrive8",
  3229. "\\??\\PhysicalDrive9",
  3230. "\\??\\PhysicalDrive10",
  3231. "\\??\\PhysicalDrive11",
  3232. "\\??\\PhysicalDrive12",
  3233. "\\??\\PhysicalDrive13",
  3234. "\\??\\PhysicalDrive14",
  3235. "\\??\\PhysicalDrive15",
  3236. "\\??\\PhysicalDrive16",
  3237. "\\??\\PhysicalDrive17",
  3238. "\\??\\PhysicalDrive18",
  3239. "\\??\\PhysicalDrive19",
  3240. "\\??\\PhysicalDrive20",
  3241. "\\??\\PhysicalDrive21",
  3242. "\\??\\PhysicalDrive22",
  3243. "\\??\\PhysicalDrive23",
  3244. "\\??\\PhysicalDrive24",
  3245. "\\??\\PhysicalDrive25",
  3246. "\\??\\PhysicalDrive26",
  3247. "\\??\\PhysicalDrive27",
  3248. "\\??\\PhysicalDrive28",
  3249. "\\??\\PhysicalDrive29",
  3250. "\\??\\PhysicalDrive30",
  3251. "\\??\\PhysicalDrive31",
  3252. "\\??\\PhysicalDrive32",
  3253. "\\??\\PhysicalDrive33",
  3254. "\\??\\PhysicalDrive34",
  3255. "\\??\\PhysicalDrive35",
  3256. "\\??\\PhysicalDrive36",
  3257. "\\??\\PhysicalDrive37",
  3258. "\\??\\PhysicalDrive38",
  3259. "\\??\\PhysicalDrive39",
  3260. "\\??\\PhysicalDrive40",
  3261. "\\??\\PhysicalDrive41",
  3262. "\\??\\PhysicalDrive42",
  3263. "\\??\\PhysicalDrive43",
  3264. "\\??\\PhysicalDrive44",
  3265. "\\??\\PhysicalDrive45",
  3266. "\\??\\PhysicalDrive46",
  3267. "\\??\\PhysicalDrive47",
  3268. "\\??\\PhysicalDrive48",
  3269. "\\??\\PhysicalDrive49",
  3270. "\\??\\PhysicalDrive50",
  3271. "\\??\\PhysicalDrive51",
  3272. "\\??\\PhysicalDrive52",
  3273. "\\??\\PhysicalDrive53",
  3274. "\\??\\PhysicalDrive54",
  3275. "\\??\\PhysicalDrive55",
  3276. "\\??\\Scsi0:",
  3277. "\\??\\Scsi1:",
  3278. "\\??\\Scsi2:",
  3279. "\\??\\Scsi3:",
  3280. "\\??\\Scsi4:",
  3281. "\\??\\Scsi5:",
  3282. "\\??\\Scsi6:",
  3283. "\\??\\Scsi7:",
  3284. "\\??\\Scsi8:",
  3285. "\\??\\Scsi9:",
  3286. "\\??\\Scsi10:",
  3287. "\\??\\Scsi11:",
  3288. "\\??\\Scsi12:",
  3289. "\\??\\Scsi13:",
  3290. "\\??\\Scsi14:",
  3291. "\\??\\Scsi15:",
  3292. "C:\\Users\\user\\AppData\\Roaming\\360NetUL\\ComputerZService.netul.log",
  3293. "D:",
  3294. "\\??\\HCD0",
  3295. "\\??\\HCD1",
  3296. "\\??\\HCD2",
  3297. "\\??\\HCD3",
  3298. "\\??\\HCD4",
  3299. "\\??\\HCD5",
  3300. "\\??\\HCD6",
  3301. "\\??\\HCD7",
  3302. "\\??\\HCD8",
  3303. "\\??\\HCD9",
  3304. "\\??\\USB#ROOT_HUB#4&24d6eb65&0#f18a0e88-c30c-11d0-8815-00a0c906bed8",
  3305. "\\??\\USB#ROOT_HUB20#4&6a987e4&0#f18a0e88-c30c-11d0-8815-00a0c906bed8",
  3306. "C:\\Program Files (x86)\\LuDaShi\\HWParams.dat",
  3307. "C:\\Users\\user\\AppData\\Roaming\\360NetUL\\MobileDeviceSrv.netul.log",
  3308. "C:\\Users\\user\\AppData\\Roaming\\Ludashi\\deviceid.ini.tmp",
  3309. "C:\\Users\\user\\AppData\\Roaming\\Ludashi\\apk\\mobiledevicesrvcache_ludashi.dat",
  3310. "C:\\Users\\user\\AppData\\Roaming\\Ludashi\\deviceid.ini",
  3311. "C:\\Users\\user\\AppData\\Roaming\\360NetUL\\NavPlugin.netul.log",
  3312. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\navplugin.ini",
  3313. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\history_chrome",
  3314. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\history.dat",
  3315. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\hao.360.cn_temp.ico",
  3316. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\2B1E03584C97951A30AF9E92B9B15F6F.ico",
  3317. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\hao.360.cn.ico",
  3318. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\A90C3F3299F57564F6C6AA862132BB89.ico",
  3319. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.baidu.com_temp.ico",
  3320. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\wan.ludashi.com_temp.ico",
  3321. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\wan.ludashi.com.ico",
  3322. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.tmall.com_temp.ico",
  3323. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.tmall.com.ico",
  3324. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.taobao.com_temp.ico",
  3325. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.taobao.com.ico",
  3326. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.jd.com_temp.ico",
  3327. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.jd.com.ico",
  3328. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\weibo.com_temp.ico",
  3329. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.sina.com.cn_temp.ico",
  3330. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.sina.com.cn.ico",
  3331. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.qunar.com_temp.ico",
  3332. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.qunar.com.ico",
  3333. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.iqiyi.com_temp.ico",
  3334. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.iqiyi.com.ico",
  3335. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.qq.com_temp.ico",
  3336. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6",
  3337. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6",
  3338. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.qq.com.ico",
  3339. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.58.com_temp.ico",
  3340. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.58.com.ico",
  3341. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.baidu.com.ico",
  3342. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\weibo.com.ico",
  3343. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\url22.txt",
  3344. "C:\\Users\\user\\AppData\\Roaming\\360NetUL\\DumpUper.netul.log",
  3345. "C:\\Users\\user\\AppData\\Local\\Temp\\LdsDumpUper\\db2c71648b5a939e38cf679b921b03dc_000.dmp"
  3346.  
  3347.  
  3348. * Deleted Files:
  3349. "C:\\Users\\user\\AppData\\Local\\Temp\\19EDA4A1-B7CB-4c9b-806E-426EC9152906.tf",
  3350. "C:\\Users\\user\\AppData\\Local\\Temp\\lud1946.tmp",
  3351. "C:\\Users\\user\\AppData\\Local\\Temp\\360Base.dll",
  3352. "C:\\Users\\user\\AppData\\Local\\Temp\\82D2A230-1B01-4337-8FA5-D76A4A2C4460.tf",
  3353. "C:\\Users\\user\\AppData\\Local\\Temp\\lud1A13.tmp",
  3354. "C:\\Users\\user\\AppData\\Local\\Temp\\360net.dll",
  3355. "C:\\Users\\user\\AppData\\Local\\Temp\\E3E8ED8A-16B3-4609-9B60-963E9042197B.tf",
  3356. "C:\\Users\\user\\AppData\\Local\\Temp\\ludashisetup.exe",
  3357. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\url22.txt",
  3358. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\url21.txt",
  3359. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\url21.txt",
  3360. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\url21.txt",
  3361. "C:\\Users\\user\\AppData\\Local\\Temp\\6FE71CCB-7D99-471b-8EDB-F7B0B976D802.tf",
  3362. "C:\\Users\\user\\AppData\\Local\\Temp\\8BE4B769-D4FD-40a6-9BC2-DB2A665DA8DC.tmp",
  3363. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\url21.txt",
  3364. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\url22.txt",
  3365. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\pc1.php",
  3366. "C:\\Users\\user\\AppData\\Local\\Temp\\CabCFF4.tmp",
  3367. "C:\\Users\\user\\AppData\\Local\\Temp\\TarCFF5.tmp",
  3368. "C:\\Users\\user\\AppData\\Local\\Temp\\CabD025.tmp",
  3369. "C:\\Users\\user\\AppData\\Local\\Temp\\TarD026.tmp",
  3370. "C:\\Users\\user\\AppData\\Local\\Temp\\CabD3C1.tmp",
  3371. "C:\\Users\\user\\AppData\\Local\\Temp\\TarD3C2.tmp",
  3372. "C:\\Users\\user\\AppData\\Local\\Temp\\496D2ADE-58D2-4f8a-AF6C-E70F4509A904.tmp\\7z.dll",
  3373. "C:\\Users\\user\\AppData\\Local\\Temp\\057A3FC4-6FA3-470c-A616-639B97DAF151.tmp",
  3374. "C:\\Users\\user\\AppData\\Local\\Temp\\CD8BEA5A-6372-4592-99D9-B9EC0F6F40D6.tmp\\360NetUL.dll",
  3375. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\8CD3B058-E34B-4f83-8FA7-46E7DCBC68BE.tf",
  3376. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp",
  3377. "C:\\Users\\user\\AppData\\Local\\Temp\\112F94FE-0F30-4f67-BA94-B25EBC651756.tmp",
  3378. "C:\\Program Files (x86)\\LuDaShi",
  3379. "C:\\Program Files (x86)\\LuDaShi\\5C60A749-8816-4f0c-83EC-6941219B91ED.tf",
  3380. "C:\\Program Files (x86)\\LuDaShi\\40B76D01-9B26-468e-8690-7C722EC4B794.tf",
  3381. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\pc1.php",
  3382. "C:\\Users\\user\\AppData\\Local\\Temp\\removelds.bat",
  3383. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\BenchmarkData\\core.spk",
  3384. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\BenchmarkData\\lds.spk",
  3385. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\BenchmarkData\\shaders_sm_3_0.cache",
  3386. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\BenchmarkData\\shaders_sm_5_0.cache",
  3387. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\deviceid.ini",
  3388. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\360LibDrvmgr.dat",
  3389. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\config\\config.xml",
  3390. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\config\\defaultskin\\defaultskin.ui",
  3391. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\config\\defaultskin\\MiniUI.xml",
  3392. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\feedback\\LuDaShiFeedback.ui",
  3393. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\feedback\\LuDaShiFeedBack.xml",
  3394. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\gameidentify.dat",
  3395. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\gameidentify_inc.dat",
  3396. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\ModeIdentify.dat",
  3397. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\widef.dat",
  3398. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Monitors.dat",
  3399. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\NNET.DAT",
  3400. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\BrowserBasic.tpi",
  3401. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\CleanTip.tpi",
  3402. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\MasterHeadline.tpi",
  3403. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\NetShield.tpi",
  3404. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\PopMgr.tpi",
  3405. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\RunExtention.tpi",
  3406. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ProcSpecial.dat",
  3407. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\SchemeLib.dat",
  3408. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\RubbishCleanEngine.dat",
  3409. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\SysSweeper.dat",
  3410. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\tracesweeper.dat",
  3411. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\WhiteList.dat",
  3412. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\BenchmarkPage\\BenchmarkPage_theme.ui",
  3413. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\BenchmarkPage\\BenchmarkPage_theme.xml",
  3414. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\CleanPage\\CleanPage_Theme.ui",
  3415. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\CleanPage\\clean_page_theme.xml",
  3416. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\default_theme.ui",
  3417. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\DownMgr\\DownMgr_theme.ui",
  3418. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\DownMgr\\downmgr_theme.xml",
  3419. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\GamePage\\GamePage_Theme.ui",
  3420. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\GamePage\\GamePage_theme.xml",
  3421. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\LdsLite\\LdsLite_theme.ui",
  3422. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\LdsLite\\LdsLite_theme.xml",
  3423. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\updatecfg.ini",
  3424. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\gamecenter.json",
  3425. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LuDaShiPreview.ui",
  3426. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LuDaShiPreview.xml",
  3427. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\navskin.ui",
  3428. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\360Base.dll",
  3429. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\360Base64.dll",
  3430. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\360Common.dll",
  3431. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\360Conf.dll",
  3432. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\360net.dll",
  3433. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\360P2SP.dll",
  3434. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\aapt.exe",
  3435. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\adb.exe",
  3436. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\AdbWinApi.dll",
  3437. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\AdbWinUsbApi.dll",
  3438. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\atiags32.dll",
  3439. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerMonZ.dll",
  3440. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ.sys",
  3441. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ1.dll",
  3442. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ10.dll",
  3443. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ11.dll",
  3444. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ2.dll",
  3445. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ4.dll",
  3446. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ4_x64.dll",
  3447. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ5.dll",
  3448. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ7.dll",
  3449. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ7_x64.dll",
  3450. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZBrowser.exe",
  3451. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZHelper_x64.exe",
  3452. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZService.exe",
  3453. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZTinyTray.exe",
  3454. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZTray.exe",
  3455. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ_Accelerator.dll",
  3456. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ_CN.exe",
  3457. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ_HardwareDll.dll",
  3458. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ_PowerSaveDll.dll",
  3459. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ComputerZ_x64.sys",
  3460. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DataMgr.dll",
  3461. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DataMgr_x64.dll",
  3462. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\360NetBase.dll",
  3463. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\360NetUL.dll",
  3464. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\7za.dll",
  3465. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\cloudcom2.dll",
  3466. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\DIFxAPI_x86.dll",
  3467. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\DownloadMgr.dll",
  3468. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\DrvInst64.exe",
  3469. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\DrvMgr.exe",
  3470. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\DrvmgrCore.dll",
  3471. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\DrvMgrUI.dll",
  3472. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\dynlenv.dll",
  3473. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\feedback\\360ScreenCapture.exe",
  3474. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\feedback\\DrvMgrFeedBack.exe",
  3475. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\feedback\\LdsMMFeedback.exe",
  3476. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\feedback\\LuDaShiFeedBack.exe",
  3477. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\ScriptExecute.exe",
  3478. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\360GameIdentify.dll",
  3479. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\360WebIdentify.dll",
  3480. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\GamePage.dll",
  3481. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\GameTray.dll",
  3482. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game\\ModeIdentify.dll",
  3483. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\HardwareProtectEx.sys",
  3484. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\HardwareProtectEx_x64.sys",
  3485. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\HardwareProtectSlim.sys",
  3486. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\HardwareProtectSlim_x64.sys",
  3487. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ipc\\ipcservice.dll",
  3488. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\LDSBenchmark.dll",
  3489. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\LdsLite.exe",
  3490. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\LiteUninst.exe",
  3491. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\LiveUpd360.dll",
  3492. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\LiveUpdate360.exe",
  3493. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\lpi\\CheckHp.dll",
  3494. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\lpi\\HpSvc.dll",
  3495. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\lpi\\TmSvc.dll",
  3496. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\MiniUI.dll",
  3497. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ModuleUpdate.exe",
  3498. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\BenchmarkLauncher.exe",
  3499. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\BenchmarkLauncher_x64.exe",
  3500. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\BenchmarkPage.dll",
  3501. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\BenchmarkSuite.dll",
  3502. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\ComputerZ_Bench.dll",
  3503. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\ComputerZ_Bench_x64.dll",
  3504. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\D3DCompiler_43.dll",
  3505. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\d3dx11_43.dll",
  3506. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\D3DX9_43.dll",
  3507. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\Display3DEx.exe",
  3508. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench\\OCLBenchmark.dll",
  3509. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\net\\netload.dll",
  3510. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\NetBridge.dll",
  3511. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\PDown.dll",
  3512. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\ConfigCenter.dll",
  3513. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\ConfigCenterStub.dll",
  3514. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin\\PopMgrStub.dll",
  3515. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\PowerSaveZ.sys",
  3516. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\PowerSaveZ_x64.sys",
  3517. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Safelive.dll",
  3518. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\SignHelper.dll",
  3519. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sites.dll",
  3520. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\SiteUIHelper.dll",
  3521. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\softmgr\\DownMgr.dll",
  3522. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\softmgr\\SoftMgr.dll",
  3523. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\softmgr\\SoftMgrInst.exe",
  3524. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\softmgr\\SoftMgrPage.dll",
  3525. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sqlite3.dll",
  3526. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\CleanHelper64.exe",
  3527. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\CleanPage.dll",
  3528. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\CleanPageEngine.dll",
  3529. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\ComputerZS1.dll",
  3530. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\HardwareCleaner.dll",
  3531. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\heavygate.dll",
  3532. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\MemoryOptimizer.exe",
  3533. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\SysSweeper.dll",
  3534. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\TEngine.dll",
  3535. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\Tracehelper.exe",
  3536. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper\\TrashClean.dll",
  3537. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\TrayHelper.exe",
  3538. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\uninst.exe",
  3539. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\update.exe",
  3540. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\arctrl.dll",
  3541. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ComputerZ12.dll",
  3542. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ComputerZ12_x64.dll",
  3543. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ComputerZ14.exe",
  3544. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ComputerZ8.dll",
  3545. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ComputerZ8_x64.dll",
  3546. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\DisPatchMini.dll",
  3547. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\Down.exe",
  3548. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\DumpUper.exe",
  3549. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\guardhp.exe",
  3550. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ie\\LdsIeView.exe",
  3551. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\iosdb.exe",
  3552. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\iosdb64.exe",
  3553. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\KitTip.dll",
  3554. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\Launcher.del.exe",
  3555. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LDSBasic.dll",
  3556. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LdsBridgeEx.exe",
  3557. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LdsDrvInst32.exe",
  3558. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LdsDrvInst64.exe",
  3559. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ldsgamecenter_ludashiembed.dll",
  3560. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\Ldshelper.exe",
  3561. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LdsMobile.exe",
  3562. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LdsVolumeCtrl.dll",
  3563. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LdsWebView.dll",
  3564. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LuDaShiHelper.dll",
  3565. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\LuDaShiPreview.exe",
  3566. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\MedalWall.exe",
  3567. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\mininews.exe",
  3568. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\MininewsPlugin.dll",
  3569. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\MobileDeviceSrv.exe",
  3570. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\NavAd.dll",
  3571. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\NavLauncher.dll",
  3572. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\NavLauncher64.dll",
  3573. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\NavPlugin.exe",
  3574. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\NavProxy64.exe",
  3575. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\PageMgr.dll",
  3576. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\Pop.dll",
  3577. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\PopEx.dll",
  3578. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\RunDll.exe",
  3579. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\SoulDancer.exe",
  3580. "C:\\Windows\\System32\\netload.dll",
  3581. "C:\\Windows\\System32\\~ld1706.tmp",
  3582. "C:\\Program Files (x86)\\LuDaShi\\HardwareProtect.sys",
  3583. "C:\\Program Files (x86)\\LuDaShi\\HardwareProtect_x64.sys",
  3584. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\pc1.php",
  3585. "C:\\Users\\user\\AppData\\Local\\Temp\\88724052-5C4D-43c2-AB79-E651A86D9696.tf",
  3586. "C:\\Users\\user\\AppData\\Local\\Temp\\F680EEB1-D32A-4b08-A7B4-4A620EDC24E1.tmp",
  3587. "C:\\Users\\user\\AppData\\Local\\Temp\\44D9C318-3C96-48bd-BEE2-728DCA60EA2D.tmp\\7z.dll",
  3588. "C:\\Users\\user\\AppData\\Local\\Temp\\7D25400F-C0D1-4d61-87A1-CDC3A014119A.tmp",
  3589. "C:\\Users\\user\\AppData\\Local\\Temp\\FD8D1A97-F266-46d4-AB52-A1B1B57B1017.tmp\\360Base.dll",
  3590. "C:\\Users\\user\\AppData\\Local\\Temp\\80FF0FC4-B660-4c6c-A9AC-9C65D281DB03.tmp",
  3591. "C:\\Users\\user\\AppData\\Local\\Temp\\DEBA4A05-2CC6-413e-8EEA-2759284E21F1.tmp\\360NetUL.dll",
  3592. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\wan1.txt",
  3593. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\D57D6E48-A965-4e2e-81DC-EE49583A0A7B.tf",
  3594. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp",
  3595. "C:\\Users\\user\\AppData\\Local\\Temp\\85C79456-8BF5-4b02-804D-994FF98CC5BE.tmp",
  3596. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\wan1.txt",
  3597. "C:\\Program Files (x86)\\LuDaShi\\gamecenter",
  3598. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\A240931B-FB7B-47e6-8FB1-EB12452FD297.tf",
  3599. "C:\\Program Files (x86)\\LuDaShi\\gamecenter\\A9D7717C-BBA4-4b59-AFCB-1267BC3C64B7.tf",
  3600. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\wan1.txt",
  3601. "C:\\Users\\user\\AppData\\Local\\Temp\\removelds_gcenter.bat",
  3602. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\alarm.mp3",
  3603. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\skin.ui",
  3604. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\updatecfg.ini",
  3605. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\cdnconfig.dat",
  3606. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\fullscreengames.json",
  3607. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\gamefixconfig.json",
  3608. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\JS\\css.js",
  3609. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\JS\\event.js",
  3610. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\JS\\ie6.js",
  3611. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\JS\\jquery.min.js",
  3612. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\JS\\json2.js",
  3613. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\JS\\utils.js",
  3614. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\GAI.dll",
  3615. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\gameuninst.exe",
  3616. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\ie\\LdsIeView.exe",
  3617. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\LDSGameCenter.exe",
  3618. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\LdsVolumeCtrl.dll",
  3619. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\LdsWebView.dll",
  3620. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\fancygame.ocx",
  3621. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\LDSGameMasterLoader.exe",
  3622. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\ZMQActiveX.ocx",
  3623. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\ZMQLaunch.exe",
  3624. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\wan1.txt",
  3625. "C:\\Users\\user\\AppData\\Local\\Temp\\14978C02-BFC3-4dc7-842F-44DB140EF4D7.tmp",
  3626. "C:\\Users\\user\\AppData\\Local\\Temp\\14978C02-BFC3-4dc7-842F-44DB140EF4D7.tmp\\FileList.xml",
  3627. "C:\\Users\\user\\AppData\\Local\\Temp\\14978C02-BFC3-4dc7-842F-44DB140EF4D7.tmp\\LDSGAMECENTER-DLL.LDSPRJ",
  3628. "C:\\Users\\user\\AppData\\Local\\Temp\\14978C02-BFC3-4dc7-842F-44DB140EF4D7.tmp\\UninstallRootDirFileList.xml",
  3629. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\ie",
  3630. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils",
  3631. "C:\\ProgramData\\CA13650D-9A13-4ed0-A280-E6776C3B647A.tmp\\Utils\\JS",
  3632. "C:\\Users\\user\\AppData\\Local\\Temp\\703B0350-B30B-4d8e-A5EF-A53DCD592433.tmp",
  3633. "C:\\Users\\user\\AppData\\Local\\Temp\\703B0350-B30B-4d8e-A5EF-A53DCD592433.tmp\\FileList.xml",
  3634. "C:\\Users\\user\\AppData\\Local\\Temp\\703B0350-B30B-4d8e-A5EF-A53DCD592433.tmp\\LDS.LDSPRJ",
  3635. "C:\\Users\\user\\AppData\\Local\\Temp\\703B0350-B30B-4d8e-A5EF-A53DCD592433.tmp\\UninstallRootDirFileList.xml",
  3636. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\BenchmarkData",
  3637. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr",
  3638. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\config",
  3639. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\config\\defaultskin",
  3640. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\DrvMgr\\feedback",
  3641. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\game",
  3642. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\ipc",
  3643. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\lpi",
  3644. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\nBench",
  3645. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\net",
  3646. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Plugin",
  3647. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\softmgr",
  3648. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\sweeper",
  3649. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes",
  3650. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default",
  3651. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\BenchmarkPage",
  3652. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\CleanPage",
  3653. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\DownMgr",
  3654. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\GamePage",
  3655. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Themes\\Default\\LdsLite",
  3656. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils",
  3657. "C:\\ProgramData\\BD6C1C80-C408-4f03-8083-1261FD97988C.tmp\\Utils\\ie",
  3658. "C:\\Windows\\System32\\config\\systemprofile\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\3RUXGK2R\\url31.txt",
  3659. "C:\\Windows\\System32\\config\\systemprofile\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\2N9ZM3JC\\url31.txt",
  3660. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\url31.txt",
  3661. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab48CE.tmp",
  3662. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar48CF.tmp",
  3663. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\url31.txt",
  3664. "C:\\Users\\user\\AppData\\Roaming\\Ludashi\\invaildhp_temp.dat",
  3665. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\user.db-wal",
  3666. "C:\\Users\\user\\AppData\\Roaming\\LDSGameCenter\\user.db-journal",
  3667. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  3668. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  3669. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\ErrorPageTemplate1",
  3670. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\errorPageStrings2",
  3671. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts1",
  3672. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\background_gradient1",
  3673. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\down1",
  3674. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012019052620190527\\index.dat",
  3675. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012019052620190527\\",
  3676. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\ErrorPageTemplate1",
  3677. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\errorPageStrings1",
  3678. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts2",
  3679. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\info_481",
  3680. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\bullet1",
  3681. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\background_gradient2",
  3682. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\jump1.txt",
  3683. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab55BE.tmp",
  3684. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar55CF.tmp",
  3685. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\url31.txt",
  3686. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\url41.txt",
  3687. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\url31.txt",
  3688. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\url22.txt",
  3689. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\url41.txt",
  3690. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\url41.txt",
  3691. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\url41.txt",
  3692. "C:\\Program Files (x86)\\LuDaShi\\update\\~282E.tmp",
  3693. "C:\\Program Files (x86)\\LuDaShi\\update\\~282E.cab",
  3694. "C:\\Program Files (x86)\\LuDaShi\\update\\~282E.cab.~p2s",
  3695. "C:\\Program Files (x86)\\LuDaShi\\update\\6FF09012-0451-4936-A587-C73F8B75E4A5",
  3696. "C:\\Program Files (x86)\\LuDaShi\\update\\update.ini",
  3697. "C:\\Windows\\System32\\~ld5923.tmp",
  3698. "C:\\Program Files (x86)\\LuDaShi\\HWParams.dat",
  3699. "C:\\Program Files (x86)\\LuDaShi\\log\\ComputerZ_HardwareDll.log",
  3700. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab6270.tmp",
  3701. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar6271.tmp",
  3702. "C:\\Program Files (x86)\\LuDaShi\\ComputerZ.dat",
  3703. "C:\\Windows\\Tasks\\ComputerZ-Tray.job",
  3704. "C:\\Windows\\sysnative\\Tasks\\ComputerZ-Tray",
  3705. "C:\\Windows\\Tasks\\Computer-Z.job",
  3706. "C:\\Windows\\sysnative\\Tasks\\Computer-Z",
  3707. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab80B6.tmp",
  3708. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar80C7.tmp",
  3709. "C:\\Users\\user\\AppData\\Roaming\\Ludashi\\deviceid.ini.tmp",
  3710. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\hao.360.cn_temp.ico",
  3711. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.baidu.com_temp.ico",
  3712. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\extend_pe.dat",
  3713. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\wan.ludashi.com_temp.ico",
  3714. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.tmall.com_temp.ico",
  3715. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.taobao.com_temp.ico",
  3716. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.jd.com_temp.ico",
  3717. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\weibo.com_temp.ico",
  3718. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.sina.com.cn_temp.ico",
  3719. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.qunar.com_temp.ico",
  3720. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.iqiyi.com_temp.ico",
  3721. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.qq.com_temp.ico",
  3722. "C:\\Users\\user\\AppData\\Roaming\\navplugin\\icohistory\\www.58.com_temp.ico",
  3723. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\url22.txt"
  3724.  
  3725.  
  3726. * Modified Registry Keys:
  3727. "HKEY_LOCAL_MACHINE\\Software\\360Safe\\Liveup",
  3728. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\360Safe\\Liveup\\mid",
  3729. "HKEY_LOCAL_MACHINE\\SOFTWARE\\LiveUpdate360",
  3730. "HKEY_LOCAL_MACHINE\\SOFTWARE\\ComMaster",
  3731. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\ComMaster\\m2",
  3732. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  3733. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\\Blob",
  3734. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\PendingFileRenameOperations",
  3735. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Ludashi",
  3736. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Ludashi\\CreateShortcut",
  3737. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Ludashi\\VendorID",
  3738. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Ludashi\\AppType",
  3739. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Ludashi\\Type",
  3740. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Ludashi\\buy",
  3741. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Svchost\\netsvcs",
  3742. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSvc\\Parameters",
  3743. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSvc\\ImagePath",
  3744. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSvc\\Start",
  3745. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSvc\\DelayedAutostart",
  3746. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSvc\\DisplayName",
  3747. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSvc\\Description",
  3748. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSvc\\Parameters\\ServiceDll",
  3749. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSvc\\Parameters\\ServiceMain",
  3750. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Ludashi\\Setup Path",
  3751. "HKEY_LOCAL_MACHINE\\SOFTWARE\\ComputerZ",
  3752. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\ComputerZ\\Setup Path",
  3753. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Ludashi\\InstallDate",
  3754. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Ludashi\\(Default)",
  3755. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\ComputerZ\\(Default)",
  3756. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Ludashi\\ReadyFor360START",
  3757. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Ludashi_is1",
  3758. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Ludashi_is1\\DisplayIcon",
  3759. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Ludashi_is1\\DisplayName",
  3760. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Ludashi_is1\\DisplayVersion",
  3761. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Ludashi_is1\\Publisher",
  3762. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Ludashi_is1\\UninstallString",
  3763. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Ludashi_is1\\URLInfoAbout",
  3764. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Ludashi_is1\\InstallLocation",
  3765. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\B1BC968BD4F49D622AA89A81F2150152A41D829C\\Blob",
  3766. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\00000005",
  3767. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000001",
  3768. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000001\\PackedCatalogItem",
  3769. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000001\\ProtocolName",
  3770. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000002",
  3771. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000002\\PackedCatalogItem",
  3772. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000002\\ProtocolName",
  3773. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000003",
  3774. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000003\\PackedCatalogItem",
  3775. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000003\\ProtocolName",
  3776. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000004",
  3777. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000004\\PackedCatalogItem",
  3778. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000004\\ProtocolName",
  3779. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000005",
  3780. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000005\\PackedCatalogItem",
  3781. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000005\\ProtocolName",
  3782. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000006",
  3783. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000006\\PackedCatalogItem",
  3784. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000006\\ProtocolName",
  3785. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000007",
  3786. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000007\\PackedCatalogItem",
  3787. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000007\\ProtocolName",
  3788. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000008",
  3789. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000008\\PackedCatalogItem",
  3790. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000008\\ProtocolName",
  3791. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000009",
  3792. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000009\\PackedCatalogItem",
  3793. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000009\\ProtocolName",
  3794. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000010",
  3795. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000010\\PackedCatalogItem",
  3796. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000010\\ProtocolName",
  3797. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000011",
  3798. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000011\\PackedCatalogItem",
  3799. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Catalog_Entries\\000000000011\\ProtocolName",
  3800. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Num_Catalog_Entries",
  3801. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Next_Catalog_Entry_ID",
  3802. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\Serial_Access_Num",
  3803. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\00000006",
  3804. "HKEY_LOCAL_MACHINE\\Software\\LDSGameCenter",
  3805. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LDSGameCenter\\InstallDate_ludashiembed",
  3806. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\GlobalAssocChangedCounter",
  3807. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesResolve",
  3808. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\Favorites",
  3809. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesChanges",
  3810. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Taskband\\FavoritesVersion",
  3811. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Ludashi\\newuser",
  3812. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Type",
  3813. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\Start",
  3814. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\ErrorControl",
  3815. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ws2ifsl\\DisplayName",
  3816. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HardwareProtect",
  3817. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HardwareProtect\\Type",
  3818. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HardwareProtect\\Start",
  3819. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HardwareProtect\\ErrorControl",
  3820. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HardwareProtect\\ImagePath",
  3821. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HardwareProtect\\DisplayName",
  3822. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HardwareProtect\\WOW64",
  3823. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
  3824. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ComputerZ_x64",
  3825. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ComputerZ_x64\\Type",
  3826. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ComputerZ_x64\\Start",
  3827. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ComputerZ_x64\\ErrorControl",
  3828. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ComputerZ_x64\\ImagePath",
  3829. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ComputerZ_x64\\DisplayName",
  3830. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\ComputerZ_x64\\WOW64",
  3831. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSvc\\Parameters\\Port",
  3832. "HKEY_LOCAL_MACHINE\\SOFTWARE\\ldssrv",
  3833. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\ldssrv\\appdata",
  3834. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSvc\\Parameters\\LDT",
  3835. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\HpSvc\\Parameters\\MET",
  3836. "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
  3837. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\ComputerZ14_RASAPI32",
  3838. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\ComputerZ14_RASAPI32\\EnableFileTracing",
  3839. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\ComputerZ14_RASAPI32\\EnableConsoleTracing",
  3840. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\ComputerZ14_RASAPI32\\FileTracingMask",
  3841. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\ComputerZ14_RASAPI32\\ConsoleTracingMask",
  3842. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\ComputerZ14_RASAPI32\\MaxFileSize",
  3843. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\ComputerZ14_RASAPI32\\FileDirectory",
  3844. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
  3845. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer",
  3846. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings",
  3847. "HKEY_LOCAL_MACHINE\\Software\\LDSGameCenterExtra",
  3848. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LDSGameCenterExtra\\LastRunVer",
  3849. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LDSGameCenter\\LastRunVer",
  3850. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BROWSER_EMULATION\\LDSGameCenter.exe",
  3851. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BLOCK_LMZ_OBJECT\\LDSGameCenter.exe",
  3852. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BLOCK_LMZ_SCRIPT\\LDSGameCenter.exe",
  3853. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LDSGameCenter\\LastShowTime",
  3854. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019072020190721",
  3855. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019072020190721\\CachePath",
  3856. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019072020190721\\CachePrefix",
  3857. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019072020190721\\CacheLimit",
  3858. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019072020190721\\CacheOptions",
  3859. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019072020190721\\CacheRepair",
  3860. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\powrprof.dll,-15",
  3861. "HKEY_CURRENT_USER\\SOFTWARE\\Ludashi",
  3862. "HKEY_CURRENT_USER\\Software\\Ludashi\\url_pid",
  3863. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\360Safe\\Liveup\\m2",
  3864. "HKEY_CURRENT_USER\\SOFTWARE\\QiLu Inc.\\mininews\\v2",
  3865. "HKEY_CURRENT_USER\\Software\\QiLu Inc.\\mininews\\v2\\screensize",
  3866. "HKEY_CURRENT_USER\\Software\\Ludashi\\360lock",
  3867. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LiveUpdate360\\IsLowPC",
  3868. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LiveUpdate360\\proxytype",
  3869. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\00000007",
  3870. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WinSock2\\Parameters\\Protocol_Catalog9\\00000008",
  3871. "HKEY_CURRENT_USER\\Software\\QiLu Inc.\\mininews\\v2\\first_time",
  3872. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
  3873. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\PreviousServiceShutdown",
  3874. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ProcessID",
  3875. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ThrottleDrege",
  3876. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Parameters\\ServiceDllUnloadOnStop",
  3877. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
  3878. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
  3879. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
  3880. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
  3881. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
  3882. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
  3883. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\C739955B-CB52-40AA-AF9D-C5156695B9B3\\Path",
  3884. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\C739955B-CB52-40AA-AF9D-C5156695B9B3\\Hash",
  3885. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\ComputerZ-Tray\\Id",
  3886. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\ComputerZ-Tray\\Index",
  3887. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\C739955B-CB52-40AA-AF9D-C5156695B9B3\\Triggers",
  3888. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\C739955B-CB52-40AA-AF9D-C5156695B9B3\\DynamicInfo",
  3889. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider",
  3890. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MediaResources\\msvideo",
  3891. "HKEY_LOCAL_MACHINE\\SOFTWARE\\QiLu Inc.\\Mobile",
  3892. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\QiLu Inc.\\Mobile\\transok",
  3893. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\MobileDeviceSrv_RASAPI32",
  3894. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\MobileDeviceSrv_RASAPI32\\EnableFileTracing",
  3895. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\MobileDeviceSrv_RASAPI32\\EnableConsoleTracing",
  3896. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\MobileDeviceSrv_RASAPI32\\FileTracingMask",
  3897. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\MobileDeviceSrv_RASAPI32\\ConsoleTracingMask",
  3898. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\MobileDeviceSrv_RASAPI32\\MaxFileSize",
  3899. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\MobileDeviceSrv_RASAPI32\\FileDirectory",
  3900. "HKEY_CURRENT_USER\\Software\\NavPlugin",
  3901. "HKEY_CURRENT_USER\\Software\\NavPlugin\\navigation",
  3902. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\NavPlugin_RASAPI32",
  3903. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\NavPlugin_RASAPI32\\EnableFileTracing",
  3904. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\NavPlugin_RASAPI32\\EnableConsoleTracing",
  3905. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\NavPlugin_RASAPI32\\FileTracingMask",
  3906. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\NavPlugin_RASAPI32\\ConsoleTracingMask",
  3907. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\NavPlugin_RASAPI32\\MaxFileSize",
  3908. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\NavPlugin_RASAPI32\\FileDirectory",
  3909. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartButtonDock",
  3910. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartButtonDock\\0",
  3911. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\StartButtonDock\\0\\ButtonHandler",
  3912. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\StartButtonDock\\0\\ButtonClassName",
  3913. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\StartButtonDock\\0\\Company",
  3914. "HKEY_CURRENT_USER\\Software\\NavPlugin\\taskbarguide",
  3915. "HKEY_CLASSES_ROOT\\CLSID\\34B3C588-D06C-4F92-929C-2C3A0BC7F821",
  3916. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\34B3C588-D06C-4F92-929C-2C3A0BC7F821\\(Default)",
  3917. "HKEY_CLASSES_ROOT\\CLSID\\34B3C588-D06C-4F92-929C-2C3A0BC7F821\\InprocServer32",
  3918. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\34B3C588-D06C-4F92-929C-2C3A0BC7F821\\InprocServer32\\(Default)",
  3919. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\34B3C588-D06C-4F92-929C-2C3A0BC7F821\\InprocServer32\\ThreadingModel",
  3920. "HKEY_CLASSES_ROOT\\CLSID\\34B3C588-D06C-4F92-929C-2C3A0BC7F821\\Implemented Categories",
  3921. "HKEY_CLASSES_ROOT\\CLSID\\34B3C588-D06C-4F92-929C-2C3A0BC7F821\\Implemented Categories\\00021492-0000-0000-C000-000000000046",
  3922. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\CEBFF5CD-ACE2-4F4F-9178-9926F41749EA\\Count\\S38OS404-1Q43-42S2-9305-67QR0O28SP23\\rkcybere.rkr",
  3923. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\CEBFF5CD-ACE2-4F4F-9178-9926F41749EA\\Count\\HRZR_PGYFRFFVBA",
  3924. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\CEBFF5CD-ACE2-4F4F-9178-9926F41749EA\\Count\\1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7\\pzq.rkr",
  3925. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\34B3C588-D06C-4F92-929C-2C3A0BC7F821 EB0FE172-1A3A-11D0-89B3-00A0C90A90AC 0xFFFF",
  3926. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Discardable\\PostSetup\\Component Categories64\\00021492-0000-0000-C000-000000000046\\Enum\\Implementing",
  3927. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\360Safe\\Liveup\\mid64"
  3928.  
  3929.  
  3930. * Deleted Registry Keys:
  3931. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46",
  3932. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\ldsuninst",
  3933. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\B1BC968BD4F49D622AA89A81F2150152A41D829C",
  3934. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\LdsTray",
  3935. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\ldsgamecenter_uninst",
  3936. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride",
  3937. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL",
  3938. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LiveUpdate360\\ieproxy",
  3939. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
  3940. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\ComputerZ-Tray.job",
  3941. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\ComputerZ-Tray.job.fp",
  3942. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\Computer-Z.job",
  3943. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\Computer-Z.job.fp",
  3944. "HKEY_CURRENT_USER\\Software\\Ludashi\\whitelistpid",
  3945. "HKEY_CURRENT_USER\\Software\\Ludashi\\enablehq"
  3946.  
  3947.  
  3948. * DNS Communications:
  3949.  
  3950. "type": "A",
  3951. "request": "s1.ludashi.com",
  3952. "answers":
  3953.  
  3954. "data": "123.125.82.104",
  3955. "type": "A"
  3956.  
  3957.  
  3958.  
  3959.  
  3960. "type": "A",
  3961. "request": "dl.360safe.com",
  3962. "answers":
  3963.  
  3964. "data": "104.192.108.17",
  3965. "type": "A"
  3966.  
  3967.  
  3968. "data": "dl.qhcdn.com",
  3969. "type": "CNAME"
  3970.  
  3971.  
  3972. "data": "104.192.108.18",
  3973. "type": "A"
  3974.  
  3975.  
  3976.  
  3977.  
  3978. "type": "A",
  3979. "request": "s.ludashi.com",
  3980. "answers":
  3981.  
  3982. "data": "114.115.221.211",
  3983. "type": "A"
  3984.  
  3985.  
  3986.  
  3987.  
  3988. "type": "A",
  3989. "request": "www.ludashi.com",
  3990. "answers":
  3991.  
  3992. "data": "114.116.39.220",
  3993. "type": "A"
  3994.  
  3995.  
  3996.  
  3997.  
  3998. "type": "A",
  3999. "request": "ocsp.verisign.com",
  4000. "answers":
  4001.  
  4002. "data": "ocsp-ds.ws.symantec.com.edgekey.net",
  4003. "type": "CNAME"
  4004.  
  4005.  
  4006. "data": "e8218.dscb1.akamaiedge.net",
  4007. "type": "CNAME"
  4008.  
  4009.  
  4010. "data": "23.50.75.27",
  4011. "type": "A"
  4012.  
  4013.  
  4014.  
  4015.  
  4016. "type": "A",
  4017. "request": "l.public.ludashi.com",
  4018. "answers":
  4019.  
  4020. "data": "115.28.112.133",
  4021. "type": "A"
  4022.  
  4023.  
  4024.  
  4025.  
  4026. "type": "A",
  4027. "request": "sf.symcd.com",
  4028. "answers":
  4029.  
  4030. "data": "ocsp-ds.ws.symantec.com.edgekey.net",
  4031. "type": "CNAME"
  4032.  
  4033.  
  4034. "data": "e8218.dscb1.akamaiedge.net",
  4035. "type": "CNAME"
  4036.  
  4037.  
  4038. "data": "23.50.75.27",
  4039. "type": "A"
  4040.  
  4041.  
  4042.  
  4043.  
  4044. "type": "A",
  4045. "request": "cdn-file-ssl-bizhi.ludashi.com",
  4046. "answers":
  4047.  
  4048. "data": "124.232.170.84",
  4049. "type": "A"
  4050.  
  4051.  
  4052. "data": "124.232.170.101",
  4053. "type": "A"
  4054.  
  4055.  
  4056. "data": "124.232.170.87",
  4057. "type": "A"
  4058.  
  4059.  
  4060. "data": "124.232.170.100",
  4061. "type": "A"
  4062.  
  4063.  
  4064. "data": "124.232.170.86",
  4065. "type": "A"
  4066.  
  4067.  
  4068. "data": "124.232.170.83",
  4069. "type": "A"
  4070.  
  4071.  
  4072. "data": "cdn-file-ssl-bizhi.ludashi.com.m.alikunlun.com",
  4073. "type": "CNAME"
  4074.  
  4075.  
  4076. "data": "124.232.170.85",
  4077. "type": "A"
  4078.  
  4079.  
  4080. "data": "124.232.170.88",
  4081. "type": "A"
  4082.  
  4083.  
  4084.  
  4085.  
  4086. "type": "A",
  4087. "request": "cdn-file-ssl-monidashi.ludashi.com",
  4088. "answers":
  4089.  
  4090. "data": "36.99.227.232",
  4091. "type": "A"
  4092.  
  4093.  
  4094. "data": "36.99.227.231",
  4095. "type": "A"
  4096.  
  4097.  
  4098. "data": "36.99.227.230",
  4099. "type": "A"
  4100.  
  4101.  
  4102. "data": "36.99.227.228",
  4103. "type": "A"
  4104.  
  4105.  
  4106. "data": "36.99.227.229",
  4107. "type": "A"
  4108.  
  4109.  
  4110. "data": "cdn-file-ssl-monidashi.ludashi.com.m.alikunlun.com",
  4111. "type": "CNAME"
  4112.  
  4113.  
  4114. "data": "36.99.227.226",
  4115. "type": "A"
  4116.  
  4117.  
  4118. "data": "36.99.227.233",
  4119. "type": "A"
  4120.  
  4121.  
  4122. "data": "36.99.227.227",
  4123. "type": "A"
  4124.  
  4125.  
  4126.  
  4127.  
  4128. "type": "A",
  4129. "request": "ini.update.360safe.com",
  4130. "answers":
  4131.  
  4132. "data": "ini.update.qhcdn.com",
  4133. "type": "CNAME"
  4134.  
  4135.  
  4136. "data": "1.192.194.229",
  4137. "type": "A"
  4138.  
  4139.  
  4140. "data": "180.153.240.52",
  4141. "type": "A"
  4142.  
  4143.  
  4144.  
  4145.  
  4146. "type": "A",
  4147. "request": "wan.ludashi.com",
  4148. "answers":
  4149.  
  4150. "data": "139.129.105.182",
  4151. "type": "A"
  4152.  
  4153.  
  4154.  
  4155.  
  4156. "type": "A",
  4157. "request": "cdn-img.ludashi.com",
  4158. "answers":
  4159.  
  4160. "data": "47.246.17.230",
  4161. "type": "A"
  4162.  
  4163.  
  4164. "data": "47.246.17.231",
  4165. "type": "A"
  4166.  
  4167.  
  4168. "data": "47.246.17.229",
  4169. "type": "A"
  4170.  
  4171.  
  4172. "data": "47.246.17.234",
  4173. "type": "A"
  4174.  
  4175.  
  4176. "data": "cdn-img.ludashi.com.w.kunlunhuf.com",
  4177. "type": "CNAME"
  4178.  
  4179.  
  4180. "data": "47.246.17.227",
  4181. "type": "A"
  4182.  
  4183.  
  4184. "data": "47.246.17.232",
  4185. "type": "A"
  4186.  
  4187.  
  4188. "data": "47.246.17.233",
  4189. "type": "A"
  4190.  
  4191.  
  4192. "data": "47.246.17.228",
  4193. "type": "A"
  4194.  
  4195.  
  4196.  
  4197.  
  4198. "type": "A",
  4199. "request": "p10.qhimg.com",
  4200. "answers":
  4201.  
  4202. "data": "p.qhimg.com.s.qihucdn.com",
  4203. "type": "CNAME"
  4204.  
  4205.  
  4206. "data": "112.64.200.166",
  4207. "type": "A"
  4208.  
  4209.  
  4210. "data": "101.226.161.171",
  4211. "type": "A"
  4212.  
  4213.  
  4214.  
  4215.  
  4216. "type": "A",
  4217. "request": "status.rapidssl.com",
  4218. "answers":
  4219.  
  4220. "data": "ocsp.digicert.com",
  4221. "type": "CNAME"
  4222.  
  4223.  
  4224. "data": "cs9.wac.phicdn.net",
  4225. "type": "CNAME"
  4226.  
  4227.  
  4228. "data": "72.21.91.29",
  4229. "type": "A"
  4230.  
  4231.  
  4232.  
  4233.  
  4234. "type": "A",
  4235. "request": "cdp.rapidssl.com",
  4236. "answers":
  4237.  
  4238. "data": "crl3.digicert.com",
  4239. "type": "CNAME"
  4240.  
  4241.  
  4242. "data": "72.21.91.29",
  4243. "type": "A"
  4244.  
  4245.  
  4246. "data": "cs9.wac.phicdn.net",
  4247. "type": "CNAME"
  4248.  
  4249.  
  4250.  
  4251.  
  4252. "type": "A",
  4253. "request": "s0.qhimg.com",
  4254. "answers":
  4255.  
  4256. "data": "54.230.192.100",
  4257. "type": "A"
  4258.  
  4259.  
  4260. "data": "54.230.192.4",
  4261. "type": "A"
  4262.  
  4263.  
  4264. "data": "54.230.192.155",
  4265. "type": "A"
  4266.  
  4267.  
  4268. "data": "d2qfvhmlvd2g6w.cloudfront.net",
  4269. "type": "CNAME"
  4270.  
  4271.  
  4272. "data": "54.230.192.175",
  4273. "type": "A"
  4274.  
  4275.  
  4276.  
  4277.  
  4278. "type": "A",
  4279. "request": "hm.baidu.com",
  4280. "answers":
  4281.  
  4282. "data": "103.235.46.191",
  4283. "type": "A"
  4284.  
  4285.  
  4286. "data": "hm.e.shifen.com",
  4287. "type": "CNAME"
  4288.  
  4289.  
  4290.  
  4291.  
  4292. "type": "A",
  4293. "request": "cdn-file.ludashi.com",
  4294. "answers":
  4295.  
  4296. "data": "124.232.169.222",
  4297. "type": "A"
  4298.  
  4299.  
  4300. "data": "124.232.169.219",
  4301. "type": "A"
  4302.  
  4303.  
  4304. "data": "124.232.169.223",
  4305. "type": "A"
  4306.  
  4307.  
  4308. "data": "124.232.169.218",
  4309. "type": "A"
  4310.  
  4311.  
  4312. "data": "124.232.169.220",
  4313. "type": "A"
  4314.  
  4315.  
  4316. "data": "124.232.169.221",
  4317. "type": "A"
  4318.  
  4319.  
  4320. "data": "124.232.169.237",
  4321. "type": "A"
  4322.  
  4323.  
  4324. "data": "124.232.169.236",
  4325. "type": "A"
  4326.  
  4327.  
  4328. "data": "cdn-file.ludashi.com.m.alikunlun.net",
  4329. "type": "CNAME"
  4330.  
  4331.  
  4332.  
  4333.  
  4334. "type": "A",
  4335. "request": "cdn-wan.ludashi.com",
  4336. "answers":
  4337.  
  4338. "data": "1.193.188.221",
  4339. "type": "A"
  4340.  
  4341.  
  4342. "data": "1.193.188.220",
  4343. "type": "A"
  4344.  
  4345.  
  4346. "data": "1.193.188.230",
  4347. "type": "A"
  4348.  
  4349.  
  4350. "data": "1.193.188.231",
  4351. "type": "A"
  4352.  
  4353.  
  4354. "data": "1.193.188.216",
  4355. "type": "A"
  4356.  
  4357.  
  4358. "data": "1.193.188.217",
  4359. "type": "A"
  4360.  
  4361.  
  4362. "data": "cdn-wan.ludashi.com.w.kunlunle.com",
  4363. "type": "CNAME"
  4364.  
  4365.  
  4366. "data": "1.193.188.218",
  4367. "type": "A"
  4368.  
  4369.  
  4370. "data": "1.193.188.219",
  4371. "type": "A"
  4372.  
  4373.  
  4374.  
  4375.  
  4376. "type": "A",
  4377. "request": "media.ludashi.com",
  4378. "answers":
  4379.  
  4380. "data": "117.78.49.231",
  4381. "type": "A"
  4382.  
  4383.  
  4384.  
  4385.  
  4386. "type": "A",
  4387. "request": "cdn-file-ssl-pc.ludashi.com",
  4388. "answers":
  4389.  
  4390. "data": "36.99.227.232",
  4391. "type": "A"
  4392.  
  4393.  
  4394. "data": "36.99.227.231",
  4395. "type": "A"
  4396.  
  4397.  
  4398. "data": "36.99.227.230",
  4399. "type": "A"
  4400.  
  4401.  
  4402. "data": "36.99.227.228",
  4403. "type": "A"
  4404.  
  4405.  
  4406. "data": "36.99.227.229",
  4407. "type": "A"
  4408.  
  4409.  
  4410. "data": "cdn-file-ssl-pc.ludashi.com.m.alikunlun.com",
  4411. "type": "CNAME"
  4412.  
  4413.  
  4414. "data": "36.99.227.226",
  4415. "type": "A"
  4416.  
  4417.  
  4418. "data": "36.99.227.233",
  4419. "type": "A"
  4420.  
  4421.  
  4422. "data": "36.99.227.227",
  4423. "type": "A"
  4424.  
  4425.  
  4426.  
  4427.  
  4428. "type": "A",
  4429. "request": "www.baidu.com",
  4430. "answers":
  4431.  
  4432. "data": "www.a.shifen.com",
  4433. "type": "CNAME"
  4434.  
  4435.  
  4436. "data": "104.193.88.77",
  4437. "type": "A"
  4438.  
  4439.  
  4440. "data": "104.193.88.123",
  4441. "type": "A"
  4442.  
  4443.  
  4444. "data": "www.wshifen.com",
  4445. "type": "CNAME"
  4446.  
  4447.  
  4448.  
  4449.  
  4450. "type": "A",
  4451. "request": "weibo.com",
  4452. "answers":
  4453.  
  4454. "data": "36.51.254.234",
  4455. "type": "A"
  4456.  
  4457.  
  4458.  
  4459.  
  4460. "type": "A",
  4461. "request": "www.weibo.com",
  4462. "answers":
  4463.  
  4464. "data": "e4141.dscb.akamaiedge.net",
  4465. "type": "CNAME"
  4466.  
  4467.  
  4468. "data": "weibo.com.edgekey.net",
  4469. "type": "CNAME"
  4470.  
  4471.  
  4472. "data": "23.221.48.212",
  4473. "type": "A"
  4474.  
  4475.  
  4476.  
  4477.  
  4478. "type": "A",
  4479. "request": "l3.public.ludashi.com",
  4480. "answers":
  4481.  
  4482. "data": "118.190.124.241",
  4483. "type": "A"
  4484.  
  4485.  
  4486.  
  4487.  
  4488. "type": "A",
  4489. "request": "update.ludashi.com",
  4490. "answers":
  4491.  
  4492. "data": "114.115.218.83",
  4493. "type": "A"
  4494.  
  4495.  
  4496.  
  4497.  
  4498. "type": "A",
  4499. "request": "ssl-hw-pc.ludashi.com",
  4500. "answers":
  4501.  
  4502. "data": "ssl-hw-pc.ludashi.com.c.cdnhwc1.com",
  4503. "type": "CNAME"
  4504.  
  4505.  
  4506. "data": "120.52.140.33",
  4507. "type": "A"
  4508.  
  4509.  
  4510. "data": "hcdnd101.gslb.c.cdnhwc2.com",
  4511. "type": "CNAME"
  4512.  
  4513.  
  4514. "data": "120.52.140.30",
  4515. "type": "A"
  4516.  
  4517.  
  4518. "data": "120.52.140.31",
  4519. "type": "A"
  4520.  
  4521.  
  4522. "data": "120.52.140.47",
  4523. "type": "A"
  4524.  
  4525.  
  4526. "data": "120.52.140.46",
  4527. "type": "A"
  4528.  
  4529.  
  4530. "data": "120.52.140.45",
  4531. "type": "A"
  4532.  
  4533.  
  4534. "data": "120.52.140.48",
  4535. "type": "A"
  4536.  
  4537.  
  4538. "data": "120.52.140.32",
  4539. "type": "A"
  4540.  
  4541.  
  4542.  
  4543.  
  4544.  
  4545. * Domains:
  4546.  
  4547. "ip": "23.50.75.27",
  4548. "domain": "sf.symcd.com"
  4549.  
  4550.  
  4551. "ip": "119.96.205.248",
  4552. "domain": "cdn-file-ssl-pc.ludashi.com"
  4553.  
  4554.  
  4555. "ip": "72.21.91.29",
  4556. "domain": "cdp.rapidssl.com"
  4557.  
  4558.  
  4559. "ip": "104.193.88.77",
  4560. "domain": "www.baidu.com"
  4561.  
  4562.  
  4563. "ip": "72.21.91.29",
  4564. "domain": "status.rapidssl.com"
  4565.  
  4566.  
  4567. "ip": "58.49.225.141",
  4568. "domain": "cdn-file.ludashi.com"
  4569.  
  4570.  
  4571. "ip": "36.99.227.228",
  4572. "domain": "cdn-file-ssl-bizhi.ludashi.com"
  4573.  
  4574.  
  4575. "ip": "47.246.18.230",
  4576. "domain": "cdn-img.ludashi.com"
  4577.  
  4578.  
  4579. "ip": "23.221.48.212",
  4580. "domain": "www.weibo.com"
  4581.  
  4582.  
  4583. "ip": "117.78.49.231",
  4584. "domain": "media.ludashi.com"
  4585.  
  4586.  
  4587. "ip": "112.64.200.166",
  4588. "domain": "p10.qhimg.com"
  4589.  
  4590.  
  4591. "ip": "36.51.254.234",
  4592. "domain": "weibo.com"
  4593.  
  4594.  
  4595. "ip": "115.28.112.133",
  4596. "domain": "l.public.ludashi.com"
  4597.  
  4598.  
  4599. "ip": "23.50.75.27",
  4600. "domain": "ocsp.verisign.com"
  4601.  
  4602.  
  4603. "ip": "1.193.188.216",
  4604. "domain": "cdn-wan.ludashi.com"
  4605.  
  4606.  
  4607. "ip": "114.115.218.83",
  4608. "domain": "update.ludashi.com"
  4609.  
  4610.  
  4611. "ip": "114.116.39.220",
  4612. "domain": "www.ludashi.com"
  4613.  
  4614.  
  4615. "ip": "119.96.205.250",
  4616. "domain": "cdn-file-ssl-monidashi.ludashi.com"
  4617.  
  4618.  
  4619. "ip": "118.190.124.241",
  4620. "domain": "l3.public.ludashi.com"
  4621.  
  4622.  
  4623. "ip": "54.230.192.155",
  4624. "domain": "s0.qhimg.com"
  4625.  
  4626.  
  4627. "ip": "103.235.46.191",
  4628. "domain": "hm.baidu.com"
  4629.  
  4630.  
  4631. "ip": "119.3.240.79",
  4632. "domain": "s.ludashi.com"
  4633.  
  4634.  
  4635. "ip": "125.88.219.50",
  4636. "domain": "ini.update.360safe.com"
  4637.  
  4638.  
  4639. "ip": "120.52.140.48",
  4640. "domain": "ssl-hw-pc.ludashi.com"
  4641.  
  4642.  
  4643. "ip": "104.192.108.17",
  4644. "domain": "dl.360safe.com"
  4645.  
  4646.  
  4647. "ip": "139.129.105.182",
  4648. "domain": "wan.ludashi.com"
  4649.  
  4650.  
  4651. "ip": "123.125.82.104",
  4652. "domain": "s1.ludashi.com"
  4653.  
  4654.  
  4655.  
  4656. * Network Communication - ICMP:
  4657.  
  4658. * Network Communication - HTTP:
  4659.  
  4660. "count": 1,
  4661. "body": "",
  4662. "uri": "http://s1.ludashi.com/url2?pid=buychannel_18&type=instonline&action=run&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4663. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  4664. "method": "GET",
  4665. "host": "s1.ludashi.com",
  4666. "version": "1.1",
  4667. "path": "/url2?pid=buychannel_18&type=instonline&action=run&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4668. "data": "GET /url2?pid=buychannel_18&type=instonline&action=run&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s1.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  4669. "port": 80
  4670.  
  4671.  
  4672. "count": 1,
  4673. "body": "",
  4674. "uri": "http://s1.ludashi.com/url2?pid=buychannel_18&type=instonline&action=down_start&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4675. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  4676. "method": "GET",
  4677. "host": "s1.ludashi.com",
  4678. "version": "1.1",
  4679. "path": "/url2?pid=buychannel_18&type=instonline&action=down_start&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4680. "data": "GET /url2?pid=buychannel_18&type=instonline&action=down_start&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s1.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  4681. "port": 80
  4682.  
  4683.  
  4684. "count": 1,
  4685. "body": "",
  4686. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  4687. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  4688. "method": "GET",
  4689. "host": "dl.360safe.com",
  4690. "version": "1.1",
  4691. "path": "/ludashi/ludashi_buy.exe",
  4692. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  4693. "port": 80
  4694.  
  4695.  
  4696. "count": 1,
  4697. "body": "",
  4698. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&type=instonline&action=run&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4699. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  4700. "method": "GET",
  4701. "host": "s.ludashi.com",
  4702. "version": "1.1",
  4703. "path": "/url2?pid=buychannel_18&type=instonline&action=run&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4704. "data": "GET /url2?pid=buychannel_18&type=instonline&action=run&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nConnection: Keep-Alive\r\nHost: s.ludashi.com\r\n\r\n",
  4705. "port": 80
  4706.  
  4707.  
  4708. "count": 1,
  4709. "body": "",
  4710. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&type=instonline&action=down_start&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4711. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  4712. "method": "GET",
  4713. "host": "s.ludashi.com",
  4714. "version": "1.1",
  4715. "path": "/url2?pid=buychannel_18&type=instonline&action=down_start&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4716. "data": "GET /url2?pid=buychannel_18&type=instonline&action=down_start&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nConnection: Keep-Alive\r\nHost: s.ludashi.com\r\n\r\n",
  4717. "port": 80
  4718.  
  4719.  
  4720. "count": 1,
  4721. "body": "",
  4722. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  4723. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  4724. "method": "GET",
  4725. "host": "dl.360safe.com",
  4726. "version": "1.1",
  4727. "path": "/ludashi/ludashi_buy.exe",
  4728. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=51806208-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  4729. "port": 80
  4730.  
  4731.  
  4732. "count": 1,
  4733. "body": "",
  4734. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  4735. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  4736. "method": "GET",
  4737. "host": "dl.360safe.com",
  4738. "version": "1.1",
  4739. "path": "/ludashi/ludashi_buy.exe",
  4740. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=12951552-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  4741. "port": 80
  4742.  
  4743.  
  4744. "count": 1,
  4745. "body": "",
  4746. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  4747. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  4748. "method": "GET",
  4749. "host": "dl.360safe.com",
  4750. "version": "1.1",
  4751. "path": "/ludashi/ludashi_buy.exe",
  4752. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=25903104-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  4753. "port": 80
  4754.  
  4755.  
  4756. "count": 1,
  4757. "body": "",
  4758. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  4759. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  4760. "method": "GET",
  4761. "host": "dl.360safe.com",
  4762. "version": "1.1",
  4763. "path": "/ludashi/ludashi_buy.exe",
  4764. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=38854656-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  4765. "port": 80
  4766.  
  4767.  
  4768. "count": 1,
  4769. "body": "",
  4770. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  4771. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  4772. "method": "GET",
  4773. "host": "dl.360safe.com",
  4774. "version": "1.1",
  4775. "path": "/ludashi/ludashi_buy.exe",
  4776. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=21080540-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  4777. "port": 80
  4778.  
  4779.  
  4780. "count": 1,
  4781. "body": "",
  4782. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  4783. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  4784. "method": "GET",
  4785. "host": "dl.360safe.com",
  4786. "version": "1.1",
  4787. "path": "/ludashi/ludashi_buy.exe",
  4788. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=50576912-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  4789. "port": 80
  4790.  
  4791.  
  4792. "count": 1,
  4793. "body": "",
  4794. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  4795. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  4796. "method": "GET",
  4797. "host": "dl.360safe.com",
  4798. "version": "1.1",
  4799. "path": "/ludashi/ludashi_buy.exe",
  4800. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=30797336-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  4801. "port": 80
  4802.  
  4803.  
  4804. "count": 1,
  4805. "body": "",
  4806. "uri": "http://s1.ludashi.com/url2?pid=buychannel_18&type=instonline&action=down_success&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4807. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  4808. "method": "GET",
  4809. "host": "s1.ludashi.com",
  4810. "version": "1.1",
  4811. "path": "/url2?pid=buychannel_18&type=instonline&action=down_success&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4812. "data": "GET /url2?pid=buychannel_18&type=instonline&action=down_success&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s1.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  4813. "port": 80
  4814.  
  4815.  
  4816. "count": 1,
  4817. "body": "",
  4818. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&type=instonline&action=down_success&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4819. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  4820. "method": "GET",
  4821. "host": "s.ludashi.com",
  4822. "version": "1.1",
  4823. "path": "/url2?pid=buychannel_18&type=instonline&action=down_success&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4824. "data": "GET /url2?pid=buychannel_18&type=instonline&action=down_success&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nConnection: Keep-Alive\r\nHost: s.ludashi.com\r\n\r\n",
  4825. "port": 80
  4826.  
  4827.  
  4828. "count": 1,
  4829. "body": "",
  4830. "uri": "http://s1.ludashi.com/url2?pid=buychannel_18&type=instonline&action=down_exec&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4831. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  4832. "method": "GET",
  4833. "host": "s1.ludashi.com",
  4834. "version": "1.1",
  4835. "path": "/url2?pid=buychannel_18&type=instonline&action=down_exec&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4836. "data": "GET /url2?pid=buychannel_18&type=instonline&action=down_exec&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s1.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  4837. "port": 80
  4838.  
  4839.  
  4840. "count": 1,
  4841. "body": "",
  4842. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=run",
  4843. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  4844. "method": "GET",
  4845. "host": "s.ludashi.com",
  4846. "version": "1.1",
  4847. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=run",
  4848. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=run HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  4849. "port": 80
  4850.  
  4851.  
  4852. "count": 1,
  4853. "body": "",
  4854. "uri": "http://s.ludashi.com/url2?pid=buy&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=res_pid",
  4855. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  4856. "method": "GET",
  4857. "host": "s.ludashi.com",
  4858. "version": "1.1",
  4859. "path": "/url2?pid=buy&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=res_pid",
  4860. "data": "GET /url2?pid=buy&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=res_pid HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  4861. "port": 80
  4862.  
  4863.  
  4864. "count": 1,
  4865. "body": "",
  4866. "uri": "http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X%2B%2BhEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECECUM6OAwYS6fK4n3BU18%2BP0%3D",
  4867. "user-agent": "Microsoft-CryptoAPI/6.1",
  4868. "method": "GET",
  4869. "host": "ocsp.verisign.com",
  4870. "version": "1.1",
  4871. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X%2B%2BhEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECECUM6OAwYS6fK4n3BU18%2BP0%3D",
  4872. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRIt2RJ89X%2B%2BhEzqoBeQg8PymQ2UQQUANhaTCXBIuWLMe9tuvPMXynxDWECECUM6OAwYS6fK4n3BU18%2BP0%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.verisign.com\r\n\r\n",
  4873. "port": 80
  4874.  
  4875.  
  4876. "count": 1,
  4877. "body": "",
  4878. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&type=instonline&action=down_exec&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4879. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  4880. "method": "GET",
  4881. "host": "s.ludashi.com",
  4882. "version": "1.1",
  4883. "path": "/url2?pid=buychannel_18&type=instonline&action=down_exec&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc",
  4884. "data": "GET /url2?pid=buychannel_18&type=instonline&action=down_exec&appver=5.0.0.2015&modver=5.0.0.2015&mid=db2c71648b5a939e38cf679b921b03dc HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nConnection: Keep-Alive\r\nHost: s.ludashi.com\r\n\r\n",
  4885. "port": 80
  4886.  
  4887.  
  4888. "count": 1,
  4889. "body": "",
  4890. "uri": "http://www.ludashi.com/stat/pc.php?pid=buychannel_18&type=instnew&action=run&appver=5.1019.1060.717&modver=5.1019.1060.717&mid=db2c71648b5a939e38cf679b921b03dc&sign_name=pc&sign=a9457a79aebd07c1df73674c1f26535c",
  4891. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  4892. "method": "GET",
  4893. "host": "www.ludashi.com",
  4894. "version": "1.1",
  4895. "path": "/stat/pc.php?pid=buychannel_18&type=instnew&action=run&appver=5.1019.1060.717&modver=5.1019.1060.717&mid=db2c71648b5a939e38cf679b921b03dc&sign_name=pc&sign=a9457a79aebd07c1df73674c1f26535c",
  4896. "data": "GET /stat/pc.php?pid=buychannel_18&type=instnew&action=run&appver=5.1019.1060.717&modver=5.1019.1060.717&mid=db2c71648b5a939e38cf679b921b03dc&sign_name=pc&sign=a9457a79aebd07c1df73674c1f26535c HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: www.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  4897. "port": 80
  4898.  
  4899.  
  4900. "count": 1,
  4901. "body": "",
  4902. "uri": "http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D",
  4903. "user-agent": "Microsoft-CryptoAPI/6.1",
  4904. "method": "GET",
  4905. "host": "ocsp.verisign.com",
  4906. "version": "1.1",
  4907. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D",
  4908. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.verisign.com\r\n\r\n",
  4909. "port": 80
  4910.  
  4911.  
  4912. "count": 1,
  4913. "body": "",
  4914. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=setup_pid",
  4915. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  4916. "method": "GET",
  4917. "host": "s.ludashi.com",
  4918. "version": "1.1",
  4919. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=setup_pid",
  4920. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=setup_pid HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  4921. "port": 80
  4922.  
  4923.  
  4924. "count": 1,
  4925. "body": "",
  4926. "uri": "http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEFG9XY5FuCoCEPF%2F5MUjNGg%3D",
  4927. "user-agent": "Microsoft-CryptoAPI/6.1",
  4928. "method": "GET",
  4929. "host": "ocsp.verisign.com",
  4930. "version": "1.1",
  4931. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEFG9XY5FuCoCEPF%2F5MUjNGg%3D",
  4932. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEFG9XY5FuCoCEPF%2F5MUjNGg%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.verisign.com\r\n\r\n",
  4933. "port": 80
  4934.  
  4935.  
  4936. "count": 1,
  4937. "body": "",
  4938. "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  4939. "user-agent": "Microsoft-CryptoAPI/6.1",
  4940. "method": "GET",
  4941. "host": "www.download.windowsupdate.com",
  4942. "version": "1.1",
  4943. "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  4944. "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86401\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Fri, 22 Feb 2019 16:53:13 GMT\r\nIf-None-Match: \"80e22c19cfcad41:0\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
  4945. "port": 80
  4946.  
  4947.  
  4948. "count": 1,
  4949. "body": "",
  4950. "uri": "http://www.ludashi.com/cms/pc_mobile/quickxiaolu.php?channel=buychannel_18&s=0&q=0&k=0&h=0",
  4951. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  4952. "method": "GET",
  4953. "host": "www.ludashi.com",
  4954. "version": "1.1",
  4955. "path": "/cms/pc_mobile/quickxiaolu.php?channel=buychannel_18&s=0&q=0&k=0&h=0",
  4956. "data": "GET /cms/pc_mobile/quickxiaolu.php?channel=buychannel_18&s=0&q=0&k=0&h=0 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: www.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  4957. "port": 80
  4958.  
  4959.  
  4960. "count": 1,
  4961. "body": "-----------------------------1qaz34940095\r\nContent-Disposition: form-data; name=\"data\"\r\n\r\nL4bwobzrJNE0zmOKR/jsmpotuoAbycKPxOTuSScrWL3kWCEtAaif3KJjoJxpcoGxYIY6g5DsPzWig+E58pcxxvQnhiwQCUi6WmGystE1BLWgDvsugLSOdTtzDkMSgIxQS/U7QgTu6h2Lh4THW4ImEJlMzLZA2ZJ9Uk/D14+tWppliGdJStNaLkWoNV7By4tEy57oCYduUm7yC2c0kfzor+FwuvOJIEvjjdzGVYCPmZDsJuRLyW1bPhwlEUIS8gtl\r\n-----------------------------1qaz34940095--\r\n",
  4962. "uri": "http://l.public.ludashi.com/pc/ud/dogsun",
  4963. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  4964. "method": "POST",
  4965. "host": "l.public.ludashi.com",
  4966. "version": "1.1",
  4967. "path": "/pc/ud/dogsun",
  4968. "data": "POST /pc/ud/dogsun HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nContent-Type: multipart/form-data; boundary=---------------------------1qaz34940095\r\nHost: l.public.ludashi.com\r\nContent-Length: 393\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n-----------------------------1qaz34940095\r\nContent-Disposition: form-data; name=\"data\"\r\n\r\nL4bwobzrJNE0zmOKR/jsmpotuoAbycKPxOTuSScrWL3kWCEtAaif3KJjoJxpcoGxYIY6g5DsPzWig+E58pcxxvQnhiwQCUi6WmGystE1BLWgDvsugLSOdTtzDkMSgIxQS/U7QgTu6h2Lh4THW4ImEJlMzLZA2ZJ9Uk/D14+tWppliGdJStNaLkWoNV7By4tEy57oCYduUm7yC2c0kfzor+FwuvOJIEvjjdzGVYCPmZDsJuRLyW1bPhwlEUIS8gtl\r\n-----------------------------1qaz34940095--\r\n",
  4969. "port": 80
  4970.  
  4971.  
  4972. "count": 1,
  4973. "body": "",
  4974. "uri": "http://sf.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEEczu2CJ4y%2FNIk0OSd62Y9o%3D",
  4975. "user-agent": "Microsoft-CryptoAPI/6.1",
  4976. "method": "GET",
  4977. "host": "sf.symcd.com",
  4978. "version": "1.1",
  4979. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEEczu2CJ4y%2FNIk0OSd62Y9o%3D",
  4980. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEEczu2CJ4y%2FNIk0OSd62Y9o%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: sf.symcd.com\r\n\r\n",
  4981. "port": 80
  4982.  
  4983.  
  4984. "count": 1,
  4985. "body": "",
  4986. "uri": "http://www.ludashi.com/stat/pc.php?pid=buychannel_18&type=instnew&action=startpage_install&appver=5.1019.1060.717&modver=5.1019.1060.717&mid=db2c71648b5a939e38cf679b921b03dc&sign_name=pc&sign=b58d3571f87526269de1d72bde5244cc",
  4987. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  4988. "method": "GET",
  4989. "host": "www.ludashi.com",
  4990. "version": "1.1",
  4991. "path": "/stat/pc.php?pid=buychannel_18&type=instnew&action=startpage_install&appver=5.1019.1060.717&modver=5.1019.1060.717&mid=db2c71648b5a939e38cf679b921b03dc&sign_name=pc&sign=b58d3571f87526269de1d72bde5244cc",
  4992. "data": "GET /stat/pc.php?pid=buychannel_18&type=instnew&action=startpage_install&appver=5.1019.1060.717&modver=5.1019.1060.717&mid=db2c71648b5a939e38cf679b921b03dc&sign_name=pc&sign=b58d3571f87526269de1d72bde5244cc HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: www.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  4993. "port": 80
  4994.  
  4995.  
  4996. "count": 1,
  4997. "body": "",
  4998. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=startpage_install",
  4999. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5000. "method": "GET",
  5001. "host": "s.ludashi.com",
  5002. "version": "1.1",
  5003. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=startpage_install",
  5004. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=startpage_install HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5005. "port": 80
  5006.  
  5007.  
  5008. "count": 1,
  5009. "body": "",
  5010. "uri": "http://cdn-file-ssl-monidashi.ludashi.com/gamemaster/update/instpatch.cab",
  5011. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5012. "method": "GET",
  5013. "host": "cdn-file-ssl-monidashi.ludashi.com",
  5014. "version": "1.1",
  5015. "path": "/gamemaster/update/instpatch.cab",
  5016. "data": "GET /gamemaster/update/instpatch.cab HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file-ssl-monidashi.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5017. "port": 80
  5018.  
  5019.  
  5020. "count": 1,
  5021. "body": "",
  5022. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=call_hpsvc_dll_start",
  5023. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5024. "method": "GET",
  5025. "host": "s.ludashi.com",
  5026. "version": "1.1",
  5027. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=call_hpsvc_dll_start",
  5028. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=call_hpsvc_dll_start HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5029. "port": 80
  5030.  
  5031.  
  5032. "count": 1,
  5033. "body": "",
  5034. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=free_hpsvc_dll_end",
  5035. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5036. "method": "GET",
  5037. "host": "s.ludashi.com",
  5038. "version": "1.1",
  5039. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=free_hpsvc_dll_end",
  5040. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=free_hpsvc_dll_end HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5041. "port": 80
  5042.  
  5043.  
  5044. "count": 1,
  5045. "body": "",
  5046. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=call_hpsvc_dll_end",
  5047. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5048. "method": "GET",
  5049. "host": "s.ludashi.com",
  5050. "version": "1.1",
  5051. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=call_hpsvc_dll_end",
  5052. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=call_hpsvc_dll_end HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5053. "port": 80
  5054.  
  5055.  
  5056. "count": 1,
  5057. "body": "",
  5058. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=free_hpsvc_dll_start",
  5059. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5060. "method": "GET",
  5061. "host": "s.ludashi.com",
  5062. "version": "1.1",
  5063. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=free_hpsvc_dll_start",
  5064. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=free_hpsvc_dll_start HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5065. "port": 80
  5066.  
  5067.  
  5068. "count": 1,
  5069. "body": "",
  5070. "uri": "http://ocsp.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D",
  5071. "user-agent": "Microsoft-CryptoAPI/6.1",
  5072. "method": "GET",
  5073. "host": "ocsp.thawte.com",
  5074. "version": "1.1",
  5075. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D",
  5076. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D HTTP/1.1\r\nCache-Control: max-age = 320712\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Wed, 20 Mar 2019 11:42:01 GMT\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.thawte.com\r\n\r\n",
  5077. "port": 80
  5078.  
  5079.  
  5080. "count": 1,
  5081. "body": "",
  5082. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=inst_lsp_fail",
  5083. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5084. "method": "GET",
  5085. "host": "s.ludashi.com",
  5086. "version": "1.1",
  5087. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=inst_lsp_fail",
  5088. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=inst_lsp_fail HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5089. "port": 80
  5090.  
  5091.  
  5092. "count": 1,
  5093. "body": "",
  5094. "uri": "http://th.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9%2BWQCtWAQU1A1lP3q9NMb%2BR%2BdMDcC98t4Vq3ECEB%2BRRV0JlxbvHSmZH0H4yIg%3D",
  5095. "user-agent": "Microsoft-CryptoAPI/6.1",
  5096. "method": "GET",
  5097. "host": "th.symcd.com",
  5098. "version": "1.1",
  5099. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9%2BWQCtWAQU1A1lP3q9NMb%2BR%2BdMDcC98t4Vq3ECEB%2BRRV0JlxbvHSmZH0H4yIg%3D",
  5100. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9%2BWQCtWAQU1A1lP3q9NMb%2BR%2BdMDcC98t4Vq3ECEB%2BRRV0JlxbvHSmZH0H4yIg%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: th.symcd.com\r\n\r\n",
  5101. "port": 80
  5102.  
  5103.  
  5104. "count": 1,
  5105. "body": "",
  5106. "uri": "http://ini.update.360safe.com/lds/update_patch.cab?t=201907201028",
  5107. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5108. "method": "GET",
  5109. "host": "ini.update.360safe.com",
  5110. "version": "1.1",
  5111. "path": "/lds/update_patch.cab?t=201907201028",
  5112. "data": "GET /lds/update_patch.cab?t=201907201028 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: ini.update.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5113. "port": 80
  5114.  
  5115.  
  5116. "count": 1,
  5117. "body": "",
  5118. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=sys_start_suc",
  5119. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5120. "method": "GET",
  5121. "host": "s.ludashi.com",
  5122. "version": "1.1",
  5123. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=sys_start_suc",
  5124. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=sys_start_suc HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5125. "port": 80
  5126.  
  5127.  
  5128. "count": 1,
  5129. "body": "",
  5130. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=sys_inst_suc",
  5131. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5132. "method": "GET",
  5133. "host": "s.ludashi.com",
  5134. "version": "1.1",
  5135. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=sys_inst_suc",
  5136. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=sys_inst_suc HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5137. "port": 80
  5138.  
  5139.  
  5140. "count": 1,
  5141. "body": "",
  5142. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=operate&action=install",
  5143. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5144. "method": "GET",
  5145. "host": "s.ludashi.com",
  5146. "version": "1.1",
  5147. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=operate&action=install",
  5148. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=operate&action=install HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5149. "port": 80
  5150.  
  5151.  
  5152. "count": 1,
  5153. "body": "",
  5154. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=install_success",
  5155. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5156. "method": "GET",
  5157. "host": "s.ludashi.com",
  5158. "version": "1.1",
  5159. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=install_success",
  5160. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=install_success HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5161. "port": 80
  5162.  
  5163.  
  5164. "count": 1,
  5165. "body": "",
  5166. "uri": "http://www.ludashi.com/stat/pc.php?pid=buychannel_18&type=instnew&action=install_success&appver=5.1019.1060.717&modver=5.1019.1060.717&mid=db2c71648b5a939e38cf679b921b03dc&sign_name=pc&sign=6ac9de34f73ee2c45dedacebf2a8bf15",
  5167. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5168. "method": "GET",
  5169. "host": "www.ludashi.com",
  5170. "version": "1.1",
  5171. "path": "/stat/pc.php?pid=buychannel_18&type=instnew&action=install_success&appver=5.1019.1060.717&modver=5.1019.1060.717&mid=db2c71648b5a939e38cf679b921b03dc&sign_name=pc&sign=6ac9de34f73ee2c45dedacebf2a8bf15",
  5172. "data": "GET /stat/pc.php?pid=buychannel_18&type=instnew&action=install_success&appver=5.1019.1060.717&modver=5.1019.1060.717&mid=db2c71648b5a939e38cf679b921b03dc&sign_name=pc&sign=6ac9de34f73ee2c45dedacebf2a8bf15 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: www.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5173. "port": 80
  5174.  
  5175.  
  5176. "count": 2,
  5177. "body": "",
  5178. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=real_new_inst",
  5179. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5180. "method": "GET",
  5181. "host": "s.ludashi.com",
  5182. "version": "1.1",
  5183. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=real_new_inst",
  5184. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=real_new_inst HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5185. "port": 80
  5186.  
  5187.  
  5188. "count": 1,
  5189. "body": "",
  5190. "uri": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.0.0.1001&type=helper&action=run&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee",
  5191. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5192. "method": "GET",
  5193. "host": "s.ludashi.com",
  5194. "version": "1.1",
  5195. "path": "/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.0.0.1001&type=helper&action=run&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee",
  5196. "data": "GET /url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.0.0.1001&type=helper&action=run&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5197. "port": 80
  5198.  
  5199.  
  5200. "count": 1,
  5201. "body": "",
  5202. "uri": "http://s.ludashi.com/wan?type=install&action=start&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=1ba29166bea96c068cd8c97645aa5c50",
  5203. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5204. "method": "GET",
  5205. "host": "s.ludashi.com",
  5206. "version": "1.1",
  5207. "path": "/wan?type=install&action=start&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=1ba29166bea96c068cd8c97645aa5c50",
  5208. "data": "GET /wan?type=install&action=start&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=1ba29166bea96c068cd8c97645aa5c50 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5209. "port": 80
  5210.  
  5211.  
  5212. "count": 1,
  5213. "body": "",
  5214. "uri": "http://s.ludashi.com/wan?type=setup_pid&action=ludashiembed__buychannel_18&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=f4e28e99d16e247a133370377be4409d",
  5215. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5216. "method": "GET",
  5217. "host": "s.ludashi.com",
  5218. "version": "1.1",
  5219. "path": "/wan?type=setup_pid&action=ludashiembed__buychannel_18&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=f4e28e99d16e247a133370377be4409d",
  5220. "data": "GET /wan?type=setup_pid&action=ludashiembed__buychannel_18&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=f4e28e99d16e247a133370377be4409d HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5221. "port": 80
  5222.  
  5223.  
  5224. "count": 1,
  5225. "body": "",
  5226. "uri": "http://s.ludashi.com/wan?type=install&action=startpage_install&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=601b2fe6e14498bf4f28bbc10eb881b5",
  5227. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5228. "method": "GET",
  5229. "host": "s.ludashi.com",
  5230. "version": "1.1",
  5231. "path": "/wan?type=install&action=startpage_install&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=601b2fe6e14498bf4f28bbc10eb881b5",
  5232. "data": "GET /wan?type=install&action=startpage_install&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=601b2fe6e14498bf4f28bbc10eb881b5 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5233. "port": 80
  5234.  
  5235.  
  5236. "count": 1,
  5237. "body": "",
  5238. "uri": "http://wan.ludashi.com/cms/install/getsetuppush.php?channel=ludashiembed__buychannel_18&version=1.2.6.1830",
  5239. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5240. "method": "GET",
  5241. "host": "wan.ludashi.com",
  5242. "version": "1.1",
  5243. "path": "/cms/install/getsetuppush.php?channel=ludashiembed__buychannel_18&version=1.2.6.1830",
  5244. "data": "GET /cms/install/getsetuppush.php?channel=ludashiembed__buychannel_18&version=1.2.6.1830 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: wan.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5245. "port": 80
  5246.  
  5247.  
  5248. "count": 1,
  5249. "body": "",
  5250. "uri": "http://cdn-img.ludashi.com/a/201807/13/5b48531dd0754.ico",
  5251. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5252. "method": "GET",
  5253. "host": "cdn-img.ludashi.com",
  5254. "version": "1.1",
  5255. "path": "/a/201807/13/5b48531dd0754.ico",
  5256. "data": "GET /a/201807/13/5b48531dd0754.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-img.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5257. "port": 80
  5258.  
  5259.  
  5260. "count": 1,
  5261. "body": "",
  5262. "uri": "http://www.ludashi.com/api/service/cfg.php?from=ms&appver=5.1019.1060.717&pid=buychannel_18&modver=6.5019.1005.221&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&hash=&os=win7",
  5263. "user-agent": "",
  5264. "method": "GET",
  5265. "host": "www.ludashi.com",
  5266. "version": "1.1",
  5267. "path": "/api/service/cfg.php?from=ms&appver=5.1019.1060.717&pid=buychannel_18&modver=6.5019.1005.221&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&hash=&os=win7",
  5268. "data": "GET /api/service/cfg.php?from=ms&appver=5.1019.1060.717&pid=buychannel_18&modver=6.5019.1005.221&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&hash=&os=win7 HTTP/1.1\r\nConnection: Close\r\nHost: www.ludashi.com\r\n\r\n",
  5269. "port": 80
  5270.  
  5271.  
  5272. "count": 1,
  5273. "body": "",
  5274. "uri": "http://s.ludashi.com/wan?type=install&action=add_game_dsk&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=f38fe438af16597a0f3ed30cb2429d22",
  5275. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5276. "method": "GET",
  5277. "host": "s.ludashi.com",
  5278. "version": "1.1",
  5279. "path": "/wan?type=install&action=add_game_dsk&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=f38fe438af16597a0f3ed30cb2429d22",
  5280. "data": "GET /wan?type=install&action=add_game_dsk&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=f38fe438af16597a0f3ed30cb2429d22 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5281. "port": 80
  5282.  
  5283.  
  5284. "count": 1,
  5285. "body": "",
  5286. "uri": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.5019.1005.221&type=svc&action=ms_lah_start&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee",
  5287. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5288. "method": "GET",
  5289. "host": "s.ludashi.com",
  5290. "version": "1.1",
  5291. "path": "/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.5019.1005.221&type=svc&action=ms_lah_start&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee",
  5292. "data": "GET /url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.5019.1005.221&type=svc&action=ms_lah_start&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5293. "port": 80
  5294.  
  5295.  
  5296. "count": 1,
  5297. "body": "",
  5298. "uri": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.5019.1005.221&type=svc&action=svc_init&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee",
  5299. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5300. "method": "GET",
  5301. "host": "s.ludashi.com",
  5302. "version": "1.1",
  5303. "path": "/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.5019.1005.221&type=svc&action=svc_init&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee",
  5304. "data": "GET /url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=6.5019.1005.221&type=svc&action=svc_init&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5305. "port": 80
  5306.  
  5307.  
  5308. "count": 1,
  5309. "body": "",
  5310. "uri": "http://s.ludashi.com/wan?type=install&action=add_game_pin&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=0c3d79e910fb813e7525e07c638cfaf4",
  5311. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5312. "method": "GET",
  5313. "host": "s.ludashi.com",
  5314. "version": "1.1",
  5315. "path": "/wan?type=install&action=add_game_pin&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=0c3d79e910fb813e7525e07c638cfaf4",
  5316. "data": "GET /wan?type=install&action=add_game_pin&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=0c3d79e910fb813e7525e07c638cfaf4 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5317. "port": 80
  5318.  
  5319.  
  5320. "count": 1,
  5321. "body": "",
  5322. "uri": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=1.5019.1005.221&type=unite&action=reject_from_svc&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&ex1=a07e4d8",
  5323. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5324. "method": "GET",
  5325. "host": "s.ludashi.com",
  5326. "version": "1.1",
  5327. "path": "/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=1.5019.1005.221&type=unite&action=reject_from_svc&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&ex1=a07e4d8",
  5328. "data": "GET /url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=1.5019.1005.221&type=unite&action=reject_from_svc&app=ludashi&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&ex1=a07e4d8 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5329. "port": 80
  5330.  
  5331.  
  5332. "count": 1,
  5333. "body": "",
  5334. "uri": "http://s.ludashi.com/wan?type=install&action=new&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=e6965e577daafd3039758a1fc330b771",
  5335. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5336. "method": "GET",
  5337. "host": "s.ludashi.com",
  5338. "version": "1.1",
  5339. "path": "/wan?type=install&action=new&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=e6965e577daafd3039758a1fc330b771",
  5340. "data": "GET /wan?type=install&action=new&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=e6965e577daafd3039758a1fc330b771 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5341. "port": 80
  5342.  
  5343.  
  5344. "count": 1,
  5345. "body": "",
  5346. "uri": "http://s.ludashi.com/wan?type=install&action=success&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=977622ec4befc6f58fcec391c704c289",
  5347. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5348. "method": "GET",
  5349. "host": "s.ludashi.com",
  5350. "version": "1.1",
  5351. "path": "/wan?type=install&action=success&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=977622ec4befc6f58fcec391c704c289",
  5352. "data": "GET /wan?type=install&action=success&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=977622ec4befc6f58fcec391c704c289 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5353. "port": 80
  5354.  
  5355.  
  5356. "count": 1,
  5357. "body": "",
  5358. "uri": "http://s.ludashi.com/wan?type=startm&action=ludashiembed__buychannelall_inst_run&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=3c1cd7c407f4dccdaad2e7346fb8202c&from=ludashiembed__buychannelall_inst_run&forcetick=34734937",
  5359. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5360. "method": "GET",
  5361. "host": "s.ludashi.com",
  5362. "version": "1.1",
  5363. "path": "/wan?type=startm&action=ludashiembed__buychannelall_inst_run&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=3c1cd7c407f4dccdaad2e7346fb8202c&from=ludashiembed__buychannelall_inst_run&forcetick=34734937",
  5364. "data": "GET /wan?type=startm&action=ludashiembed__buychannelall_inst_run&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=3c1cd7c407f4dccdaad2e7346fb8202c&from=ludashiembed__buychannelall_inst_run&forcetick=34734937 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5365. "port": 80
  5366.  
  5367.  
  5368. "count": 1,
  5369. "body": "",
  5370. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=xleh_shortcut_rate_low",
  5371. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5372. "method": "GET",
  5373. "host": "s.ludashi.com",
  5374. "version": "1.1",
  5375. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=xleh_shortcut_rate_low",
  5376. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=xleh_shortcut_rate_low HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5377. "port": 80
  5378.  
  5379.  
  5380. "count": 1,
  5381. "body": "",
  5382. "uri": "http://wan.ludashi.com/cms/web/stat/domain_list.php?version=1.2.6.1830&channel=ludashiembed__buychannel_18",
  5383. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5384. "method": "GET",
  5385. "host": "wan.ludashi.com",
  5386. "version": "1.1",
  5387. "path": "/cms/web/stat/domain_list.php?version=1.2.6.1830&channel=ludashiembed__buychannel_18",
  5388. "data": "GET /cms/web/stat/domain_list.php?version=1.2.6.1830&channel=ludashiembed__buychannel_18 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: wan.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5389. "port": 80
  5390.  
  5391.  
  5392. "count": 3,
  5393. "body": "\n\t\"protocol\":\t\"1.0\",\n\t\"version\":\t\"1.2.6.1830\",\n\t\"channel\":\t\"ludashiembed__buychannel_18\"\n",
  5394. "uri": "http://wan.ludashi.com/Getconfig?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36",
  5395. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5396. "method": "POST",
  5397. "host": "wan.ludashi.com",
  5398. "version": "1.1",
  5399. "path": "/Getconfig?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36",
  5400. "data": "POST /Getconfig?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nContent-Type: application/x-www-form-urlencoded\r\nHost: wan.ludashi.com\r\nContent-Length: 91\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n\n\t\"protocol\":\t\"1.0\",\n\t\"version\":\t\"1.2.6.1830\",\n\t\"channel\":\t\"ludashiembed__buychannel_18\"\n",
  5401. "port": 80
  5402.  
  5403.  
  5404. "count": 1,
  5405. "body": "",
  5406. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=finish_close",
  5407. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5408. "method": "GET",
  5409. "host": "s.ludashi.com",
  5410. "version": "1.1",
  5411. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=finish_close",
  5412. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1060.717&type=instnew&action=finish_close HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5413. "port": 80
  5414.  
  5415.  
  5416. "count": 1,
  5417. "body": "eG+/ly+1WJxU+zHTH0vQ9hHZqxQyDXL4F2Z56HiRcUnOXZ379w+1QRRX+wszMQ3J/PfTPzHOF9hEJu3J8ZK7Rw4NsfS6fr9XZW7mbO28xyqCu4NlubKjVlVN35CwrU8EEHeULU03BZZU4+VFTL/O7WZgar10/gDCsuon4AkUn4CvBW8ayjIUMNFPsieWExCV2p77KRNA/sOuYR+sX10exFUNuGbj/LlIN07PWiVFwKA=",
  5418. "uri": "http://wan.ludashi.com/ajax/Getdetailbygamename?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36",
  5419. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5420. "method": "POST",
  5421. "host": "wan.ludashi.com",
  5422. "version": "1.1",
  5423. "path": "/ajax/Getdetailbygamename?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36",
  5424. "data": "POST /ajax/Getdetailbygamename?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nContent-Type: application/x-www-form-urlencoded\r\nHost: wan.ludashi.com\r\nContent-Length: 236\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\neG+/ly+1WJxU+zHTH0vQ9hHZqxQyDXL4F2Z56HiRcUnOXZ379w+1QRRX+wszMQ3J/PfTPzHOF9hEJu3J8ZK7Rw4NsfS6fr9XZW7mbO28xyqCu4NlubKjVlVN35CwrU8EEHeULU03BZZU4+VFTL/O7WZgar10/gDCsuon4AkUn4CvBW8ayjIUMNFPsieWExCV2p77KRNA/sOuYR+sX10exFUNuGbj/LlIN07PWiVFwKA=",
  5425. "port": 80
  5426.  
  5427.  
  5428. "count": 1,
  5429. "body": "",
  5430. "uri": "http://wan.ludashi.com/cms/app/message.php?version=1.2.6.1830&channel=ludashiembed__buychannel_18",
  5431. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5432. "method": "GET",
  5433. "host": "wan.ludashi.com",
  5434. "version": "1.1",
  5435. "path": "/cms/app/message.php?version=1.2.6.1830&channel=ludashiembed__buychannel_18",
  5436. "data": "GET /cms/app/message.php?version=1.2.6.1830&channel=ludashiembed__buychannel_18 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: wan.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5437. "port": 80
  5438.  
  5439.  
  5440. "count": 1,
  5441. "body": "",
  5442. "uri": "http://s.ludashi.com/wan?type=show&action=ludashiembed__buychannelall_inst_run&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=012df18f03d9ef5ee28e9292b68d9ed5&from=ludashiembed__buychannelall_inst_run&forcetick=34797137",
  5443. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5444. "method": "GET",
  5445. "host": "s.ludashi.com",
  5446. "version": "1.1",
  5447. "path": "/wan?type=show&action=ludashiembed__buychannelall_inst_run&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=012df18f03d9ef5ee28e9292b68d9ed5&from=ludashiembed__buychannelall_inst_run&forcetick=34797137",
  5448. "data": "GET /wan?type=show&action=ludashiembed__buychannelall_inst_run&channel=ludashiembed__buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&uid=d&appver=1.2.6.1830&modver=1.2.6.1830&sign=012df18f03d9ef5ee28e9292b68d9ed5&from=ludashiembed__buychannelall_inst_run&forcetick=34797137 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5449. "port": 80
  5450.  
  5451.  
  5452. "count": 1,
  5453. "body": "",
  5454. "uri": "http://wan.ludashi.com/ajax/Getnewpush?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36&gameid=ms&from=ludashiembed__buychannelall_inst_run",
  5455. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5456. "method": "GET",
  5457. "host": "wan.ludashi.com",
  5458. "version": "1.1",
  5459. "path": "/ajax/Getnewpush?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36&gameid=ms&from=ludashiembed__buychannelall_inst_run",
  5460. "data": "GET /ajax/Getnewpush?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36&gameid=ms&from=ludashiembed__buychannelall_inst_run HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: wan.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5461. "port": 80
  5462.  
  5463.  
  5464. "count": 1,
  5465. "body": "\n\t\"protocol\":\t\"1.0\",\n\t\"version\":\t\"1.2.6.1830\",\n\t\"channel\":\t\"ludashiembed__buychannel_18\"\n",
  5466. "uri": "http://wan.ludashi.com/getconfig/Jsbyversionandchannel?version=1.2.6.1830&insttime=2019-07-20%2010:28:36",
  5467. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5468. "method": "POST",
  5469. "host": "wan.ludashi.com",
  5470. "version": "1.1",
  5471. "path": "/getconfig/Jsbyversionandchannel?version=1.2.6.1830&insttime=2019-07-20%2010:28:36",
  5472. "data": "POST /getconfig/Jsbyversionandchannel?version=1.2.6.1830&insttime=2019-07-20%2010:28:36 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nContent-Type: application/x-www-form-urlencoded\r\nHost: wan.ludashi.com\r\nContent-Length: 91\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n\n\t\"protocol\":\t\"1.0\",\n\t\"version\":\t\"1.2.6.1830\",\n\t\"channel\":\t\"ludashiembed__buychannel_18\"\n",
  5473. "port": 80
  5474.  
  5475.  
  5476. "count": 1,
  5477. "body": "\n\t\"protocol\":\t\"1.0\",\n\t\"version\":\t\"1.2.6.1830\",\n\t\"channel\":\t\"ludashiembed__buychannel_18\"\n",
  5478. "uri": "http://wan.ludashi.com/getconfig/urlblack?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36",
  5479. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5480. "method": "POST",
  5481. "host": "wan.ludashi.com",
  5482. "version": "1.1",
  5483. "path": "/getconfig/urlblack?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36",
  5484. "data": "POST /getconfig/urlblack?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nContent-Type: application/x-www-form-urlencoded\r\nHost: wan.ludashi.com\r\nContent-Length: 91\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n\n\t\"protocol\":\t\"1.0\",\n\t\"version\":\t\"1.2.6.1830\",\n\t\"channel\":\t\"ludashiembed__buychannel_18\"\n",
  5485. "port": 80
  5486.  
  5487.  
  5488. "count": 1,
  5489. "body": "",
  5490. "uri": "http://wan.ludashi.com/pageV2/index?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36",
  5491. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5492. "method": "GET",
  5493. "host": "wan.ludashi.com",
  5494. "version": "1.1",
  5495. "path": "/pageV2/index?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36",
  5496. "data": "GET /pageV2/index?version=1.2.6.1830&channel=ludashiembed__buychannel_18&insttime=2019-07-20%2010:28:36 HTTP/1.1\r\nAccept: */*\r\nAccept-Language: en-us\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: wan.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5497. "port": 80
  5498.  
  5499.  
  5500. "count": 1,
  5501. "body": "",
  5502. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=trayrun",
  5503. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5504. "method": "GET",
  5505. "host": "s.ludashi.com",
  5506. "version": "1.1",
  5507. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=trayrun",
  5508. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=trayrun HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5509. "port": 80
  5510.  
  5511.  
  5512. "count": 1,
  5513. "body": "",
  5514. "uri": "http://wan.ludashi.com/account/jump?channel=ludashiembed__buychannel_18&from=ldsxbtx_ms&game=ms&server=1318&version=1.2.6.1830",
  5515. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5516. "method": "GET",
  5517. "host": "wan.ludashi.com",
  5518. "version": "1.1",
  5519. "path": "/account/jump?channel=ludashiembed__buychannel_18&from=ldsxbtx_ms&game=ms&server=1318&version=1.2.6.1830",
  5520. "data": "GET /account/jump?channel=ludashiembed__buychannel_18&from=ldsxbtx_ms&game=ms&server=1318&version=1.2.6.1830 HTTP/1.1\r\nAccept: */*\r\nAccept-Language: en-us\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: wan.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  5521. "port": 80
  5522.  
  5523.  
  5524. "count": 1,
  5525. "body": "",
  5526. "uri": "http://p10.qhimg.com/t0111d422c70cdbbc8c.png",
  5527. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5528. "method": "GET",
  5529. "host": "p10.qhimg.com",
  5530. "version": "1.1",
  5531. "path": "/t0111d422c70cdbbc8c.png",
  5532. "data": "GET /t0111d422c70cdbbc8c.png HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: p10.qhimg.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5533. "port": 80
  5534.  
  5535.  
  5536. "count": 2,
  5537. "body": "",
  5538. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.5019.1005.326&type=computerzservice&action=run",
  5539. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5540. "method": "GET",
  5541. "host": "s.ludashi.com",
  5542. "version": "1.1",
  5543. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.5019.1005.326&type=computerzservice&action=run",
  5544. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.5019.1005.326&type=computerzservice&action=run HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5545. "port": 80
  5546.  
  5547.  
  5548. "count": 1,
  5549. "body": "",
  5550. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAilokbNS1yMg9cCtLurU0k%3D",
  5551. "user-agent": "Microsoft-CryptoAPI/6.1",
  5552. "method": "GET",
  5553. "host": "ocsp.digicert.com",
  5554. "version": "1.1",
  5555. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAilokbNS1yMg9cCtLurU0k%3D",
  5556. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAilokbNS1yMg9cCtLurU0k%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  5557. "port": 80
  5558.  
  5559.  
  5560. "count": 1,
  5561. "body": "",
  5562. "uri": "http://status.rapidssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRhhZrQET0hvbSHUJmNfBKqR%2FiT7wQUU8oXWfxrwAMhLxqu5KqoHIJW2nUCEAdsKEeZF4BydNE94gKO3oA%3D",
  5563. "user-agent": "Microsoft-CryptoAPI/6.1",
  5564. "method": "GET",
  5565. "host": "status.rapidssl.com",
  5566. "version": "1.1",
  5567. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRhhZrQET0hvbSHUJmNfBKqR%2FiT7wQUU8oXWfxrwAMhLxqu5KqoHIJW2nUCEAdsKEeZF4BydNE94gKO3oA%3D",
  5568. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRhhZrQET0hvbSHUJmNfBKqR%2FiT7wQUU8oXWfxrwAMhLxqu5KqoHIJW2nUCEAdsKEeZF4BydNE94gKO3oA%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: status.rapidssl.com\r\n\r\n",
  5569. "port": 80
  5570.  
  5571.  
  5572. "count": 1,
  5573. "body": "",
  5574. "uri": "http://cdp.rapidssl.com/RapidSSLRSACA2018.crl",
  5575. "user-agent": "Microsoft-CryptoAPI/6.1",
  5576. "method": "GET",
  5577. "host": "cdp.rapidssl.com",
  5578. "version": "1.1",
  5579. "path": "/RapidSSLRSACA2018.crl",
  5580. "data": "GET /RapidSSLRSACA2018.crl HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: cdp.rapidssl.com\r\n\r\n",
  5581. "port": 80
  5582.  
  5583.  
  5584. "count": 1,
  5585. "body": "",
  5586. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=suspendrun",
  5587. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5588. "method": "GET",
  5589. "host": "s.ludashi.com",
  5590. "version": "1.1",
  5591. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=suspendrun",
  5592. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=suspendrun HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5593. "port": 80
  5594.  
  5595.  
  5596. "count": 1,
  5597. "body": "",
  5598. "uri": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1030&type=pop&action=start&app=ludashi",
  5599. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5600. "method": "GET",
  5601. "host": "s.ludashi.com",
  5602. "version": "1.1",
  5603. "path": "/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1030&type=pop&action=start&app=ludashi",
  5604. "data": "GET /url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1030&type=pop&action=start&app=ludashi HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5605. "port": 80
  5606.  
  5607.  
  5608. "count": 1,
  5609. "body": "",
  5610. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1005.509&type=suspend&action=show",
  5611. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5612. "method": "GET",
  5613. "host": "s.ludashi.com",
  5614. "version": "1.1",
  5615. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1005.509&type=suspend&action=show",
  5616. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1005.509&type=suspend&action=show HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5617. "port": 80
  5618.  
  5619.  
  5620. "count": 1,
  5621. "body": "",
  5622. "uri": "http://cdn-file.ludashi.com/cms/project_16/cfg_center/mod_list.js?t=2019072010:25",
  5623. "user-agent": "",
  5624. "method": "GET",
  5625. "host": "cdn-file.ludashi.com",
  5626. "version": "1.1",
  5627. "path": "/cms/project_16/cfg_center/mod_list.js?t=2019072010:25",
  5628. "data": "GET /cms/project_16/cfg_center/mod_list.js?t=2019072010:25 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5629. "port": 80
  5630.  
  5631.  
  5632. "count": 1,
  5633. "body": "",
  5634. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=boot&action=tray_actived",
  5635. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5636. "method": "GET",
  5637. "host": "s.ludashi.com",
  5638. "version": "1.1",
  5639. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=boot&action=tray_actived",
  5640. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=boot&action=tray_actived HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5641. "port": 80
  5642.  
  5643.  
  5644. "count": 1,
  5645. "body": "",
  5646. "uri": "http://sf.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CECYnnw8vEZcNzPY%2Buojy1MQ%3D",
  5647. "user-agent": "Microsoft-CryptoAPI/6.1",
  5648. "method": "GET",
  5649. "host": "sf.symcd.com",
  5650. "version": "1.1",
  5651. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CECYnnw8vEZcNzPY%2Buojy1MQ%3D",
  5652. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CECYnnw8vEZcNzPY%2Buojy1MQ%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: sf.symcd.com\r\n\r\n",
  5653. "port": 80
  5654.  
  5655.  
  5656. "count": 1,
  5657. "body": "",
  5658. "uri": "http://wan.ludashi.com/account?game=ms&channel=ludashiembed__buychannel_18&from=ldsxbtx_ms",
  5659. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5660. "method": "GET",
  5661. "host": "wan.ludashi.com",
  5662. "version": "1.1",
  5663. "path": "/account?game=ms&channel=ludashiembed__buychannel_18&from=ldsxbtx_ms",
  5664. "data": "GET /account?game=ms&channel=ludashiembed__buychannel_18&from=ldsxbtx_ms HTTP/1.1\r\nAccept: application/x-ms-application, image/jpeg, application/xaml+xml, image/gif, image/pjpeg, application/x-ms-xbap, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*\r\nAccept-Language: en-US\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: wan.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5665. "port": 80
  5666.  
  5667.  
  5668. "count": 1,
  5669. "body": "",
  5670. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=from_user",
  5671. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5672. "method": "GET",
  5673. "host": "s.ludashi.com",
  5674. "version": "1.1",
  5675. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=from_user",
  5676. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=operate&action=from_user HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5677. "port": 80
  5678.  
  5679.  
  5680. "count": 1,
  5681. "body": "",
  5682. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=hpl&action=qh_app0_lds_hp0",
  5683. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5684. "method": "GET",
  5685. "host": "s.ludashi.com",
  5686. "version": "1.1",
  5687. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=hpl&action=qh_app0_lds_hp0",
  5688. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=hpl&action=qh_app0_lds_hp0 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5689. "port": 80
  5690.  
  5691.  
  5692. "count": 1,
  5693. "body": "",
  5694. "uri": "http://www.ludashi.com/cms/pc_mobile/news.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702",
  5695. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5696. "method": "GET",
  5697. "host": "www.ludashi.com",
  5698. "version": "1.1",
  5699. "path": "/cms/pc_mobile/news.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702",
  5700. "data": "GET /cms/pc_mobile/news.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: www.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5701. "port": 80
  5702.  
  5703.  
  5704. "count": 1,
  5705. "body": "",
  5706. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=trayrun&action=trayinfo_1_1_0",
  5707. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5708. "method": "GET",
  5709. "host": "s.ludashi.com",
  5710. "version": "1.1",
  5711. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=trayrun&action=trayinfo_1_1_0",
  5712. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=trayrun&action=trayinfo_1_1_0 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5713. "port": 80
  5714.  
  5715.  
  5716. "count": 1,
  5717. "body": "",
  5718. "uri": "http://www.ludashi.com/cms/pcDaoliang/mergeAll.php?from=ludashi&pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=1.0.1.1035&modver=1.0.1.1035&mod=pc_pop_outside",
  5719. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5720. "method": "GET",
  5721. "host": "www.ludashi.com",
  5722. "version": "1.1",
  5723. "path": "/cms/pcDaoliang/mergeAll.php?from=ludashi&pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=1.0.1.1035&modver=1.0.1.1035&mod=pc_pop_outside",
  5724. "data": "GET /cms/pcDaoliang/mergeAll.php?from=ludashi&pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=1.0.1.1035&modver=1.0.1.1035&mod=pc_pop_outside HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: www.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5725. "port": 80
  5726.  
  5727.  
  5728. "count": 2,
  5729. "body": "",
  5730. "uri": "http://cdn-file.ludashi.com/pc/device/deviceid.ini",
  5731. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5732. "method": "GET",
  5733. "host": "cdn-file.ludashi.com",
  5734. "version": "1.1",
  5735. "path": "/pc/device/deviceid.ini",
  5736. "data": "GET /pc/device/deviceid.ini HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5737. "port": 80
  5738.  
  5739.  
  5740. "count": 1,
  5741. "body": "",
  5742. "uri": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1005.505&type=wd&action=reg_succ&app=ludashi",
  5743. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5744. "method": "GET",
  5745. "host": "s.ludashi.com",
  5746. "version": "1.1",
  5747. "path": "/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1005.505&type=wd&action=reg_succ&app=ludashi",
  5748. "data": "GET /url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1005.505&type=wd&action=reg_succ&app=ludashi HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5749. "port": 80
  5750.  
  5751.  
  5752. "count": 1,
  5753. "body": "",
  5754. "uri": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=screen_resolution_change&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1",
  5755. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5756. "method": "GET",
  5757. "host": "s.ludashi.com",
  5758. "version": "1.1",
  5759. "path": "/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=screen_resolution_change&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1",
  5760. "data": "GET /url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=screen_resolution_change&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5761. "port": 80
  5762.  
  5763.  
  5764. "count": 1,
  5765. "body": "",
  5766. "uri": "http://s.ludashi.com/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1005.505&type=wd&action=start&app=ludashi",
  5767. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5768. "method": "GET",
  5769. "host": "s.ludashi.com",
  5770. "version": "1.1",
  5771. "path": "/url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1005.505&type=wd&action=start&app=ludashi",
  5772. "data": "GET /url3?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1005.505&type=wd&action=start&app=ludashi HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5773. "port": 80
  5774.  
  5775.  
  5776. "count": 1,
  5777. "body": "",
  5778. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=band&action=bandinfo_0_1_0_1",
  5779. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5780. "method": "GET",
  5781. "host": "s.ludashi.com",
  5782. "version": "1.1",
  5783. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=band&action=bandinfo_0_1_0_1",
  5784. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=band&action=bandinfo_0_1_0_1 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5785. "port": 80
  5786.  
  5787.  
  5788. "count": 1,
  5789. "body": "",
  5790. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=band&action=succ_vista_x64",
  5791. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5792. "method": "GET",
  5793. "host": "s.ludashi.com",
  5794. "version": "1.1",
  5795. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=band&action=succ_vista_x64",
  5796. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=band&action=succ_vista_x64 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5797. "port": 80
  5798.  
  5799.  
  5800. "count": 1,
  5801. "body": "",
  5802. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=tray&action=bandrun_succ",
  5803. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5804. "method": "GET",
  5805. "host": "s.ludashi.com",
  5806. "version": "1.1",
  5807. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=tray&action=bandrun_succ",
  5808. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=tray&action=bandrun_succ HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5809. "port": 80
  5810.  
  5811.  
  5812. "count": 1,
  5813. "body": "",
  5814. "uri": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_init&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1",
  5815. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5816. "method": "GET",
  5817. "host": "s.ludashi.com",
  5818. "version": "1.1",
  5819. "path": "/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_init&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1",
  5820. "data": "GET /url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_init&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5821. "port": 80
  5822.  
  5823.  
  5824. "count": 1,
  5825. "body": "",
  5826. "uri": "http://cdn-wan.ludashi.com/assets/supercss/login.css?v=20181120",
  5827. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5828. "method": "GET",
  5829. "host": "cdn-wan.ludashi.com",
  5830. "version": "1.1",
  5831. "path": "/assets/supercss/login.css?v=20181120",
  5832. "data": "GET /assets/supercss/login.css?v=20181120 HTTP/1.1\r\nAccept: */*\r\nReferer: http://wan.ludashi.com/account?game=ms&channel=ludashiembed__buychannel_18&from=ldsxbtx_ms\r\nAccept-Language: en-US\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: cdn-wan.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5833. "port": 80
  5834.  
  5835.  
  5836. "count": 5,
  5837. "body": "",
  5838. "uri": "http://cdn-file.ludashi.com/bizhi/recommend.dat?t=10",
  5839. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5840. "method": "GET",
  5841. "host": "cdn-file.ludashi.com",
  5842. "version": "1.1",
  5843. "path": "/bizhi/recommend.dat?t=10",
  5844. "data": "GET /bizhi/recommend.dat?t=10 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5845. "port": 80
  5846.  
  5847.  
  5848. "count": 1,
  5849. "body": "",
  5850. "uri": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_start&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1",
  5851. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5852. "method": "GET",
  5853. "host": "s.ludashi.com",
  5854. "version": "1.1",
  5855. "path": "/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_start&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1",
  5856. "data": "GET /url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_start&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5857. "port": 80
  5858.  
  5859.  
  5860. "count": 1,
  5861. "body": "",
  5862. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=active",
  5863. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5864. "method": "GET",
  5865. "host": "s.ludashi.com",
  5866. "version": "1.1",
  5867. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=active",
  5868. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=active HTTP/1.1\r\nAccept: */*\r\nUA-CPU: AMD64\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5869. "port": 80
  5870.  
  5871.  
  5872. "count": 1,
  5873. "body": "",
  5874. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=tray_1",
  5875. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5876. "method": "GET",
  5877. "host": "s.ludashi.com",
  5878. "version": "1.1",
  5879. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=tray_1",
  5880. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=tray_1 HTTP/1.1\r\nAccept: */*\r\nUA-CPU: AMD64\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5881. "port": 80
  5882.  
  5883.  
  5884. "count": 1,
  5885. "body": "",
  5886. "uri": "http://www.ludashi.com/cms/pc/tray_switch.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702",
  5887. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5888. "method": "GET",
  5889. "host": "www.ludashi.com",
  5890. "version": "1.1",
  5891. "path": "/cms/pc/tray_switch.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702",
  5892. "data": "GET /cms/pc/tray_switch.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: www.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5893. "port": 80
  5894.  
  5895.  
  5896. "count": 1,
  5897. "body": "",
  5898. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=trayinfo_1_1_0",
  5899. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5900. "method": "GET",
  5901. "host": "s.ludashi.com",
  5902. "version": "1.1",
  5903. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=trayinfo_1_1_0",
  5904. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.2.0.1070&type=bandinit&action=trayinfo_1_1_0 HTTP/1.1\r\nAccept: */*\r\nUA-CPU: AMD64\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5905. "port": 80
  5906.  
  5907.  
  5908. "count": 1,
  5909. "body": "",
  5910. "uri": "http://media.ludashi.com/n/mini?pid=buychannel_18&appver=5.1019.1060.717&modver=1.5019.1015.617&from=ludashi&iever=ie8&os=win7&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&manual=0&showpro=&awake=0&screentype=0&screesize=1920_962&instdate=2019-07-20%2010:28:36&atdate=&m_ver=3.0.0.1085",
  5911. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5912. "method": "GET",
  5913. "host": "media.ludashi.com",
  5914. "version": "1.1",
  5915. "path": "/n/mini?pid=buychannel_18&appver=5.1019.1060.717&modver=1.5019.1015.617&from=ludashi&iever=ie8&os=win7&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&manual=0&showpro=&awake=0&screentype=0&screesize=1920_962&instdate=2019-07-20%2010:28:36&atdate=&m_ver=3.0.0.1085",
  5916. "data": "GET /n/mini?pid=buychannel_18&appver=5.1019.1060.717&modver=1.5019.1015.617&from=ludashi&iever=ie8&os=win7&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&manual=0&showpro=&awake=0&screentype=0&screesize=1920_962&instdate=2019-07-20%2010:28:36&atdate=&m_ver=3.0.0.1085 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: media.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5917. "port": 80
  5918.  
  5919.  
  5920. "count": 1,
  5921. "body": "",
  5922. "uri": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_regpopmgr_succ&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1",
  5923. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  5924. "method": "GET",
  5925. "host": "s.ludashi.com",
  5926. "version": "1.1",
  5927. "path": "/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_regpopmgr_succ&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1",
  5928. "data": "GET /url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_regpopmgr_succ&ex4=a07e4d85e0340169b0718f4436b93b54&ex5=1 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  5929. "port": 80
  5930.  
  5931.  
  5932. "count": 2,
  5933. "body": "",
  5934. "uri": "http://cdn-file.ludashi.com/pc/common/cdn_common.json?t=201907201028",
  5935. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5936. "method": "GET",
  5937. "host": "cdn-file.ludashi.com",
  5938. "version": "1.1",
  5939. "path": "/pc/common/cdn_common.json?t=201907201028",
  5940. "data": "GET /pc/common/cdn_common.json?t=201907201028 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5941. "port": 80
  5942.  
  5943.  
  5944. "count": 1,
  5945. "body": "",
  5946. "uri": "http://s.ludashi.com/bizhi?pid=ludashi&mid=db2c71648b5a939e38cf679b921b03dc&appver=&modver=1.0.0.85&type=ludashi&action=navguide_show",
  5947. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5948. "method": "GET",
  5949. "host": "s.ludashi.com",
  5950. "version": "1.1",
  5951. "path": "/bizhi?pid=ludashi&mid=db2c71648b5a939e38cf679b921b03dc&appver=&modver=1.0.0.85&type=ludashi&action=navguide_show",
  5952. "data": "GET /bizhi?pid=ludashi&mid=db2c71648b5a939e38cf679b921b03dc&appver=&modver=1.0.0.85&type=ludashi&action=navguide_show HTTP/1.1\r\nAccept: */*\r\nConnection: Close\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: s.ludashi.com\r\nCache-Control: no-cache\r\n\r\n",
  5953. "port": 80
  5954.  
  5955.  
  5956. "count": 1,
  5957. "body": "-----------------------------1qaz34889410\r\nContent-Disposition: form-data; name=\"data\"\r\n\r\n68vGuxujIEQF9raq0hQfLcJERaVPsKJLtd8jla5rY2AbDNI86r30YtQ/qKDiol6pXawNJiusLtC2OGUeSp0bgqiZurbOa/rJ2iHU7bTzwtAI9u9gnCx4uvzHpU6gVXNQ3GMkc9eQzj9VKYDNttZMi2mX9UFB+dIFROUMcvLkcyVyWqLSUK77ApY7dQQGI0RJsXoqfMMEX6BkMF8WiKlpzpcQXeuu03qCG9yJ1xaU/ZMS4cSXke/G0ra83qMHGA+H0mm9llMihn12wEhanCN8I2CyXqx87QFr\r\n-----------------------------1qaz34889410--\r\n",
  5958. "uri": "http://l.public.ludashi.com/pc/updata/diskdump?ver=1002",
  5959. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5960. "method": "POST",
  5961. "host": "l.public.ludashi.com",
  5962. "version": "1.1",
  5963. "path": "/pc/updata/diskdump?ver=1002",
  5964. "data": "POST /pc/updata/diskdump?ver=1002 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nContent-Type: multipart/form-data; boundary=---------------------------1qaz34889410\r\nHost: l.public.ludashi.com\r\nContent-Length: 425\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n-----------------------------1qaz34889410\r\nContent-Disposition: form-data; name=\"data\"\r\n\r\n68vGuxujIEQF9raq0hQfLcJERaVPsKJLtd8jla5rY2AbDNI86r30YtQ/qKDiol6pXawNJiusLtC2OGUeSp0bgqiZurbOa/rJ2iHU7bTzwtAI9u9gnCx4uvzHpU6gVXNQ3GMkc9eQzj9VKYDNttZMi2mX9UFB+dIFROUMcvLkcyVyWqLSUK77ApY7dQQGI0RJsXoqfMMEX6BkMF8WiKlpzpcQXeuu03qCG9yJ1xaU/ZMS4cSXke/G0ra83qMHGA+H0mm9llMihn12wEhanCN8I2CyXqx87QFr\r\n-----------------------------1qaz34889410--\r\n",
  5965. "port": 80
  5966.  
  5967.  
  5968. "count": 1,
  5969. "body": "",
  5970. "uri": "http://cdn-file.ludashi.com/bizhi/navextend.dat",
  5971. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5972. "method": "GET",
  5973. "host": "cdn-file.ludashi.com",
  5974. "version": "1.1",
  5975. "path": "/bizhi/navextend.dat",
  5976. "data": "GET /bizhi/navextend.dat HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  5977. "port": 80
  5978.  
  5979.  
  5980. "count": 1,
  5981. "body": "",
  5982. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D",
  5983. "user-agent": "Microsoft-CryptoAPI/6.1",
  5984. "method": "GET",
  5985. "host": "ocsp.digicert.com",
  5986. "version": "1.1",
  5987. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D",
  5988. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D HTTP/1.1\r\nCache-Control: max-age = 135176\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 05:30:18 GMT\r\nIf-None-Match: \"5cecc76a-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  5989. "port": 80
  5990.  
  5991.  
  5992. "count": 1,
  5993. "body": "",
  5994. "uri": "http://cdn-file.ludashi.com/bizhi/ico/hao.360.cn.ico",
  5995. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  5996. "method": "GET",
  5997. "host": "cdn-file.ludashi.com",
  5998. "version": "1.1",
  5999. "path": "/bizhi/ico/hao.360.cn.ico",
  6000. "data": "GET /bizhi/ico/hao.360.cn.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6001. "port": 80
  6002.  
  6003.  
  6004. "count": 1,
  6005. "body": "",
  6006. "uri": "http://cdn-file.ludashi.com/bizhi/navspread.dat",
  6007. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6008. "method": "GET",
  6009. "host": "cdn-file.ludashi.com",
  6010. "version": "1.1",
  6011. "path": "/bizhi/navspread.dat",
  6012. "data": "GET /bizhi/navspread.dat HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6013. "port": 80
  6014.  
  6015.  
  6016. "count": 1,
  6017. "body": "",
  6018. "uri": "http://cdn-img.ludashi.com/a/201812/06/5c08c9afc9173.ico",
  6019. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6020. "method": "GET",
  6021. "host": "cdn-img.ludashi.com",
  6022. "version": "1.1",
  6023. "path": "/a/201812/06/5c08c9afc9173.ico",
  6024. "data": "GET /a/201812/06/5c08c9afc9173.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-img.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6025. "port": 80
  6026.  
  6027.  
  6028. "count": 1,
  6029. "body": "",
  6030. "uri": "http://cdn-file.ludashi.com/bizhi/ico/www.baidu.com.ico",
  6031. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6032. "method": "GET",
  6033. "host": "cdn-file.ludashi.com",
  6034. "version": "1.1",
  6035. "path": "/bizhi/ico/www.baidu.com.ico",
  6036. "data": "GET /bizhi/ico/www.baidu.com.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6037. "port": 80
  6038.  
  6039.  
  6040. "count": 2,
  6041. "body": "",
  6042. "uri": "http://cdn-file.ludashi.com/bizhi/ico/wan.ludashi.com.ico",
  6043. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6044. "method": "GET",
  6045. "host": "cdn-file.ludashi.com",
  6046. "version": "1.1",
  6047. "path": "/bizhi/ico/wan.ludashi.com.ico",
  6048. "data": "GET /bizhi/ico/wan.ludashi.com.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6049. "port": 80
  6050.  
  6051.  
  6052. "count": 1,
  6053. "body": "",
  6054. "uri": "http://cdn-file-ssl-pc.ludashi.com/bizhi/ico/xiaoshuo.png",
  6055. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6056. "method": "GET",
  6057. "host": "cdn-file-ssl-pc.ludashi.com",
  6058. "version": "1.1",
  6059. "path": "/bizhi/ico/xiaoshuo.png",
  6060. "data": "GET /bizhi/ico/xiaoshuo.png HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file-ssl-pc.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6061. "port": 80
  6062.  
  6063.  
  6064. "count": 1,
  6065. "body": "",
  6066. "uri": "http://cdn-file.ludashi.com/bizhi/ico/www.tmall.com.ico",
  6067. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6068. "method": "GET",
  6069. "host": "cdn-file.ludashi.com",
  6070. "version": "1.1",
  6071. "path": "/bizhi/ico/www.tmall.com.ico",
  6072. "data": "GET /bizhi/ico/www.tmall.com.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6073. "port": 80
  6074.  
  6075.  
  6076. "count": 1,
  6077. "body": "",
  6078. "uri": "http://cdn-file.ludashi.com/bizhi/ico/www.taobao.com.ico",
  6079. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6080. "method": "GET",
  6081. "host": "cdn-file.ludashi.com",
  6082. "version": "1.1",
  6083. "path": "/bizhi/ico/www.taobao.com.ico",
  6084. "data": "GET /bizhi/ico/www.taobao.com.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6085. "port": 80
  6086.  
  6087.  
  6088. "count": 1,
  6089. "body": "",
  6090. "uri": "http://cdn-file.ludashi.com/bizhi/ico/www.jd.com.ico",
  6091. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6092. "method": "GET",
  6093. "host": "cdn-file.ludashi.com",
  6094. "version": "1.1",
  6095. "path": "/bizhi/ico/www.jd.com.ico",
  6096. "data": "GET /bizhi/ico/www.jd.com.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6097. "port": 80
  6098.  
  6099.  
  6100. "count": 1,
  6101. "body": "",
  6102. "uri": "http://cdn-file.ludashi.com/bizhi/ico/weibo.com.ico",
  6103. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6104. "method": "GET",
  6105. "host": "cdn-file.ludashi.com",
  6106. "version": "1.1",
  6107. "path": "/bizhi/ico/weibo.com.ico",
  6108. "data": "GET /bizhi/ico/weibo.com.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6109. "port": 80
  6110.  
  6111.  
  6112. "count": 2,
  6113. "body": "",
  6114. "uri": "http://cdn-file.ludashi.com/bizhi/ico/www.sina.com.cn.ico",
  6115. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6116. "method": "GET",
  6117. "host": "cdn-file.ludashi.com",
  6118. "version": "1.1",
  6119. "path": "/bizhi/ico/www.sina.com.cn.ico",
  6120. "data": "GET /bizhi/ico/www.sina.com.cn.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6121. "port": 80
  6122.  
  6123.  
  6124. "count": 1,
  6125. "body": "",
  6126. "uri": "http://weibo.com/",
  6127. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6128. "method": "GET",
  6129. "host": "weibo.com",
  6130. "version": "1.1",
  6131. "path": "/",
  6132. "data": "GET / HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: weibo.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6133. "port": 80
  6134.  
  6135.  
  6136. "count": 1,
  6137. "body": "",
  6138. "uri": "http://cdn-file.ludashi.com/bizhi/ico/www.qunar.com.ico",
  6139. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6140. "method": "GET",
  6141. "host": "cdn-file.ludashi.com",
  6142. "version": "1.1",
  6143. "path": "/bizhi/ico/www.qunar.com.ico",
  6144. "data": "GET /bizhi/ico/www.qunar.com.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6145. "port": 80
  6146.  
  6147.  
  6148. "count": 1,
  6149. "body": "",
  6150. "uri": "http://cdn-file.ludashi.com/bizhi/ico/www.iqiyi.com.ico",
  6151. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6152. "method": "GET",
  6153. "host": "cdn-file.ludashi.com",
  6154. "version": "1.1",
  6155. "path": "/bizhi/ico/www.iqiyi.com.ico",
  6156. "data": "GET /bizhi/ico/www.iqiyi.com.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6157. "port": 80
  6158.  
  6159.  
  6160. "count": 1,
  6161. "body": "",
  6162. "uri": "http://cdn-file.ludashi.com/bizhi/ico/www.qq.com.ico",
  6163. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6164. "method": "GET",
  6165. "host": "cdn-file.ludashi.com",
  6166. "version": "1.1",
  6167. "path": "/bizhi/ico/www.qq.com.ico",
  6168. "data": "GET /bizhi/ico/www.qq.com.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6169. "port": 80
  6170.  
  6171.  
  6172. "count": 1,
  6173. "body": "",
  6174. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D",
  6175. "user-agent": "Microsoft-CryptoAPI/6.1",
  6176. "method": "GET",
  6177. "host": "ocsp.digicert.com",
  6178. "version": "1.1",
  6179. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D",
  6180. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D HTTP/1.1\r\nCache-Control: max-age = 142986\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 07:40:28 GMT\r\nIf-None-Match: \"5cece5ec-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  6181. "port": 80
  6182.  
  6183.  
  6184. "count": 1,
  6185. "body": "",
  6186. "uri": "http://cdn-file.ludashi.com/bizhi/ico/58.com.ico",
  6187. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6188. "method": "GET",
  6189. "host": "cdn-file.ludashi.com",
  6190. "version": "1.1",
  6191. "path": "/bizhi/ico/58.com.ico",
  6192. "data": "GET /bizhi/ico/58.com.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6193. "port": 80
  6194.  
  6195.  
  6196. "count": 1,
  6197. "body": "",
  6198. "uri": "http://weibo.com/us",
  6199. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6200. "method": "GET",
  6201. "host": "weibo.com",
  6202. "version": "1.1",
  6203. "path": "/us",
  6204. "data": "GET /us HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\nHost: weibo.com\r\n\r\n",
  6205. "port": 80
  6206.  
  6207.  
  6208. "count": 1,
  6209. "body": "",
  6210. "uri": "http://www.baidu.com/favicon.ico",
  6211. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6212. "method": "GET",
  6213. "host": "www.baidu.com",
  6214. "version": "1.1",
  6215. "path": "/favicon.ico",
  6216. "data": "GET /favicon.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: www.baidu.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6217. "port": 80
  6218.  
  6219.  
  6220. "count": 1,
  6221. "body": "",
  6222. "uri": "http://weibo.com/favicon.ico",
  6223. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6224. "method": "GET",
  6225. "host": "weibo.com",
  6226. "version": "1.1",
  6227. "path": "/favicon.ico",
  6228. "data": "GET /favicon.ico HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: weibo.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6229. "port": 80
  6230.  
  6231.  
  6232. "count": 1,
  6233. "body": "",
  6234. "uri": "http://www.ludashi.com/api/ppwin/params.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702&si=0",
  6235. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6236. "method": "GET",
  6237. "host": "www.ludashi.com",
  6238. "version": "1.1",
  6239. "path": "/api/ppwin/params.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702&si=0",
  6240. "data": "GET /api/ppwin/params.php?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&appver=5.1019.1060.717&modver=5.1019.1030.702&si=0 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: www.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6241. "port": 80
  6242.  
  6243.  
  6244. "count": 2,
  6245. "body": "",
  6246. "uri": "http://cdn-file.ludashi.com/pc/hao/external.dat?t=10",
  6247. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6248. "method": "GET",
  6249. "host": "cdn-file.ludashi.com",
  6250. "version": "1.1",
  6251. "path": "/pc/hao/external.dat?t=10",
  6252. "data": "GET /pc/hao/external.dat?t=10 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6253. "port": 80
  6254.  
  6255.  
  6256. "count": 1,
  6257. "body": "",
  6258. "uri": "http://l3.public.ludashi.com/pc/updata/hwinfov2",
  6259. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6260. "method": "POST",
  6261. "host": "l3.public.ludashi.com",
  6262. "version": "1.1",
  6263. "path": "/pc/updata/hwinfov2",
  6264. "data": "POST /pc/updata/hwinfov2 HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nContent-Type: multipart/form-data; boundary=---------------------------1qaz35203616\r\nHost: l3.public.ludashi.com\r\nContent-Length: 6121\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6265. "port": 80
  6266.  
  6267.  
  6268. "count": 1,
  6269. "body": "",
  6270. "uri": "http://cdn-file.ludashi.com/pc/hao/invalidhp.dat",
  6271. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  6272. "method": "GET",
  6273. "host": "cdn-file.ludashi.com",
  6274. "version": "1.1",
  6275. "path": "/pc/hao/invalidhp.dat",
  6276. "data": "GET /pc/hao/invalidhp.dat HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: cdn-file.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  6277. "port": 80
  6278.  
  6279.  
  6280. "count": 1,
  6281. "body": "",
  6282. "uri": "http://update.ludashi.com/update/pc/?mid=db2c71648b5a939e38cf679b921b03dc&version=5.1019.1060.717&pid=buychannel_18&m2=b9eced82243023931d3c446e4d355e5cd84c59932bee&t=35463646",
  6283. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  6284. "method": "GET",
  6285. "host": "update.ludashi.com",
  6286. "version": "1.1",
  6287. "path": "/update/pc/?mid=db2c71648b5a939e38cf679b921b03dc&version=5.1019.1060.717&pid=buychannel_18&m2=b9eced82243023931d3c446e4d355e5cd84c59932bee&t=35463646",
  6288. "data": "GET /update/pc/?mid=db2c71648b5a939e38cf679b921b03dc&version=5.1019.1060.717&pid=buychannel_18&m2=b9eced82243023931d3c446e4d355e5cd84c59932bee&t=35463646 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: update.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  6289. "port": 80
  6290.  
  6291.  
  6292. "count": 1,
  6293. "body": "",
  6294. "uri": "http://ssl-hw-pc.ludashi.com/c/201904/01/noUpdate.cab",
  6295. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  6296. "method": "GET",
  6297. "host": "ssl-hw-pc.ludashi.com",
  6298. "version": "1.1",
  6299. "path": "/c/201904/01/noUpdate.cab",
  6300. "data": "GET /c/201904/01/noUpdate.cab HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: ssl-hw-pc.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  6301. "port": 80
  6302.  
  6303.  
  6304. "count": 1,
  6305. "body": "",
  6306. "uri": "http://s.ludashi.com/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_first_pop&ex4=a07e4d85e0340169b0718f4436b93b54&ex1=653&ex5=1",
  6307. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  6308. "method": "GET",
  6309. "host": "s.ludashi.com",
  6310. "version": "1.1",
  6311. "path": "/url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_first_pop&ex4=a07e4d85e0340169b0718f4436b93b54&ex1=653&ex5=1",
  6312. "data": "GET /url4?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=1.5019.1015.617&type=minipage&action=pull_mininews_first_pop&ex4=a07e4d85e0340169b0718f4436b93b54&ex1=653&ex5=1 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  6313. "port": 80
  6314.  
  6315.  
  6316. "count": 1,
  6317. "body": "",
  6318. "uri": "http://s.ludashi.com/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=tray&action=inst_lsp_fail",
  6319. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  6320. "method": "GET",
  6321. "host": "s.ludashi.com",
  6322. "version": "1.1",
  6323. "path": "/url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=tray&action=inst_lsp_fail",
  6324. "data": "GET /url2?pid=buychannel_18&mid=db2c71648b5a939e38cf679b921b03dc&mid2=b9eced82243023931d3c446e4d355e5cd84c59932bee&appver=5.1019.1060.717&modver=5.1019.1030.702&type=tray&action=inst_lsp_fail HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\nCookie: lds_wan_channel=ludashiembed__buychannel_18; lds_wan_from=ldsxbtx_ms; prevUrl=http%3A%2F%2Fwan.ludashi.com%2Fyeyou%2Fms%3Fsub%3Ddefault%26s%3D1318%26needfancy%3D0%26client%3D\r\n\r\n",
  6325. "port": 80
  6326.  
  6327.  
  6328. "count": 1,
  6329. "body": "",
  6330. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D",
  6331. "user-agent": "Microsoft-CryptoAPI/6.1",
  6332. "method": "GET",
  6333. "host": "ocsp.digicert.com",
  6334. "version": "1.1",
  6335. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D",
  6336. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D HTTP/1.1\r\nCache-Control: max-age = 149079\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Sat, 23 Mar 2019 11:10:47 GMT\r\nIf-None-Match: \"5c961437-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  6337. "port": 80
  6338.  
  6339.  
  6340.  
  6341. * Network Communication - SMTP:
  6342.  
  6343. * Network Communication - Hosts:
  6344.  
  6345. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment